De Nederlandse Kubernetes Podcast
Ronald Kers en Jan Stomphorst

Nieuwste aflevering
144 afleveringen
- In this episode, Ronald and Jan talk with Idit Levine, founder and CEO of Solo.io. Idit shares how a single job interview shaped her career and how she picked Kubernetes as the winner when Docker Swarm and Mesos were still in the race.
She is refreshingly honest about service mesh, including where Istio went wrong and why she believes Ambient mode finally gets it right. Then the conversation turns to AI: why agents are stateful workloads that don't fit the classic Kubernetes model, why Solo.io built and donated kagent to the CNCF, and what that means for platform engineers.
We also discuss whether AI will replace engineers, what a young person entering IT should learn today, and Idit's warning to the community: if Kubernetes doesn't evolve for AI workloads, it risks losing relevance.
A candid conversation about vision, mistakes, and the future of cloud native.
Stuur ons een bericht.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Dutch Cloud Native Day 2026
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT - We sit down with Simone Rodigari, software engineer in Azure Core Container Networking and one of the maintainers of Retina, the eBPF-based observability project. Simone had just delivered his session on Kubernetes networking, and we asked him to give our listeners the same mental model, the one you need when something breaks and you have no idea where to start tracing.
We start at the ground rules: every pod gets an IP, every pod can reach every other pod. That's the expectation Kubernetes sets, but Kubernetes doesn't implement it, the CNI does. Simone walks us through the pod network namespace, the veth pair that works like a virtual cable, and what actually happens to a packet on its way out of the node.
From there we get into the real trade-offs:
Overlay (VXLAN, IP-in-IP, Geneve) versus underlay and direct routing with BGP portability versus performance, and why the answer is always "it depends"
Why pods being ephemeral forces the Service abstraction, and how DNAT and load balancing actually work underneath
kube-proxy modes iptables, IPVS, nftables and why linear rule traversal hurts at scale while eBPF maps give you constant-time lookups
Where eBPF has its own limits: map sizes, memory and CPU
Hubble as a Kubernetes-aware tcpdump, and how Retina brings that same flow visibility to any CNI even Flannel
Jan's production pain: hitting the Cilium identity ceiling on managed AKS and the hack he needed to work around it
We close on the future: operating clusters at massive scale, AI moving from training to inference, and Simone's warning that the community should solve real problems instead of bending Kubernetes to fit every new one.
🎧 A grounded, practical episode for anyone who has ever stared at a dropped packet and wondered which component to blame.
Stuur ons een bericht.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Dutch Cloud Native Day 2026
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT - Bij de AIVD kom je niet zomaar binnen. Je legt je telefoon en je spullen weg, je gaat door de security check en de poortjes, en pas daarna ga je aan het werk. De netwerken daarachter zijn net zo streng afgesloten: de meeste hebben geen internet, ze leven helemaal los van elkaar, en data kan er maar één kant op.
In deze aflevering van De Nederlandse Kubernetes Podcast spreken Ronald Kers en Jan Stomphorst met Wouter en Nick, die bij de AIVD in het platformteam werken.
Ze vertellen hoe updates via data diodes naar binnen komen, waarbij data maar één kant op kan en niet terug. Packages en images die ontwikkelaars nodig hebben moeten offline beschikbaar zijn, zodat een ontwikkelaar binnen dezelfde ervaring heeft als iemand die wel internet heeft. Wat binnenkomt wordt eerst gecontroleerd voordat het in de repository terechtkomt.
Verder in het gesprek: waarom ze werken met één groot multitenant cluster dat elk kwartaal wordt geüpdatet, waarom vuile data daar bewust buiten blijft, hoe ze Cluster API en de bijbehorende image builder gebruiken om eigen images te bouwen volgens eigen regels, en waarom hun filosofie is om zoveel mogelijk open source te gebruiken om vendor lock-in te voorkomen.
Ook aan bod: hoe applicaties organisch redundant zijn geworden doordat nodes gewoon 's nachts worden gerecycled, de oriëntatiefase rond Gateway API, GPU's in de eigen omgeving, de samenwerking met de MIVD en JIVC, en de grootste uitdaging voor de toekomst, namelijk dat steeds meer producten alleen nog als SaaS beschikbaar zijn.
https://werkenbijdeaivd.nl/
De Nederlandse Kubernetes Podcast is een initiatief van ACC ICT
Stuur ons een bericht.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Dutch Cloud Native Day 2026
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT - Kubernetes 1.37 verscheen eind augustus onder de naam Garhwal, genoemd naar de Noord-Indiase regio waar de release lead zelf vandaan komt. Op papier een rustige release: 67 enhancements, waarvan zestien naar Stable, drieëntwintig naar Beta en zevenentwintig nieuw in Alpha. Jan constateert dat Kubernetes al een tijd steeds stabieler wordt en dat breaking changes zeldzamer worden. Goed nieuws, al maakt het de zoektocht naar een spannend verhaal voor een release-aflevering er niet makkelijker op. Deze keer valt er genoeg uit te diepen.
IPVS gaat eruit. Jan legt uit wat kube-proxy doet en waarom IPVS-mode, ooit geïntroduceerd omdat iptables te klein werd, nu zelf wordt uitgefaseerd. Het probleem is structureel: elke node draagt de IP-adressen van elke service. Bij twintig services merk je daar niks van, bij tweeduizend wel. In 1.43 verdwijnt IPVS volledig, maar het moment waarop je het gaat voelen ligt eerder. De praktische boodschap: stap over naar nftables vóór 1.40, en besef dat een upgrade dat niet voor je doet. Je moet het expliciet instellen.
iptables versus nftables. Een heldere uitleg van wat iptables eigenlijk is, namelijk firewall én routing op Linux met één lineaire regellijst die per pakket wordt doorlopen, en waarom dat in Kubernetes tegen een plafond loopt. De API ondersteunt geen incrementele updates, dus voor één regel moet de hele set opnieuw geladen worden. nftables gebruikt sets, maps en efficiëntere datastructuren, en biedt één uniform framework voor IPv4, IPv6, ARP en bridge filtering. Wel opletten: de twee zijn niet volledig compatibel met elkaar, en je hebt een recente kernel nodig.
Scale-to-zero is nu native. De HPA kan naar nul zonder dat je iets aan je bestaande configuratie hoeft te veranderen. Waar eerst één stond, kan nu nul staan. De afweging is opstarttijd bij de eerste request, maar als er niets draait betaal je ook niets. Jan wijst op het slimme detail: de HPA schaalt alleen terug omhoog als hij zelf naar nul is gegaan. Zet je de replicas handmatig op nul om iets immutables aan te passen, dan laat de autoscaler je met rust. Een herkenbare praktijkergernis, opgelost.
En KEDA dan? Ronald en Jan zetten ze naast elkaar en komen uit op complementair in plaats van concurrerend. KEDA's voordeel is dat het buiten het cluster kan kijken: een firewall of een externe dienst kan het signaal geven dat een pod moet starten. Jan schetst een bijna-serverless patroon waarin verkeer binnenkomt, KEDA de pod start, het request wordt afgehandeld en de pod daarna weer verdwijnt.
Twee harde eisen. containerd 1.x moet eruit en cgroup v1 moet eruit. Allebei niet nieuw: failCgroupV1 staat sinds 1.35 standaard op true. Jan vertelt hoe dat bij kube-spray in de praktijk uitpakte. Een mismatch tussen de cgroup-driver van de kubelet en die van de runtime levert het vervelendste type storing op. Niet kapot, maar onvoorspelbaar, met de OOM killer die processen afschiet die er niets aan kunnen doen. Bij ACC ICT wordt zoiets standaard eerst getest en worden nodes vaak simpelweg vervangen door nieuwe machines in plaats van online geüpgraded.
containerd 2.0 verandert ook je security-defaults. Containers zonder host-netwerk of user namespaces mogen nu poorten onder 1024 binden zonder CAP_NET_BIND_SERVICE, en ping draaien zonder CAP_NET_RAW. Een afspraak van decennia oud, stilzwijgend versoepeld. Terug te draaien, maar je moet het nu bewust configureren.
Verder in deze aflevering: waarom Ubuntu geen excuus meer is, hoe een onbewaakte auto-update je zomaar een major containerd-versie kan opleveren, wat managed clusters wél en niet voor je regelen, en Jans terugkerende standpunt door de hele aflevering heen: het meeste hiervan is geen probleem zodra je je machines gewoon actueel houdt.
Stuur ons een bericht.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Dutch Cloud Native Day 2026
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT - Andrew "Andy" Block writes books and reviews pull requests at thirty thousand feet over the Pacific, because as he says, he can sleep when he's dead. Between Red Hat's services organization and four talks at KubeCon Amsterdam, he sat down with Ronald Kers and Jan Stomphorst to talk about the first major Helm release in almost five years.
Helm 4 is a story about restraint. Helm has become load bearing for an enormous number of enterprises, and a strict versioning policy left technical debt with nowhere to go. Helm 4 clears that debt without breaking anyone. Replace the binary, keep your charts, notice almost nothing. After what the Tiller removal in Helm 3 cost teams like Jan's, that is the achievement.
Underneath sits more than the version number suggests: a Wasm based plugin model that finally makes Helm properly extensible, a serious API and logging cleanup, and better status handling built on libraries contributed out of the Flux community. Charts v3 comes next, letting you swap Go templating for Jinja or Rust, and opening the door to downloader and signer plugins.
That plugin model matters most for signing. Andy asked a room of roughly three hundred people how many sign their Helm charts. Three hands went up. GPG is painful enough that even a security specialist avoids it, so Sigstore behind a plugin becomes the realistic path to provenance. On the OCI side, per repository credentials and transparent mirroring mean organizations can stop forking charts just to repoint them internally.
The conversation widens from there: why Kustomize and Helm complement rather than compete, why European organizations are moving back on prem, and whether AI now produces code faster than any maintainer can honestly review it.
Andy's crystal ball isn't about features at all. It's about approachability, and lowering the barrier for the newcomers who made up well over half the room at KubeCon.
Stuur ons een bericht.
ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal
Dutch Cloud Native Day 2026
Two days of cloud native talks, workshops and community in Utrecht, exploring how AI is changing the way we build, run and scale modern platforms.
Like and subscribe! It helps out a lot.
You can also find us on:
De Nederlandse Kubernetes Podcast - YouTube
Nederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTok
De Nederlandse Kubernetes Podcast
Where can you meet us:
Events
This Podcast is powered by:
ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
Meer Onderwijs podcasts
Trending Onderwijs -podcasts
Over De Nederlandse Kubernetes Podcast
De Nederlandse Kubernetes Podcast: gemaakt door én voor mensen met een hart voor IT. In deze reeks gaan Ronald Kers en Jan Stomphorst in gesprek over Kubernetes met als doel Kubernetes toegankelijk te maken voor iedereen.
Podcast websiteLuister naar De Nederlandse Kubernetes Podcast, Taal.Guru Spaans el Primer Paso en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies
Ontvang de gratis radio.net app
- Zenders en podcasts om te bookmarken
- Streamen via Wi-Fi of Bluetooth
- Ondersteunt Carplay & Android Auto
- Veel andere app-functies


De Nederlandse Kubernetes Podcast
Scan de code,
download de app,
luisteren.
download de app,
luisteren.













