Blog
September 4, 2026
Prometheus, Pruning, and Recovery
Deploying kube-prometheus-stack through Flux and Helm, then tracing a pruning cascade through Git and recovering the cluster from desired state.
September 1, 2026
Ciphertext In, Credentials Out
Using SOPS, age and Flux to make Kubernetes Secrets encrypted in Git, recoverable by the cluster and useful only where they are needed.
August 29, 2026
No Open Ports, No Problem
Publishing Linkding through a locally managed Cloudflare Tunnel while keeping the Kubernetes Service private and the tunnel credential out of Git.
August 23, 2026
Keep the Data, Lose the Root
Using Flux, K3s local-path storage and Kubernetes security contexts to make Linkding survive pod replacement without leaving its container running as root.
August 20, 2026
Commit, Push, Reconcile
Deploying Linkding to my K3s homelab through Flux, Kustomize and Git—without reaching for kubectl apply.
August 18, 2026
Git Gets the Keys
Bootstrapping Flux into my K3s homelab and turning a GitHub repository into the declared source of cluster state.
August 17, 2026
One Node, One Character Off
Installing K3s on the ZBook, investigating two deceptively similar Helm flags and securely managing the cluster from my MacBook.
August 12, 2026
Homelab Day 1: From Shelfware to Server
Giving an unused HP ZBook a second life as the physical Ubuntu Server at the centre of my Kubernetes homelab.
May 23, 2025
From Certified to Deployed
Building a serverless AWS portfolio and a GitHub Actions pipeline that deploys it without long-lived cloud credentials.
May 20, 2025
Certified, but Not Yet Deployed
Passing AWS Cloud Practitioner validated the theory. The Cloud Resume Challenge would test whether I could turn it into a working system.