Containers rely on many privilege separation systems to do what they do, they are in fact a rather extreme case of multi-user systems, but they tend to present as “single” user environs to the container’s processes.
Hundreds, in my case. We have a sidecar here or there, but essentially our entire operation is run in distroless containers that consume config maps. We have one source of truth for 5 baremetal cloud regions, a number of private on-prem cloud regions, our build and test infrastructure, and nearly everything else, it is our Argo repo and the auto-generated operator manifests from our operator mono-repo. We have a common client library that abstracts our CRDs into easy to consume functions, and in the end using Kubernetes as an API for infrastructure operations does exactly what it should; allows full consistency and visibility on configuration.
You use machineConfigs that are used to provision the base OS and configure it, and the clusterConfig is used to bootstrap k8s on those machines. You can make subtypes and super types, you can have different networking setups, whatever you like, just apply and the OS is driven to state, then k8s is brought up from there. You are presented a kubeconfig after. Changes are done via application of updated machineConfig. Works great in practices and if you write an operator you can manage the config generation via k8s manifests and get wild with it.
We operate talos and alpine based nodes, many thousands of them. The build chain for alpine is many orders of magnitude more complex than the build pipe for our talos image modifications. Alpine is really not made for doing a lot of “host” tasks and needs much coercion to get it to be capable of running something like k3s, and much more complex to get kubeadm clusters running on it. In the end the complexity is required for flexibility, alpine nodes can be modified on a whim, talos is R/O and ephemeral, but more secure.
You literally do not need more than the most basic of host-OS facilities to run any Linux workload you want in a pod, the OS just needs to run containerd and have a kernel, talos adds the management plane to that mix to make it useable, but the userland provided by the oci image will not see any difference at all than if it were running on Ubuntu; it will see the kernel.
We run many talos clusters at Civo, and they are far easier to manage than the other cluster types that use a standard Linux distribution stripped and stuffed with what we need, and the custom image build process is easy to get running in CI, all in all talos is wonderful both as tenant nodes and our region supercluster nodes, and much simpler process to add/remove nodes to the pool and do a few other k8s-centric tasks like etcd snapshot backups and pre-configuration of our regions before we have kit on the ground.
This fits the bill for terrorism in my mind, it is an intentional act to directly affect the people of a nation, and if it causes even one death it becomes way more likely the law will see it as such. Who knows when (one of these events will eventually cause a response from fed) cyberattack becomes synonymous with terror attack, though. Could be this one, could be the future (hypothetical) attack on Fox News or CNN, could be someone turning off the sewage treatment plant for DC, one of them will ruffle the right feather, eventually.
I’ll not speak on the side of potential bad, but I will talk on what I see as good about these teams being CNA’d. The entire policy chain depends on them, and requires them to do their work, which makes it easy to point at as a team and say “one of our core values is making that CVE list trustable” instead of it being used to hide reports.
I adore Nikon, but always wondered how they managed to be the only cameras in the US space program. Guess I know, they played hard ball on the firmware and delivered something nobody else was going to.
Good luck with me, I use 34 keys in a Colemak layout with 8 levels of layers, essentially rendering it all useless, many strokes are rolled into the next, and chorded combos will sound like one ambiguous click.
Finally. My love of the sweep has proven to be correct, two thumb keys is the way. I am using a ZMK powered Urchin, a sweep variant, as my only daily use keyboard, 34 keys of love.
None of you here know me, and Kris did not know me before we did this very personal podcast with Rich. This is about both our times as homeless tech people. She was the reason I am who I am, and we didn't know that until we did this. https://kubecuddle.transistor.fm/episodes/dave-fogle-and-kri...