Week 1, Devops Notes and Lessons Learned

I'm still not entirely sure why I am building this beyond just seeing whether I can or not. Generally:

  1. I want to se how much these LLM tools can do.
  2. I want a better understanding of how one setups up and maintains a devops stack
  3. I have an itch to build something but I'm not entirely sure what.

Secrets, Security, and Gitops

  • Gitleaks is useful as when initially starting to launch apps on kubernetes, the bot (and human) will usually leave passwords out in your yaml files.
  • Telling the bot you want gitops and tools like ArgoCD would make you think that it would set up each app after ArgoCD to be deployed through a GitOps pattern. You would be wrong. So having multiple models review the implementation helped handle this.
  • Sealing secrets in Kubernetes was new to me. In the beginning there was a mix of using Github secrets in addition to Bitnami Sealed Secrets in Kubernetes, but eventually
  • Keycloak was reasonably quick to setup as the authentication service. I haven't setup 2FA or a full registraation process but it looks like all of those features are there.

Networking and access

I was dreading this the most but I got to say Tailscale and Cloudflare are awesome. Setting up VPN like service used to suck and now definitely doesn't. It is really when i can just immediately ssh from my ipad to home computers without having to slog through inevitable errors that used to occur.

In terms of setting up a domain, and a reverse proxy (Cloudflare Tunnel) to my home network, Cloudflare made the whole process relatively painless. Although Im still not sure what the difference between "Cloudflare" and "Cloudflare One" is.

← All posts