<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rémy Gaudey, auteur/autrice sur dbi Blog</title>
	<atom:link href="https://www.dbi-services.com/blog/author/remygaudey/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dbi-services.com/blog/author/remygaudey/</link>
	<description></description>
	<lastBuildDate>Mon, 29 Jun 2026 08:02:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/05/cropped-favicon_512x512px-min-32x32.png</url>
	<title>Rémy Gaudey, auteur/autrice sur dbi Blog</title>
	<link>https://www.dbi-services.com/blog/author/remygaudey/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Expose your Kubernetes pods to your Tailnet using Tailscale operator</title>
		<link>https://www.dbi-services.com/blog/expose-your-kubernetes-pods-to-your-via-tailnet-using-tailscale-operator/</link>
					<comments>https://www.dbi-services.com/blog/expose-your-kubernetes-pods-to-your-via-tailnet-using-tailscale-operator/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 13:14:15 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[kubernetes]]></category>
		<category><![CDATA[tailscale]]></category>
		<category><![CDATA[tailscale-operator]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=45221</guid>

					<description><![CDATA[<p>In one of my previous blogs, I explained how to use a Tailscale sidecar container into an existing pod to expose it to your Tailnet. Even though this works fine, it can be tedious to set up and not very convenient for every use case and not scalable at all. Another solution is to use [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/expose-your-kubernetes-pods-to-your-via-tailnet-using-tailscale-operator/">Expose your Kubernetes pods to your Tailnet using Tailscale operator</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In one of my previous blogs, I explained how to <a href="https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/">use a Tailscale sidecar container into an existing pod</a> to expose it to your Tailnet. Even though this works fine, it can be tedious to set up and not very convenient for every use case and not scalable at all. Another solution is to use the Tailscale Kubernetes Operator. <br>Rather than going through all that manual configuration, you can simply add some annotations on your Kubernetes services and call it a day.</p>



<p class="wp-block-paragraph">Yes, there&#8217;s a bit of upfront setup involved but once that&#8217;s out of the way, day-to-day management becomes significantly less painful, especially for the workloads. The operator sits inside your cluster and keeps an eye on things, picking up on any Kubernetes resource changes and making sure your Tailscale network reflects those changes accordingly.</p>



<p class="wp-block-paragraph">My use case is as follows: I&#8217;ve installed ArgoCD at home and want to access it through my Tailnet. In this blog, the example will focus on an Nginx pod, but the principle is exactly the same. We&#8217;re not making any changes whatsoever to the pods or deployments; only the Services matter.</p>



<p class="wp-block-paragraph">Let me guide you through the configuration of the Tailscale Operator and see how convenient it is. You&#8217;ll love it, I swear!</p>



<p class="wp-block-paragraph"></p>



<h2 id="h-step-1-set-up-an-acl-policy" class="wp-block-heading">Step 1: Set up an ACL policy</h2>



<p class="wp-block-paragraph">Before anything else, you&#8217;ll need to set up some new ACL policy rules in Tailscale, this allows any tailnet devices that the operator spins up to be identified as belonging to your Tailnet.</p>



<p class="wp-block-paragraph">Login to your Tailscale admin section &#8211;&gt; Access Controls &#8211;&gt; Tags</p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e1dce&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e1dce" class="wp-block-image size-large wp-lightbox-container"><img fetchpriority="high" decoding="async" width="1024" height="460" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-23-1024x460.png" alt="Setup ACL policy" class="wp-image-45230" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-23-1024x460.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-23-300x135.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-23-768x345.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-23.png 1157w" sizes="(max-width: 1024px) 100vw, 1024px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<h3 id="h-create-the-2-tags" class="wp-block-heading">Create the 2 tags:</h3>



<p class="wp-block-paragraph">You&#8217;ll need to define 2 tags: <strong>k8s-operator</strong> and <strong>k8s</strong>. <br>Make sure <strong>k8s-operator</strong> is set as an owner of <strong>k8s</strong></p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<figure data-wp-context="{&quot;galleryId&quot;:&quot;6a6702b3e2194&quot;}" data-wp-interactive="core/gallery" class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e2541&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e2541" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" width="472" height="342" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" data-id="45238" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-31.png" alt="Create tag" class="wp-image-45238" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-31.png 472w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-31-300x217.png 300w" sizes="(max-width: 472px) 100vw, 472px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>
</figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<figure data-wp-context="{&quot;galleryId&quot;:&quot;6a6702b3e28f5&quot;}" data-wp-interactive="core/gallery" class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e2c72&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e2c72" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" width="470" height="342" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" data-id="45239" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-32.png" alt="Create tag with owner" class="wp-image-45239" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-32.png 470w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-32-300x218.png 300w" sizes="(max-width: 470px) 100vw, 470px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>
</figure>
</div>
</div>



<p class="wp-block-paragraph">If you open the JSON editor tab, the equivalent in JSON format should be this:</p>



<pre class="wp-block-code"><code>{
  "tagOwners": {
	"tag:k8s-operator": &#091;],
	"tag:k8s": &#091;"tag:k8s-operator"]
  }
}</code></pre>



<p class="wp-block-paragraph"></p>



<h2 id="h-step-2-create-an-oauth-client" class="wp-block-heading">Step 2: Create an OAuth client</h2>



<p class="wp-block-paragraph">Your operator needs an OAuth client to authenticate to your Tailnet and register new pods and services.</p>



<p class="wp-block-paragraph">Navigate to the admin console&#8217;s Settings &#8211;&gt; Trust credentials &#8211;&gt; Add Credential :</p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e3531&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e3531" class="wp-block-image size-large wp-lightbox-container"><img loading="lazy" decoding="async" width="1024" height="467" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-45-1024x467.png" alt="Createa an OAuth credential" class="wp-image-45266" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-45-1024x467.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-45-300x137.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-45-768x350.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-45.png 1160w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<p class="wp-block-paragraph">Choose OAuth, give your auth key a name, click continue.</p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e3a6f&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e3a6f" class="wp-block-image size-full wp-lightbox-container"><img loading="lazy" decoding="async" width="593" height="368" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-39.png" alt="New OAuth credential" class="wp-image-45257" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-39.png 593w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-39-300x186.png 300w" sizes="auto, (max-width: 593px) 100vw, 593px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<p class="wp-block-paragraph">Give <strong>Read+Write</strong> permissions under the &#8220;<strong>Devices</strong>&#8221; section.</p>



<p class="wp-block-paragraph">Deploy the Keys section and add <strong>Read+Write</strong> permissions to the <strong>Auth Keys</strong> parameters.</p>



<p class="wp-block-paragraph">Select the&nbsp;<code>tag:k8s-operator</code>&nbsp;tag created earlier from the dropdown to ensure devices created by the operator will have the tag assigned.</p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e4093&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e4093" class="wp-block-image size-full wp-lightbox-container"><img loading="lazy" decoding="async" width="612" height="795" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-40.png" alt="OAuth Devices setup" class="wp-image-45259" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-40.png 612w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-40-231x300.png 231w" sizes="auto, (max-width: 612px) 100vw, 612px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e4612&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e4612" class="wp-block-image size-full wp-lightbox-container"><img loading="lazy" decoding="async" width="619" height="877" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-41.png" alt="OAuth keys settings" class="wp-image-45260" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-41.png 619w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-41-212x300.png 212w" sizes="auto, (max-width: 619px) 100vw, 619px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow"></div>
</div>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="518" height="353" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-42.png" alt="OAuth credential example" class="wp-image-45261 size-full" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-42.png 518w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-42-300x204.png 300w" sizes="auto, (max-width: 518px) 100vw, 518px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Once you click &#8220;Generate credential&#8221;, a pop-up window displays the key. Make sure to copy it in a safe place as it won&#8217;t be shown again.</p>
</div></div>



<p class="wp-block-paragraph"></p>



<h2 id="h-step-3-install-the-operator-on-your-kubernetes-cluster" class="wp-block-heading">Step 3: Install the Operator on your Kubernetes cluster</h2>



<ul class="wp-block-list">
<li>Add the helm repository</li>
</ul>



<pre class="wp-block-code"><code># Add the repository
$ helm repo add tailscale https://pkgs.tailscale.com/helmcharts

# Update your client’s package list
$ helm repo update</code></pre>



<ul class="wp-block-list">
<li>Run the helm install command to install the tailscale-operator</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
$ helm upgrade --install tailscale-operator tailscale/tailscale-operator \
  --namespace=tailscale \
  --create-namespace \
  --set-string oauth.clientId=&lt;oauth_client_id&gt; \
  --set-string oauth.clientSecret=&lt;oauth_client_secret&gt; \
  --wait
</pre></div>


<p class="wp-block-paragraph">Replace the <strong><code>&lt;oauth_client_id&gt;</code></strong> and <strong><code>&lt;oauth_client_secret&gt;</code></strong> placeholders with the actual values you copied down at the end of the previous step.</p>



<ul class="wp-block-list">
<li>After a few seconds, check that the operator&#8217;s pod is up:</li>
</ul>



<pre class="wp-block-code"><code>rancher:~ # kubectl get pods -n tailscale
NAME                        READY   STATUS    RESTARTS       AGE
operator-7699b5555b-v6wgw   1/1     Running   20 (16h ago)   55d</code></pre>



<ul class="wp-block-list">
<li>Log into your Tailscale account and you should see the operator as a machine:</li>
</ul>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e5113&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e5113" class="wp-block-image size-large wp-lightbox-container"><img loading="lazy" decoding="async" width="1024" height="345" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-37-1024x345.png" alt="Tailscale operator seen as a new machine in your Tailnet" class="wp-image-45249" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-37-1024x345.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-37-300x101.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-37-768x259.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-37.png 1142w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<p class="wp-block-paragraph"></p>



<h2 id="h-step-4-expose-your-kubernetes-services-easily" class="wp-block-heading">Step 4: Expose your Kubernetes services easily</h2>



<p class="wp-block-paragraph">For the purpose of this article, we&#8217;ll keep things simple: we&#8217;re just going to walk through a basic example that exposes an nginx service in your tailnet.</p>



<pre class="wp-block-code"><code>apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx
  labels:
    app: nginx
spec:
  replicas: 1
  selector:
    matchLabels:
      app: nginx
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
        - name: nginx
          image: nginx:latest
          ports:
            - containerPort: 80

---

apiVersion: v1
kind: Service
metadata:
  name: nginx
  annotations:
    tailscale.com/expose: "true"
spec:
  selector:
    app: nginx
  ports:
    - port: 80
      targetPort: 80</code></pre>



<p class="wp-block-paragraph">Take a closer look at the Service part of the YAML file. The key element here is the <code>tailscale.com/expose</code> annotation, sitting under the service&#8217;s <code>metadata.annotations</code> field. </p>



<p class="wp-block-paragraph">That single annotation is all it takes to automatically expose the service in your Tailnet. <br>Once you apply it to your cluster, the Tailscale Operator picks it up on its own and takes care of setting up the appropriate route behind the scenes.</p>



<p class="wp-block-paragraph">Set it to &#8220;true&#8221; if you want to expose the service and to &#8220;false&#8221; if not, it&#8217;s that easy!</p>



<p class="wp-block-paragraph">Log back into your Tailscale account, you should see the service as a new device and your nginx pod should be exposed and reachable via its Tailscale IP address !<br></p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a6702b3e58b2&quot;}" data-wp-interactive="core/image" data-wp-key="6a6702b3e58b2" class="wp-block-image size-large wp-lightbox-container"><img loading="lazy" decoding="async" width="1024" height="342" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-38-1024x342.png" alt="" class="wp-image-45252" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-38-1024x342.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-38-300x100.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-38-768x257.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-38.png 1140w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="813" height="543" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-43.png" alt="" class="wp-image-45263" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-43.png 813w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-43-300x200.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/06/image-43-768x513.png 768w" sizes="auto, (max-width: 813px) 100vw, 813px" /></figure>



<p class="wp-block-paragraph">That&#8217;s it. <br>From now on, whatever you deploy in your Kubernetes cluster, and as long as it has the right annotation, will be detected by the Tailscale operator and exposed to your tailnet.</p>



<p class="wp-block-paragraph">Cool, no?</p>
<p>L’article <a href="https://www.dbi-services.com/blog/expose-your-kubernetes-pods-to-your-via-tailnet-using-tailscale-operator/">Expose your Kubernetes pods to your Tailnet using Tailscale operator</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/expose-your-kubernetes-pods-to-your-via-tailnet-using-tailscale-operator/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Overcoming RDP connection issues on Windows 11</title>
		<link>https://www.dbi-services.com/blog/overcoming-rdp-connection-issues-on-windows11/</link>
					<comments>https://www.dbi-services.com/blog/overcoming-rdp-connection-issues-on-windows11/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Wed, 04 Feb 2026 15:23:03 +0000</pubDate>
				<category><![CDATA[Operating systems]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MobaXterm]]></category>
		<category><![CDATA[RDP]]></category>
		<category><![CDATA[Windows 11]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=42789</guid>

					<description><![CDATA[<p>The problem: I faced an issue today where one of my colleagues was struggling to remotely connect to a Windows server via RDP. He was using the default Remote Desktop app that comes standard with Windows 11 and everytime he&#8217;d connect, the application would hang at login. Something between 2 to 4 minutes, until he [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/overcoming-rdp-connection-issues-on-windows11/">Overcoming RDP connection issues on Windows 11</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-the-problem">The problem:</h2>



<p class="wp-block-paragraph">I faced an issue today where one of my colleagues was struggling to remotely connect to a Windows server via RDP.</p>



<p class="wp-block-paragraph">He was using the default Remote Desktop app that comes standard with Windows 11 and everytime he&#8217;d connect, the application would hang at login. Something between 2 to 4 minutes, until he could finally type his password and access his remote machine.</p>



<p class="wp-block-paragraph">Even after checking our firewall rules inside out, tracing his connections, nothing obvious could be found.</p>



<h2 class="wp-block-heading" id="h-the-checks">The checks:</h2>



<p class="wp-block-paragraph">I then decided to run a bunch of tests:</p>



<ul class="wp-block-list">
<li>1st test &#8211; Connection from a Mac:</li>
</ul>



<p class="wp-block-paragraph">I tried accessing the remote server from my Mac using &#8220;Windows App&#8221;, no issues at all. The connection to the remote host works like a charm.</p>



<ul class="wp-block-list">
<li>2st test &#8211; Connection from an old laptop running Windows10:</li>
</ul>



<p class="wp-block-paragraph">We still had an old laptop running Windows10 in the office, I wanted to give it a try. There again, no issue. The connection is lightning fast.</p>



<p class="wp-block-paragraph">Even chatGPT was about to give up, after suggesting in turn, to check:<br>&#8211; IPv6 timeout<br>&#8211; Disable auto-redirect of local devices (printers, drives, smart cards&#8230;)<br>&#8211; Reverse DNS lookup delay<br>&#8211; Kerberos delay<br>&#8211; Windows Defender<br>&#8211; Power throttling<br>&#8211; &#8230;</p>



<p class="wp-block-paragraph">It turns out that none of these suggestions actually worked.</p>



<p class="wp-block-paragraph">As I am writing this article, I am still not sure what the root cause is. For sure, it is the Windows Remote Desktop application that either waits for a timeout of some sort or another child process preventing Remote Desktop to initiate the connection in a timely manner.</p>



<p class="wp-block-paragraph">I&#8217;d put my 2 cents on Windows Security having to do with the problem, but I can&#8217;t really prove it at this stage.</p>



<h2 class="wp-block-heading" id="h-the-solution">The Solution:</h2>



<p class="wp-block-paragraph">Just do not use Remote Desktop with Windows 11 <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /><br>I downloaded <a href="https://mobaxterm.mobatek.net/download.html">MobaXterm</a>, opened a RDP connection to my remote host and it worked right away.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Yes, sometimes you just spend a lot of time trying to fix stuff&#8230; until you realize there isn&#8217;t much you can do about it.</p>



<p class="wp-block-paragraph"></p>
<p>L’article <a href="https://www.dbi-services.com/blog/overcoming-rdp-connection-issues-on-windows11/">Overcoming RDP connection issues on Windows 11</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/overcoming-rdp-connection-issues-on-windows11/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Access your Kubernetes pods via Tailscale using a Sidecar container</title>
		<link>https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/</link>
					<comments>https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Tue, 13 Jan 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[kubernetes]]></category>
		<category><![CDATA[speedtest-tracker]]></category>
		<category><![CDATA[tailscale]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=42364</guid>

					<description><![CDATA[<p>Tailscale is a mesh VPN (Virtual Private Network) service that streamlines connecting devices and services securely across different networks. It enables encrypted point-to-point connections using the open source WireGuard protocol, which means only devices on your private network can communicate with each other. (source: https://tailscale.com/kb/1151/what-is-tailscale) I’ve been using Tailscale to connect my personal devices for [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/">Access your Kubernetes pods via Tailscale using a Sidecar container</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Tailscale is a mesh VPN (Virtual Private Network) service that streamlines connecting devices and services securely across different networks. It enables encrypted point-to-point connections using the open source WireGuard protocol, which means only devices on your private network can communicate with each other. <br>(source: <a href="https://tailscale.com/kb/1151/what-is-tailscale">https://tailscale.com/kb/1151/what-is-tailscale</a>)</p>



<p class="wp-block-paragraph">I’ve been using Tailscale to connect my personal devices for a while. I have it installed almost everywhere: on my laptop, my phone, my Synology NAS, etc. It is very convenient as it helps me connect to any device, from anywhere. Tailscale adds a virtual interface to your device and manages its own IP address (you’ll understand why this is important in a minute)</p>



<p class="wp-block-paragraph">Tailscale automatically assigns a unique IP address to each device in your Tailscale network (known as a tailnet). This IP address is known as a Tailscale IP address and comes from the shared address space defined in RFC6598, known as Carrier-Grade NAT (CGNAT). <br>(source: <a href="https://tailscale.com/kb/1015/100.x-addresses">https://tailscale.com/kb/1015/100.x-addresses</a>)</p>



<p class="wp-block-paragraph">Today, I’m taking it to the next level: I’d like to install Tailscale alongside one of my application pod and access the web interface my pod exposes, directly from my Tailscale network (aka Tailnet).</p>



<h2 class="wp-block-heading" id="h-the-challenge"><strong>The challenge:</strong></h2>



<p class="wp-block-paragraph">I’ve installed Tailscale on the VM hosting my Kubernetes cluster (it’s a 1 node cluster, just for playing). Cool, I can access the VM from any other device. However, what about the web app my pod provides? How can I access it from my Tailnet?<br><br>As mentioned before, Tailscale has its own IP addressing, using 100.x.y.z addresses : your devices are assigned an IP from this address space.</p>



<p class="wp-block-paragraph">Moreover, the network interface Tailscale creates (tailscale0) is not a standard interface and Kubernetes cannot simply expose services through that interface as for any other NodePort. To do so, you need to deploy Tailscale in your Kubernetes cluster.</p>



<p class="wp-block-paragraph">Let’s do that.</p>



<h2 class="wp-block-heading" id="h-the-options"><strong>The options:</strong></h2>



<p class="wp-block-paragraph" id="h-the-options-tailscale-offers-several-options-to-connect-your-cluster-to-your-tailnet">Tailscale offers several options to connect your cluster to your tailnet:</p>



<ul class="wp-block-list">
<li><strong>Proxy</strong>: Tailscale proxies traffic to one of your Kubernetes services. Your tailnet devices can communicate with the service but not with any other Kubernetes resources. Tailscale users can reach the service using the proxy&#8217;s name.</li>



<li><strong>Sidecar</strong>: Tailscale runs as a sidecar next to a specific pod in your cluster. It lets you expose that pod on your tailnet without allowing access to any others. Tailscale users can connect to the pod using its name.</li>



<li><strong>Subnet router</strong>: A subnet router deployment exposes your entire cluster network in your tailnet. Your Tailscale devices can connect to any pod or service in your cluster, provided that applicable Kubernetes network policies and Tailscale access controls allow it.</li>
</ul>



<p class="wp-block-paragraph">My use-case is to expose a specific pod to my tailnet (my speedtest-tracker app frontend), the “sidecar” option is then enough for my need.<br>Let’s see how to configure that together.<br><br>I invite you to read <a href="https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/">my other blog about speedtest-tracker</a>. This is the app we are going to work with today.<br>I’ve been using speedtest-tracker for a while, but the app is only available from within my local network for now. Let’s see how to adapt my app’s deployment definition to add the Tailscale sidecar container.</p>



<h2 class="wp-block-heading" id="h-what-we-need"><strong>What we need:</strong></h2>



<ol class="wp-block-list">
<li>An application (that’s my speedtest-tracker app that already exists)</li>



<li>To generate an auth key that will be used by the Tailscale service deployed into the cluster</li>



<li>A secret with this auth key value in my cluster, for my pod to authenticate to my Tailscale account.</li>



<li>A service account, role and role binding to configure RBAC for my deployment ( my pod will use this service account and RBAC permissions to interact with the cluster)</li>



<li>Finally, I will add the sidecar container running Tailscale alongside my speedtest-tracker app container</li>
</ol>



<h2 class="wp-block-heading" id="h-generate-an-auth-key">Generate an auth key</h2>



<p class="wp-block-paragraph">First, let’s generate the auth key from my Tailscale account web interface. <br>This is done under Settings &#8211;&gt; Keys &#8211;&gt; Generate auth key…</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-1024x645.png" alt="" class="wp-image-42368" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-1024x645.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-300x189.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-768x483.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-1536x967.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky-2048x1289.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Fill out the form, and make the key reusable. Then configure the device this key applies to as ephemeral (so is your pod).<br>Copy the key value somewhere as we are going to need it in a moment.</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="508" height="708" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky2.png" alt="" class="wp-image-42369" style="width:418px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky2.png 508w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/BLOG-auth-ky2-215x300.png 215w" sizes="auto, (max-width: 508px) 100vw, 508px" /></figure>



<h2 class="wp-block-heading" id="h-create-a-secret">Create a secret</h2>



<p class="wp-block-paragraph">I create my secret, here is my tailscale-secret.yaml file:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: yaml; title: ; notranslate">
apiVersion: v1
kind: Secret
metadata:
  name: tailscale-auth
stringData:
  TS_AUTHKEY: &lt;my key value from previous step&gt;
</pre></div>


<p class="wp-block-paragraph">I apply the configuration to my speedtest namespace:</p>



<pre class="wp-block-code"><code>kubectl apply -f tailscale-secret.yaml -n speedtest</code></pre>



<h2 class="wp-block-heading">Service account, role and role binding</h2>



<p class="wp-block-paragraph">Next step is to configure RBAC for my Tailscale deployment. I need a service account, a role and role binding. Lucky me, Tailscale doc is well written, all I need is to follow their instructions.</p>



<p class="wp-block-paragraph">I create a manifest called tailscale-rbac.yaml:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: yaml; title: ; notranslate">
apiVersion: v1
kind: ServiceAccount
metadata:
  name: tailscale

---

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: tailscale
rules:
  - apiGroups: &#x5B;&quot;&quot;]
    resourceNames: &#x5B;&quot;tailscale-auth&quot;]
    resources: &#x5B;&quot;secrets&quot;]
    verbs: &#x5B;&quot;get&quot;, &quot;update&quot;, &quot;patch&quot;]

---

apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: tailscale
subjects:
  - kind: ServiceAccount
    name: tailscale
roleRef:
  kind: Role
  name: tailscale
  apiGroup: rbac.authorization.k8s.io
</pre></div>


<p class="wp-block-paragraph">I apply the configuration to my speedtest namespace:</p>



<pre class="wp-block-code"><code>kubectl apply -f tailscale-rbac.yaml -n speedtest</code></pre>



<h2 class="wp-block-heading" id="h-add-the-sidecar-container-to-my-deployment">Add the sidecar container to my deployment</h2>



<p class="wp-block-paragraph">Last step is to adapt my existing deployment to add the tailscale sidecar container.</p>



<p class="wp-block-paragraph">Under the spec section, we need to assign the serviceAccount created previously, to the pod:</p>



<pre class="wp-block-code"><code>serviceAccountName: tailscale</code></pre>



<p class="wp-block-paragraph">Then I create the sidecar container as per the tailscale documentation</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: yaml; title: ; notranslate">
apiVersion: apps/v1
kind: Deployment
metadata:
  name: speedtest-tracker
spec:
  replicas: 1
  revisionHistoryLimit: 0
  selector:
    matchLabels:
      app: speedtest-tracker
  template:
    metadata:
      labels:
        app: speedtest-tracker
    spec:
      serviceAccountName: tailscale  ## &lt;-- Add the Service Account Name
      containers:
        ##### Tailscal sidecar container definition#######
        - name: tailscale-sidecar
          image: ghcr.io/tailscale/tailscale:latest
          env:
            - name: TS_KUBE_SECRET
              value: tailscale-auth
            - name: TS_AUTHKEY
              valueFrom:
                secretKeyRef:
                  name: tailscale-auth
                  key: TS_AUTHKEY
            - name: TS_USERSPACE
              value: &quot;false&quot;
          securityContext:
            capabilities:
              add:
               - NET_ADMIN
        ######################

        - name: speedtest-tracker
          image: lscr.io/linuxserver/speedtest-tracker:latest
          ports:
            - containerPort: 80
          env:
            - name: PUID
              value: &quot;1000&quot;
            - name: PGID
              value: &quot;1000&quot;
            - name: DB_CONNECTION
              value: pgsql
            - name: DB_HOST
              value: postgres
            - name: DB_PORT
              value: &quot;5432&quot;
            - name: DB_DATABASE
              value: speedtest_tracker
            - name: DB_USERNAME
              value: speedy
            - name: DB_PASSWORD
              value: password

          volumeMounts:
            - mountPath: /config
              name: speedtest-tracker
      volumes:
        - name: speedtest-tracker
          persistentVolumeClaim:
            claimName: speedtest-tracker

</pre></div>


<p class="wp-block-paragraph">I apply the configuration to my speedtest namespace:</p>



<pre class="wp-block-code"><code>kubectl apply -f speedtest-tracker.yaml -n speedtest</code></pre>



<p class="wp-block-paragraph">Quick check, my speedtest-tracker pod is now running with 2 containers inside:</p>



<pre class="wp-block-code"><code>Rancher:~/syno/speedtest # kubectl get pods -n speedtest
NAME                                READY   STATUS    RESTARTS   AGE
postgres-7958dd877c-f4d2l           1/1     Running   0          22h
speedtest-tracker-8975967cd-s2fmc   2/2     Running   0          105m
</code></pre>



<p class="wp-block-paragraph">And that’s it!</p>



<p class="wp-block-paragraph">I can now access my app from both networks : my local network and my tailnet.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="499" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-1-1024x499.png" alt="" class="wp-image-42377" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-1-1024x499.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-1-300x146.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-1-768x375.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-1.png 1384w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">My pod is now seen as a device in my Tailscale network and can communicate with my other machines.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="904" height="534" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-2.png" alt="" class="wp-image-42378" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-2.png 904w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-2-300x177.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2026/01/Picture-2-768x454.png 768w" sizes="auto, (max-width: 904px) 100vw, 904px" /></figure>



<h2 class="wp-block-heading" id="h-conclusion">Conclusion</h2>



<p class="wp-block-paragraph">What we&#8217;ve done is to turn our Pod into a Tailscale node by injecting a WireGuard interface into the Pod’s shared network namespace, with the help of a tailscale sidecar container. This allows encrypted traffic to flow directly to the app container without Kubernetes Services or Ingress.</p>



<p class="wp-block-paragraph">This is it, I hope you enjoyed reading this blog and that you learned something new.</p>



<p class="wp-block-paragraph"> If so, drop a like, it&#8217;s always appreciated 😉</p>



<p class="wp-block-paragraph">To go further, please visit the Tailscale official documentation that will take you through all the steps and options to configure your tailnet on Kubernetes:<br><a href="https://tailscale.com/learn/managing-access-to-kubernetes-with-tailscale#sidecar-deployments">https://tailscale.com/learn/managing-access-to-kubernetes-with-tailscale#sidecar-deployments</a></p>



<p class="wp-block-paragraph"></p>
<p>L’article <a href="https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/">Access your Kubernetes pods via Tailscale using a Sidecar container</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/access-your-kubernetes-pods-via-tailscale-using-a-sidecar-container/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Monitor your ISP&#8217;s performance with Speedtest Tracker</title>
		<link>https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/</link>
					<comments>https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Tue, 05 Aug 2025 07:30:00 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[rke2]]></category>
		<category><![CDATA[speedtest]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=39861</guid>

					<description><![CDATA[<p>I recently changed ISP, and I wanted to monitor its performance and make sure I get what I&#8217;m paying for. I initially started writing a bash script that I was running in a crontab, then writing the results in an md file. But that&#8217;s not very sexy. I wanted something graphical with a nice UI. [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/">Monitor your ISP&#8217;s performance with Speedtest Tracker</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I recently changed ISP, and I wanted to monitor its performance and make sure I get what I&#8217;m paying for. I initially started writing a bash script that I was running in a crontab, then writing the results in an md file. <br>But that&#8217;s not very sexy. I wanted something graphical with a nice UI.</p>



<p class="wp-block-paragraph">It turns out that there is a project called <a href="https://github.com/alexjustesen/speedtest-tracker">Speedtest-tracker</a>, written and maintained by <a href="https://www.linkedin.com/in/alexander-justesen/">Alex Justesen</a> on GitHub that does just what I was looking for. Behind the scenes, speedtest-tracker uses the <a href="https://www.speedtest.net/apps/cli">official Ookla CLI</a>.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">Speedtest Tracker is a self-hosted application that monitors the performance and uptime of your internet connection. Built using Laravel and Speedtest CLI from Ookla®, deployable with Docker.</p>
</blockquote>



<p class="wp-block-paragraph">The cool thing is that Speedtest Tracker is containerized; you can run it anywhere you want! At first, I had installed it as a Docker container on my Synology, but the NAS I own only has 1Gbps Ethernet ports, and my ISP advertises DL/UL speeds of 5 Gbps / 900 Mbps</p>



<p class="wp-block-paragraph">I have a mini PC that I use for my <a href="https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/">YaK projects</a>, which embeds a 2.5Gbps Ethernet card. I&#8217;d rather use this machine than the NAS. Even though I will not be able to test the full speed my ISP provides, at least I will be able to see if I get near 2.5Gbps, which is already a great download speed.</p>



<p class="wp-block-paragraph">OK, enough talking, let&#8217;s get our hands dirty and let&#8217;s deploy Speedtest-tracker!</p>



<h2 class="wp-block-heading" id="h-your-list-of-ingredients">Your list of ingredients</h2>



<p class="wp-block-paragraph">Here is what you need to add to your recipe:</p>



<ul class="wp-block-list">
<li>A hypervisor, in my case I&#8217;m using Proxmox</li>



<li>A virtual machine (on which I&#8217;m using SUSE Linux, but any distro will work just fine)</li>



<li>A Kubernetes cluster. Keep it simple, <a href="https://docs.rke2.io/install/quickstart">install a single node RKE2</a></li>



<li>A persistent volume: <a href="https://github.com/rancher/local-path-provisioner">local-path provisioner</a> does the job</li>
</ul>



<p class="wp-block-paragraph">I&#8217;m passing these steps here, but you can find them in <a href="https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/">my other blog</a> dedicated to installing the YaK, if you need.</p>



<p class="wp-block-paragraph">Everything is well documented on <a href="https://docs.speedtest-tracker.dev/">Speedtest tracker web page</a></p>



<p class="wp-block-paragraph">There is already a <a href="https://github.com/maximemoreillon/kubernetes-manifests/tree/master/speedtest-tracker">community manifest</a> available for Kubernetes, written and maintained by <a href="https://github.com/maximemoreillon">Maxime Moreillon</a>.</p>



<h2 class="wp-block-heading" id="h-how-to-install-speedtest-tracker">How to install speedtest-tracker?</h2>



<p class="wp-block-paragraph">Installing speedtest tracker is as simple as deploying 2 yaml files:</p>



<ul class="wp-block-list">
<li>1 for the postgreSQL database</li>



<li>1 for the frontend app</li>
</ul>



<p class="wp-block-paragraph">The PG database and the application manifests are available <a href="https://github.com/maximemoreillon/kubernetes-manifests/tree/master/speedtest-tracker">here</a>.<br>All the credit goes to <a href="https://github.com/maximemoreillon">Maxime Moreillon</a>, who wrote these manifests and made them available to the community.<br>All I had to do was save the files to my &#8220;speedtest&#8221; folder and adjust them to my context.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~ # cd speedtest
localhost:~/speedtest # ls -ltrh
total 8.0K
-rw-r--r-- 1 root root 1.1K Jul 29 16:29 postgres.yaml
-rw-r--r-- 1 root root 2.2K Aug  3 18:48 speedtest-tracker.yaml
</pre></div>


<h3 class="wp-block-heading" id="h-my-postgres-manifest">My Postgres manifest </h3>



<p class="wp-block-paragraph">I haven&#8217;t changed a single line from Maxime Moreillon&#8217;s code. The manifest includes the PVC definition, the PostgreSQL deployment itself, and a service:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: yaml; title: ; notranslate">
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: postgres
spec:
  accessModes:
    - ReadWriteOnce
  resources:
    requests:
      storage: 50Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: postgres
spec:
  replicas: 1
  selector:
    matchLabels:
      app: postgres
  template:
    metadata:
      labels:
        app: postgres
    spec:
      containers:
        - name: postgres
          image: postgres:15.1
          env:
            - name: POSTGRES_PASSWORD
              value: password
            - name: POSTGRES_DB
              value: speedtest_tracker
            - name: POSTGRES_USER
              value: speedy
          volumeMounts:
            - mountPath: /var/lib/postgresql/data
              name: postgres
      volumes:
        - name: postgres
          persistentVolumeClaim:
            claimName: postgres

---
apiVersion: v1
kind: Service
metadata:
  name: postgres
spec:
  ports:
    - port: 5432
  selector:
    app: postgres
  type: ClusterIP
</pre></div>


<h3 class="wp-block-heading" id="h-my-speedtest-tracker-manifest">My speedtest-tracker manifest </h3>



<p class="wp-block-paragraph">With a few adjustments from Maxime&#8217;s code to fit my needs. It comes with the PVC definition, the application deployment, and the service:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: yaml; title: ; notranslate">
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: speedtest-tracker
spec:
  accessModes:
    - ReadWriteOnce
  resources:
    requests:
      storage: 5Gi
  storageClassName: local-path  # Adjust if you&#039;re using a different StorageClass

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: speedtest-tracker
spec:
  replicas: 1
  revisionHistoryLimit: 0
  selector:
    matchLabels:
      app: speedtest-tracker
  template:
    metadata:
      labels:
        app: speedtest-tracker
    spec:
      containers:
        - name: speedtest-tracker
          image: lscr.io/linuxserver/speedtest-tracker:latest
          ports:
            - containerPort: 80
          env:
            - name: PUID
              value: &quot;1000&quot;
            - name: PGID
              value: &quot;1000&quot;
            - name: DB_CONNECTION
              value: pgsql
            - name: DB_HOST
              value: postgres
            - name: DB_PORT
              value: &quot;5432&quot;
            - name: DB_DATABASE
              value: speedtest_tracker
            - name: DB_USERNAME
              value: speedy
            - name: DB_PASSWORD
              value: password

########MY PERSONAL ENV VARIABLES########
            - name: APP_NAME
              value: home-speedtest-k8s
            - name: APP_KEY
              value: &lt;generate your own app key&gt;
            - name: DISPLAY_TIMEZONE
              value: Europe/Paris
            - name: SPEEDTEST_SERVERS
              value: &quot;62493&quot;
            - name: SPEEDTEST_SCHEDULE
              value: &#039;*/30 * * * *&#039;
            - name: PUBLIC_DASHBOARD
              value: &quot;true&quot;
#########################################

          volumeMounts:
            - mountPath: /config
              name: speedtest-tracker
      volumes:
        - name: speedtest-tracker
          persistentVolumeClaim:
            claimName: speedtest-tracker

---
apiVersion: v1
kind: Service
metadata:
  name: speedtest-tracker
  labels:
    app: speedtest-tracker
spec:
  selector:
    app: speedtest-tracker
  type: NodePort
  ports:
    - name: http
      port: 80
      targetPort: 80
      nodePort: 30080  # You can change this to any port in the 30000-32767 range
</pre></div>


<p class="wp-block-paragraph">Now, generate your own APP KEY and paste the value in the placeholder in the code above (including the <code>base64:</code> prefix), here is how:</p>



<pre class="wp-block-code"><code>
echo -n 'base64:'; openssl rand -base64 32;</code></pre>



<p class="wp-block-paragraph">And that&#8217;s it!<br>Once your manifests are ready and once you are happy with the environment variables you want (the list of env. variables is <a href="https://docs.speedtest-tracker.dev/getting-started/environment-variables">available here</a>), you just need to create your namespace on your cluster and apply the configuration:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
kubectl create ns speedtest
kubectl apply -f speedtest/postgres.yaml -n speedtest
kubectl apply -f speedtest/speedtest-racker.yaml -n speedtest
</pre></div>


<p class="wp-block-paragraph">After a few seconds, your pods will come up:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~/speedtest # kubectl get pods -n speedtest
NAME                                 READY   STATUS    RESTARTS        AGE
postgres-6c8499b968-rbwlw            1/1     Running   2 (4d18h ago)   5d21h
speedtest-tracker-7997cbdc8f-64n7c   1/1     Running   0               19h
</pre></div>


<h2 class="wp-block-heading" id="h-enjoy">Enjoy !</h2>



<p class="wp-block-paragraph">If you did things right, you should be able to monitor your internet speed and display the results on a neat UI. In my case, I fire a speedtest every 30 minutes (I know, that&#8217;s overkill, but I just wanted to play a bit. I will reduce the frequency to something more reasonable, I promise <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /> )<br></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="601" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-1024x601.png" alt="Speedtest-tracker UI" class="wp-image-39874" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-1024x601.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-300x176.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-768x451.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-1536x901.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/08/image-1-2048x1201.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cool, no?</p>



<h2 class="wp-block-heading" id="h-to-go-further">To go further</h2>



<p class="wp-block-paragraph">I&#8217;d love to monitor the full bandwidth my ISP advertises, but I&#8217;m limited by my hardware: my router does not support link aggregation, and it only comes with one 10G fiber-optic WAN interface + one 2.5 Gbps and two 1Gbps LAN interfaces. There is no chance I can test the full fiber-optic capacity with this hardware.</p>



<p class="wp-block-paragraph">In the future, I might buy a switch that supports LACP and configure my router in bridge mode to be able to reach the full WAN bandwidth, or invest in a router that provides more high-speed interfaces. But to be honest, the investment is not really worth it.</p>



<p class="wp-block-paragraph">One thing I could do however would be to enable HTTPS and add a Let&#8217;s Encrypt certificate to secure the connections to my frontend. That&#8217;s an improvement I could make soon.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/">Monitor your ISP&#8217;s performance with Speedtest Tracker</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/monitor-your-isps-performance-with-speedtest-tracker/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Try YaK for free with YaK Demo</title>
		<link>https://www.dbi-services.com/blog/try-yak-for-free-with-yak-demo/</link>
					<comments>https://www.dbi-services.com/blog/try-yak-for-free-with-yak-demo/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Tue, 29 Jul 2025 07:40:00 +0000</pubDate>
				<category><![CDATA[YaK]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=39584</guid>

					<description><![CDATA[<p>dbi services makes free demo environments available to all, so that you can play with the YaK and deploy instances and components to Azure and AWS. The YaK Demo environment is hosted on one of dbi services AWS tenants and is automatically destroyed after 4 hours. The demo environment is not supposed to be used [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/try-yak-for-free-with-yak-demo/">Try YaK for free with YaK Demo</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">dbi services makes free demo environments available to all, so that you can play with the <a href="https://yak4all.io/">YaK</a> and deploy instances and components to Azure and AWS. The <a href="https://yak4all.io/demo">YaK Demo</a> environment is hosted on one of dbi services AWS tenants and is automatically destroyed <strong>after 4 hours</strong>.</p>



<p class="is-style-plain wp-block-paragraph"><em>The demo environment is not supposed to be used for production purpose (it’s just a demo and everything is scrubbed after 4 hours)</em><br><em>dbi services shall not be held liable for any data loss on this demo environmen</em>t.</p>



<h2 class="wp-block-heading" id="wanna-give-it-a-try"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#wanna-give-it-a-try"></a>Wanna give it a try?</h2>



<p class="wp-block-paragraph">To do so, simply connect to <a href="https://yak4all.io/demo/">https://yak4all.io/demo/</a>, fill in the form and you will receive a confirmation email from <strong>no-reply@dbi-services.com</strong>.</p>



<p class="wp-block-paragraph">Please allow 5 to 10 minutes for the environment to be provisioned and the YaK to spin up. Once up and running you&#8217;ll receive a second email from <strong>no-reply@demo.yak4all.io</strong> with the URL and credentials to connect to your YaK.</p>



<p class="wp-block-paragraph">Check your inbox and junk mail to make sure you don&#8217;t miss out on your YaK experience!</p>



<h3 class="wp-block-heading" id="limitations"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#limitations"></a>Limitations</h3>



<p class="wp-block-paragraph">The demo environment we provision comes with the following restrictions (this will not be the case with a regular installation of YaK):</p>



<ul class="wp-block-list">
<li>AWS infrastructure:
<ul class="wp-block-list">
<li><strong>Available shapes</strong>: t3.micro, t3.small, t3.medium</li>



<li><strong>Available disk types:</strong> gp2, gp3</li>



<li><strong>Disk sizes:</strong> max 50gb</li>



<li><strong>Available component:</strong> PostgreSQL</li>



<li><strong>AWS Region:</strong> eu-west-1</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li>Azure infrastructure:
<ul class="wp-block-list">
<li><strong>Available shapes</strong>: Standard_B2s, Standard_B2ms</li>



<li><strong>Available disk types:</strong> Standard_LRS, StandardSSD_LRS</li>



<li><strong>Disk sizes:</strong> max 64gb</li>



<li><strong>Available component:</strong> PostgreSQL</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading" id="yak-login-page"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#yak-login-page"></a>YaK Login Page</h2>



<p class="wp-block-paragraph">Open the link received and log into the YaK with the credentials from the email.</p>


<div class="wp-block-image">
<figure class="aligncenter is-resized"><img decoding="async" src="https://dbi-services.gitbook.io/yak-user-doc/~gitbook/image?url=https%3A%2F%2F2436296891-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FMGFsptWcTlGb6Djq7qsZ%252Fuploads%252Fgit-blob-b9dc83c9accd5b35765d2050064ef9091960a0dc%252FYaK_login_page.png%3Falt%3Dmedia&amp;width=768&amp;dpr=4&amp;quality=100&amp;sign=3eab5c65&amp;sv=2" alt="YaK Login page" style="width:548px;height:auto" /></figure>
</div>


<h2 class="wp-block-heading" id="where-to-start"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#where-to-start"></a>Where to start?</h2>



<p class="wp-block-paragraph">Alright, you&#8217;re all set, your environment is ready. Let&#8217;s give it a try!</p>



<p class="wp-block-paragraph">We have pre-provisioned the YaK with a few things for you so that you can almost immediately deploy your servers and components:</p>



<ul class="wp-block-list">
<li>2 infrastructures have been pre-provisioned:
<ul class="wp-block-list">
<li>An AWS demo infrastructure:<strong> &#8220;aws-demo-1&#8221;</strong></li>



<li>A Microsoft Azure demo infrastructure: <strong>&#8220;azure-demo-1&#8221;</strong></li>
</ul>
</li>



<li>Cloud providers secrets have been attached to these infrastructures</li>



<li>A PostgreSQL component type is available to you</li>
</ul>



<h2 class="wp-block-heading" id="what-you-need-to-do-now"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#what-you-need-to-do-now"></a>What you need to do now</h2>



<p class="wp-block-paragraph">Well, we&#8217;ve thought of a scenario, but feel free to explore the YaK on your own if you prefer.</p>



<p class="wp-block-paragraph">Our use case here is to deploy a server to AWS or to Azure and then deploy a PostgreSQL database instance on it.</p>



<h3 class="wp-block-heading" id="id-1.-declare-a-ssh-key"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-1.-declare-a-ssh-key"></a>1. Declare a SSH key</h3>



<p class="wp-block-paragraph">In order to connect securely to the Linux servers once created, a pair of SSH keys must be generated and the <strong>private key</strong> must be transferred to the servers.</p>



<ul class="wp-block-list">
<li>Generate your SSH key:</li>
</ul>



<p class="wp-block-paragraph">SSH keys can be generated from any Linux-based machine running openSSH with the &#8220;ssh-keygen&#8221; command.</p>



<pre class="wp-block-code"><code>$ ssh-keygen -b 4096 -m PEM -t rsa -f my-ssh-key -q -N ""</code></pre>



<p class="wp-block-paragraph">Windows users can generate SSH keys using the PuTTYgen utility (<a href="https://dbi-services.gitbook.io/yak-user-doc/appendix/create-ssh-keys-with-puttygen">follow this link</a>)</p>



<ul class="wp-block-list">
<li>Copy the content of the <strong>private key</strong> file:</li>
</ul>



<pre class="wp-block-code"><code>$ cat my-ssh-key
##This is just an example, generate your own private key

-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABASDILVb1
MiZ78g848c6Dk6KYwkJZXloSIruLe+Sid0Xd+Lb1rAxbwzAhXWRMzzBT5k3WciXk2fMhUD
p4YSahpYvquZK950aXiZNDOJpKZP8wjf4g4nQyiJZ/0G0J9mIaI2h/fr8TA67KHYtu/Eyf
PN9bKJwII3aiGlu5/Viq2cgYT8jJ01AK8cY3tSqKdlrN2GyxllBFl42QplbxA2USPJ1E6v
VIjtbmJjdz&#091;...........................................]qAc4HxP02t/N2ZN
q+dDNWeShfVz4zjApPQCzdiGqLAlzUy67KNxQgljhaOEaYTQgrLE8XNGsIFNZwGvsEo/xZ
XnN2p
-----END OPENSSH PRIVATE KEY-----</code></pre>



<ol class="wp-block-list">
<li>Feed the YaK with the SSH key:
<ul class="wp-block-list">
<li>From the menu, navigate to <strong>Configuration</strong> -&gt; S<strong>ecrets</strong></li>



<li>Click &#8220;<strong>Declare</strong>&#8220;</li>



<li>Give a name to your secret (my-ssh-key)</li>



<li>Select &#8220;<strong>ssh key</strong>&#8221; as secret type</li>
</ul>
</li>



<li>Paste the entirety of the <strong>private key</strong> previously copied, into the corresponding field of the form</li>



<li>Click &#8220;<strong>Save</strong>&#8220;</li>
</ol>



<h3 class="wp-block-heading" id="id-2.-attach-your-ssh-secret"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-2.-attach-your-ssh-secret"></a>2. Attach your SSH key to the infrastructure</h3>



<ol class="wp-block-list">
<li>From the menu, navigate to &#8220;<strong>Infrastructures</strong>&#8220;</li>



<li>Select the infrastructure you would like to deploy to in the list (<strong>&#8220;aws-demo-1&#8221;</strong> or <strong>&#8220;azure-demo-1&#8221;</strong>)</li>



<li>Click the &#8220;<strong>Action</strong>&#8221; button</li>



<li>Click &#8220;<strong>Attach secret</strong>&#8220;</li>



<li>Select the SSH secret created in the previous step from the list</li>



<li>Click &#8220;<strong>Attach</strong>&#8220;</li>
</ol>



<h3 class="wp-block-heading" id="id-3.-declare-a-server"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-3.-declare-a-server"></a>3. Declare a server</h3>



<ol class="wp-block-list">
<li>Navigate to the &#8220;<strong>Servers</strong>&#8221; menu</li>



<li>Click &#8220;<strong>Declare</strong>&#8220;</li>



<li>Give it a name</li>



<li>Select the <strong>Infrastructure </strong>to deploy your server to (<strong>&#8220;aws-demo-1&#8221;</strong> or <strong>&#8220;azure-demo-1&#8221;</strong>)</li>



<li>Select an <strong>Image</strong> to install : let&#8217;s take Debian 12 for example</li>



<li>Select a server <strong>Shape</strong></li>



<li>Add custom tags as per your need (optional)</li>



<li>Network section:
<ul class="wp-block-list">
<li>Mode: <strong>automatic</strong></li>



<li>IP: <strong>leave blank</strong></li>



<li>Scope: <strong>public</strong></li>



<li>Tick the &#8220;Admin access&#8221; checkbox: this defines the IP address used to connect to the server for configuration purpose.</li>
</ul>
</li>



<li>Click <strong>Save</strong></li>
</ol>



<p class="wp-block-paragraph"><em>In Azure, VM names must be unique. Since we&#8217;re all sharing the same demo environment, avoid instance names that are too obvious and could conflict with other users&#8217; machines, such as “srv01”, ‘server1’, “myserver”, etc. Be creative to avoid potential conflicts with other users </em><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<h3 class="wp-block-heading" id="id-4.-deploy-server"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-4.-deploy-server"></a>4. Deploy your server</h3>



<ol class="wp-block-list">
<li>Select your server in the list</li>



<li>Click &#8220;<strong>Deploy</strong>&#8221; from the &#8220;<strong>Actions</strong>&#8221; menu</li>



<li>Confirm &#8220;<strong>Deploy</strong>&#8221; in the pop up box
<ul class="wp-block-list">
<li>Follow the deployment steps from the Jobs menu to see what the YaK is doing behind the scene. If you&#8217;ve followed the steps it should succeed (if not you must have missed something <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f604.png" alt="😄" class="wp-smiley" style="height: 1em; max-height: 1em;" />)</li>
</ul>
</li>



<li>Wait until the job status is <strong>&#8220;Successful&#8221;</strong></li>



<li>Your server should be started automatically and will soon be in a <strong>&#8220;running&#8221;</strong> state
<ul class="wp-block-list">
<li>You should already be able to connect to it via SSH by selecting the server and retrieving the <strong>public IP</strong> from the server parameters. (see step &#8220;7. Connect to your server&#8221;)</li>



<li>But hold your horses! Let&#8217;s deploy a component on it! (if you can&#8217;t wait, skip the component deployment and come back to it later, that&#8217;s OK)</li>
</ul>
</li>
</ol>



<h3 class="wp-block-heading" id="id-5.-declare-component"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-5.-declare-component"></a>5. Declare your component</h3>



<ol class="wp-block-list">
<li>Navigate to the &#8220;<strong>Components</strong>&#8221; menu</li>



<li>Click &#8220;<strong>Declare</strong>&#8220;</li>



<li>Give it a name (ex: PG01)</li>



<li>Select your component type (postgresql_instance)</li>



<li>Select your subcomponent type (standalone)
<ul class="wp-block-list">
<li>HA requires 3 servers be deployed, in this example we will consider a <strong>standalone</strong> setup as we have declared 1 server only</li>
</ul>
</li>



<li>Choose your Provider (here it will be <strong>aws </strong>or<strong> azure</strong>)</li>



<li>Select the <strong>PostgreSQL host</strong> where you want to deploy your database instance (the server created previously)</li>



<li>Fill in the <strong>&#8220;Instance name&#8221;</strong> field (ex: mypgdb)</li>



<li>Navigate to the <strong>&#8220;Storage&#8221;</strong> tab and fill in the required fields.
<ul class="wp-block-list">
<li>Set <strong>Max size of component disks</strong> for the 3 file systems:
<ul class="wp-block-list">
<li>/u01 -&gt; <strong>40GB</strong></li>



<li>/u02 -&gt; <strong>20GB</strong></li>



<li>/u90 -&gt; <strong>20GB</strong></li>
</ul>
</li>
</ul>
</li>



<li>Click &#8220;<strong>Save</strong>&#8220;</li>
</ol>



<h3 class="wp-block-heading" id="id-6.-deploy-component"><a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo#id-6.-deploy-component"></a>6. Deploy your component</h3>



<p class="wp-block-paragraph">Your PostgreSQL database instance is configured, now let&#8217;s deploy it:</p>



<ol class="wp-block-list">
<li>Select the component you&#8217;ve just configured from the list</li>



<li>Click &#8220;<strong>Actions</strong>&#8220;</li>



<li>Then click <strong>&#8220;Deploy a new PostgreSQL Standalone instance&#8221;</strong></li>



<li>Confirm your choice in the pop-up menu</li>



<li>Seat back, relax, follow the deployment steps from the <strong>jobs</strong> menu and wait until your component is successfully installed and configured.</li>
</ol>



<h3 class="wp-block-heading" id="h-7-connect-to-your-server-and-play-around">7. Connect to your server and play around</h3>



<ul class="wp-block-list">
<li>Open a SSH connection to the <strong>public IP address</strong> of your server:</li>
</ul>



<pre class="wp-block-code"><code>DEMOUSER@demo$ ssh -i my-ssh-key &lt;user&gt;@&lt;PUBLIC_IP&gt;</code></pre>



<ul class="wp-block-list">
<li>Your <code>PUBLIC_IP</code> address can be retrieved from <strong>Servers</strong> -&gt; <strong>Parameters</strong></li>



<li>User:
<ul class="wp-block-list">
<li><strong>Azure</strong> default user is <code>azureuser</code></li>



<li><strong>AWS</strong> default users (see <a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/managing-users.html">AWS doc</a> for more details):
<ul class="wp-block-list">
<li>The default user for debian based AMI is &#8220;<code>admin</code>&#8220;, but this could be something else, based on the AMI you selected.</li>



<li>For an Amazon Linux AMI, the username is <code>ec2-user</code>.</li>



<li>For a CentOS AMI, the username is <code>centos</code> or <code>ec2-user</code>.
<ul class="wp-block-list">
<li>For a Debian AMI, the username is <code>admin</code>.</li>



<li>For a Fedora AMI, the username is <code>fedora</code> or <code>ec2-user</code>.</li>



<li>For a RHEL AMI, the username is <code>ec2-user</code> or <code>root</code>.</li>



<li>For a SUSE AMI, the username is <code>ec2-user</code> or <code>root</code>.</li>



<li>For an Ubuntu AMI, the username is <code>ubuntu</code>.</li>



<li>For an Oracle AMI, the username is <code>ec2-user</code>.</li>



<li>For a Bitnami AMI, the username is <code>bitnami</code>.</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li>Play with your PostgreSQL database instance!</li>
</ul>



<pre class="wp-block-code"><code>admin@my-server1:~$ sudo su - postgres


 PostgreSQL Clusters up and running on this host:
 ----------------------------------------------------------------------------------------------
    mypgdb      -&gt;  /u02/pgdata/17/mypgdb                                    -&gt;  5432  ==&gt; OPEN

 PostgreSQL Clusters NOT running on this host:
 ----------------------------------------------------------------------------------------------

16:39:13 postgres@my-server1:/home/postgres/ &#091;pg17.2] psql -p 5432
psql (17.2 dbi services build)
Type "help" for help.

postgres=#</code></pre>



<p class="wp-block-paragraph">Thanks for reading this blog, for more info about the YaK, visit&nbsp;<a href="https://yak4all.io/">yak4all.io</a> or <a href="https://yak4all.io/contact/">contact us</a> directly.</p>



<p class="wp-block-paragraph">Read my <a href="https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/">other blog</a> if you&#8217;d like to install your own RKE2 Kubernetes cluster and your own YaK at home!<br><br>Happy YaKing <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /> !<br></p>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://yak4all.io/contact/">Contact the YaK team</a></div>



<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://yak4all.io/">Visit yak4all.io</a></div>
</div>



<p class="wp-block-paragraph"></p>
<p>L’article <a href="https://www.dbi-services.com/blog/try-yak-for-free-with-yak-demo/">Try YaK for free with YaK Demo</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/try-yak-for-free-with-yak-demo/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Install a single node Kubernetes cluster with SUSE RKE2 and deploy your own YaK instance</title>
		<link>https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/</link>
					<comments>https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Tue, 15 Jul 2025 07:30:00 +0000</pubDate>
				<category><![CDATA[YaK]]></category>
		<category><![CDATA[#yak]]></category>
		<category><![CDATA[kubernetes]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=39390</guid>

					<description><![CDATA[<p>I bought a mini PC last year and I use it as a home lab to test things and play around.So I thought, why not install a RKE2 Kubernetes cluster and deploy my own YaK instance on it? Let’s dive-in. In this article, I will explain how I installed a single node Kubernetes cluster with [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/">Install a single node Kubernetes cluster with SUSE RKE2 and deploy your own YaK instance</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I bought a mini PC last year and I use it as a home lab to test things and play around.<br>So I thought, why not install a RKE2 Kubernetes cluster and deploy my own YaK instance on it?</p>



<p class="wp-block-paragraph">Let’s dive-in.</p>



<p class="wp-block-paragraph">In this article, I will explain how I installed a single node Kubernetes cluster with SUSE RKE2 and deployed my own local YaK instance.</p>



<p class="wp-block-paragraph">Here is my setup:</p>



<ul class="wp-block-list">
<li>Intel NUC 13 Pro (with Intel Core i5-1340P)</li>



<li>64GB of RAM DDR4</li>



<li>1TB SSD</li>
</ul>



<p class="wp-block-paragraph">I’m using <a href="https://www.proxmox.com/en/">Proxmox</a> as a virtualisation platform on this mini PC, and I’ve chosen SUSE Leap 15.6 as the operating system for the virtual machine that will host my RKE2 installation.</p>



<h2 class="wp-block-heading" id="h-create-my-vm-in-proxmox">Create my VM in Proxmox</h2>



<p class="wp-block-paragraph">First, I created a VM and dedicated some resources to my instance.</p>



<p class="wp-block-paragraph">SUSE recommends at least 8GB of RAM and 4vCPU for RKE2 to run smoothly.</p>



<p class="wp-block-paragraph">Let’s start with that, I can adjust later if the system struggles.</p>



<p class="wp-block-paragraph">I added 50GB of storage, that should be more than enough (that’s a lot of storage, we really don’t need that much for the YaK itself, but I might reuse this VM for other purposes too)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="904" height="478" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-9.png" alt="" class="wp-image-39392" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-9.png 904w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-9-300x159.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-9-768x406.png 768w" sizes="auto, (max-width: 904px) 100vw, 904px" /></figure>



<p class="wp-block-paragraph">I’m passing the installation steps of SUSE Leap in server mode, as they are straightforward.<br>But, just in case, I&#8217;m adding the links to <a href="https://www.proxmox.com/en/products/proxmox-virtual-environment/get-started">Proxmox</a> and to <a href="https://doc.opensuse.org/documentation/leap/startup/html/book-startup/art-opensuse-installquick.html">SUSE Leap</a> install docs here.</p>



<h2 class="wp-block-heading" id="h-install-packages">Install packages</h2>



<p class="wp-block-paragraph">First of all, we need to install the following packages on the VM hosting the YaK:</p>



<ul class="wp-block-list">
<li>Tar</li>



<li>Git</li>



<li>Helm</li>
</ul>



<p class="wp-block-paragraph">Let’s check what is already installed by default with SUSE Leap 15.6:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; highlight: [12,20,25]; title: ; notranslate">
localhost:~ # zypper se --installed-only tar
Loading repository data...
Reading installed packages...

S  | Name                    | Summary                                          | Type
---+-------------------------+--------------------------------------------------+--------
i  | cantarell-fonts         | Contemporary Humanist Sans Serif Font            | package
i  | deltarpm                | Tools to Create and Apply deltarpms              | package
i  | shared-python-startup   | Startup script shared by all Python interpreters | package
i  | star                    | POSIX.1-2001-Compliant Tar Implementation        | package
i  | star-rmt                | Magnetic tape control and server                 | package
i  | tar                     | GNU implementation of ((t)ape (ar)chiver)        | package
i  | tar-lang                | Translations for package tar                     | package
i  | tar-rmt                 | Remote tape drive control server by GNU          | package
i  | zypper-needs-restarting | needs-restarting compatibility with zypper       | package

localhost:~ # zypper se --installed-only git
Loading repository data...
Reading installed packages...
No matching items found.

localhost:~ # zypper se --installed-only helm
Loading repository data...
Reading installed packages...
No matching items found.
</pre></div>


<p class="wp-block-paragraph">As you can see, <strong>Tar</strong> is already installed but not <strong>Git</strong> nor <strong>Helm</strong>. Let’s install them:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~ # zypper install git
localhost:~ # zypper install helm
</pre></div>


<h2 class="wp-block-heading" id="h-stop-firewalld">Stop firewalld</h2>



<p class="wp-block-paragraph">As a <a href="https://dbi-services.gitbook.io/yak-user-doc/installation/system-requirements">pre-requisite</a>, Firewalld must be stopped. <br>Let’s check its status:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; highlight: [4]; title: ; notranslate">
localhost:~ # systemctl status firewalld
● firewalld.service - firewalld - dynamic firewall daemon
     Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; preset: disabled)
     Active: active (running) since Wed 2025-04-30 12:12:43 CEST; 2h 7min ago
       Docs: man:firewalld(1)
   Main PID: 743 (firewalld)
      Tasks: 2 (limit: 4915)
        CPU: 349ms
     CGroup: /system.slice/firewalld.service
             └─743 /usr/bin/python3 /usr/sbin/firewalld --nofork --nopid

Apr 30 12:12:43 localhost systemd&#x5B;1]: Starting firewalld - dynamic firewall daemon...
Apr 30 12:12:43 localhost systemd&#x5B;1]: Started firewalld - dynamic firewall daemon.

</pre></div>


<p class="wp-block-paragraph">Firewalld is active. I need to stop and disable the service so that it does not restart at system startup:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: plain; title: ; notranslate">
localhost:~ # systemctl stop firewalld
localhost:~ # systemctl disable firewalld
</pre></div>


<h2 class="wp-block-heading" id="h-install-rke2">Install RKE2</h2>



<p class="wp-block-paragraph">Next, I installed RKE2. To do so, I simply followed the official procedure: <a href="https://docs.rke2.io/install/quickstart">https://docs.rke2.io/install/quickstart</a></p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~ # curl -sfL https://get.rke2.io | sh -
localhost:~ # systemctl enable rke2-server.service
localhost:~ # systemctl start rke2-server.service

</pre></div>


<p class="wp-block-paragraph">As mentioned in the RKE2 documentation: <em>“additional utilities will be installed at&nbsp;<code>/var/lib/rancher/rke2/bin/</code>. They include:&nbsp;kubectl,&nbsp;crictl, and&nbsp;ctr.<br>Note that these are not on your path by default.”</em></p>



<p class="wp-block-paragraph">I’m adding the repository to my default PATH (this step can be done temporarily or permanently, by editing your <code>~/.bashrc file</code>). I chose to make it permanent by editing my <code>~/.bashrc file</code>, but it’s up to you.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
export PATH=&quot;/var/lib/rancher/rke2/bin:$PATH&quot;
</pre></div>


<p class="wp-block-paragraph">RKE2 install writes a kubeconfig file to&nbsp;<code>/etc/rancher/rke2/rke2.yaml</code><strong>.</strong><br>Again, I’m adding this into my <code>~/.bashrc</code> file</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
export KUBECONFIG=/etc/rancher/rke2/rke2.yaml
</pre></div>


<p class="wp-block-paragraph">I check that the Kubernetes cluster is up and pods are running:</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; highlight: [1,5]; title: ; notranslate">
localhost:~ # kubectl get nodes
NAME        STATUS   ROLES                       AGE   VERSION
localhost   Ready    control-plane,etcd,master   22m   v1.31.7+rke2r1

localhost:~ # kubectl get pods -A
NAMESPACE     NAME                                                    READY   STATUS      RESTARTS      AGE
kube-system   cloud-controller-manager-localhost                      1/1     Running     1 (23m ago)   22m
kube-system   etcd-localhost                                          1/1     Running     0             22m
kube-system   helm-install-rke2-canal-nxphw                           0/1     Completed   0             23m
kube-system   helm-install-rke2-coredns-2whps                         0/1     Completed   0             23m
kube-system   helm-install-rke2-ingress-nginx-9mpwb                   0/1     Completed   0             23m
kube-system   helm-install-rke2-metrics-server-t8g27                  0/1     Completed   0             23m
kube-system   helm-install-rke2-runtimeclasses-nbq2v                  0/1     Completed   0             23m
kube-system   helm-install-rke2-snapshot-controller-crd-fmwqh         0/1     Completed   0             23m
kube-system   helm-install-rke2-snapshot-controller-nqq5g             0/1     Completed   1             23m
kube-system   kube-apiserver-localhost                                1/1     Running     0             22m
kube-system   kube-controller-manager-localhost                       1/1     Running     0             22m
kube-system   kube-proxy-localhost                                    1/1     Running     0             22m
kube-system   kube-scheduler-localhost                                1/1     Running     0             22m
kube-system   rke2-canal-qlk8b                                        2/2     Running     0             22m
kube-system   rke2-coredns-rke2-coredns-autoscaler-596dcdf688-dsjjz   1/1     Running     0             22m
kube-system   rke2-coredns-rke2-coredns-cf7df985b-zqwqn               1/1     Running     0             22m
kube-system   rke2-ingress-nginx-controller-b52nh                     1/1     Running     0             21m
kube-system   rke2-metrics-server-58ff89f9c7-dndfb                    0/1     Running     0             21m
kube-system   rke2-snapshot-controller-58dbcfd956-srw5z               1/1     Running     0             21m

</pre></div>


<h2 class="wp-block-heading" id="h-add-a-persistent-volume">Add a persistent volume</h2>



<p class="wp-block-paragraph">We need some storage, don&#8217;t we?<br>By default, RKE2 does not provide persistent volumes.<br>However, “Local Path Provisioner” provides a way for the Kubernetes users to utilize the local storage in each node (<a href="https://github.com/rancher/local-path-provisioner">https://github.com/rancher/local-path-provisioner</a>). Let&#8217;s use that.</p>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; highlight: [1]; title: ; notranslate">
localhost:~ # kubectl apply -f https://raw.githubusercontent.com/rancher/local-path-provisioner/v0.0.31/deploy/local-path-storage.yaml
namespace/local-path-storage created
serviceaccount/local-path-provisioner-service-account created
role.rbac.authorization.k8s.io/local-path-provisioner-role created
clusterrole.rbac.authorization.k8s.io/local-path-provisioner-role created
rolebinding.rbac.authorization.k8s.io/local-path-provisioner-bind created
clusterrolebinding.rbac.authorization.k8s.io/local-path-provisioner-bind created
deployment.apps/local-path-provisioner created
storageclass.storage.k8s.io/local-path created
configmap/local-path-config created
</pre></div>


<h2 class="wp-block-heading" id="h-install-yak">Install YaK</h2>



<p class="wp-block-paragraph">Alright, I now have a fully functional Kubernetes cluster.<br>Let’s install the YaK on it now.</p>



<ul class="wp-block-list">
<li>Create a namespace:</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
kubectl create ns yak
</pre></div>


<ul class="wp-block-list">
<li>Add yak repo</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
helm repo add yak https://gitlab.com/api/v4/projects/63133284/packages/helm/stable &amp;&amp; helm repo update
</pre></div>


<ul class="wp-block-list">
<li>Create the yak.values.yaml definition file</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~ # vi yak.values.yaml
</pre></div>

<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
global:
  hostname: yak.lab
  admin_credentials:
    password: &quot;ABCdef1234@&quot; #default password to be changed to your need

yak-postgres:
  postgresPassword: &quot;&quot; # Randomly generated if not set
  persistence:
    size: 20Gi
    storageClassName: &quot;local-path&quot; # Uses default if empty

yak-graphile:
  # Archive storage stores the component types archives at import time
  persistence: &amp;archives_storage
    size: 20Gi
    storageClassName: &quot;local-path&quot; # Uses default if empty
  # If using a multi-node cluster, uncomment these 2 lines:
    #accessModes:
     # - ReadWriteMany

  # If you want to expose the rest API at https://hostname/data/graphql and have the postgraphile UI at https://yak.my-domain.local/data/graphiql
  ingress:
    enabled: true
    className: &quot;&quot; # Uses default if empty
    tls:
     - secretName: yak-tls-secret
       hosts:
       - yak.lab

yak-runner:
  image:
    pullPolicy: Always
  persistence:
  # Runner shares the archives storage with graphile
    graphile: *archives_storage
    components:
      enabled: true
      storageClassName: &quot;local-path&quot; # Uses default if empty
      size: 8Gi
    sshconfig:
      enabled: true
      storageClassName: &quot;local-path&quot; # Uses default if empty
      size: 1Gi

yak-ui:
  # Mandatory if you want to access the UI through ingress
  ingress:
    enabled: true
    className: &quot;&quot; # Uses default if empty
    tls:
     - secretName: yak-tls-secret
       hosts:
       - yak.lab

</pre></div>


<ul class="wp-block-list">
<li>Run Helm install YaK</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
helm install yak yak/yak -f yak.values.yaml -n yak
</pre></div>


<ul class="wp-block-list">
<li>Check that YaK is properly deployed (all 4 pods should be Running after a few minutes)</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
localhost:~ # kubectl get pods -n yak
NAME                            READY   STATUS    RESTARTS   AGE
yak-graphile-5b5454fd64-hmk2c   1/1     Running   0          1m
yak-postgres-7bcf4f9897-7mrdg   1/1     Running   0          1m
yak-runner-6669948599-9ggwn     1/1     Running   0          1m
yak-ui-7f6d77c765-spgfn         1/1     Running   0          1m

</pre></div>


<h2 class="wp-block-heading" id="h-connect-to-the-yak-with-https">Connect to the YaK with https</h2>



<p class="wp-block-paragraph">Finally, let&#8217;s connect to our web app!</p>



<ul class="wp-block-list">
<li>Update your local <code>/etc/hosts</code> file and add your YaK server, in my case:</li>
</ul>


<div class="wp-block-syntaxhighlighter-code "><pre class="brush: bash; title: ; notranslate">
192.168.10.185   yak.lab
</pre></div>


<ul class="wp-block-list">
<li>Open a web browser and navigate to your URL : https://yak.lab
<ul class="wp-block-list">
<li>Default credentials :
<ul class="wp-block-list">
<li>User: admin</li>



<li>Password: ABCdef1234@</li>
</ul>
</li>
</ul>
</li>
</ul>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="650" height="500" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-15.png" alt="YaK login page" class="wp-image-39435" style="width:650px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-15.png 650w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-15-300x231.png 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="692" height="446" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-16.png" alt="YaK Dashboard" class="wp-image-39436" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-16.png 692w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/07/image-16-300x193.png 300w" sizes="auto, (max-width: 692px) 100vw, 692px" /></figure>



<p class="wp-block-paragraph">Voilà!!</p>



<p class="wp-block-paragraph">I’ve now got a local YaK on RKE2 running at home, ready to deploy infrastructures, servers and components wherever I want.</p>



<p class="wp-block-paragraph">For more info about the YaK, visit <a href="https://yak4all.io">yak4all.io</a></p>



<p class="wp-block-paragraph">And if you can&#8217;t be bothered installing your own YaK, you can bring up a fully functional YaK demo environment, within minutes : <a href="https://yak4all.io/demo/">yak4all.io/demo</a><br>Feel free to play around and explore our <a href="https://dbi-services.gitbook.io/yak-user-doc/yak-demo">use cases</a> </p>



<p class="wp-block-paragraph">Happy YaKing 😉 !</p>
<p>L’article <a href="https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/">Install a single node Kubernetes cluster with SUSE RKE2 and deploy your own YaK instance</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/install-a-single-node-kubernetes-cluster-with-suse-rke2-and-deploy-your-own-yak-instance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>My journey to KubeCon 2025</title>
		<link>https://www.dbi-services.com/blog/my-journey-to-kubecon-2025-day-1/</link>
					<comments>https://www.dbi-services.com/blog/my-journey-to-kubecon-2025-day-1/#comments</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Mon, 07 Apr 2025 09:53:40 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=37914</guid>

					<description><![CDATA[<p>Wednesday, April 2nd. Today is my first day at the KubeCon 2025 in London. It’s 8 AM, I’m in the lobby of my hotel and I can already hear “HAProxy”, “NGINX”, “Pipeline”, and “Kubernetes” here and there. There is no doubt, I am at the right place. When I walked to the Excel London, I [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/my-journey-to-kubecon-2025-day-1/">My journey to KubeCon 2025</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-wednesday-april-2nd"><strong>Wednesday, April 2nd.</strong></h2>



<p class="wp-block-paragraph"><br>Today is my first day at the KubeCon 2025 in London. It’s 8 AM, I’m in the lobby of my hotel and I can already hear “HAProxy”, “NGINX”, “Pipeline”, and “Kubernetes” here and there. There is no doubt, I am at the right place.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="768" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/8DDFAD0C-EB7A-4048-BECE-A4F95EDC611A_1_105_c-1.jpeg" alt="" class="wp-image-37917" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/8DDFAD0C-EB7A-4048-BECE-A4F95EDC611A_1_105_c-1.jpeg 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/8DDFAD0C-EB7A-4048-BECE-A4F95EDC611A_1_105_c-1-300x225.jpeg 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/8DDFAD0C-EB7A-4048-BECE-A4F95EDC611A_1_105_c-1-768x576.jpeg 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">When I walked to the Excel London, I didn’t know what to expect. The place is just huge. The day has not started, and I already know I should have grabbed another pair of shoes.</p>



<p class="wp-block-paragraph">To give you an idea, they expect between 12 and 15 thousand people….<br>I’m starting to realize this event is a one-of-a-kind.</p>



<p class="wp-block-paragraph">Opening session in the Auditorium, my first thought was: how are they gonna fit all these people in? <br>Well, the Linux Foundation organizers seem to know what they are doing… <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /><br>Drum rolls, lights shade, this is not just another IT people gathering, it’s a freaking show.</p>



<p class="wp-block-paragraph">The tone is set, a few welcome words from the CNCF representatives and we are already talking about LLM. This is not a surprise; Artificial Intelligence is everywhere in this Kubecon.<br><br><strong>Christin Yen</strong>, CEO and cofounder at Honeycomb tells us about observability and the impact of application development on users. How can AI help improve user experience by monitoring response time and analyzing tons of metadata.</p>



<p class="wp-block-paragraph">Followed by <strong>Vijay Samuel</strong>, Architect at Ebay enlightening us on how they are making use of AI and LLM: human comprehension is limited, and the systems we manage have become so complex and so big that sorting of logs is impossible without the help of machine learning to attach a root cause to an alert.</p>



<p class="wp-block-paragraph"><strong>Andrew Randall</strong> reminds us how awesome Kubernetes is but also how intimidating it can be for novice users. There is no such thing as a simple <em>“apt-get install kubernetes” </em>command: willing to install a Vanilla Kubernetes? You’d have to figure it out yourself, it’s a steep learning curve before you can even deploy your first cluster.<br>Based on this observation and willingness to reduce the impact on developers’ productivity, Microsoft has announced a new project called Headlamp, designed to make Kubernetes easier to use and, above all, easier to adopt. It comes with an in-cluster web portal (a k8s dashboard), a unified UI for multiple remote clusters, and a “Kubernetes Desktop”.<br>Pretty much like what our SUSE friends have accomplished with the great SUSE Rancher ;-). Let’s see!</p>



<p class="wp-block-paragraph"><strong>Greg Kroah-Hartmann</strong> (Linux maintainer, Linux Foundation) attended to discuss the Linux Kernel and how they are integrating Rust and C into it.<br>Today’s Linux kernel contains 34 million lines of C, and about 25000 lines of Rust code.<br>Rust brings more safety as it allows the kernel to “crash safely” when an error occurs and makes the code more “maintainable”. Rust can prevent a huge majority of security issues at build time, not at review time: code is simpler, reviewing is easier, fewer bugs, more fun!</p>



<p class="wp-block-paragraph">Closing the keynote with a great use-case of AI, I loved it because it really demonstrated how technology can improve people’s lives and I truly believe this is what technology should be about: moving science forward, promoting education, and closing the gap between our societies. Indeed, <strong>Rob Koch</strong> from <strong>Slalom </strong>explained how AI, combined with Kubernetes, is revolutionizing the world of deaf people with AI-driven sign language interpretation and recognition.<br>He explained the challenges they’re facing as it is overly complicated for a machine to capture the movement of a hand when hand-signing.<br>Making the difference between a “P” and a “Q” is a good example of this complexity as these 2 signs are very similar in sign language and capturing the right sign highly depends on the camera’s angle of view: perspective and scaling are important. AI models need a phenomenal amount of authentic data and scenarios to be trained. Moreover, machines need to “understand” the context of the conversation, not only words.<br>Kubernetes is ideal for that as it provides scaling capabilities, resource optimization for video processing, and task repeatability.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="782" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/Screenshot-2025-04-07-at-10.35.36-1024x782.png" alt="" class="wp-image-37920" style="width:420px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/Screenshot-2025-04-07-at-10.35.36-1024x782.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/Screenshot-2025-04-07-at-10.35.36-300x229.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/Screenshot-2025-04-07-at-10.35.36-768x586.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/Screenshot-2025-04-07-at-10.35.36.png 1040w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>End of the keynote</strong>, it&#8217;s time for me to wander the corridors of the KubeCon and visit the booths.<br>All the big tech players are there of course…. but dozens of open source projects that we use daily within our infrastructures are represented and have a booth. It’s great to see that Open Source solutions are everywhere and everybody’s using them. I feel like a kid in a candy shop!</p>



<p class="wp-block-paragraph">Alright, let’s &#8220;get some swag&#8221;. There are enough tee shirts, stickers, and other cool gadgets at this KubeCon for me to fill a massive suitcase, but I will try to be reasonable. Everyone has something to propose: hats, backpacks, tote bags, stickers, keyrings, lego sets. It’s too tempting, let’s see how long I can refrain from taking it all.</p>



<p class="wp-block-paragraph"><strong>Visiting the RedHat stand:</strong><br>I met with Stevan Le Meur, a developer at RedHat and we had a great exchange on what RedHat does with regards to Kubernetes. Stevan specializes in bootable containers and invited me to take a closer look at what <a href="https://docs.fedoraproject.org/en-US/bootc/getting-started/">bootc</a> and <a href="https://podman.io/">podman</a> can achieve.<br>The occasion for me to talk about our <a href="https://yak4all.io">YaK project</a>. Why not consider bootable containers with the YaK in a future release?<br>That’s clearly a topic we can discuss during our next roadmap meeting, let’s see if we add it to the list of upcoming features&#8230;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="768" height="1024" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/7C18A2CC-2B98-4489-83FC-C59FED64BB36_1_105_c.jpeg" alt="" class="wp-image-37925" style="width:333px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/7C18A2CC-2B98-4489-83FC-C59FED64BB36_1_105_c.jpeg 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2025/04/7C18A2CC-2B98-4489-83FC-C59FED64BB36_1_105_c-225x300.jpeg 225w" sizes="auto, (max-width: 768px) 100vw, 768px" /></figure>
</div>


<p class="wp-block-paragraph">Walking down the hallway, I passed by the <strong>Linux Foundation booth</strong> where the topic being discussed was the certification exams.<br>For those interested in the CKA (Certified Kubernetes Administrator) exam, know that a new version has just been released.<br>This new version is a bit more difficult than the previous one, the passing score is still 66% and the format has not changed: it is still a proctored hands-on lab exam.</p>



<p class="wp-block-paragraph">Good resources to practice before the exam: killer.sh (<a href="https://killer.sh/">https://killer.sh/</a>) , and the great environments and training material provided by KodeKloud (<a href="https://kodekloud.com/">https://kodekloud.com/</a>)</p>



<p class="wp-block-paragraph">That’s enough reading for today.</p>
<p>L’article <a href="https://www.dbi-services.com/blog/my-journey-to-kubecon-2025-day-1/">My journey to KubeCon 2025</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/my-journey-to-kubecon-2025-day-1/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Introducing YaK 2.0: The future of effortless PaaS deployments across Clouds and On-Premises</title>
		<link>https://www.dbi-services.com/blog/introducing-yak-automated-multi-cloud-deployment/</link>
					<comments>https://www.dbi-services.com/blog/introducing-yak-automated-multi-cloud-deployment/#respond</comments>
		
		<dc:creator><![CDATA[Rémy Gaudey]]></dc:creator>
		<pubDate>Wed, 15 Jan 2025 07:13:37 +0000</pubDate>
				<category><![CDATA[YaK]]></category>
		<guid isPermaLink="false">https://www.dbi-services.com/blog/?p=35489</guid>

					<description><![CDATA[<p>Hello, dear tech enthusiasts and cloud aficionados! We’ve got some news that’s about to make your life —or your deployments, at least— a whole lot easier. Meet YaK 2.0, the latest game-changer in the world of automated multi-cloud PaaS deployment. After months of development, testing, troubleshooting, a fair share of meetings and way too much [&#8230;]</p>
<p>L’article <a href="https://www.dbi-services.com/blog/introducing-yak-automated-multi-cloud-deployment/">Introducing YaK 2.0: The future of effortless PaaS deployments across Clouds and On-Premises</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="278" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-1024x278.png" alt="YaK 2.0 Automated multi-cloud PaaS deployment" class="wp-image-35562" style="width:442px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-1024x278.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-300x81.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-768x208.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-1536x417.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YAK-logotype-CMJN-2022-1-2048x555.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">Hello, dear tech enthusiasts and cloud aficionados!</p>



<p class="wp-block-paragraph">We’ve got some news that’s about to make your life —or your deployments, at least— a whole lot easier. Meet YaK 2.0, the latest game-changer in the world of automated multi-cloud PaaS deployment. After months of development, testing, troubleshooting, a fair share of meetings and way too much coffee, YaK is officially launching today.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1200" height="1500" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/11/YaK-Launch1.jpg" alt="" class="wp-image-35633" style="width:442px;height:auto" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/11/YaK-Launch1.jpg 1200w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/11/YaK-Launch1-240x300.jpg 240w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/11/YaK-Launch1-819x1024.jpg 819w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/11/YaK-Launch1-768x960.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></figure>
</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading" id="h-automated-multi-cloud-paas-deployment-what-s-the-deal-with-yak-2-0">Automated multi-cloud PaaS deployment. What’s the deal with YaK 2.0?</h2>



<p class="wp-block-paragraph">Because we believe IT professionals should spend time on complex, value-added tasks, but not on repetitive setups, we have decided to develop the YaK.<br>YaK is a framework that allows anyone to deploy any type of component on any platform, while ensuring quality, cost efficiency and reducing deployment time.</p>



<p class="wp-block-paragraph">YaK 2.0 is your new best friend when it comes to deploying infrastructure that’s not just efficient but also identical across every platform you’re working with &#8211; be it multi-cloud or on-premises. Originating from the need to deploy multi-technology infrastructures quickly and effortlessly, YaK ensures your setup is consistent, whether you&#8217;re working with AWS, Azure, Oracle Cloud, or your own on-prem servers.</p>



<p class="wp-block-paragraph">In simpler terms, YaK makes sure your deployment process is consistent and reliable, no matter where. Whether you’re scaling in the cloud or handling things in-house, YaK’s got your back.</p>



<h2 class="wp-block-heading" id="h-why-you-should-have-a-look-at-yak-2-0">Why you should have a look at YaK 2.0?</h2>



<p class="wp-block-paragraph">Here’s why we think YaK is going to become your favorite pet:</p>



<ul class="wp-block-list">
<li><strong>Flexibility:</strong> Deploy across AWS, Azure, OCI, or your own servers—YaK adapts to your infrastructure, making every platform feel like home.</li>



<li><strong>Automation:</strong> Eliminate repetitive setups with automated deployments, saving you time and headaches.</li>



<li><strong>Cost efficiency &amp; speed:</strong> YaK cuts time-to-market, streamlining deployments for fast, standardized rollouts that are both cost-effective and secure.</li>



<li><strong>Freedom from vendor lock-In:</strong> YaK is vendor-neutral, letting you deploy on your terms, across any environment.</li>



<li><strong>Swiss software </strong>backed up by a consulting company (<a href="https://www.dbi-services.com/">dbi services</a>) with extensive expertise in deployments.</li>
</ul>



<p class="wp-block-paragraph">With this release, we’re excited to announce a major upgrade:</p>



<ul class="wp-block-list">
<li><strong>Sleek new user interface:</strong> YaK 2.0 now comes with a user-friendly interface, making it easier than ever to manage your deployments. Say hello to intuitive navigation.</li>
</ul>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="621" data-id="35560" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-1024x621.png" alt="YaK 2.0 Automated multi-cloud PaaS deployment" class="wp-image-35560" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-1024x621.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-300x182.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-768x466.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-1536x931.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK-UI_main_screen-2048x1242.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<ul class="wp-block-list">
<li><strong>Components: </strong>We’ve got components on our roadmap (available with an annual subscription), and we’ll be announcing them shortly&nbsp;: <strong>Oracle Database, PostgreSQL, MongoDB, </strong>and<strong> Kubernetes </strong>are already on the list and will be released soon.</li>
</ul>



<p class="wp-block-paragraph">Many more will follow&#8230; Stay tuned!<strong></strong></p>



<h2 class="wp-block-heading" id="h-how-does-it-work">How does it work?</h2>



<p class="wp-block-paragraph"><strong>YaK Core</strong> is the open-source part and is the heart of our product, featuring Ansible playbooks and a custom plugin that provides a single inventory for all platforms, making your server deployments seamless across clouds like AWS, Azure, and OCI.<br>If you want to see for yourself, our GitLab project is <a href="https://gitlab.com/yak4all/yak_core/-/blob/main/README.md" target="_blank" rel="noreferrer noopener">available here!</a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-1024x645.png" alt="YaK 2.0 Automated multi-cloud PaaS deployment" class="wp-image-35559" srcset="https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-1024x645.png 1024w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-300x189.png 300w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-768x484.png 768w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-1536x967.png 1536w, https://www.dbi-services.com/blog/wp-content/uploads/sites/2/2024/10/YaK_core-2048x1290.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>YaK Components</strong> are the value-added part of the product and bring you expert-designed modules for deploying databases and application servers, with an annual subscription to dbi services.</p>



<h2 class="wp-block-heading" id="h-join-the-yak-pack">Join the YaK pack</h2>



<p class="wp-block-paragraph">Explore the power of automated multi-cloud PaaS deployment with YaK 2.0 and experience a new level of efficiency and flexibility. We can’t wait for you to try it out and see just how much it can streamline your deployment process. Whether you’re a startup with big dreams or an established enterprise looking to optimize, YaK is here to make your life easier.</p>



<p class="wp-block-paragraph">Our YaK deserved its own web page, check it out for more information, to contact us or to try it out (free demo environments will be available soon): <a href="https://yak4all.io/">yak4all.io</a></p>



<p class="wp-block-paragraph">Wanna ride the YaK? Check out our <a href="https://dbi-services.gitbook.io/yak-user-doc/" target="_blank" rel="noreferrer noopener">user documentation</a> to get started!<br>We promise it’ll be the smoothest ride you’ve had in a while.</p>



<p class="wp-block-paragraph">We’re not just launching a product; we’re building a community. We’d love for you to chime in, share your experiences, and help us make YaK even better. Follow us on LinkedIn, <a href="https://gitlab.com/yak4all">join our community on GitLab</a>, and let’s create something amazing together.</p>



<p class="wp-block-paragraph">Feel free to reach out to us for more details or for a live presentation: <a href="mailto:info@dbi-services.com" target="_blank" rel="noreferrer noopener">info@dbi-services.com</a></p>



<p class="wp-block-paragraph">Thanks for being part of this exciting journey. We can’t wait to see what you build with YaK.</p>



<p class="wp-block-paragraph">The YaK Team</p>



<p class="wp-block-paragraph">&#8212;</p>



<p class="wp-block-paragraph"><em>P.S. If you’re wondering about the name, well, yaks are known for being hardy, reliable, and able to thrive in any environment. </em><em>Plus, they look pretty cool, don’t you think?</em></p>
<p>L’article <a href="https://www.dbi-services.com/blog/introducing-yak-automated-multi-cloud-deployment/">Introducing YaK 2.0: The future of effortless PaaS deployments across Clouds and On-Premises</a> est apparu en premier sur <a href="https://www.dbi-services.com/blog">dbi Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dbi-services.com/blog/introducing-yak-automated-multi-cloud-deployment/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)

Served from: www.dbi-services.com @ 2026-07-27 09:03:16 by W3 Total Cache
-->