Why Orkestra?
Kubernetes has always promised declarative infrastructure. You describe what you want. The platform makes it so. That promise holds everywhere — until you need to extend Kubernetes …
Read moreEngineering deep-dives, release notes, and design thinking from the people building Orkestra.
Kubernetes has always promised declarative infrastructure. You describe what you want. The platform makes it so. That promise holds everywhere — until you need to extend Kubernetes …
Read moreThe engineering argument for why the operator should have always been the CRD. In 2017, Kubernetes shipped Custom Resource Definitions as the stable mechanism for extending its …
Read moreMost Kubernetes operators are massively over-permissioned. Not slightly, not accidentally — structurally. Inspect the RBAC of a typical production operator and you will find …
Read moreA few years ago I went for an interview and didn’t get the job. The requirement was that the person knew how to write Kubernetes controllers and operators. Several of them. I …
Read moreOrkestra does not give you a better way to build operator infrastructure. It removes it. Every operator author starts in the same place. Before a single line of business logic, …
Read moreSo I built one. Every team that operates Kubernetes eventually writes the same functions. hasCrashingPod. rolloutComplete. allReplicasReady. isTerminating. The names vary slightly. …
Read moreEvery generation of ops shifted what the primary artifact was. We might be due for another shift. A short history of shifting artifacts Every major ops movement of the last twenty …
Read moreAnd every time I thought I had it, the project outgrew the words. I shipped the first version of Orkestra with a GitHub description that said: “Declarative runtime for …
Read moreOrkestra started with two places where you could decide whether something should happen: at admission (before the CR hits etcd) and inside the reconciler (once it was there). That …
Read moreThere is a particular kind of cleanup pass that every solo builder knows. The one you do when the project has been growing fast and you finally let yourself look at the parts you …
Read moreEvery resource in Orkestra applies to Kubernetes via server-side apply. That patch call has one flag that matters more than the others: Force. When Force is true, the field manager …
Read more