Daniele Polencic
@danielepolencic
Teaching Kubernetes at @LearnKube.com
Just landed: Learn Kubernetes weekly 195! My top picks: 🔒 Nodes/proxy Get: One Permission Too Many 🔑 Kubernetes AuthN the Hard Way 🐛 ArgoCD ServerSideDiff Vulnerability 🛠️ Okteto Dev Platform Read it here: https://kube.today/issues/195
We’ve just confirmed 3 private Kubernetes training engagements for September alone Want to level up your team’s Kubernetes and platform engineering skills? Teams: https://learnkube.com/corporate-training Individuals: https://learnkube.com/training
Just landed: Learn Kubernetes weekly 194! My top picks: 🎮 Game Servers with Agones 🤝 Multi-Agent A2A on EKS ✍️ Docker Image Signing and Verification 🖥️ AI Cluster Runtime for K8s: NVIDIA AICR Read it here: https://kube.today/issues/194
One million output tokens per second. On Kubernetes KubeFM Season 9 starts with a bang! Federico Iezzi explains how he reached that milestone with Qwen 3.5, vLLM, GKE Autopilot and B200 GPUs 🎙Bart is back. KubeFM is back https://ku.bz/1xD9Md0mb
Just landed: Learn Kubernetes weekly 193! My top picks: 🚧 Kubernetes Gotchas Breaking Laravel Deploys 🕵️ Catching Helm Drift 🧩 Fixing 502 Bad Gateway in GKE and Istio 🛡️ Copy Fail Destroyer Read it here: https://kube.today/issues/193
Just landed: Learn Kubernetes weekly 192! My top picks: 🔑 EKS Pod Identity Session Policies 🛡️ Blocking Copy Fail with Tetragon 🌐 PodCIDR Pools with Cilium and vCluster 🗺️ k8scout Attack Path Mapper Read it here: https://kube.today/issues/192
Just landed: Learn Kubernetes weekly 191! My top picks: 🛡️ Secure AI Kubernetes Debugging ☁️ On-Prem Meets Cloud, Finally 📊 Local EKS Log Monitoring 🚫 Copy Fail Blocker Read it here: https://kube.today/issues/191
Just landed: Learn Kubernetes weekly 190! My top picks: 🔒 L7 Filtering with Cilium eBPF 🐛 Debugging Across Container Boundaries 🛡️ Automating Pod Disruption Budgets ⛵ Luxury Yacht: K8s Management App Read it here: https://kube.today/issues/190
Just landed: Learn Kubernetes weekly 189! My top picks: 🚀 GitOps at Enterprise Scale 🖥️ Generative AI at the Edge with EKS Hybrid Nodes 🪖 Deploying OpenClaw with Helm 🐘 OpenEverest Database Platform Read it here: https://kube.today/issues/189
Just landed: Learn Kubernetes weekly 188! My top picks: 🚀 Stateless ArgoCD for Bare-Metal 🔏 Signed, Sealed, and Admitted 🔐 Securing Inference with Authorino 🔍 xpdig: Explore Crossplane Traces Read it here: https://kube.today/issues/188
Just landed: Learn Kubernetes weekly 187! My top picks: 🔐 OAuth with Kindling 🔀 Sharded Multi-Cluster cert-manager 🏗️ Private EKS Cluster with OpenVPN and Grafana 🗃️ Chainloop SDLC Evidence Store Read it here: https://kube.today/issues/187
Just landed: Learn Kubernetes weekly 186! My top picks: 🔧 Fixing ISR Revalidation Across Replicas 🌐 GKE Multi-cluster Gateway 🚀 Migrating VPC CNI to EKS Managed Add-on 🗼 hanoi-cli Read it here: https://kube.today/issues/186
Gulcan did an excellent job turning this into a concrete walkthrough, with examples for users, Pods, projected tokens, TokenReview, and AWS IAM federation. https://learnkube.com/authentication-kubernetes
Inside the cluster, TokenReview is the simpler version of the same idea. Send Kubernetes a token. Get back whether it is valid, and which identity it represents.
This is also why EKS IRSA works. AWS does not ask the Kubernetes API server whether the Pod exists. It verifies the projected token through the cluster OIDC issuer and JWKS endpoint, then returns temporary AWS credentials.
That pod binding is important. It means the token is not just “some secret in a volume”. It can be scoped to a specific workload, for a specific audience, with a specific expiry.
Pods take a different path. They use service accounts. The token mounted into a Pod is a JWT, and with TokenRequest it can carry: - audience - issuer - expiry - subject - pod binding
Kubernetes has no `User` resource. For people, the identity comes from outside the cluster: OIDC, client certificates, webhooks, proxies, or static token files. The API server only needs the result: username, UID, groups, and extras.
RBAC, OIDC, service accounts, IRSA, TokenReview. Kubernetes auth is usually presented as a bag of separate topics. The API server starts from a smaller question: Who is making this request?
Just landed: Learn Kubernetes weekly 185! My top picks: 🏥 Designing for Failure with CloudNativePG 🏠 Homelab Kubernetes Cluster with $0 Cloud Costs 🔐 From ACM to ALB on EKS Auto Mode ⚡ Zeropod: Scale to Zero Read it here: https://kube.today/issues/185
Just landed: Learn Kubernetes weekly 184! My top picks: 🔒 Securing Crossplane Dashboard 🔑 Leaked Secrets in Version Control 🍓 Production Kubernetes on Raspberry Pi 🩺 Node Healthcheck Operator Read it here: https://kube.today/issues/184
Gulcan Topcu traced the path end to end in a new LearnKube deep dive. If you care about Kubernetes metrics beyond dashboard labels, this is worth reading: https://learnkube.com/kubernetes-metrics-cadvisor-kubelet-cri
This is the part that is hard to find in one place: where cgroups stop, where cAdvisor starts, what kubelet exposes, and when the runtime becomes the source of truth for pod stats.
But kubelet can also ask the container runtime directly. Through CRI, containerd or CRI-O can return pod and container stats without kubelet rediscovering everything from the host.
For years, cAdvisor has been the familiar path. It runs inside kubelet, reads host-level cgroup data, labels it with Kubernetes context, and exposes container metrics for Prometheus to scrape.
Kubelet sits in the middle. It knows about pods and containers, but the raw usage data comes from lower layers. That is why kubelet exposes multiple views: /metrics, /metrics/cadvisor, /metrics/resource, and /stats/summary.
For pod and container usage, the story starts in Linux. Kubernetes declares requests and limits, but cgroups enforce them and expose the counters behind CPU, memory, and process metrics.
Kubernetes metrics are not one thing. Node metrics, control-plane metrics, object-state metrics, and pod/container usage all come from different layers. If you debug the wrong layer, the numbers will not make sense.
Most Kubernetes metrics tutorials stop just as the interesting part begins. They show Prometheus or Metrics Server, then skip kubelet, cAdvisor, CRI, containerd, and Linux cgroups. That's the part you need if you want to trust your dashboards.
Just landed: Learn Kubernetes weekly 183! My top picks: 🎙️ Vibe Coding a K8s Media Server 🐘 CloudnativePG: Postgres on Kubernetes ⚡ CRaC: 88% Faster Spring Boot 👾 Kubeinvaders: Cluster Resilience Testing Read it here: https://kube.today/issues/183