Blog
Cloud-Native Insights & Expertise

Discover our latest articles about cloud-native technologies, Kubernetes, DevOps, and modern software development. From practical tutorials to in-depth analyses.

Latest Blog Posts

Stay up to date with our latest articles about cloud-native technologies, Kubernetes, and DevOps.

1219 posts

Storage in Kubernetes

Storage in Kubernetes

Storage in Kubernetes is by no means trivial. Stateful workloads impose the highest demands on stability, performance, and availability—handling persistent data is thus one of the most complex tasks in the Cloud-Native environment. This article provides a comprehensive overview: from CSI, Cloud vs. On-Premise CSI, Longhorn, Ceph, and another solution, to Cloud-Controller-Manager, costs, scaling, redundancy, security, and the challenges of local storage landscapes.

Immutable Releases on GitHub – A Significant Milestone for a Secure Software Supply Chain

Immutable Releases on GitHub – A Significant Milestone for a Secure Software Supply Chain

The security of the software supply chain is one of the central topics in modern software development. With every new dependency, external artifact, and library used, the attack surface grows – and so does the responsibility of developers to secure this chain against manipulations and accidental errors. GitHub has now introduced a feature called **Immutable Releases**, which marks a significant step in this direction: once published, releases can no longer be altered.

Kyverno vs. OPA – Policy Control for Kubernetes in Regulated Environments

Kyverno vs. OPA – Policy Control for Kubernetes in Regulated Environments

Kubernetes has become the de facto standard for operating cloud-native applications. However, with its flexibility comes immense complexity. In highly regulated environments—such as finance, healthcare, or public administration—secure use of Kubernetes is only possible when **policies** strictly control the behavior of clusters, workloads, and users. Without such mechanisms, there is a risk of compliance violations, security gaps, and uncontrolled deviations from internal standards.

Spotify Backstage – Potentials and Challenges of Internal Developer Platforms

Spotify Backstage – Potentials and Challenges of Internal Developer Platforms

Internal Developer Platforms (IDPs) have been a hot topic in software development for several years. Companies face the challenge of managing complex cloud-native landscapes with microservices, APIs, Kubernetes clusters, and a multitude of tools. Developer teams lose time due to context switching, incomplete documentation, and fragmented toolchains. This is where [Spotify Backstage](https://backstage.io) comes in – an open-source platform for developer portals, released by [Spotify](https://engineering.atspotify.com) in 2020 and now part of the [Cloud Native Computing Foundation (CNCF)](https://www.cncf.io).

Sovereign Alternatives to Hyperscalers – Does It Always Have to Be Another "Cloud"?

Sovereign Alternatives to Hyperscalers – Does It Always Have to Be Another "Cloud"?

The debate about sovereignty in the cloud in Europe often revolves around the question: *Do we need our own hyperscalers to be independent?* Many see the solution in a "European cloud" that should replace AWS, Azure, or Google Cloud. But the reality is much more complex—and in many ways, more pragmatic. Most services offered by hyperscalers are based on well-known open-source projects. The difference lies in branding, integration, and pricing. Those truly seeking sovereignty don't necessarily need to build a new hyperscaler. The real alternative is closer: Kubernetes as a foundation and open tools instead of proprietary "cloud services."

Sovereign AI for Europe – The Supply Chain Problem

Sovereign AI for Europe – The Supply Chain Problem

The European debate on "sovereign AI" is often reduced to regulation, data protection, and societal acceptance. What is often overlooked: Sovereignty in Artificial Intelligence is not only determined by algorithms or models but crucially by the supply chain of the underlying hardware. Without chips, without GPUs, without the necessary infrastructure, any vision of European AI sovereignty is nothing more than an academic exercise. In this post, I aim to highlight the real bottlenecks blocking Europe on this path and simultaneously identify the remaining opportunities for action. This will not be a romantic plea for autarky, but a sober analysis of dependencies, market mechanisms, and industrial policy options.

Databases in Kubernetes – Alternatives to Cloud-Hosted DB

Databases in Kubernetes – Alternatives to Cloud-Hosted DB

Operating databases in Kubernetes was long considered risky: Stateful workloads, persistent data, and container orchestration seemed incompatible. Today, the situation is different. Specialized operators, optimized storage solutions, and proven practices have made relational and document-based databases stable building blocks for cloud-native architectures.

Observability in Kubernetes – A Comprehensive Comparison

Observability in Kubernetes – A Comprehensive Comparison

Kubernetes has become the standard for running containerized applications in recent years. As its adoption grows, so does the need to monitor clusters and applications transparently, traceably, and efficiently. **Observability** – the ability to reconstruct the state of a system from external signals such as logs, metrics, and traces – is a central concept for this purpose.

Egress Traffic Management in Kubernetes

Egress Traffic Management in Kubernetes

For years, Kubernetes has provided proven mechanisms to manage incoming traffic into a cluster. Ingress controllers serve as a defined "bottleneck" through which external requests enter and are handled with clear rules – such as for routing, TLS, or authentication. However, the situation for outgoing traffic, known as **egress traffic**, is less clear. By default, egress traffic leaves the cluster via the node where the pod initiating the connection is running. There is no central control instance comparable to the ingress controller.

From OTRS to Zammad – 50,000 Tickets Find a New Home

From OTRS to Zammad – 50,000 Tickets Find a New Home

The transition from OTRS to Zammad is more than just a technical upgrade for many organizations – it's a step towards a sovereign, modern, and highly available ticketing infrastructure. In this blog post, we describe in detail how we successfully migrated **50,000 tickets** from a non-highly available OTRS 6 instance to a **self-hosted Zammad instance** running on Kubernetes.

Digital Powerlessness – Germany Ensnared by Big Tech - A Film by ARD

Digital Powerlessness – Germany Ensnared by Big Tech - A Film by ARD

The fact that the Bundeswehr will store its data in the Google Cloud is not an IT project. It is a security policy capitulation. Just like the decision to give Peter Thiel's Palantir direct access to German police data. These two examples are not isolated missteps – they are expressions of systemic failure. Germany has relinquished its digital sovereignty.

Microsoft Eliminates Traditional Volume Licenses

Microsoft Eliminates Traditional Volume Licenses

Starting November 1, 2025, Microsoft will eliminate traditional volume licenses. Specifically affected are the major licensing models **Enterprise Agreement (EA)** and **Microsoft Products and Services Agreement (MPSA)**. Previously, companies could receive discounts between 6 and 12 percent off the list price depending on the volume purchased. This will soon end. From November, all customers will fall into price level A – and will pay the **full list price** as it appears on the Microsoft website.

k3k: agent-less k3s in Kubernetes

k3k: agent-less k3s in Kubernetes

* **Controlplane on demand:** With k3k, you can run a **fully-fledged k3s control plane as a Kubernetes workload** – without agent nodes. This enables lightning-fast **spin-up/down** of complete, valid k3s clusters for testing, tenants, or edge scenarios. (Background: *agent-less servers* are a feature of k3s where the control plane is not a normal node in the cluster, as is usually the case)

Zero Trust Network Access (ZTNA) with NetBird – The Open-Source Alternative

Zero Trust Network Access (ZTNA) with NetBird – The Open-Source Alternative

In a world where cloud-native architectures, remote development, and complex multi-cluster infrastructures have become the norm, traditional VPN-based access is simply outdated. Zero Trust Network Access (ZTNA) is not just a trend but a necessity: a modern paradigm where **trust is never blind and every access is explicitly verified**—regardless of location, device, or network.

Artifact Management – Why Blind Trust in Public Artifacts is Dangerous

Artifact Management – Why Blind Trust in Public Artifacts is Dangerous

Cloud-native software development is built on a foundation that usually remains invisible: **artifacts**. These include Docker images, Helm charts, operator packages, and other components essential in modern Kubernetes workflows. Almost every project—from small APIs to complex AI platforms—relies on these packages. But how stable is this foundation really when sourced from the **community or third parties** without safeguards, mirroring, or governance?

Developer Platforms by ayedo: Tailored, Flexible, and Future-Oriented

Developer Platforms by ayedo: Tailored, Flexible, and Future-Oriented

At its core, Developer Platforms enable teams to guide software securely, efficiently, and automatically through the entire Software Development & Delivery Lifecycle. As a Managed Service Provider for cloud-native platforms, ayedo designs these platforms not as a rigid product but as a dynamic infrastructure that responds to customer needs just like a sophisticated GitOps pipeline.

Kira: Why We Are the First to Use an AI Influencer – and What It Means for ayedo

Kira: Why We Are the First to Use an AI Influencer – and What It Means for ayedo

An AI influencer is not a human who spontaneously decides whether to post a video or a post today. An AI influencer is a digital persona, fully constructed, always available, never in need of a vacation, and capable of producing high-quality content in seconds. That's exactly what Kira is. She will speak for us – about Cloud-Native technologies, AI and hosting news, in videos, podcasts, and on LinkedIn.

Why Helm is the Standard for Kubernetes Apps

Why Helm is the Standard for Kubernetes Apps

In recent years, Kubernetes has evolved from an experimental playground to the de facto standard for cloud-native applications. Its flexibility and scalability are impressive, but they come at a cost: significantly increased complexity in managing deployments, configurations, and releases. Anyone seriously operating or delivering software on Kubernetes will sooner or later face the question: How do I package my application so that it is reproducible, maintainable, and easily integrable?