De Nederlandse Kubernetes Podcast

Ronald Kers en Jan Stomphorst

De Nederlandse Kubernetes Podcast: gemaakt door én voor mensen met een hart voor IT. In deze reeks gaan Ronald Kers en Jan Stomphorst in gesprek over Kubernetes met als doel Kubernetes toegankelijk te maken voor iedereen.

  1. 1 dag geleden

    #142 Kubernetes 1.37 Garhwal

    Kubernetes 1.37 verscheen eind augustus onder de naam Garhwal, genoemd naar de Noord-Indiase regio waar de release lead zelf vandaan komt. Op papier een rustige release: 67 enhancements, waarvan zestien naar Stable, drieëntwintig naar Beta en zevenentwintig nieuw in Alpha. Jan constateert dat Kubernetes al een tijd steeds stabieler wordt en dat breaking changes zeldzamer worden. Goed nieuws, al maakt het de zoektocht naar een spannend verhaal voor een release-aflevering er niet makkelijker op. Deze keer valt er genoeg uit te diepen. IPVS gaat eruit. Jan legt uit wat kube-proxy doet en waarom IPVS-mode, ooit geïntroduceerd omdat iptables te klein werd, nu zelf wordt uitgefaseerd. Het probleem is structureel: elke node draagt de IP-adressen van elke service. Bij twintig services merk je daar niks van, bij tweeduizend wel. In 1.43 verdwijnt IPVS volledig, maar het moment waarop je het gaat voelen ligt eerder. De praktische boodschap: stap over naar nftables vóór 1.40, en besef dat een upgrade dat niet voor je doet. Je moet het expliciet instellen. iptables versus nftables. Een heldere uitleg van wat iptables eigenlijk is, namelijk firewall én routing op Linux met één lineaire regellijst die per pakket wordt doorlopen, en waarom dat in Kubernetes tegen een plafond loopt. De API ondersteunt geen incrementele updates, dus voor één regel moet de hele set opnieuw geladen worden. nftables gebruikt sets, maps en efficiëntere datastructuren, en biedt één uniform framework voor IPv4, IPv6, ARP en bridge filtering. Wel opletten: de twee zijn niet volledig compatibel met elkaar, en je hebt een recente kernel nodig. Scale-to-zero is nu native. De HPA kan naar nul zonder dat je iets aan je bestaande configuratie hoeft te veranderen. Waar eerst één stond, kan nu nul staan. De afweging is opstarttijd bij de eerste request, maar als er niets draait betaal je ook niets. Jan wijst op het slimme detail: de HPA schaalt alleen terug omhoog als hij zelf naar nul is gegaan. Zet je de replicas handmatig op nul om iets immutables aan te passen, dan laat de autoscaler je met rust. Een herkenbare praktijkergernis, opgelost. En KEDA dan? Ronald en Jan zetten ze naast elkaar en komen uit op complementair in plaats van concurrerend. KEDA's voordeel is dat het buiten het cluster kan kijken: een firewall of een externe dienst kan het signaal geven dat een pod moet starten. Jan schetst een bijna-serverless patroon waarin verkeer binnenkomt, KEDA de pod start, het request wordt afgehandeld en de pod daarna weer verdwijnt. Twee harde eisen. containerd 1.x moet eruit en cgroup v1 moet eruit. Allebei niet nieuw: failCgroupV1 staat sinds 1.35 standaard op true. Jan vertelt hoe dat bij kube-spray in de praktijk uitpakte. Een mismatch tussen de cgroup-driver van de kubelet en die van de runtime levert het vervelendste type storing op. Niet kapot, maar onvoorspelbaar, met de OOM killer die processen afschiet die er niets aan kunnen doen. Bij ACC ICT wordt zoiets standaard eerst getest en worden nodes vaak simpelweg vervangen door nieuwe machines in plaats van online geüpgraded. containerd 2.0 verandert ook je security-defaults. Containers zonder host-netwerk of user namespaces mogen nu poorten onder 1024 binden zonder CAP_NET_BIND_SERVICE, en ping draaien zonder CAP_NET_RAW. Een afspraak van decennia oud, stilzwijgend versoepeld. Terug te draaien, maar je moet het nu bewust configureren. Verder in deze aflevering: waarom Ubuntu geen excuus meer is, hoe een onbewaakte auto-update je zomaar een major containerd-versie kan opleveren, wat managed clusters wél en niet voor je regelen, en Jans terugkerende standpunt door de hele aflevering heen: het meeste hiervan is geen probleem zodra je je machines gewoon actueel houdt. Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #142 Kubernetes 1.37 Garhwal
  2. 21 aug

    #141 Helm 4 - Plugins, OCI and Why Nothing Broke

    Andrew "Andy" Block writes books and reviews pull requests at thirty thousand feet over the Pacific, because as he says, he can sleep when he's dead. Between Red Hat's services organization and four talks at KubeCon Amsterdam, he sat down with Ronald Kers and Jan Stomphorst to talk about the first major Helm release in almost five years. Helm 4 is a story about restraint. Helm has become load bearing for an enormous number of enterprises, and a strict versioning policy left technical debt with nowhere to go. Helm 4 clears that debt without breaking anyone. Replace the binary, keep your charts, notice almost nothing. After what the Tiller removal in Helm 3 cost teams like Jan's, that is the achievement. Underneath sits more than the version number suggests: a Wasm based plugin model that finally makes Helm properly extensible, a serious API and logging cleanup, and better status handling built on libraries contributed out of the Flux community. Charts v3 comes next, letting you swap Go templating for Jinja or Rust, and opening the door to downloader and signer plugins. That plugin model matters most for signing. Andy asked a room of roughly three hundred people how many sign their Helm charts. Three hands went up. GPG is painful enough that even a security specialist avoids it, so Sigstore behind a plugin becomes the realistic path to provenance. On the OCI side, per repository credentials and transparent mirroring mean organizations can stop forking charts just to repoint them internally. The conversation widens from there: why Kustomize and Helm complement rather than compete, why European organizations are moving back on prem, and whether AI now produces code faster than any maintainer can honestly review it. Andy's crystal ball isn't about features at all. It's about approachability, and lowering the barrier for the newcomers who made up well over half the room at KubeCon. Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #141 Helm 4 - Plugins, OCI and Why Nothing Broke
  3. 4 aug

    #140 Why Your VPN Is Lying to You About Security

    Ronald and Jan talk with Peter O'Neill and Boris Kurktchiev from Teleport about their talk "Signed, Sealed, Delivered: Why Reverse Proxies Beat VPNs." Both guests bring deep networking and security backgrounds, from early desktop support and Slackware days to leading Teleport's solutions engineering and CNCF community work. The core argument: traditional VPNs grant broad network access once a user authenticates, creating large lateral movement risk with little to no granular control or auditing. Peter and Boris propose replacing that model with an identity layer using OIDC and a reverse proxy (Envoy), authenticated via an identity provider like Keycloak. Instead of trusting users based on network location, every connection is signed and validated against intent, who is accessing what, and why. They walk through how this works in practice (SSH access, internal apps, audit logging that captures actual user identity instead of just status codes) and discuss trade-offs: more endpoints to manage, added resource and scaling costs, and real implementation complexity at enterprise scale. Boris is candid that VPNs aren't dead, they still serve as a useful front gate, but shouldn't be the only layer of defense. The conversation also touches on how AI agents on a network expose the weaknesses of old identity assumptions, since AI will scan and probe everything it can reach unless access is explicitly scoped. The episode closes with both guests' hopes for the future of Kubernetes and CNCF: more community involvement in AI-related working groups, and more regional KubeCon-style events outside the usual hubs. Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #140 Why Your VPN Is Lying to You About Security
  4. 21 jul

    #139 Waarom een Kubernetes-cluster zichzelf niet moet beheren

    In deze aflevering gaan Ronald en Jan in gesprek met Eric de Witte, Cloud Native Solutions Architect bij Nutanix, over hoe moderne Kubernetes-platformen worden uitgerold en beheerd over virtualisatielagen, bare metal en de cloud heen. Eric heeft een lange geschiedenis die teruggaat tot de vroege vCenter-tijd, via de opkomst van container orchestration (Mesos, Docker Swarm) tot het huidige Cluster API-gedreven platform bij Nutanix. Het gesprek behandelt hoe Cluster API de onderliggende infrastructuurprovider abstraheert (VMware, Nutanix, AWS, Azure, bare metal), waardoor Kubernetes zijn eigen clusters kan uitrollen en beheren, inclusief self-healing nodes en complete procedures voor het afsluiten en opnieuw opstarten van een datacenter. Ze bespreken verschillende filosofieën rond bootstrap clusters versus een permanent management cluster, en waarom Kubernetes geen besturingssysteem is, ook al wordt het vaak zo genoemd. Een groot deel van het gesprek gaat over de huidige situatie rond VMware en Broadcom: de licentieveranderingen, de focus op grote klanten, en waarom veel organisaties hierdoor hun virtualisatiestrategie heroverwegen, ook al erkent Eric dat VMware technisch nog steeds een sterk product is. Daarnaast wordt diep ingegaan op de operationele realiteit van databases en stateful workloads op Kubernetes, de toenemende afhankelijkheid van operators, de uitdaging om interoperabiliteit te valideren bij elke nieuwe Kubernetes-release, en waarom backup en disaster recovery op applicatieniveau moeten gebeuren in plaats van puur op VM-niveau. Ze sluiten af met een blik op soevereine cloud-ambities, de kloof tussen on-prem en hyperscaler-functionaliteit, en Eric's visie op de komende tien jaar van Kubernetes: meer enterprise-adoptie, meer abstractie, maar ook meer complexiteit, waarbij networking-kennis de grootste drempel blijft voor nieuwkomers. Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #139 Waarom een Kubernetes-cluster zichzelf niet moet beheren
  5. 7 jul

    #138 We Built Our Own Wormhole to Migrate 150 Kubernetes Clusters

    In this episode, recorded live at KubeCon, Ronald and Jan talk with Jannis Relakis and Michael Seiwald-McCarty, both senior platform engineers at Celonis. Celonis manages over 150 Kubernetes clusters across GKE, AKS, and EKS, but it wasn't always that clean. They started with six different Kubernetes flavors, including Gardener, K-Ops, and OpenShift (both Rosa and ARO), spread across multiple cloud providers. In their KubeCon talk "No Shame in Just Paying," they shared how they tackled this consolidation project: migrating all workloads to three standardized, fully managed Kubernetes distributions. Key topics include their self-built cross-cluster connectivity tool called "Wormhole" (powered by Envoy's dynamic forward proxy), RabbitMQ federation for seamless message queue migration, and how they used Karpenter and Cilium to align node and network management across clouds. They also get candid about what went wrong: an accidental ArgoCD sync that caused a 10-minute full environment outage, the pain of "snowflake" environments (including one requiring full HIPAA compliance with Istio mTLS), and the constant fight against scope creep that threatened to derail the entire project. The episode closes with a forward-looking discussion on FinOps, resource rightsizing, the future of VPA, and whether Kubernetes and serverless can ever truly converge.Powered by ACC ICT Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

  6. 23 jun

    #137 The hidden performance tax you're paying on every cloud deployment

    In this episode, Ronald and Jan sit down with Luigi Nardi, founder and CEO of DB tune, at KubeCon. Luigi brings a rare mix of academic depth (PhD in computer science, postdocs at Imperial College London and Stanford, professor at Lund University) and startup pragmatism. The conversation digs into why database tuning is fundamentally a combinatorial optimization problem that humans aren't wired to solve well, and why AI is uniquely suited for it. DB tune focuses entirely on Postgres and deploys a narrow, production-safe AI agent that reads performance metrics and iteratively adjusts server parameters (GUCs) until the system converges on an optimal configuration. No LLMs, no hallucinations — just purpose-built ML that operates in a closed feedback loop. The agent integrates with AWS RDS, Aurora, Azure Flexible Server, Google Cloud SQL, and Cloud Native PG (the Kubernetes Postgres operator). Luigi shares a standout story: a water management company ran the agent on their production system — with a hospital's water supply on the line — and achieved a 2.5x performance improvement in just a few hours. He also explains how tuning isn't a one-time exercise: cloud workloads change, hardware scales up and down, and DB tune's model called "Newton" was specifically engineered to prevent unstable, oscillating parameter changes. The episode closes with a compelling FinOps angle: tuning doesn't just make your database faster, it can also shrink your instance size and cut infrastructure costs — a perfect fit for the Kubernetes-native world. Powered by ACC ICT Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #137 The hidden performance tax you're paying on every cloud deployment
  7. 9 jun

    #136: vLLM, LMD, and the Quest to Build the Linux of AI Inference

    In this episode, hosts Ronald and Jan are joined at KubeCon by two guests from Red Hat: Brian Stevens, AI CTO and one of the original architects behind the creation of Kubernetes and the CNCF, and Rob Shaw, co-lead of the vLLM project and maintainer of LMD. Brian shares the remarkable backstory of how Kubernetes came to be open source, including how Red Hat negotiated a single committer seat before agreeing to be a launch partner, and how he later pushed Google to contribute Kubernetes to the newly formed CNCF rather than keeping it proprietary like TensorFlow. Rob explains what an inference runtime actually is: the critical piece of software that takes an abstract AI model and runs it as efficiently as possible on a GPU or other accelerator — handling everything from CUDA-level kernel optimization to memory management and concurrent request scheduling. vLLM serves as a "Rosetta Stone" between the ever-growing zoo of models (Llama, DeepSeek, Mistral, Qwen, Nvidia Nemotron) and accelerators (Nvidia, AMD, Intel, Google TPUs). The conversation covers model compression and quantization how techniques like 4-bit precision can deliver 2x hardware efficiency gains while preserving 99%+ model accuracy. Brian and Rob also address the "big model vs. many small models" debate, recommending to always start with the largest capable model to validate a use case before optimizing down. Looking ahead, both guests see inference as potentially the single largest workload ever run on Kubernetes, and position LMD (now contributed to the CNCF) as the distributed inference layer that will make this possible across heterogeneous accelerator environments  preventing enterprises from ending up with 42 incompatible AI stacks. The episode closes with a discussion on AI slop, human-in-the-loop thinking, and the future of Kubernetes as the universal platform for running AI agents at scale. Powered by  @acc-ict ​ Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #136: vLLM, LMD, and the Quest to Build the Linux of AI Inference
  8. 26 mei

    #135 The Return of OpenStack: Kubernetes & Sovereign Infrastructure

    In Episode 135 of the Dutch Kubernetes Podcast, Ronald Kers and Jan Stomphorst sit down with Mohamed Nasser, CEO of VEXXHOST and OpenInfra Foundation board member, together with Thierry Carrez, General Manager of the OpenInfra Foundation and Linux Foundation Europe. The conversation explores the growing relevance of OpenStack in a world increasingly focused on digital sovereignty, private cloud, AI workloads, and secure infrastructure. The episode dives into how the industry shifted from private infrastructure toward hyperscalers between 2016 and 2020, and why many organizations are now reconsidering that strategy. Thierry explains how geopolitical tensions, vendor lock-in, and changing licensing models have renewed interest in sovereign cloud solutions powered by open source technologies like OpenStack. Mohamed and Thierry discuss why OpenStack is still highly relevant at massive scale, especially for organizations requiring multi-tenancy, hardware abstraction, GPU enablement, HPC workloads, and advanced networking performance. They explain how Kubernetes has become the user-facing interface, while OpenStack increasingly operates invisibly underneath many modern platforms. Examples discussed include rail infrastructure, gaming companies, telecom providers, and even government environments. The discussion also explores how Kubernetes and OpenStack complement each other instead of competing. Mohamed explains how many providers now run OpenStack itself on Kubernetes, leveraging cloud-native tooling such as Prometheus and Loki to simplify operations and observability. The hosts also discuss storage abstraction, CSI drivers, bare-metal provisioning with Ironic, and why virtualization still offers major operational advantages in large-scale Kubernetes environments. Towards the end of the episode, the conversation shifts toward the future of open infrastructure, including confidential computing, Kata Containers, AI security, GPU orchestration, and the growing collaboration between the Linux Foundation, CNCF, and OpenInfra Foundation. Thierry highlights how secure container isolation and confidential computing are becoming increasingly important as AI workloads spread across Kubernetes platforms. Powered by ACC ICT Stuur ons een bericht. Dutch Cloud Native Day 2026 Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms. Like and subscribe! It helps out a lot. You can also find us on: De Nederlandse Kubernetes Podcast - YouTube Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok De Nederlandse Kubernetes Podcast Where can you meet us: Events This Podcast is powered by: ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

    #135 The Return of OpenStack: Kubernetes & Sovereign Infrastructure
5
van 5
5 beoordelingen

Info

De Nederlandse Kubernetes Podcast: gemaakt door én voor mensen met een hart voor IT. In deze reeks gaan Ronald Kers en Jan Stomphorst in gesprek over Kubernetes met als doel Kubernetes toegankelijk te maken voor iedereen.

Suggesties voor jou