Skip to main content

Practical DevOps, Cloud, AI & Linux engineering guides

Featured Article

GitLab's New Rate Limits: What to Fix Before Oct 19

GitLab is capping unauthenticated API calls at 60 an hour starting October 19, and the preview windows land before most teams will have noticed.

KU
Kiril UrbonasAI Engineer
|Oct 4, 2026
GitLab's New Rate Limits: What to Fix Before Oct 19

Most read

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05

Topics

Latest Articles

View All →
Both manage Kubernetes manifests across environments, but they solve it in opposite ways. Templating versus patching, and when each one actually wins.
••last month

Helm vs Kustomize: Which Kubernetes Config Tool to Use

Both manage Kubernetes manifests across environments, but they solve it in opposite ways. Templating versus patching, and when each one actually wins.

KU
Kiril Urbonas·2 min read·16
Read article
A synthesis of this year's major industry surveys (Stack Overflow, GitHub Octoverse, CNCF, DORA, and more), with the actual numbers and what they mean for a working team.
••last month

The State of DevOps and AI Tooling in 2026: What the Data Actually Shows

A synthesis of this year's major industry surveys (Stack Overflow, GitHub Octoverse, CNCF, DORA, and more), with the actual numbers and what they mean for a working team.

KU
Kiril Urbonas·3 min read·39
Read article
The default filesystem your distro picks is not always the right one for your workload. Here is what actually differs and when each one wins.
••last month

ext4 vs XFS vs Btrfs: Choosing a Filesystem for a Server

The default filesystem your distro picks is not always the right one for your workload. Here is what actually differs and when each one wins.

KU
Kiril Urbonas·2 min read·41
Read article
One is a full secrets platform, one is AWS-native and hands-off, and one is built for developer workflow. Picking by feature list alone misses the real tradeoff.
••last month

Vault vs AWS Secrets Manager vs Doppler: Choosing a Secrets Tool

One is a full secrets platform, one is AWS-native and hands-off, and one is built for developer workflow. Picking by feature list alone misses the real tradeoff.

KU
Kiril Urbonas·2 min read·18
Read article
Business logic vulnerabilities exploit legitimate application workflows rather than broken code, so scanners routinely miss them entirely.
••last month

Business Logic Vulnerabilities: The Flaws Scanners Can't Find

Business logic vulnerabilities exploit legitimate application workflows rather than broken code, so scanners routinely miss them entirely.

KU
Kiril Urbonas·2 min read·20
Read article
journald is the default log sink on every systemd distro, and most of it runs on defaults nobody chose. Here is how to actually control it.
••last month

journald Log Management: Retention, Filtering, and Forwarding

journald is the default log sink on every systemd distro, and most of it runs on defaults nobody chose. Here is how to actually control it.

KU
Kiril Urbonas·2 min read·32
Read article
GraphQL's single flexible endpoint creates attack surfaces REST checklists miss, from introspection exposure to query depth and batching abuse.
••last month

GraphQL Security Best Practices

GraphQL's single flexible endpoint creates attack surfaces REST checklists miss, from introspection exposure to query depth and batching abuse.

KU
Kiril Urbonas·2 min read·23
Read article
Secrets slip into git through habit and haste, and the only reliable fix is catching them before they're committed, not after.
••last month

Secret Scanning: Stop Secrets From Leaking Into Git

Secrets slip into git through habit and haste, and the only reliable fix is catching them before they're committed, not after.

KU
Kiril Urbonas·2 min read·26
Read article
A practical comparison of static and dynamic application security testing, what each catches, and how to combine them in your pipeline.
••last month

SAST vs DAST: Which Security Testing Do You Need

A practical comparison of static and dynamic application security testing, what each catches, and how to combine them in your pipeline.

KU
Kiril Urbonas·2 min read·11
Read article
JWTs get misused in the same handful of ways across codebases, from trusting the algorithm header to skipping issuer and audience checks.
••last month

JWT Security: Common Vulnerabilities and How to Avoid Them

JWTs get misused in the same handful of ways across codebases, from trusting the algorithm header to skipping issuer and audience checks.

KU
Kiril Urbonas·2 min read·21
Read article
\"It's always DNS\" is a joke because the failure modes are so scattered: resolver config, caching, search domains, split DNS. Here is where to actually look.
••last month

DNS Troubleshooting on Linux: A Systematic Approach

\"It's always DNS\" is a joke because the failure modes are so scattered: resolver config, caching, search domains, split DNS. Here is where to actually look.

KU
Kiril Urbonas·2 min read·34
Read article
Security misconfiguration quietly outranks flashier bugs as a top cause of breaches, yet teams rarely treat it as a real engineering problem.
••last month

Security Misconfiguration: The OWASP Category Nobody Talks About

Security misconfiguration quietly outranks flashier bugs as a top cause of breaches, yet teams rarely treat it as a real engineering problem.

KU
Kiril Urbonas·2 min read·23
Read article
Page 4 of 47 · 559 posts