Ilia Gusev

273 posts

Ilia Gusev

Ilia Gusev

@persikbl

Writing Podo Stack 🍇 - tools that survived production, weekly https://t.co/VZpVsZuNCR

Katılım Ocak 2026
30 Takip Edilen5 Takipçiler
Ilia Gusev
Ilia Gusev@persikbl·
Your NetworkPolicy uses IP addresses. Your pods change IPs on every restart. See the problem? Cilium fixes this with identity-based security. No IPs. Just labels. podostack.com/p/cilium-ebpf-…
Ilia Gusev tweet media
English
1
0
0
3
Ilia Gusev
Ilia Gusev@persikbl·
We replaced 47 NetworkPolicies with 12 CiliumNetworkPolicies. Same security posture. L7 visibility we never had before. The policies became readable. That alone was worth it. Full identity + L7 guide: podostack.com/p/cilium-ebpf-… 🛠️
English
0
0
0
3
Ilia Gusev
Ilia Gusev@persikbl·
Scaling becomes a non-issue. Pods come and go. IPs change. Replicas scale from 3 to 30. The policy says "app=payments" - not a list of IPs. Zero policy updates when you scale. Zero drift.
English
1
0
0
4
Ilia Gusev
Ilia Gusev@persikbl·
What if you could see every network request between your services - not in logs, but live? Hubble does this. From the kernel. Zero instrumentation. podostack.com/p/cilium-ebpf-…
Ilia Gusev tweet media
English
1
1
0
2
Ilia Gusev
Ilia Gusev@persikbl·
One covering index turned a 4.2s dashboard query into 38ms. No app changes. No caching layer. Just the right columns in the right index. Full guide with EXPLAIN examples and sizing math: podostack.com/p/covering-ind… 🛠️
English
0
0
0
1
Ilia Gusev
Ilia Gusev@persikbl·
When NOT to use them: - Wide indexes waste memory (buffer pool pressure) - High-write tables pay on every INSERT/UPDATE - If you SELECT *, nothing is covering Best for: read-heavy queries with known column lists. Dashboards, reports, API endpoints returning the same fields.
English
1
0
0
4
Ilia Gusev
Ilia Gusev@persikbl·
We used to spend hours debugging connectivity issues. Now it takes 30 seconds with hubble observe. The best part? It's built in. Install Cilium, enable Hubble, done. Full Hubble deep dive: podostack.com/p/cilium-ebpf-… 🛠️
English
0
0
0
3
Ilia Gusev
Ilia Gusev@persikbl·
Policy troubleshooting becomes trivial. "Why can't pod A reach pod B?" Run hubble observe --verdict DROPPED. It tells you which policy denied it and why. No more guessing. No more kubectl describe on 15 NetworkPolicies.
English
1
0
0
1