Roman Ashikov
DevOps Team Lead
A public engineering knowledge base.
I publish notes, guides, incident reviews, and practical approaches from my daily work.
Main topics:
- Kubernetes
- Linux
- DevOps
- CI/CD
- Automation
- AIOps
- Engineering documentation
DevOps Team Lead
A public engineering knowledge base.
I publish notes, guides, incident reviews, and practical approaches from my daily work.
Main topics:

Why acceptance criteria and verification methods should be defined before implementation, so that the meaning of done is not adjusted to fit the resulting solution.

How a public draft helps reconstruct a causal chain, expose hidden dependencies, and define the guarantees of an engineering solution.

How an article moves through two repositories, where CI ends, and which part of delivery belongs to Flux.

Why CI could not block Flux after a direct push and how a Merge Request with auto-merge moved validation before the watched branch.

How to turn ticket histories and chat discussions into documentation, checks, and automation that engineers can reuse.

An authorization error from kubectl exec often looks illogical: cannot create resource "pods/exec" The Pod already exists. The command does not create another Pod or modify its specification. get or update might therefore seem like the expected permission, but Kubernetes checks for create. The reason is that RBAC describes Kubernetes API operations, not the literal meaning of kubectl commands. exec is a separate subresource kubectl exec does not operate directly on the pods resource. It calls the pods/exec subresource: ...

A green Ready status and a correct node configuration are not the same guarantee. I ran into that distinction while standardizing kubelet settings across several node classes in a Kubernetes cluster I operated. Each class had a configuration baseline stored in Git. It defined resource reservations, eviction thresholds, and image garbage collection settings. Kubernetes reported the nodes as Ready, yet a separate check found that the local /var/lib/kubelet/config.yaml on some of them no longer matched the expected file. ...

How a final newline differs from a blank line and why one byte affects git diff and git blame.

Why AGENTS.md should be seen not only as AI instructions, but also as part of a DocOps approach to engineering context.

Why AGENTS.md should stay short and not replace README, ADR, CHANGELOG, or project documentation.