How I Ran Public and Private Services on a Single Kubernetes Node

Context My homelab runs on a single physical server: an old i7 with 32 GB of RAM. On top of it, I built a Kubernetes cluster with microk8s. It scales easily, the community is huge, and there is a tool for everything: logs, security, backups. It can also run in hybrid mode, with my local node and some nodes in the cloud if I ever need them. I didn’t start with a few containers and migrate later. I went straight to Kubernetes. ...

October 5, 2026 · 7 min · Flavien Jourdren

HTTPS with Let's Encrypt, Traefik and Cloudflare on a multi-domain Kubernetes cluster

Users expect every service to be secure by default. You never know who might be listening, even on your own network. That’s why HTTPS has become standard in any modern setup. This article covers how I set it up on a Kubernetes cluster with Cloudflare, Traefik and Let’s Encrypt’s DNS-01 challenge. One of my constraints was to be able to reinstall the whole server very quickly. And that’s exactly what got me a Let’s Encrypt 429, rate-limited. So if you don’t want to wait 24 hours for nothing like I did, read this carefully. ...

August 29, 2026 · 6 min · Flavien Jourdren

Tailscale on a Local Kubernetes Homelab

Context My homelab server runs 28 services. Most of them are private, and I wanted an easy way to reach them from outside. I chose Tailscale. Here is how I set it up. The network underneath Before the VPN setup, some context on how my Kubernetes cluster network is laid out. Most of my services are private, a few are internet-facing. That split gave me two classes of service, and each class has its own namespace, network, and security rules (NetworkPolicies). ...

August 19, 2026 · 6 min · Flavien Jourdren

How I Migrated an Untested Codebase with Loops and an AI Harness

I was handed a SaaS running on Firebase that had to move to Supabase, on a very low budget. This article covers the techniques I used to get it done with an AI harness. Starting point The application was a Nuxt.js SaaS with 20 large screens running on Firebase, already written in TypeScript. It worked as a workflow that enriched business data step by step. Users could manage multiple projects. Each project was owned by one or several “managers”, who could invite “contributors” to go through the workflow. That implied a role system. There was also an admin area. ...

August 8, 2026 · 6 min · Flavien Jourdren

Installing DevStack

DevStack is a project whose purpose is to quickly deploy a development and testing environment for OpenStack. DevStack supports Ubuntu 16.04/17.04, Fedora 24/25, CentOS/RHEL 7, as well as Debian and OpenSUSE. In this article, we will install the Ocata version of OpenStack. DevStack installs the following modules by default: Keystone: Identity service. Nova: Virtualization management module. Cinder: Storage. Neutron: Network module. Horizon: Web interface. Warning: DevStack is not designed to be restarted. It cannot be used as a production environment. ...

June 7, 2018 · 3 min · Flavien Jourdren

Building a REST API

The principle is to break down the application into resources that clients can use through HTTP requests. This architecture for distributed systems was created in 2000 by Roy Fielding in his doctoral thesis. The benefit of a REST API is making the application’s resources usable by all its components. This enables implementing microservices, portability, and giving external parties access to certain features. Resource Identification by URL Each resource must be identified via a URL that is logically structured. Resource names should use the plural form to indicate that without filtering parameters, all elements are displayed. When filtering, we keep the plural, implying that we retrieve all elements then return only the filtered one. ...

June 6, 2018 · 3 min · Flavien Jourdren

Continuous Deployment with Docker and Jenkins

The goal of this tutorial is to set up continuous and automatic deployment of an application with Jenkins on a Docker architecture. Continuous and automatic deployment is one of the key concepts of the DevOps movement. The purpose is to foster application industrialization by enabling a system to: test the application, build the container image, and deploy it to production. Prerequisites: Docker Docker-compose How It Works Our deployment system will use 4 layers to deploy the application to production: ...

April 14, 2018 · 5 min · Flavien Jourdren

Load Balancing Fundamentals

Load balancing is one of the essential concepts for building architectures that can handle heavy traffic and are resilient to failures. It is a set of techniques for distributing workload across different computers in a group. The use cases for load balancing are increasingly numerous, especially with the advent of cloud computing and decentralized data architectures. These techniques are used in: supercomputers, high-traffic HTTP services, databases requiring permanent access, big data, neural network training, etc. ...

April 7, 2018 · 3 min · Flavien Jourdren

Installing Jenkins

Jenkins is an open source continuous integration tool developed in Java. Adding Repositories to Install Java 8 Adding repositories: echo "deb http://ppa.launchpad.net/webupd8team/java/ubuntu xenial main" | tee /etc/apt/sources.list.d/webupd8team-java.list echo "deb-src http://ppa.launchpad.net/webupd8team/java/ubuntu xenial main" | tee -a /etc/apt/sources.list.d/webupd8team-java.list Adding the package verification certificate: apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys EEA14886 Updating repositories: apt-get update Installing Java 8 Install the Java 8 package and accept its terms of use: apt-get install oracle-java8-installer Installing Jenkins We will use wget to download the Jenkins .war file: ...

April 6, 2018 · 1 min · Flavien Jourdren

MySQL Master-Master Replication with Load Balancing

This article covers the procedure for setting up a MySQL Master-Master (and Master-Slave) server with a load balancing system using the round robin algorithm (via HAProxy). In our example, we will have three servers: one managing load balancing (named SRV-LBSQL with IP address 10.0.0.100) and two MySQL servers connected to each other (named SRV-MYSQL01 and SRV-MYSQL02 with IP addresses 10.0.0.1 and 10.0.0.2 respectively). Each MySQL server will process SQL queries in turn. The database servers will replicate data between each other using a dual Master-Slave relationship. ...

March 28, 2018 · 5 min · Flavien Jourdren