<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Container Runtime on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/container-runtime/</link>
    <description>Recent content in Container Runtime on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 17 Jun 2025 10:10:03 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/container-runtime/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From Dev to Prod: Making Distroless Images Your Default </title>
      <link>https://www.msbiro.net/posts/from-dev-to-prod-making-distroless-images-your-default/</link>
      <pubDate>Tue, 17 Jun 2025 10:10:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/from-dev-to-prod-making-distroless-images-your-default/</guid>
      <description>Explore the importance of using distroless container images to reduce security vulnerabilities in production. This post covers practical advice on adopting distroless images using multi-stage builds, along with comprehensive debugging techniques including the open-source cdebug tool, Docker Debug, and Kubernetes&amp;#39; kubectl debug with ephemeral containers. Learn how strategic container image choices improve security, efficiency, and maintainability from development through production.</description>
    </item>
    <item>
      <title>Apple container announced</title>
      <link>https://www.msbiro.net/posts/apple-container-oss-macos26/</link>
      <pubDate>Tue, 10 Jun 2025 14:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/apple-container-oss-macos26/</guid>
      <description>Apple announced its new open-source container runtime for macOS 26, enabling developers to run OCI-compliant Linux containers natively on Apple silicon with enhanced isolation, security, and Rosetta 2 support. This post explores the features, requirements, and how this solution compares to Docker and Podman for macOS developers.</description>
    </item>
    <item>
      <title>Securing Kubernetes 1.33 Pods: The Impact of User Namespace Isolation</title>
      <link>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</link>
      <pubDate>Fri, 16 May 2025 09:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</guid>
      <description>Kubernetes 1.33 enables user namespace isolation by default for pods, greatly enhancing security by mapping container root users to unprivileged host UIDs. This post explores the feature’s security benefits including process isolation and lateral movement prevention, infrastructure requirements like Linux kernel 6.3 and compatible container runtimes, and how to enable user namespaces in your pod specifications. Learn why this advancement is crucial for securing Kubernetes workloads in modern environments.</description>
    </item>
    <item>
      <title>macOS, Podman Desktop and the Podman Machine: Pay Close Attention to the Podman Version</title>
      <link>https://www.msbiro.net/posts/podman-desktop-and-podman-machine-on-macos-pay-attention-to-podman-version/</link>
      <pubDate>Fri, 10 Jan 2025 11:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/podman-desktop-and-podman-machine-on-macos-pay-attention-to-podman-version/</guid>
      <description>This post explores compatibility issues when using Podman Desktop on macOS, particularly the Podman machine failing to start due to legacy Podman installations. It shares practical troubleshooting steps including identifying version conflicts, removing unsupported Podman machines, and successfully recreating them for smooth container management. Essential reading for developers managing container runtimes on macOS.</description>
    </item>
    <item>
      <title>Resolving Podman Log Rotation Issues in CyberArk Conjur Container 12.9 Deployments</title>
      <link>https://www.msbiro.net/posts/resolving-podman-log-rotation-issue-conjur-enterprise-129/</link>
      <pubDate>Wed, 24 May 2023 17:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/resolving-podman-log-rotation-issue-conjur-enterprise-129/</guid>
      <description>This post addresses a log rotation issue seen in CyberArk Conjur 12.9 container deployments running on Podman. Unlike Docker, Podman requires the container to be recreated with the AUDIT_WRITE capability added and a specific permission set on the Nginx log directory for proper log rotation. The resolution was developed collaboratively with CyberArk support and is now documented for future updates. Essential guidance for operators using Podman with Conjur containers.</description>
    </item>
    <item>
      <title>CyberArk Conjur: A Quick Overview of Architecture and System Requirements</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-architecture-system-requirements/</link>
      <pubDate>Sun, 24 Jul 2022 11:40:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-architecture-system-requirements/</guid>
      <description>This post provides a comprehensive overview of CyberArk Conjur Enterprise architecture, detailing its multi-node cluster design with auto-failover capabilities, follower deployment for scaling, and essential system requirements for production and test environments. Essential reading for anyone planning to deploy Conjur as an enterprise-grade secrets manager.</description>
    </item>
  </channel>
</rss>
