Quantcast
Channel: Sidero Labs
Browsing index pages (201 articles)

The Talos Linux Cluster API providers are moving to community maintenance

Sidero Labs is moving the Talos Linux Cluster API providers to community maintenance. The code stays open source and nothing breaks.

View Article


How Talos Omni makes Talos Linux more secure

Talos Linux removes attack surface at the node. Omni extends that across the fleet, enrollment, encrypted management traffic, access policy, secrets, and recovery.

View Article


Infrastructure brief for building predictable Kubernetes infrastructure at scale

There are four architectural approaches to running Kubernetes at scale, and each comes with unique benefits. Here's how they break down.

View Article

Security and compliance brief for platform teams running Kubernetes in...

Most Kubernetes security programs try to harden a mutable OS after the fact. Talos takes the opposite approach: remove the attack surface entirely.

View Article

Patching Won't Save You

Your patch windows and testing process is going to get your hacked. It's time to move from reactive vulnerability management to proactive software curation.

View Article


Exploit Fail: Why CVE-2026-31431 (Copy Fail) barely scratches Talos Linux

Even if your kernel has vulnerabilities, security is applied in layers. You can minimize the threat impact. That's why Copy Fail barely touches Talos Linux.

View Article

Scale infrastructure without scaling headcount: A Platform Engineering brief

Tired of upgrades that worked in staging broke production or identically configured clusters that behave differently? Teams must start by addressing the root architectural cause.

View Article

Applying modern DevOps and Platform Engineering practices to a homelab with...

When one engineering manager needed to build production Kubernetes infrastructure, he decided the best place to start testing was his homelab. Here's how he succeeded.

View Article


The cloud you own: Webinar feat. Oxide

When Amazon goes down, every company running on AWS goes down with it. When your own infrastructure fails, only you are affected. Here's how to run the Talos Platform on Oxide hardware and start owning...

View Article


STACKIT: A cloud-to-edge continuum for Europe’s largest retailer

From embedded Linux to Kubernetes at Europe's largest retailer: why autonomy matters more than connectivity at the edge.

View Article

Building a Kubernetes cluster with Talos on Hetzner bare metal servers

How to build bare metal Kubernetes clusters on Hetzner to run KubeVirt as a cost-effective way to provide VM-based development environments.

View Article

Is your Kubernetes secure? Webinar feat. DataDog

Kubernetes isn't secure by default. Flexibility comes at a cost. Your threat model should drive your security decisions, not assumptions about what's "out of the box."

View Article

Top trends in the Kubernetes security space

Here's how "shifting down" may be the next step from the shift left, and what it means for Kubernetes security.

View Article


10 practical Kubernetes checks for 7 compliance frameworks

10 checks, 7 frameworks, one small platform team. Marcus Ross of Hamburg Port Authority breaks down how to map Kubernetes security best practices to CIS, NIST, ISO 27001, PCI DSS, SOC2, NIS2, and GDPR .

View Article

Why Talos Linux has zero Go vulnerability exclusions and what that means for...

During a recent vulnerability assessment with an enterprise security partner, we were asked to provide our gap analysis for Go-based vulnerabilities in Talos Linux. The expectation was standard: they...

View Article


Scaling Kubernetes requires predictability, not operational heroics

Is your platform team spending more time firefighting than building? For organizations running Kubernetes at scale, infrastructure drift, manual patching, and unreliable upgrades have become the...

View Article

From image integrity to zero-trust clusters: What’s new in Q1 2026

📌 TL;DR

View Article


Why temporary fixes break long-term infrastructure

Manual interventions during an incident are a standard reality of operating complex systems. A temporary patch restores service. A sysctl parameter is modified to stabilize a node under heavy load. The...

View Article

How radical subtraction simplifies the Kubernetes lifecycle

Modern infrastructure has a hoarding problem. Whenever a system breaks or a new requirement emerges, the industry reflex is to add another layer: an agent for security, a daemon for telemetry, a new...

View Article

Kubernetes complexity and the design choices that amplify it

Most engineering managers recognize the warning signs of complexity before they can fully explain them.

View Article
Browsing index pages (201 articles)


Latest Images