Posts
fixing memory leaks in python services: diagnostics and dump collection
Python services under load can silently consume memory until the cgroup limit triggers an OOM kill. Without systematic dump collection and introspection, …
SSH key best practices
SSH keys are the de facto standard for authenticating to infrastructure, but poor management turns every deployment into a potential vulnerability. This note …
kubectl cheatsheet: essential commands for Kubernetes
kubectl is the primary interface to a Kubernetes cluster. This cheatheet covers routine operations — from context setup to pod debugging and namespace …
Git Tag: Marking Releases and Bookmarks in History
Git Tag: Marking Releases and Bookmarks in History Tags are Git’s mechanism for assigning meaningful labels to specific commits. Unlike branches, tags don’t …
Creating User and Role in Kubernetes and Binding Them via RBAC
In Kubernetes there are no “users” in the traditional sense — there are ServiceAccounts and certificates, bound to roles through RBAC. Without proper …
ulimit and systemd LimitNOFILE — why ulimit -n inside a unit doesn't stick
What is nofile and where it lives nofile is the maximum number of open file descriptors per process. That’s not just regular files — it covers sockets, pipes, …
Deploying with a post-receive Git Hook
Deploying through CI is great, but sometimes you just need to push code to a server with a single git push. The post-receive hook in a bare repository handles …
ThinLinc: Remote Access to Linux Desktops
ThinLinc: Remote Access to Linux Desktops In enterprise environments, remote access to Linux desktops often comes down to VNC with flaky encryption or RDP …
Sudoers: NOPASSWD Without Holes
Unrestricted NOPASSWD in sudoers is a misconfiguration that grants root access without a password, turning any user script or library vulnerability into a full …
scp — Secure Copy Over SSH
scp — a utility for copying files over SSH using the SSH protocol. It works from the terminal, requires no extra server setup — just a running sshd and working …
Docker logs and journald: choosing a logging driver
When a container crashes, logs are the first thing you need to see. docker logs looks simple, but under the hood different logging drivers are at work, and the …
curl --resolve and SNI: Testing Virtual Hosts Without /etc/hosts
When you need to test a virtual host on a specific IP but don’t want to edit /etc/hosts — whether due to permissions, conflicts with other services, or just the …