footer trimmed to the credit line; podman and oc throughout (Containerfile, podman docs links)

This commit is contained in:
2026-08-17 16:11:22 +10:00
parent b12e435003
commit d8a39c6a6c
2 changed files with 16 additions and 18 deletions
+15 -17
View File
@@ -11,7 +11,7 @@
<p class="kt">Index</p>
<ol>
<li><a href="#c0"><b>Course 00</b><span>Aperitif - three commands, and what actually just happened</span></a></li>
<li><a href="#c1"><b>Course I</b><span>Docker - an image is a stack of frozen diffs</span></a></li>
<li><a href="#c1"><b>Course I</b><span>Podman - an image is a stack of frozen diffs</span></a></li>
<li><a href="#c2"><b>Course II</b><span>Kubernetes - a cluster is a promise, not a place</span></a></li>
<li><a href="#c3a"><b>Course III</b><span>The node - where intent becomes a process</span></a></li>
<li><a href="#c3b"><b>Course III</b><span>The pod - one IP, shared fate</span></a></li>
@@ -52,15 +52,15 @@
<img class="flat" src="__HERO_SURROUND__"
alt="Six dark armour fragments with neon seams framing a large empty centre - the
casing of a machine caught the instant before it comes apart.">
<div class="crt" role="img" aria-label="A terminal transcript: docker build, docker push,
kubectl apply, kubectl get pods showing Running - then the question: but what
<div class="crt" role="img" aria-label="A terminal transcript: podman build, podman push,
oc apply, oc get pods showing Running - then the question: but what
actually just happened?">
<p class="line">$ docker build -t shop/api:1.4.2 .</p>
<p class="line">$ podman build -t shop/api:1.4.2 .</p>
<p class="line ok">=&gt; exported image sha256:9f2c41...</p>
<p class="line">$ docker push shop/api:1.4.2</p>
<p class="line">$ kubectl apply -f deploy.yaml</p>
<p class="line">$ podman push shop/api:1.4.2</p>
<p class="line">$ oc apply -f deploy.yaml</p>
<p class="line ok">deployment.apps/api created</p>
<p class="line">$ kubectl get pods</p>
<p class="line">$ oc get pods</p>
<p class="line ok">api-7d4b9c6-x2k4f&nbsp;&nbsp;1/1&nbsp;&nbsp;Running</p>
<p class="line q">...but what actually just happened?</p>
</div>
@@ -78,7 +78,7 @@
<!-- ============ COURSE I ============ -->
<section class="course" id="c1" data-scene="docker" aria-labelledby="c1h">
<header class="chead">
<p class="eyebrow">Course I &middot; Docker</p>
<p class="eyebrow">Course I &middot; Podman</p>
<h2 id="c1h" class="thesis">An image is not a box.<br><em>It is a stack of frozen diffs.</em></h2>
<p class="lede">Scroll, and the thing you keep calling "a container image" comes apart in your
hands. Four layers. Each one only stores what changed from the layer under it - and here they
@@ -108,17 +108,17 @@
<p>The builder caches layer by layer, and a cached layer survives only while everything
beneath it is unchanged. Put <span class="mono">COPY . .</span> above your dependency
install and you have told the builder to throw the dependency cache away every time one
line of code changes. Dependencies first, code last - a Dockerfile is a cache policy that
line of code changes. Dependencies first, code last - a Containerfile is a cache policy that
happens to build software.</p>
<p class="fieldnote"><b>Field note.</b> A rebuild that takes twenty minutes and one that
takes twenty seconds are usually the same Dockerfile with the lines swapped.</p>
takes twenty seconds are usually the same Containerfile with the lines swapped.</p>
<p class="closeline">This stack explains the whole ecosystem above it: sharing explains why
pulls are fast, immutability explains why a digest can name the exact bytes (Course VII),
and the throwaway top layer explains why state needs volumes. One idea - frozen diffs -
all the way down.</p>
<p class="reads"><b>Pre-reads:</b> none - start here
&ensp;<b>Further:</b> <a href="https://docs.docker.com/get-started/">Docker get-started</a> &middot;
<a href="https://docs.docker.com/build/">Docker build + layers</a></p>
&ensp;<b>Further:</b> <a href="https://podman.io/get-started">Podman get-started</a> &middot;
<a href="https://docs.podman.io/">Podman docs + builds</a></p>
</div>
</section>
@@ -146,7 +146,7 @@
<div class="prose">
<h3>Desired against actual, forever</h3>
<p>The habit underneath everything: the <b>reconciliation loop</b> - compare desired state
against actual state, fix the difference, repeat. That <span class="mono">kubectl apply</span>
against actual state, fix the difference, repeat. That <span class="mono">oc apply</span>
didn't launch anything; it filed paperwork. The machine took it from there, and it never
stops taking it from there: kill a pod and it returns, not because something noticed the
crash but because the loop noticed the difference.</p>
@@ -340,7 +340,7 @@
<h2 id="c6h" class="thesis">Nobody deploys anything.<br><em>The cluster syncs itself.</em></h2>
<p class="lede">The mental model everyone arrives with: someone with credentials pushes manifests
at the cluster. In GitOps nothing is pushed. A repository holds the desired state, an agent
inside the cluster watches it, and the cluster pulls its own future from git. kubectl is for
inside the cluster watches it, and the cluster pulls its own future from git. oc is for
looking; git is for changing.</p>
</header>
<div class="pin">
@@ -362,7 +362,7 @@
revision - watch this branch of this repository - and the controller renders what it finds
there, compares it against the live cluster, and syncs the difference. The deploy button is a
git commit; the audit log is git log; code review <i>is</i> change control.</p>
<p class="sayit">kubectl apply is for archaeology, not for change.</p>
<p class="sayit">oc apply is for archaeology, not for change.</p>
<h3>Pull, not push - the security inversion</h3>
<p>The cluster <b>pulls</b>. No CI system, no laptop, no build pipeline holds a credential that
can touch it - the agent inside holds a read-only deploy key, and the trust arrow points out.
@@ -645,8 +645,6 @@
</section>
<footer class="outro">
<p>The Exploded Cluster &middot; every scene is one generated hero, sliced and scrubbed -
no diagrams were harmed.</p>
<p>&copy; 2026 Jonathon Wright &middot; <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/">CC BY-NC-SA 4.0</a>
&middot; built with GSAP, shipped via GitOps &middot; <a href="https://www.bztmon.com/">bztmon.com</a></p>
</footer>
+1 -1
View File
@@ -457,7 +457,7 @@
{
"name": "console",
"title": "oc + console",
"blurb": "kubectl, extended - the operator's handheld.",
"blurb": "The CLI and the web console - the operator's handheld.",
"z": 0,
"points": [
[