<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>cossth.com // Systems Engineering Journal</title>
    <link>https://cossth.com</link>
    <description>Security-reviewed engineering notes about Kubernetes, observability, storage, databases, and reliable operations.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Sep 2026 05:30:00 GMT</lastBuildDate>
    <atom:link href="https://cossth.com/rss.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>Retiring 24/7 Nginx Pods: Static Sites on Object Storage Without Losing GitOps Safety</title>
      <link>https://cossth.com/blog/retiring-24-7-nginx-pods-object-storage-gitops</link>
      <guid isPermaLink="true">https://cossth.com/blog/retiring-24-7-nginx-pods-object-storage-gitops</guid>
      <pubDate>Wed, 30 Sep 2026 05:30:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Kubernetes</category>
      <category>GitOps</category>
      <category>Object Storage</category>
      <category>Platform Engineering</category>
      <category>SRE</category>
      <description>Static frontends do not always need a permanent web-server pod. This case study explains how we replaced always-on Nginx workloads with short-lived synchronization jobs, versioned object storage, and a shared read-only delivery gateway while preserving GitOps deployment and rollback safety.</description>
    </item>

    <item>
      <title>The 328% Memory Mirage: A Safer Kubernetes Memory Rightsizing Method</title>
      <link>https://cossth.com/blog/the-328-percent-memory-mirage-kubernetes-ghost-limits</link>
      <guid isPermaLink="true">https://cossth.com/blog/the-328-percent-memory-mirage-kubernetes-ghost-limits</guid>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Kubernetes</category>
      <category>SRE</category>
      <category>Observability</category>
      <category>Prometheus</category>
      <category>Capacity Planning</category>
      <category>Linux Kernel</category>
      <description>A telemetry review found that configured Kubernetes memory ceilings exceeded available capacity by more than threefold. This anonymized case study explains how to identify policy drift, stage safer changes, and verify the outcome without exposing operational details.</description>
    </item>

    <item>
      <title>Postmortem: A Kubernetes Control-Plane Memory and Storage Cascade</title>
      <link>https://cossth.com/blog/postmortem-control-plane-memory-exhaustion-iscsi-failover</link>
      <guid isPermaLink="true">https://cossth.com/blog/postmortem-control-plane-memory-exhaustion-iscsi-failover</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Kubernetes</category>
      <category>SRE</category>
      <category>Storage</category>
      <category>Linux Kernel</category>
      <category>Postmortem</category>
      <description>A blameless, anonymized review of how control-plane memory pressure, storage latency, and health-check failures combined into an availability incident—and how verified monitoring changes improved response.</description>
    </item>

    <item>
      <title>Choosing Between eBPF Auto-Instrumentation and OpenTelemetry SDKs</title>
      <link>https://cossth.com/blog/zero-overhead-distributed-tracing-ebpf-vs-otel-sdk</link>
      <guid isPermaLink="true">https://cossth.com/blog/zero-overhead-distributed-tracing-ebpf-vs-otel-sdk</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Observability</category>
      <category>eBPF</category>
      <category>OpenTelemetry</category>
      <category>Go</category>
      <description>A security-safe, qualitative comparison of kernel-assisted auto-instrumentation and in-process OpenTelemetry SDKs, covering overhead, semantic context, privacy, and hybrid design.</description>
    </item>

    <item>
      <title>Postmortem: Kernel-Memory Growth and Intermittent Connection Resets</title>
      <link>https://cossth.com/blog/postmortem-ebpf-socket-filter-leak-tcp-resets</link>
      <guid isPermaLink="true">https://cossth.com/blog/postmortem-ebpf-socket-filter-leak-tcp-resets</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Kernel</category>
      <category>eBPF</category>
      <category>Kubernetes</category>
      <category>SRE</category>
      <description>An educational case study and systems engineering reference on kernel resource accounting in Linux telemetry: why user-space process restarts fail to reclaim kernel-resident BPF state, and how to verify lifecycle invariants.</description>
    </item>

    <item>
      <title>Avoiding Redundant Replication in Kubernetes Database Storage</title>
      <link>https://cossth.com/blog/migrating-cnpg-to-single-replica-longhorn</link>
      <guid isPermaLink="true">https://cossth.com/blog/migrating-cnpg-to-single-replica-longhorn</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Storage</category>
      <category>Kubernetes</category>
      <category>Database</category>
      <category>SRE</category>
      <description>An anonymized case study on assigning recovery responsibility between database and storage layers, reducing duplicated write work without presenting the design as a universal rule.</description>
    </item>

    <item>
      <title>Architecture Decision: Evaluating an Immutable Kubernetes Operating System</title>
      <link>https://cossth.com/blog/adr-009-immutable-talos-linux-vs-ubuntu-baremetal</link>
      <guid isPermaLink="true">https://cossth.com/blog/adr-009-immutable-talos-linux-vs-ubuntu-baremetal</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <author>shubham@cossth.com (Shubham Sharma)</author>
      <category>Talos</category>
      <category>Architecture</category>
      <category>Kubernetes</category>
      <category>Linux</category>
      <description>An anonymized architecture decision explaining why a declarative, immutable Kubernetes operating system reduced configuration drift while introducing a stricter operational model.</description>
    </item>
  </channel>
</rss>
