the boy in the cap holding a shield marked with a no-entry symbol, blocking a spiky cube of gears and skulls from crossing into a framed panel on the right, where the robot with a wrench watches the same spiky cube become a smooth plain block

🔄 Someone kubectl apply'd a Hotfix Directly. How Do You Detect and Prevent It?

Manual kubectl in production is the Kubernetes equivalent of SSH’ing into a server and editing files. It works until it doesn’t, and when it doesn’t, nobody knows why.

the boy in the cap dropping a code card into a slot in a small git-marked box, which is joined by a single hose to a larger cube marked with the git and Kubernetes symbols; the robot watches from the left

🔑 Deploy to Kubernetes Without Storing Any Cluster Credentials in CI

A common interview question in 2026. If your answer is ‘kubeconfig in a CI secret’, you’re not wrong — but you’re also not getting the job.

the robot turning a key in the dial of a large safe door marked with a cloud, drawing a small scroll out along an arrow toward the boy in the cap, who holds an open cardboard box marked with a padlock ready to receive it

🤫 How Do You Handle Secrets in a GitOps Repository?

GitOps says Git is the source of truth. Secrets say don’t put them in Git. These two things appear to be in direct conflict. They’re not.

the boy in the cap plugging a network cable into a server rack while the robot stands beside him holding a small server box in both hands, eyes closed and grinning

🏗️ My Homelab Runs on GitOps. Here's What That Actually Means.

I wanted to learn production-grade Kubernetes patterns without breaking production. One node, a full GitOps stack, and a hard rule: no manual kubectl after bootstrap.