1 minute read

A few good hindsight design posts this week, both on API design and on data storage cost control. As with lots of decisions, you can apply some patterns too early, but knowing you’ll need to change later if you succeed is useful to remember.

StackHawk sponsors Devops Weekly

Trying to figure out how to keep your APIs secure? You’re not the only one. See how DataRobot is automating API security testing with StackHawk.


A good post on the early decisions (in this case around data storage) that can lead to cost control discussions later. You can apply this to other systems as well.

Details on combining ttl.sh (which provides anonymous and ephemeral container registries) and Cosign to sign the images. A few interesting use cases for this sort of thing.

A critical review of the recently released Kubernetes security guidance from the NSA, including some up-to-date recommendations.

Authentication of the Docker socket is all or nothing, but you can always use a reverse proxy for finer-grained control. A good example using Caddy.

An interesting observation about the relationship between observability and the needs of auditors for compliance.

Whenever you’re building a new API, or consuming an API of another system, you quickly build up opinions about what a good API feels like. This post has some good advice for both processes, practices and principles.


SLO Tracker is a dashboard application for displaying SLO and error budget information, based on integration to gather SLI data from Prometheus, Grafana, Datadog and other monitoring tools.

EKS Anywhere is an option to run AWS EKS (the AWS Kubernetes service) on your own infrastructure. The main use case is to standardise the management side of operating a service like this.