
De Nederlandse Kubernetes Podcast
Ronald Kers en Jan Stomphorst
Geef deze podcast je waardering
De Nederlandse Kubernetes Podcast: gemaakt door én voor mensen met een hart voor IT. In deze reeks gaan Ronald Kers en Jan Stomphorst in gesprek over Kubernetes met als doel Kubernetes toegankelijk te maken voor iedereen.


#144 Kubernetes Doesn't Build Your Network
22 sep · 41 min
We sit down with Simone Rodigari, software engineer in Azure Core Container Networking and one of the maintainers of Retina, the eBPF-based observability project. Simone had just delivered his session on Kubernetes networking, and we asked him to give our listeners the same mental model, the one you need when something breaks and you have no idea where to start tracing.
We start at the ground rules: every pod gets an IP, every pod can reach every other pod. That's the expectation Kubernetes sets, but Kubernetes doesn't implement it, the CNI does. Simone walks us through the pod network namespace, the veth pair that works like a virtual cable, and what actually happens to a packet on its way out of the node.
From there we get into the real trade-offs:
- Overlay (VXLAN, IP-in-IP, Geneve) versus underlay and direct routing with BGP portability versus performance, and why the answer is always "it depends"
- Why pods being ephemeral forces the Service abstraction, and how DNAT and load balancing actually work underneath
- kube-proxy modes iptables, IPVS, nftables and why linear rule traversal hurts at scale while eBPF maps give you constant-time lookups
- Where eBPF has its own limits: map sizes, memory and CPU
- Hubble as a Kubernetes-aware tcpdump, and how Retina brings that same flow visibility to any CNI even Flannel
- Jan's production pain: hitting the Cilium identity ceiling on managed AKS and the hack he needed to work around it
We close on the future: operating clusters at massive scale, AI moving from training to inference, and Simone's warning that the community should solve real problems instead of bending Kubernetes to fit every new one.
🎧 A grounded, practical episode for anyone who has ever stared at a dropped packet and wondered which component to blame.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#143 Kubernetes bij de AIVD: achter de poortjes
15 sep · 43 min
Bij de AIVD kom je niet zomaar binnen. Je legt je telefoon en je spullen weg, je gaat door de security check en de poortjes, en pas daarna ga je aan het werk. De netwerken daarachter zijn net zo streng afgesloten: de meeste hebben geen internet, ze leven helemaal los van elkaar, en data kan er maar één kant op.
In deze aflevering van De Nederlandse Kubernetes Podcast spreken Ronald Kers en Jan Stomphorst met Wouter en Nick, die bij de AIVD in het platformteam werken.
Ze vertellen hoe updates via data diodes naar binnen komen, waarbij data maar één kant op kan en niet terug. Packages en images die ontwikkelaars nodig hebben moeten offline beschikbaar zijn, zodat een ontwikkelaar binnen dezelfde ervaring heeft als iemand die wel internet heeft. Wat binnenkomt wordt eerst gecontroleerd voordat het in de repository terechtkomt.
Verder in het gesprek: waarom ze werken met één groot multitenant cluster dat elk kwartaal wordt geüpdatet, waarom vuile data daar bewust buiten blijft, hoe ze Cluster API en de bijbehorende image builder gebruiken om eigen images te bouwen volgens eigen regels, en waarom hun filosofie is om zoveel mogelijk open source te gebruiken om vendor lock-in te voorkomen.
Ook aan bod: hoe applicaties organisch redundant zijn geworden doordat nodes gewoon 's nachts worden gerecycled, de oriëntatiefase rond Gateway API, GPU's in de eigen omgeving, de samenwerking met de MIVD en JIVC, en de grootste uitdaging voor de toekomst, namelijk dat steeds meer producten alleen nog als SaaS beschikbaar zijn.
https://werkenbijdeaivd.nl/
De Nederlandse Kubernetes Podcast is een initiatief van ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#142 Kubernetes 1.37 Garhwal
04 sep · 28 min
Kubernetes 1.37 verscheen eind augustus onder de naam Garhwal, genoemd naar de Noord-Indiase regio waar de release lead zelf vandaan komt. Op papier een rustige release: 67 enhancements, waarvan zestien naar Stable, drieëntwintig naar Beta en zevenentwintig nieuw in Alpha. Jan constateert dat Kubernetes al een tijd steeds stabieler wordt en dat breaking changes zeldzamer worden. Goed nieuws, al maakt het de zoektocht naar een spannend verhaal voor een release-aflevering er niet makkelijker op. Deze keer valt er genoeg uit te diepen.
IPVS gaat eruit. Jan legt uit wat kube-proxy doet en waarom IPVS-mode, ooit geïntroduceerd omdat iptables te klein werd, nu zelf wordt uitgefaseerd. Het probleem is structureel: elke node draagt de IP-adressen van elke service. Bij twintig services merk je daar niks van, bij tweeduizend wel. In 1.43 verdwijnt IPVS volledig, maar het moment waarop je het gaat voelen ligt eerder. De praktische boodschap: stap over naar nftables vóór 1.40, en besef dat een upgrade dat niet voor je doet. Je moet het expliciet instellen.
iptables versus nftables. Een heldere uitleg van wat iptables eigenlijk is, namelijk firewall én routing op Linux met één lineaire regellijst die per pakket wordt doorlopen, en waarom dat in Kubernetes tegen een plafond loopt. De API ondersteunt geen incrementele updates, dus voor één regel moet de hele set opnieuw geladen worden. nftables gebruikt sets, maps en efficiëntere datastructuren, en biedt één uniform framework voor IPv4, IPv6, ARP en bridge filtering. Wel opletten: de twee zijn niet volledig compatibel met elkaar, en je hebt een recente kernel nodig.
Scale-to-zero is nu native. De HPA kan naar nul zonder dat je iets aan je bestaande configuratie hoeft te veranderen. Waar eerst één stond, kan nu nul staan. De afweging is opstarttijd bij de eerste request, maar als er niets draait betaal je ook niets. Jan wijst op het slimme detail: de HPA schaalt alleen terug omhoog als hij zelf naar nul is gegaan. Zet je de replicas handmatig op nul om iets immutables aan te passen, dan laat de autoscaler je met rust. Een herkenbare praktijkergernis, opgelost.
En KEDA dan? Ronald en Jan zetten ze naast elkaar en komen uit op complementair in plaats van concurrerend. KEDA's voordeel is dat het buiten het cluster kan kijken: een firewall of een externe dienst kan het signaal geven dat een pod moet starten. Jan schetst een bijna-serverless patroon waarin verkeer binnenkomt, KEDA de pod start, het request wordt afgehandeld en de pod daarna weer verdwijnt.
Twee harde eisen. containerd 1.x moet eruit en cgroup v1 moet eruit. Allebei niet nieuw: failCgroupV1 staat sinds 1.35 standaard op true. Jan vertelt hoe dat bij kube-spray in de praktijk uitpakte. Een mismatch tussen de cgroup-driver van de kubelet en die van de runtime levert het vervelendste type storing op. Niet kapot, maar onvoorspelbaar, met de OOM killer die processen afschiet die er niets aan kunnen doen. Bij ACC ICT wordt zoiets standaard eerst getest en worden nodes vaak simpelweg vervangen door nieuwe machines in plaats van online geüpgraded.
containerd 2.0 verandert ook je security-defaults. Containers zonder host-netwerk of user namespaces mogen nu poorten onder 1024 binden zonder CAP_NET_BIND_SERVICE, en ping draaien zonder CAP_NET_RAW. Een afspraak van decennia oud, stilzwijgend versoepeld. Terug te draaien, maar je moet het nu bewust configureren.
Verder in deze aflevering: waarom Ubuntu geen excuus meer is, hoe een onbewaakte auto-update je zomaar een major containerd-versie kan opleveren, wat managed clusters wél en niet voor je regelen, en Jans terugkerende standpunt door de hele aflevering heen: het meeste hiervan is geen probleem zodra je je machines gewoon actueel houdt.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:

#141 Helm 4 - Plugins, OCI and Why Nothing Broke
21 aug · 38 min
Andrew "Andy" Block writes books and reviews pull requests at thirty thousand feet over the Pacific, because as he says, he can sleep when he's dead. Between Red Hat's services organization and four talks at KubeCon Amsterdam, he sat down with Ronald Kers and Jan Stomphorst to talk about the first major Helm release in almost five years.
Helm 4 is a story about restraint. Helm has become load bearing for an enormous number of enterprises, and a strict versioning policy left technical debt with nowhere to go. Helm 4 clears that debt without breaking anyone. Replace the binary, keep your charts, notice almost nothing. After what the Tiller removal in Helm 3 cost teams like Jan's, that is the achievement.
Underneath sits more than the version number suggests: a Wasm based plugin model that finally makes Helm properly extensible, a serious API and logging cleanup, and better status handling built on libraries contributed out of the Flux community. Charts v3 comes next, letting you swap Go templating for Jinja or Rust, and opening the door to downloader and signer plugins.
That plugin model matters most for signing. Andy asked a room of roughly three hundred people how many sign their Helm charts. Three hands went up. GPG is painful enough that even a security specialist avoids it, so Sigstore behind a plugin becomes the realistic path to provenance. On the OCI side, per repository credentials and transparent mirroring mean organizations can stop forking charts just to repoint them internally.
The conversation widens from there: why Kustomize and Helm complement rather than compete, why European organizations are moving back on prem, and whether AI now produces code faster than any maintainer can honestly review it.
Andy's crystal ball isn't about features at all. It's about approachability, and lowering the barrier for the newcomers who made up well over half the room at KubeCon.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#140 Why Your VPN Is Lying to You About Security
04 aug · 29 min
Ronald and Jan talk with Peter O'Neill and Boris Kurktchiev from Teleport about their talk "Signed, Sealed, Delivered: Why Reverse Proxies Beat VPNs." Both guests bring deep networking and security backgrounds, from early desktop support and Slackware days to leading Teleport's solutions engineering and CNCF community work.
The core argument: traditional VPNs grant broad network access once a user authenticates, creating large lateral movement risk with little to no granular control or auditing. Peter and Boris propose replacing that model with an identity layer using OIDC and a reverse proxy (Envoy), authenticated via an identity provider like Keycloak. Instead of trusting users based on network location, every connection is signed and validated against intent, who is accessing what, and why.
They walk through how this works in practice (SSH access, internal apps, audit logging that captures actual user identity instead of just status codes) and discuss trade-offs: more endpoints to manage, added resource and scaling costs, and real implementation complexity at enterprise scale. Boris is candid that VPNs aren't dead, they still serve as a useful front gate, but shouldn't be the only layer of defense.
The conversation also touches on how AI agents on a network expose the weaknesses of old identity assumptions, since AI will scan and probe everything it can reach unless access is explicitly scoped. The episode closes with both guests' hopes for the future of Kubernetes and CNCF: more community involvement in AI-related working groups, and more regional KubeCon-style events outside the usual hubs.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In deze aflevering gaan Ronald en Jan in gesprek met Eric de Witte, Cloud Native Solutions Architect bij Nutanix, over hoe moderne Kubernetes-platformen worden uitgerold en beheerd over virtualisatielagen, bare metal en de cloud heen. Eric heeft een lange geschiedenis die teruggaat tot de vroege vCenter-tijd, via de opkomst van container orchestration (Mesos, Docker Swarm) tot het huidige Cluster API-gedreven platform bij Nutanix.
Het gesprek behandelt hoe Cluster API de onderliggende infrastructuurprovider abstraheert (VMware, Nutanix, AWS, Azure, bare metal), waardoor Kubernetes zijn eigen clusters kan uitrollen en beheren, inclusief self-healing nodes en complete procedures voor het afsluiten en opnieuw opstarten van een datacenter. Ze bespreken verschillende filosofieën rond bootstrap clusters versus een permanent management cluster, en waarom Kubernetes geen besturingssysteem is, ook al wordt het vaak zo genoemd.
Een groot deel van het gesprek gaat over de huidige situatie rond VMware en Broadcom: de licentieveranderingen, de focus op grote klanten, en waarom veel organisaties hierdoor hun virtualisatiestrategie heroverwegen, ook al erkent Eric dat VMware technisch nog steeds een sterk product is.
Daarnaast wordt diep ingegaan op de operationele realiteit van databases en stateful workloads op Kubernetes, de toenemende afhankelijkheid van operators, de uitdaging om interoperabiliteit te valideren bij elke nieuwe Kubernetes-release, en waarom backup en disaster recovery op applicatieniveau moeten gebeuren in plaats van puur op VM-niveau. Ze sluiten af met een blik op soevereine cloud-ambities, de kloof tussen on-prem en hyperscaler-functionaliteit, en Eric's visie op de komende tien jaar van Kubernetes: meer enterprise-adoptie, meer abstractie, maar ook meer complexiteit, waarbij networking-kennis de grootste drempel blijft voor nieuwkomers.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode, recorded live at KubeCon, Ronald and Jan talk with Jannis Relakis and Michael Seiwald-McCarty, both senior platform engineers at Celonis. Celonis manages over 150 Kubernetes clusters across GKE, AKS, and EKS, but it wasn't always that clean. They started with six different Kubernetes flavors, including Gardener, K-Ops, and OpenShift (both Rosa and ARO), spread across multiple cloud providers.
In their KubeCon talk "No Shame in Just Paying," they shared how they tackled this consolidation project: migrating all workloads to three standardized, fully managed Kubernetes distributions. Key topics include their self-built cross-cluster connectivity tool called "Wormhole" (powered by Envoy's dynamic forward proxy), RabbitMQ federation for seamless message queue migration, and how they used Karpenter and Cilium to align node and network management across clouds.
They also get candid about what went wrong: an accidental ArgoCD sync that caused a 10-minute full environment outage, the pain of "snowflake" environments (including one requiring full HIPAA compliance with Istio mTLS), and the constant fight against scope creep that threatened to derail the entire project.
The episode closes with a forward-looking discussion on FinOps, resource rightsizing, the future of VPA, and whether Kubernetes and serverless can ever truly converge.Powered by ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode, Ronald and Jan sit down with Luigi Nardi, founder and CEO of DB tune, at KubeCon. Luigi brings a rare mix of academic depth (PhD in computer science, postdocs at Imperial College London and Stanford, professor at Lund University) and startup pragmatism. The conversation digs into why database tuning is fundamentally a combinatorial optimization problem that humans aren't wired to solve well, and why AI is uniquely suited for it.
DB tune focuses entirely on Postgres and deploys a narrow, production-safe AI agent that reads performance metrics and iteratively adjusts server parameters (GUCs) until the system converges on an optimal configuration. No LLMs, no hallucinations — just purpose-built ML that operates in a closed feedback loop. The agent integrates with AWS RDS, Aurora, Azure Flexible Server, Google Cloud SQL, and Cloud Native PG (the Kubernetes Postgres operator).
Luigi shares a standout story: a water management company ran the agent on their production system — with a hospital's water supply on the line — and achieved a 2.5x performance improvement in just a few hours. He also explains how tuning isn't a one-time exercise: cloud workloads change, hardware scales up and down, and DB tune's model called "Newton" was specifically engineered to prevent unstable, oscillating parameter changes. The episode closes with a compelling FinOps angle: tuning doesn't just make your database faster, it can also shrink your instance size and cut infrastructure costs — a perfect fit for the Kubernetes-native world.
Powered by ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode, hosts Ronald and Jan are joined at KubeCon by two guests from Red Hat: Brian Stevens, AI CTO and one of the original architects behind the creation of Kubernetes and the CNCF, and Rob Shaw, co-lead of the vLLM project and maintainer of LMD.
Brian shares the remarkable backstory of how Kubernetes came to be open source, including how Red Hat negotiated a single committer seat before agreeing to be a launch partner, and how he later pushed Google to contribute Kubernetes to the newly formed CNCF rather than keeping it proprietary like TensorFlow.
Rob explains what an inference runtime actually is: the critical piece of software that takes an abstract AI model and runs it as efficiently as possible on a GPU or other accelerator — handling everything from CUDA-level kernel optimization to memory management and concurrent request scheduling. vLLM serves as a "Rosetta Stone" between the ever-growing zoo of models (Llama, DeepSeek, Mistral, Qwen, Nvidia Nemotron) and accelerators (Nvidia, AMD, Intel, Google TPUs).
The conversation covers model compression and quantization how techniques like 4-bit precision can deliver 2x hardware efficiency gains while preserving 99%+ model accuracy. Brian and Rob also address the "big model vs. many small models" debate, recommending to always start with the largest capable model to validate a use case before optimizing down.
Looking ahead, both guests see inference as potentially the single largest workload ever run on Kubernetes, and position LMD (now contributed to the CNCF) as the distributed inference layer that will make this possible across heterogeneous accelerator environments preventing enterprises from ending up with 42 incompatible AI stacks.
The episode closes with a discussion on AI slop, human-in-the-loop thinking, and the future of Kubernetes as the universal platform for running AI agents at scale.
Powered by @acc-ict
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In Episode 135 of the Dutch Kubernetes Podcast, Ronald Kers and Jan Stomphorst sit down with Mohamed Nasser, CEO of VEXXHOST and OpenInfra Foundation board member, together with Thierry Carrez, General Manager of the OpenInfra Foundation and Linux Foundation Europe. The conversation explores the growing relevance of OpenStack in a world increasingly focused on digital sovereignty, private cloud, AI workloads, and secure infrastructure.
The episode dives into how the industry shifted from private infrastructure toward hyperscalers between 2016 and 2020, and why many organizations are now reconsidering that strategy. Thierry explains how geopolitical tensions, vendor lock-in, and changing licensing models have renewed interest in sovereign cloud solutions powered by open source technologies like OpenStack.
Mohamed and Thierry discuss why OpenStack is still highly relevant at massive scale, especially for organizations requiring multi-tenancy, hardware abstraction, GPU enablement, HPC workloads, and advanced networking performance. They explain how Kubernetes has become the user-facing interface, while OpenStack increasingly operates invisibly underneath many modern platforms. Examples discussed include rail infrastructure, gaming companies, telecom providers, and even government environments.
The discussion also explores how Kubernetes and OpenStack complement each other instead of competing. Mohamed explains how many providers now run OpenStack itself on Kubernetes, leveraging cloud-native tooling such as Prometheus and Loki to simplify operations and observability. The hosts also discuss storage abstraction, CSI drivers, bare-metal provisioning with Ironic, and why virtualization still offers major operational advantages in large-scale Kubernetes environments.
Towards the end of the episode, the conversation shifts toward the future of open infrastructure, including confidential computing, Kata Containers, AI security, GPU orchestration, and the growing collaboration between the Linux Foundation, CNCF, and OpenInfra Foundation. Thierry highlights how secure container isolation and confidential computing are becoming increasingly important as AI workloads spread across Kubernetes platforms.
Powered by ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#134 Kubernetes at the Edge: Hype, Reality and Trade-offs
12 mei · 1 u 1 min
In episode 134, Ronald and Jan reconnect with Carl Moberg from Avassa, live from KubeCon Amsterdam, nearly two years after their first spontaneous conversation about edge computing.
Since that first meeting, the edge landscape has evolved rapidly. What was once a niche topic has now become a serious focus area for industries ranging from retail and manufacturing to telecom and AI-driven infrastructure.
Carl shares how organizations are increasingly moving workloads closer to where data is created, whether that is inside factories, retail stores, industrial environments or remote edge locations. The discussion explores the differences between IoT, edge and far edge computing, and why these environments introduce unique operational and security challenges.
A major theme throughout the episode is the role of Kubernetes at the edge. While Kubernetes remains a powerful platform, Carl explains why it is not always the most practical solution for highly distributed or resource-constrained environments. The real challenge is often not starting containers, but everything around them: observability, secrets management, lifecycle management, networking, upgrades and reliability at scale.
The conversation also connects naturally to the previous episode with Neil Cresswell from Portainer. Both episodes explore the same core question from different perspectives:
How do you reliably run modern applications across thousands of edge locations?
An in-depth discussion about containers, operational complexity, AI at the edge, industrial automation and the future of distributed application platforms.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#133 Kubernetes everywhere: how far can it really go?
05 mei · 30 min
In this episode, Ronald and Jan talk with Neil Cresswell, CEO, CTO, and co-founder of Portainer. Neil shares how Portainer started as a simple Docker UI and evolved into a platform for managing Docker, Podman, and Kubernetes environments at scale.
A key topic in this episode is Kube Solo, a lightweight Kubernetes distribution that can run on roughly 200 MB of RAM. The goal is to make Kubernetes usable in environments where traditional clusters are too heavy, such as IoT, edge, and far edge use cases. Think of AI-powered cameras, self-checkout systems, Nvidia Jetsons, and even tractors running intelligent workloads.
Neil explains that Kubernetes itself isn’t getting simpler, but it does need to become more intuitive. Portainer aims to make Kubernetes accessible to IT generalists, reducing the need for highly specialized teams while still leveraging the full power of the ecosystem.
This episode explores simplicity, scalability, edge computing, and what it takes to bring Kubernetes everywhere.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#132 From CPU to GPU: The New Reality of Kubernetes 1.36
21 apr · 40 min
In this episode, Ronald and Jan are joined by Nigel Douglas, Head of Developer Relations at Cloudsmith, to discuss the upcoming Kubernetes 1.36 release and the broader evolution of the Kubernetes ecosystem.
Nigel shares his journey from help desk and cybersecurity roles into open source, eventually working closely with Kubernetes through projects like Calico and Falco within the CNCF ecosystem.
The conversation centers around Kubernetes 1.36, which marks a shift from foundational features toward optimization and new use cases. A major theme in this release is the growing importance of AI workloads. Kubernetes is increasingly positioned as the orchestration platform for AI, with features like Dynamic Resource Allocation (DRA) enabling better management of GPUs and specialized hardware.
Security is another dominant theme. Many of the changes in this release focus on closing gaps and improving control, such as more fine-grained authorization, better admission control during node startup, and addressing previously existing vulnerabilities.
Additionally, the episode highlights several practical improvements, including better snapshot capabilities for stateful workloads, enhanced observability features like native histograms, and improvements in workload scheduling that take hardware topology into account.
The discussion also touches on a common challenge in the Kubernetes world: upgrading. Many organizations still run older versions due to the complexity of dependencies and ecosystem changes, making transitions non-trivial.
Looking ahead, Nigel emphasizes the need for more standardization within Kubernetes to make it easier for organizations to adapt when components change or become deprecated, reinforcing the importance of a stable and predictable ecosystem.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#131 Securing the Software Supply Chain in Kubernetes
31 mrt · 35 min
In this episode, Ronald and Jan talk with Zahra Dehghanpour (platform engineer at bol.com) and Feike Wierda (Senior DevOps Engineer @Bol. via HCS Company) about software supply chain security in Kubernetes environments.
Zahra shares her journey from development to platform engineering, driven by the constant challenges and unpredictability of working with infrastructure. Her earlier experience working in Iran, where infrastructure had to be built and maintained under constraints, shaped her approach to designing resilient and fault-tolerant systems.
Feike explains that software supply chain security covers everything that touches your software, from dependencies and tooling to people and processes. At bol.com, this is addressed by standardizing pipelines, controlling dependencies through internal repositories, and applying security scanning early in the process.
A key theme is balance: developers need freedom, but within secure guardrails. That’s why pipelines are not immediately blocked on vulnerabilities, but first used to provide visibility and gradually increase maturity.
The episode also highlights that security is never “done.” It’s an ongoing process where automation, better tooling, and AI will play an increasingly important role, especially in areas like code review and vulnerability management.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#130 What If You Never Had to Patch CVEs Again?
17 mrt · 38 min
In this episode, Ronald and Jan are joined by Hannah Hawken, partner sales at Chainguard, who brings a fresh perspective on something every Kubernetes team struggles with: security.
What starts as a conversation about career paths quickly turns into a deeper discussion about how we’ve been approaching security all wrong for years. Coming from a background in development and later moving into security, she reflects on what it feels like to build software without truly understanding the risks—and why so many teams are still in that exact position today.
Instead of reacting to vulnerabilities after they appear, the conversation explores a different mindset. One where security isn’t something you bolt on later, but something you start with. Not “shift left”… but start left.
From there, the discussion moves into the reality many teams face: thousands of CVEs, endless patching cycles, and security teams constantly playing catch-up. What if that entire model could be flipped? What if the software you build on is already secure by design?
That idea opens the door to a broader conversation about trust in open source, the hidden complexity of dependencies, and the trade-offs between speed and security. Along the way, Ronald and Jan challenge what this means in practice. How do you actually adopt a different approach? What changes for developers? And where does this fit in real-world environments?
The episode also touches on the future. Not just of Kubernetes, but of the infrastructure powering AI and modern applications. Because if workloads are becoming more complex and critical, the foundation they run on needs to evolve as well.
By the end, one thing becomes clear:
security isn’t just a step in the process anymore… it’s becoming the starting point
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#129 AI, Legacy en de Illusie van Modernisering
24 feb · 41 min
In aflevering 129 spreken Ronald en Jan met Jan Buurman van HCS Company iemand die al sinds zijn 17e in de IT zit en de evolutie van mainframes tot Kubernetes van dichtbij heeft meegemaakt
Jan begon als COBOL-programmeur en groeide door richting organisatie, processen en platformstrategie
Vanuit die brede ervaring kijkt hij anders naar Kubernetes dan veel engineers: niet als eindoplossing, maar als onderdeel van een groter geheel.
Een van de scherpste inzichten uit het gesprek:
Veel organisaties draaien al vijf jaar Kubernetes, maar hebben vaak nog maar 5–10% van hun applicatielandschap gemoderniseerd
Volgens Jan ligt het echte probleem niet bij het platform, maar bij legacy-applicaties en de businesscontext eromheen. Hij deelt een confronterende anekdote van een overheidsorganisatie waar Kubernetes technisch succesvol was geïmplementeerd, maar het onderliggende probleem niet oploste, omdat de oude COBOL- en Oracle Forms-applicaties nog steeds herbouwd moesten worden
We praten over:
- Waarom platform engineering niet automatisch modernisering betekent
- De kloof tussen “de bubbel” en de realiteit bij developers buiten de cloud-native wereld
- Community-denken binnen organisaties als versneller voor standaardisatie
- AI als mogelijke katalysator om legacy sneller te migreren naar Kubernetes
- En waarom standaardisatie vaak het ondergeschoven kindje blijft
Jan sluit af met een nuchtere blik op de toekomst van Kubernetes: niets is permanent in IT. Ook Kubernetes zal ooit verdwijnen — maar tot die tijd is het dé standaard
Een aflevering over realisme, organisatieverandering en waarom techniek zelden het echte probleem is.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode of The Dutch Kubernetes Podcast, Ronald and Jan are joined by Maurice Côté, VP of Products at Devolutions, to talk about one of the most misunderstood topics in modern IT security: Privileged Access Management (PAM).
Too often, PAM is treated as a compliance checkbox. Something you buy because an auditor, insurer, or regulation tells you to. Maurice explains why that mindset is dangerous — and why access itself has become one of the biggest attack surfaces in today’s infrastructures.
The conversation explores how Zero Trust principles apply in real-world environments, including Kubernetes and DevOps workflows. Topics include least privilege, just-in-time access, identity-based authentication, service accounts, and why traditional passwords are slowly disappearing in favor of certificates, passkeys, and identity providers.
They also discuss upcoming regulations like NIS2 and DORA, and why security isn’t about passing audits, but about being able to survive, recover, and continue operating when something goes wrong. From bastion hosts and privileged access workstations to secret rotation and Kubernetes-native integrations, this episode focuses on practical security — not buzzwords.
The key takeaway is clear:
Security is not a product you buy once. It’s a discipline you practice continuously.
A must-listen episode for platform engineers, DevOps teams, security architects, and anyone working with Kubernetes in regulated or high-risk environments.
Powered By ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode of The Dutch Kubernetes Podcast, Ronald and Jan talk with Yahya Al-Salqan, CEO and co-founder of Jaffa.Net Software, about building and scaling global software companies far beyond the traditional tech hubs.
Yahya shares his personal journey from academia and Silicon Valley, where he worked at Sun Microsystems, back to Palestine to found Jaffa.Net. What started as a mission-driven decision to contribute to his community has grown into a company with over 26 years of experience, serving international clients such as Intel, BMW, Fujitsu, Lufthansa, Oxford University, and several Dutch organizations.
The conversation explores how modern software engineering practices and cloud-native technologies make it possible to deliver enterprise-grade solutions globally. Kubernetes and container technologies play a key enabling role by providing consistent environments, repeatable deployments, version control, and zero-downtime upgrades for customers running ERP and custom software solutions.
Beyond technology, the episode highlights the Palestinian IT ecosystem, the importance of education, and how software development allows talent to transcend physical and political borders. Yahya explains why the IT sector is one of the fastest-growing contributors to the local economy and why investing in people and skills is the most sustainable path forward.
The discussion also touches on future trends such as AI, blockchain, and programmable digital money, and how companies must continuously evolve to stay relevant. Throughout the episode, one theme remains central: global software scale is no longer defined by geography, but by mindset, tooling, and execution.
Powered by ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In episode 126 of De Nederlandse Kubernetes Podcast, Ronald and Jan sit down with Chris Noon, Technical Solution Director at Alkira, to talk about one of the most underestimated challenges in cloud-native environments: networking.
Chris shares his journey from traditional telco and enterprise networking, through VMware NSX, to modern cloud and Kubernetes platforms. The conversation dives deep into why networking often becomes more complex—not less—once organizations adopt multi-cloud, hybrid cloud, and Kubernetes at scale.
Key topics include:
- Why IPsec meshes don’t scale in multi-cloud environments
- How “hair-pinning” traffic across regions creates massive latency
- Alkira’s cloud-native approach to connecting AWS, Azure, GCP, and on-prem
- Networking considerations around Kubernetes, CNI’s, and Zero Trust
- DORA compliance, security architecture, and data sovereignty
- Why AI workloads make networking and data placement more critical than ever
A great episode for anyone who realizes that cloud-native doesn’t end at Kubernetes—it starts with solid network architecture.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode of The Dutch Kubernetes Podcast, Ronald and Jan sit down with Jussi Nummelin, Senior Principal Engineer at Mirantis, to explore the world of lightweight Kubernetes, edge computing, and multi-cluster orchestration.
Jussi introduces k0s, a fully upstream Kubernetes distribution packaged as a single, statically compiled binary with zero dependencies. He explains why simplicity, predictability, and minimal operational overhead are essential for edge and IoT environments such as factory floors, industrial controllers, and remote locations with limited connectivity.
The conversation then moves to K0rdent, Mirantis’ multi-cluster management layer built on top of Cluster API. K0rdent enables organizations to declaratively manage large numbers of clusters while automatically deploying essential “beachhead services” like CNI, storage, and observability across environments.
Finally, Jussi shares his perspective on the future of Kubernetes: why it’s here to stay, how edge and cloud are converging, and why Kubernetes is becoming the standard orchestration layer far beyond the traditional datacenter.
A practical and forward-looking episode packed with real-world use cases, architectural insights, and a clear vision of where Kubernetes is heading.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#124 Van Image Max Age tot DRA: de praktische kant van Kubernetes 1.35
24 dec 2025 · 35 min
In aflevering 124 van De Nederlandse Kubernetes Podcast bespreken Jan Stomphorst en Ronald Kers de nieuwste Kubernetes-release: versie 1.35.
Dit keer geen volledige lijst met alle wijzigingen, maar een bewuste keuze voor impactvolle features die in de praktijk het verschil maken.
Een van de eerste onderwerpen is Image Max Age, een nieuwe kubelet-optie waarmee je expliciet kunt bepalen hoe lang ongebruikte container images op nodes blijven staan. Dit helpt bij het voorkomen van volle disks, onverwachte opruimacties en onnodige image downloads, vooral in grote clusters.
Daarna komt Max Parallel Image Pulls aan bod. Deze feature voorkomt zogeheten image pull storms wanneer veel nodes tegelijkertijd een nieuwe image moeten downloaden. Door het pullgedrag te limiteren, blijven clusters stabieler en worden registries minder zwaar belast.
Ook Dynamic Resource Allocation (DRA) krijgt aandacht. Hiermee kunnen resources buiten CPU en geheugen, zoals GPU’s en andere gespecialiseerde hardware, beter en veiliger worden toegewezen aan workloads. Kubernetes 1.35 voegt bovendien verbeterde foutmeldingen toe, waardoor het veel duidelijker wordt waarom een workload niet start.
Tot slot bespreken Jan en Ronald verbeteringen rond StatefulSets, waaronder meer controle over parallelle updates. Dit maakt updates van databases en andere stateful workloads sneller en beter voorspelbaar.
Kortom: Kubernetes 1.35 laat zien dat de focus steeds meer ligt op stabiliteit, schaalbaarheid en real-world operaties, in plaats van alleen nieuwe features toevoegen.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#123 How Kubernetes and AI are helping prevent wildfires
16 dec 2025 · 32 min
In this episode of The Dutch Kubernetes Podcast, Ronald and Jan talk with Andrea Giardini, cloud native consultant and trainer, live from Dutch Cloud Native Day. Andrea shares his journey into cloud and Kubernetes and dives deep into a real-world use case where Kubernetes, data engineering, and AI are used to help prevent wildfires.
Andrea explains how his client Overstory uses satellite and aerial imagery to monitor vegetation near power lines. By combining geospatial data, machine learning models, and infrastructure data from energy providers, they can calculate risk profiles and alert operators before vegetation causes sparks or fires. Instead of reacting to disasters, the platform focuses on prevention.
From a technical perspective, Kubernetes plays a critical role. The workloads vary massively, ranging from small CPU-based tasks to extremely heavy jobs requiring dozens of CPUs, large amounts of memory, or GPUs. Kubernetes provides the flexibility to dynamically scale these workloads, spin resources up and down when needed, and keep costs under control.
The conversation also covers the data engineering workflow. JupyterHub is used extensively for data exploration, but Andrea explains why notebooks alone are not reliable for long-term, repeatable processing. Once experiments are validated, workflows are moved into reproducible Python pipelines using a cloud-native workflow orchestrator (Dagster), fully integrated with Kubernetes.
They further discuss handling large datasets in object storage, running different pipeline steps with different resource profiles, GPU scheduling, and improving developer experience with pull-request-based preview environments. The episode highlights how cloud native technologies are not just about infrastructure efficiency, but can have real-world impact on safety, sustainability, and climate-related challenges.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#122: Helm, Hiccups, and High Scale: Adobe’s Kubernetes Story
09 dec 2025 · 33 min
In deze aflevering spreken Ronald en Jan met Giorgia Fiscaletti, Cloud Reliability Engineer bij Adobe. Giorgia vertelt hoe ze vanuit een creatieve achtergrond — kunst en digital design — uiteindelijk in de wereld van cloud engineering en Kubernetes terechtkwam.
Bij Adobe werkt Giorgia aan Adobe Experience Manager, een enorm platform dat draait op tientallen Kubernetes-clusters met honderden namespaces per cluster. Ze deelt hoe Adobe Helm inzet voor het managen van applicaties op schaal en welke uitdagingen daarbij komen kijken.
Belangrijkste inzichten uit het gesprek:
Van creatieve roots naar cloud engineering: Een onverwachte maar krachtige overgang van artistieke studies naar high-scale cloudplatforms.
Helm op massale schaal: Adobe gebruikte aanvankelijk per namespace een eigen helm-controller en source-controller, maar bij clusters met 200–300 namespaces leidde dit tot overbelasting van de API-server.
Sharding als oplossing: Door controllers te centraliseren en te sharden over labels werd de druk op de API-server drastisch verlaagd.
Etcd-problemen: Helm release secrets stapelden zich op, wat clusters richting read-only situaties duwde. Giorgia legt uit hoe dit werd geïdentificeerd en verholpen.
Complexe customization-lagen: Adobe combineert Helm met meerdere configuratielagen voor klantomgevingen, interne features en experimentele patches.
Real-world scale: 50+ clusters, ~200 namespaces per cluster, Argo CD pipelines, Flux controllers en zeer diverse klantconfiguraties — allemaal parallel draaiend.
Werken bij Adobe: Giorgia geeft een uniek inkijkje in de tooling, architectuur en cultuur achter een platform waar duizenden engineers op bouwen.
Deze aflevering biedt een zeldzaam kijkje in de schaalproblemen, designkeuzes en technische creativiteit die nodig zijn om Kubernetes in enterprise-omgeving zoals Adobe soepel te laten functioneren.
Powered by ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#121 SBOM or Be Doomed: Surviving the Next Supply-Chain Meltdown
02 dec 2025 · 32 min
In this episode of The Dutch Kubernetes Podcast, Ronald and Jan sit down with Soroosh Khodami to explore one of the most urgent questions in modern software engineering: are we truly ready for the next Log4Shell-level cyber crisis?
Soroosh, a hands-on solution architect currently supporting security platform services at Rabobank, takes us deep into the evolving threat landscape. From classic vulnerabilities like SQL injection to modern supply-chain attacks and the infamous XZ backdoor, he explains how seemingly small weaknesses can cascade into full-cluster compromise — especially in cloud-native and Kubernetes environments.
The conversation covers:
- How a simple SQL injection can escalate into full Kubernetes root access, thanks to lateral movement and unpatched dependencies
- What supply-chain attacks really are, and why they’re becoming the attackers' favorite weapon
- Low-effort, high-impact practices to secure your CI/CD pipeline
- Shift-Left Security & DevSecOps — what’s hype, what’s real, and how teams need to evolve
- Why SBOMs are becoming mandatory, and how they help organizations prepare for future zero-days
- Essential tooling for SBOM generation, scanning and continuous monitoring
- How new EU regulations (DORA & CRA) will impact developers, architects and enterprises in the coming years
Soroosh also shares practical stories from the field, including real-world examples of dependency attacks, insecure pipelines, and security mistakes that happen even in mature organizations.
This episode is a must-listen for developers, architects, platform engineers, and anyone building or deploying software in 2025 and beyond.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#120 Let Them Cook — Inside the Kubernetes Recipes Cookbook
25 nov 2025 · 25 min
In this episode, we sit down with Luca Berton and Grzegorz (Greg) Stencel, authors of the brand-new book Kubernetes Recipes — a 400+ page cookbook packed with real, practical solutions for everyday Kubernetes challenges.
Luca and Greg explain how the idea for the book started: most Kubernetes books do a great job explaining theory, but very few show how to solve the messy, real-world issues engineers actually face.
So instead of writing “yet another reference manual,” they chose the cookbook format:
👉 a problem,
👉 a clear solution,
👉 and deeper explanations when needed.
We discuss:
- How they co-wrote the book late at night while balancing work, family life, and open source contributions.
- Why enterprise Kubernetes, especially in heavily regulated environments like finance, is a completely different beast.
- How their recipes cover everything from beginner topics to advanced CRDs, operators, networking, storage, NFS, stateful apps, and multi-cloud clusters.
- The tools that actually help developers — from KubeLens to vCluster.
- Why writing a book forces more accuracy and consistency than video tutorials.
- How they used real questions (including many from Stack Overflow) to choose the most relevant scenarios.
We also talk about the future of Kubernetes:
- Luca sees AI workloads, better observability, and complexity-reducing tooling as the next big wave.
- Greg stresses that developer experience must improve — especially for developers suddenly expected to “learn Kubernetes” overnight. And yes, cluster upgrades remain painful.
A fun and insightful conversation about practical Kubernetes knowledge, open source culture, and what engineers actually need today.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#119 Your Web App Scaling Tricks Don’t Work for LLMs
18 nov 2025 · 37 min
In this episode, we talk with Abdel Sghiouar and Mofi Rahman, Developer Advocates at Google and (guest) hosts of the Kubernetes Podcast from Google.
Together, we dive into one central question: can you truly run LLMs reliably and at scale on Kubernetes?
It quickly becomes clear that LLM workloads behave nothing like traditional web applications:
- GPUs are scarce, expensive, and difficult to schedule.
- Models are massive — some reaching 700GB — making load times, storage throughput, and caching critical.
- Containers become huge, making “build small containers” nearly impossible.
- Autoscaling on CPU or RAM doesn’t work; new signals like GPU cache pressure, queue depth, and model latency take over.
- LLMs don’t run in parallel, so batching and routing through the Inference Gateway API become essential.
- Device Management and Dynamic Resource Allocation (DRA) are forming the new foundation for GPU/TPU orchestration.
- Security shifts as rootless containers often no longer work with hardware accelerators.
- Guardrails (input/output filtering) become a built-in part of the inference path.
And then there’s the occasional request from customers who want deterministic LLM output —
to which Mofi dryly responds:
“You don’t need a model — you need a database.”
Powered by: ACC ICT
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#118 Why Ceph Still Rules Cloud-Native Storage
11 nov 2025 · 40 min
In this episode of De Nederlandse Kubernetes Podcast, we talk with Travis Nielsen, one of the original creators of the Rook project, about the evolution of cloud-native storage and how Rook and Ceph make reliable, distributed storage accessible to Kubernetes users.
Travis shares the story of how Rook started back in 2016 when Kubernetes was still young and how it became the bridge that made Ceph, a powerful but complex storage system, usable in the cloud-native era.
We discuss:
- What Ceph actually is and why it remains one of the most trusted open-source storage platforms.
- How Rook simplifies Ceph deployment and management inside Kubernetes clusters.
- The difference between NFS and CephFS, and when to use each.
- The best ways to run databases on Ceph and how to balance performance, consistency, and replication.
- Multi-tenancy, scaling, and failure domains how Ceph handles massive distributed systems.
- Common mistakes people make when setting up Ceph and how to avoid them.
- The future of storage in the Kubernetes ecosystem and why Ceph remains essential for stateful workloads.
A deep dive into the intersection of data durability, Kubernetes, and open source innovation from someone who helped build it all.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#117 How Policy as Code Is Changing Kubernetes Forever
04 nov 2025 · 37 min
In this episode of De Nederlandse Kubernetes Podcast, we talk with Jim Bugwadia, founder and CEO of Nirmata, and Shuting Zhao, Staff Engineer and one of the maintainers of Kyverno — the CNCF project for Kubernetes policy management.
Jim and Shuting share how Kyverno was born from Nirmata’s commercial work and has since become one of the most widely adopted open source projects in Kubernetes governance, with over 3.4 billion image pulls.
We explore the real question: Why does Kubernetes need policies if it’s already declarative?
Jim explains how policy as code helps developers, operators, and security teams collaborate on cluster configuration at scale — from pod security to resource quotas, network policies, and automation.
Shuting dives deeper into how Kyverno enables granular control, policy exceptions, and flexible enforcement modes — from audit to enforce. They discuss how large organizations use policy automation to improve compliance, security, and even cost efficiency, citing use cases like Adidas saving 50% in dev/test environments using policy-driven resource management.
We also touch on:
- 🧠 The evolution of policy as code and its parallels with infrastructure as code (like Terraform)
- 🧩 The role of AI in simplifying policy authoring (“I don’t want to run as root — just write the policy for me”)
- ⚙️ Nirmata’s Control Hub, a collaboration layer for DevSecOps teams
- 🔒 Shift-down security, where platform teams integrate security directly into Kubernetes itself
A deep-dive episode into how Kyverno and Nirmata are shaping the future of secure, automated Kubernetes governance — blending open source, AI, and DevSecOps collaboration.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT

#116 Running AI on Kubernetes: From GPUs to CRO
28 okt 2025 · 43 min
In this episode of De Nederlandse Kubernetes Podcast, we talk with Carlos Santana, Principal Partner Solution Architect at AWS and long-time contributor to the Kubernetes and AI communities.
Carlos joins us to explore what it really takes to run AI workloads on Kubernetes, from GPU scheduling to scaling inference and training efficiently across clusters. We discuss how AI and machine learning are transforming the cloud-native ecosystem — and why orchestration is becoming just as important as the models themselves.
He shares insights into:
- 💡 The challenges of scheduling and sharing GPUs in multi-tenant Kubernetes clusters
- ⚙️ Why Kubernetes Resource Orchestrator (CRO) could be the next big abstraction layer
- 🚀 The balance between performance, cost efficiency, and developer experience
- 🧠 His hands-on experiments with Jetson devices, edge computing, and model optimization
- 🌐 How open source projects and cloud providers are shaping the future of AI infrastructure
A forward-looking conversation about where AI, Kubernetes, and cloud-native engineering are heading — from someone building that future at scale.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT











de Volkskrant Elke Dag
Dit Is Amerika
FD Dagkoers
Zo simpel is het niet – Stellinga & Schinkel over economie
Voorheen Schaamteloos Randstedelijk (VSR)
Victor Duidt TV
Het Beurscafé
IEX BeleggersPodcast
The Diary Of A CEO with Steven Bartlett
Zogenaamd Succesvol
Dutch Dragons
BNR Nieuws Vandaag