HabrJuly 21, 2026🇷🇺Translated from Russian

OTUS Publishes Extensive Digest Covering Kubernetes, GitLab CI, DevSecOps and Infrastructure Reliability

OTUS has published a comprehensive digest designed to help IT specialists tackle complex infrastructure tasks that rarely occur in isolation. The material connects issues such as unstable deployments with CI/CD pipelines, container management, secrets handling, performance problems with monitoring and load testing, and network failures with routing, high availability, and Linux configuration.

The digest is structured into several thematic blocks. The first block offers free lessons on Kubernetes, containers and automation. Scheduled sessions include “K8S + Vault — how to obtain secrets?”, “Using GitLab CI for Ansible”, “Docker in production”, “Kubernetes + CI/CD + GitOps”, and “DRY principle in GitLab CI”.

A separate section covers monitoring, logging and performance with lessons on OpenTelemetry, first load testing practices, and comparison of ELK, EFK and Graylog systems.

Network, storage and resilience topics feature lessons on VLAN configuration, RAID5 recovery in Linux, MPLS for corporate networks, and building fault-tolerant clusters using VRRP and HAProxy.

DevSecOps and infrastructure security lessons address business outcomes of DevSecOps projects, practical secure release processes involving SAST, SCA, container scanning and security gates, as well as Linux kernel protection mechanisms.

Additional lessons focus on Linux kernel modules and expert-level PostgreSQL administration for high-load environments.

The article section contains practical guides such as “Your docker-compose.yml will break: 5 settings everyone forgets”, migration from Fail2Ban to CrowdSec for Netbird and Caddy, IP forwarding at L2 and L3 layers, self-service deployment strategies, Kubernetes architecture overview, container security with capabilities, seccomp and AppArmor, L2 loop and broadcast storm detection, CI automation anti-patterns, and a case study of an Intel X710 multicast storm.

For deeper study, OTUS presents advanced courses with entrance testing: “DevSecOps Implementation”, “Observability”, “High-Load Systems Infrastructure”, “Linux Kernel Development”, “PostgreSQL Administration — Expert Level”, “Network Engineer — Advanced”, “Kubernetes Infrastructure Platform”, and “CI/CD with GitLab”.

Related articles

AntiMalwareOther

Xello and Kode Bezopasnosti Sign Technological Partnership to Integrate Equipment Emulation into Xello Deception Platform

Xello, a Russian developer of data and infrastructure protection platforms, and Kode Bezopasnosti, a Russian developer of software and hardware information security tools, have signed a technological partnership agreement. The collaboration will enable emulation of Kode Bezopasnosti equipment within Xello Deception, the first domestic Distributed Deception Platform designed to protect against targeted attacks. This integration will enhance the creation of a realistic false layer of IT assets and expand use cases for early threat detection in customer environments. Xello product head Rustam Zakirov emphasized that the partnership addresses customer needs by making the deception layer more authentic for organizations using Kode Bezopasnosti solutions while fostering expertise exchange. Kode Bezopasnosti strategic marketing head Pavel Korostelev highlighted the growing demand for deception technologies amid rising targeted attacks and the value of supporting proactive detection capabilities on the Russian market. The agreement combines both companies' strengths to improve practical scenarios for cyber deception deployment.

HabrOther

How Ideco Measures NGFW Performance Using TRex ASTF and RFC 9411 Methodology

Ideco engineers have published a detailed methodology for benchmarking the performance of their Ideco NGFW Novum product on the Ideco EX hardware platform. The team uses TRex in Advanced Stateful mode to generate realistic L4-L7 traffic and follows RFC 9411 guidelines to ensure reproducible results across different test environments. Key metrics include throughput on UDP 1518-byte frames reaching 200 Gbit/s, TCP/HTTP performance varying from 100 Gbit/s down to 62 Gbit/s depending on object size, and EMIX mixed traffic dropping from 92 Gbit/s with firewall only to 15.5 Gbit/s when all inspection engines are enabled. The methodology incorporates binary search for maximum load, a 1% session drop threshold, and 300-second hold times per test point to capture real-world behavior rather than short-term peaks. All tests were performed without TLS decryption, with separate plans for hardware-based Keysight BreakingPoint testing when decryption is required. The full article includes hardware specifications, traffic profiles, loss calculation formulas, and configuration details to allow anyone to reproduce the measurements.

安全客Other

Siemens Industrial AI Drives Green Efficiency Revolution in Infrastructure Cooling, Parks, and Data Centers

The article explores how Siemens is applying industrial AI to transform physical infrastructure operations across buildings, industrial parks, and data centers in China. It details the company's non-invasive AI BOX solution that optimizes cooling systems in hotels and other facilities without replacing existing equipment, achieving around 7% additional energy savings. The Smart ECX platform enables integrated source-grid-load-storage management for zero-carbon factories, delivering 30% cost reductions and over 90% overall energy efficiency. Siemens also supplies critical power distribution hardware such as NXAirS medium-voltage switchgear and SIVACON S8 low-voltage cabinets to support high-reliability AI data center operations. The coverage highlights alignment with China's 15th Five-Year Plan carbon peaking policies and real-world deployments at venues including the Shanghai Yingyi Crowne Plaza Holiday Hotel and Sichuan Chuanrun's Chengdu factory. Overall, Siemens emphasizes combining domain physics models with machine learning to deliver verifiable, replicable industrial value rather than generic AI concepts.

AntiMalwareOther

RuBackup 2.9.0 Receives Official Compatibility Certificate with BAUM-Inform Storage Systems

RuBackup version 2.9.0 from the Astra Group has successfully passed compatibility testing with storage systems produced by BAUM-Inform. The verification confirmed that the backup solution can reliably perform data backup and recovery operations using BAUM-Inform hardware. Testing followed a predefined program and methodology, although detailed results and the full list of tested configurations were not disclosed. BAUM-Inform systems are designed for corporate data storage and processing, while RuBackup supports servers, workstations, virtualization environments, mail systems, databases, and domain infrastructure. The certification allows organizations to deploy both products together without additional integration validation. Both companies stated that the verified combination reduces deployment risks and supports the development of fully domestic data protection infrastructures.