<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Alexej Disterhoft</title>
    <link>https://alexej.disterhoft.de/</link>
    <description>Practical notes on Kubernetes, platform engineering, and observability.</description>
    <language>en</language>
    <atom:link href="https://alexej.disterhoft.de/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sat, 03 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Scale ARC runner nodes with NAP</title>
      <link>https://alexej.disterhoft.de/posts/scale-arc-runner-nodes-with-nap/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/scale-arc-runner-nodes-with-nap/</guid>
      <pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate>
      <description>How I run the nodes under my GitHub Actions runners on AKS node auto provisioning: one NodePool, a hook that protects running jobs, and no spot VMs.</description>
      <category>github-actions</category>
      <category>kubernetes</category>
      <category>aks</category>
      <category>azure</category>
    </item>
    <item>
      <title>Why user namespaces can't run Docker-in-Docker yet</title>
      <link>https://alexej.disterhoft.de/posts/why-user-namespaces-cant-run-docker-in-docker/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/why-user-namespaces-cant-run-docker-in-docker/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>Setting hostUsers: false on a Kubernetes Pod maps container root to nobody, but dockerd still can't start a container. Here's the exact wall, and the KEP that should remove it.</description>
      <category>github-actions</category>
      <category>kubernetes</category>
    </item>
    <item>
      <title>Run self-hosted GitHub Actions runners with ARC</title>
      <link>https://alexej.disterhoft.de/posts/run-self-hosted-github-actions-runners-with-arc/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/run-self-hosted-github-actions-runners-with-arc/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>How I run self-hosted GitHub Actions runners inside private Azure networks: Actions Runner Controller, a GitHub App, a small runner image and one test job.</description>
      <category>github-actions</category>
      <category>kubernetes</category>
      <category>aks</category>
      <category>azure</category>
    </item>
    <item>
      <title>Use CiliumCIDRGroup to simplify Cilium network policies on AKS</title>
      <link>https://alexej.disterhoft.de/posts/use-ciliumcidrgroup-to-simplify-cilium-network-policies-on-aks/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/use-ciliumcidrgroup-to-simplify-cilium-network-policies-on-aks/</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <description>How to use CiliumCIDRGroup on AKS to model external Azure endpoints as reusable, labeled policy targets for cleaner Cilium network policies.</description>
      <category>cilium</category>
      <category>kubernetes</category>
      <category>network-policy</category>
      <category>aks</category>
      <category>azure</category>
      <category>security</category>
    </item>
    <item>
      <title>Reverse-engineering the MapR ticket format</title>
      <link>https://alexej.disterhoft.de/posts/reverse-engineering-the-mapr-ticket-format/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/reverse-engineering-the-mapr-ticket-format/</guid>
      <pubDate>Tue, 26 Dec 2023 12:00:00 GMT</pubDate>
      <description>How I reverse-engineered the MapR ticket format, recovered its protobuf definition and parsed tickets in Python, using only public artifacts.</description>
      <category>mapr</category>
      <category>kubernetes</category>
      <category>reverse-engineering</category>
      <category>security</category>
    </item>
    <item>
      <title>Use Touch ID for sudo on macOS Sonoma and newer</title>
      <link>https://alexej.disterhoft.de/posts/sudo-touch-id-macos/</link>
      <guid isPermaLink="true">https://alexej.disterhoft.de/posts/sudo-touch-id-macos/</guid>
      <pubDate>Tue, 26 Dec 2023 00:00:00 GMT</pubDate>
      <description>On macOS Sonoma and newer, you can enable Touch ID for sudo with a local PAM file that survives system updates.</description>
      <category>macos</category>
      <category>sonoma</category>
    </item>
  </channel>
</rss>
