Skip to main content

Recently Updated Pages

Service map

The Lab, End-to-End

Every box and what it does, with a pointer to the book that covers it in depth. VM Address Wha...

Updated 2 months ago by Eslam Shapsough

The address plan and naming

The Lab, End-to-End

A small, boring, consistent address plan saves you a surprising amount of grief. Here's the whole...

Updated 2 months ago by Eslam Shapsough

How a request reaches an app

The Lab, End-to-End

Say you open https://app.example.com in a browser. Here's the whole journey: browser | https:/...

Updated 2 months ago by Eslam Shapsough

Lessons on data and observability

Data & Observability

Match storage to the workload: databases get local disk on dedicated VMs, never NFS. Tune for th...

Updated 2 months ago by Eslam Shapsough

The big picture

The Lab, End-to-End

Everything lives behind one firewall, on one private network. The only things exposed to the outs...

Updated 2 months ago by Eslam Shapsough

Seeing what the cluster is doing: logs to Loki

Data & Observability

The lab already had a central log store (Loki — see its book in Core Infrastructure), with a Prom...

Updated 2 months ago by Eslam Shapsough

Every app gets its own credentials

Data & Observability

This is a hard rule in the lab: no application ever connects as the database admin. Each app gets...

Updated 2 months ago by Eslam Shapsough

Tuning a database for the hardware it has

Data & Observability

A freshly installed database ships with cautious, generic defaults. On a box you've sized deliber...

Updated 2 months ago by Eslam Shapsough

Three databases, on purpose

Data & Observability

The platform runs three relational databases — PostgreSQL (10.100.100.13), MariaDB (10.100.100.14...

Updated 2 months ago by Eslam Shapsough

If you are new to this

Principles & Lessons Learned

A closing note, since teaching newcomers is half of why this lab exists. You don't learn infrastr...

Updated 2 months ago by Eslam Shapsough

Reproducible, disposable, observable

Principles & Lessons Learned

Three habits that show up in every corner of the lab: Reproducible. Every VM is a clone of one g...

Updated 2 months ago by Eslam Shapsough

Capacity is just arithmetic (done early)

Principles & Lessons Learned

Every VM was sized by doing the math first, against the one resource that actually runs out here:...

Updated 2 months ago by Eslam Shapsough

One edge, one door

Principles & Lessons Learned

Two things in this lab are deliberately funnelled through a single chokepoint each: All HTTPS te...

Updated 2 months ago by Eslam Shapsough

Least privilege, everywhere

Principles & Lessons Learned

The single most repeated decision in this lab: give each thing the narrowest access that lets it ...

Updated 2 months ago by Eslam Shapsough

Read this one even if you skip the rest

Principles & Lessons Learned

The other books are how. This one is why — the handful of principles that shaped every decision i...

Updated 2 months ago by Eslam Shapsough

Start here: what this lab is

The Lab, End-to-End

This is a home lab. One Proxmox host, a pile of virtual machines, and a small-but-real platform r...

Updated 2 months ago by Eslam Shapsough

Assignment 2: GitOps-deploy your app with Argo CD

Module 8 — CI/CD

Goal: Use Argo CD to deploy the image you built in Assignment 1 onto the lab's live Kubernetes cl...

Updated 2 months ago by Eslam Shapsough

Assignment 1: Build-and-push pipeline on the lab runner

Module 8 — CI/CD

Goal: Write a GitHub-Actions-style workflow that builds a container image from your app and pushe...

Updated 2 months ago by Eslam Shapsough

Lesson: Pull-Based Deployment with Argo CD

Module 8 — CI/CD

What you'll learn The GitOps principle: Git as the single source of truth for what runs in your ...

Updated 2 months ago by Eslam Shapsough

Lesson: Bitbucket Pipelines & Jenkins

Module 8 — CI/CD

What you'll learn What Bitbucket Pipelines is and how its YAML compares to GitHub Actions. The J...

Updated 2 months ago by Eslam Shapsough