Kubernetes ValidatingAdmissionPolicy: CEL Policy Without a Webhook
How to design, bind, stage, observe, and safely enforce in-process Kubernetes admission rules with ValidatingAdmissionPolicy and CEL.
whoami
Deep technical notes on operating systems, virtualization, cloud infrastructure, kernels, filesystems, emulation, and the history behind essential tools.
How to design, bind, stage, observe, and safely enforce in-process Kubernetes admission rules with ValidatingAdmissionPolicy and CEL.
How OCI image indexes connect platform descriptors to immutable manifests, and how runtimes select, verify, publish, and debug multi-platform images.
A hardware-aware guide to FDAPM information, idle modes, standby, suspend, poweroff, reboot, disk handling, and cache safety on FreeDOS.
How FreeDOS LBACACHE accelerates BIOS sector reads, uses XMS, observes writes without delaying them, reports hit rates, and unloads safely.
A practical guide to inspecting FreeBSD process arguments, descriptors, mappings, credentials, signals, threads, and core files with procstat.
How FreeBSD RCTL identifies subjects, measures resources, applies deny or throttle actions, persists rules, and exposes real usage safely.
Haiku R1/beta6 arrives on August 26, 2026 with Firefox, NVMM acceleration, a new allocator, broad performance work, and more than 530 resolved tickets.
How Haiku tracks running applications, resolves signatures and files, enforces launch modes, sends roster notifications, and returns BMessengers.
A precise look at how fs-verity authenticates read-only files, verifies page-cache reads, exposes stable digests, and differs from dm-verity.
How Linux PID file descriptors provide stable process identity for signaling, polling, waiting, and descriptor duplication without PID reuse races.
Posts revised with new sources, corrected facts, or fixed links - not just new posts.