Ansible can be used in many ways: most people likely execute their playbooks on their local machines. Then there is Ansible Automation Platform (AAP) (formerly Ansible Tower) and its small brother AWX. Both are the standard in larger organizations to allow for a more controlled way of running Ansible playbooks and offer RBAC capabilities. These two are also really “heavy” and require a lot of resources to run. Since some time both also require a Kubernetes backend.
These facts are not attractive for homelabs or other small-scale use cases. Luckily, Semaphore exists, which is a project aiming to provide a lightweight alternative to AAP. Maybe there are also even more alternatives, yet I was not able to find any others when researching the topic until today.
Kubernetes ist zum Rückgrat der modernen digitalen Infrastruktur geworden – es treibt alles an, von SaaS-Plattformen bis hin zu unternehmenskritischen Systemen im Gesundheitswesen, in der Finanzbranche und in der öffentlichen Verwaltung.
Doch eine Sache wird immer noch weit unterschätzt: Kubernetes allein reicht nicht.
Der Betrieb von Kubernetes in Produktion erfordert weit mehr als das Upstream-Projekt. Du brauchst Netzwerk, Storage, Observability, Security-Hardening, Upgrade-Tooling und operative Prozesse – alles eng integriert und kontinuierlich gepflegt.
Genau hier kommen Kubernetes-Distributionen ins Spiel.
Und wenn du diese Komplexität nicht selbst betreiben möchtest, gibt es eine Abstraktionsebene höher: Managed Kubernetes oder Managed OpenShift.
In diesem Beitrag werfen wir einen Blick auf die Kubernetes-Distributionslandschaft im Jahr 2026 und erklären, warum das Auslagern des Betriebs oft die klügste Wahl ist.
The RouterKit mission is to provide a plattform to deploy software defined routers and firewalls. This goal is supported by providing…
Mit ALASCA - Verband für betriebsfähige, offene Cloud-Infrastrukturen e.V. positionieren wir uns als Cloud- und Open-Source-Verein für die gemeinsame (Weiter)-Entwicklung betriebsfähiger Open-Source-Projekte. Den Grundstein für die Schaffung eines breiten Spektrums technologischer Tools, die den Eigenbetrieb digitaler Cloud-Infrastrukturen ermöglichen, legt hierbei Yaook – unser Lifecycle Management Tool für OpenStack und SecuStack.
Mit einer starken Community und der geballten Kompetenz unserer Vereinsmitglieder treiben wir die Digitale Souveränität in Deutschland und Europa nachhaltig voran – auch in Zusammenarbeit mit weiteren Open-Source Initiativen und Communities der digitalen Szene.
Wir freuen uns über neue Mitglieder, die nicht nur die Vision der Digitalen Souveränität und Leidenschaft für Open-Source teilen, sondern auch gemeinsam mit uns anpacken wollen, um eine echte Veränderung zu schaffen.
Weitere Infos zur Mitgliedschaft findet ihr auf: https://alasca.cloud/
![]()
Die Gründung im Jahr 2022.
Yaook ist nicht nur das Urprojekt ALASCAs, sondern hat auch den Grundstein für die Entstehung des Vereins gelegt: ALASCAs Gründungsmitglieder Cloud&Heat Technologies und STACKIT entwickeln bereits seit Ende 2020 an dem gemeinsam initiierten Open-Source Tool; und mit dem Anwachsen der Community und zunehmender Adaption des Tools wuchs schließlich der Wunsch, Yaook von den beiden Unternehmen zu entkoppeln und es auf eigene Beine zu stellen – nicht zuletzt auch, um eine unabhängige Weiterentwicklung zu fördern.
Die Idee zu ALASCA war geboren – und mit ihr das klare Ziel, neben Yaook weitere quelloffene Projekte, die Bau und Betrieb von Cloud-Infrastrukturen ermöglichen, im Verein aufzunehmen und damit einen Beitrag zur Stärkung der Digitalen Souveränität Deutschlands und Europas zu leisten.
Im September 2022 fand die Gründungsversammlung in Dresden statt, bei der die sieben Gründungsunternehmen Cloud&Heat Technologies, Cyberus Technology, D3TN, dNation, secunet, secustack und STACKIT feierlich und voller Motivation den Beginn von ALASCA besiegelten. Wenige Wochen später – im Januar 2023 – traten wir schließlich an die Öffentlichkeit und stellten ALASCA erstmals der Welt vor.
![]()
Deliver fully-managed clusters at scale everywhere with your own Gardener installation
SeaweedFS is a fast distributed storage system for blobs, objects, files, and data lake, for billions of files! Blob store has O(1) disk seek, cloud tiering. Filer supports Cloud Drive, xDC replication, Kubernetes, POSIX FUSE mount, S3 API, S3 Gateway, Hadoop, WebDAV, encryption, Erasure Coding. Enterprise version is at seaweedfs.com.
Ein Vortrag über die Entstehung, Entwicklung des Incus Projekts seit 2023 und die Möglichkeiten zur Verwaltung von System Container und virtuellen Maschinen.
Incus ist ein fork des LXD-Projektes, welches viele Jahre als Teil der Linux Container Community entwickelt und gepflegt wurde. Es bezeichnet sich selbst als modernes, sicheres und mächtiges Verwaltungswerkzeug für System Container und virtuelle Maschinen.
Der Vortrag soll einen Überblick zum genannten Projekt verschaffen und klären, wie Incus gegenüber den bekannten Projekten wie Proxmox und XCP-ng einzuordnen ist.
Im ersten Teil meines Vortrags zeige ich u. a. die Möglichkeiten auf, welche Incus bei der Verwaltung von System Container und Virtuellen Maschinen bietet. Hierbei wird auch der Unterschied erklärt zwischen Application Container, System Container und virtuellen Maschinen. Im zweiten Teil meines Vortrags gebe ich einen Überblick, wie sich Incus seit dem initialen Release im Oktober 2023 entwickelt hat und was es noch so rund um Incus gibt bzw. was für 2025 geplant ist. Zum Abschluss wird es natürlich auch eine kurze Demo geben.
Antmicro provides engineering services, open source tools, platforms and strategic R&D for high-tech products.
Renode is an open source software development framework with commercial support from Antmicro that lets you develop, debug and test multi-node device systems reliably, scalably and effectively.
Renode strengths:
- full determinism of execution, shared virtual time
- transparent & robust debugging, tracing, analysis, even in multi-node setups
- easy integration with your everyday tools, plugins
- rich model abstractions with additional functionality "for free" + modular platform
description format - automated tests and CI integrations, other collaboration features
It lets you run, debug and test unmodified embedded software on your PC - from bare System-on-Chips, through complete devices to multi-node systems.
Xous is a microkernel operating system with processes, threads, and messages. It is designed to have an extremely small kernel that delegates as much as possible to userspace. This book describes the operating system kernel as well as the services that support normal operating system behavior.
As this book is a work in progress, some chapters are placeholders and will appear blank.
The book is written for two audiences: kernel maintainers, and application developers.
-
Chapters 2 (Server Architecture),
- 3 (Introducing the Kernel), and
- 5 (System Startup) are primarily for kernel maintainers and system programmers.
-
Chapters 1 (Getting Started),
- 4 (Renode Emulation),
- 6 (Build System Overview),
- 7 (Messages) and
- 8 (Graphics) are more appropriate for application developers.
-
Chapter 9 (PDDB) covers the Plausibly Deniable DataBase, and has sub-sections for both kernel and application developers.

This version of the text assumes you’re using Rust 1.85.0 (released 2025-02-17) or later with edition = "2024" in the Cargo.toml file of all projects to configure them to use Rust 2024 Edition idioms. See the “Installation” section of Chapter 1 for instructions on installing or updating Rust, and see Appendix E for information on editions.
The HTML format is available online at https://doc.rust-lang.org/stable/book/ and offline with installations of Rust made with rustup; run rustup doc --book to open.
Several community translations are also available.
This website is an experiment by the Cognitive Engineering Lab at Brown University. The goal of this experiment is to evaluate and improve the content of the Rust Book to help people learn Rust more effectively.
🦀

Kanidm is a simple and secure identity management platform, allowing other applications and services to offload the challenge of authenticating and storing identities to Kanidm.
The goal of this project is to be a complete identity provider, covering the broadest possible set of requirements and integrations. You should not need any other components (like Keycloak) when you use Kanidm - we already have everything you need!
To achieve this we rely heavily on strict defaults, simple configuration, and self-healing components. This allows Kanidm to run from small home labs, for families, small business, and all the way to the largest enterprise needs.
If you want to host your own authentication service, then Kanidm is for you!
Features
- Webauthn (passkeys) for secure cryptographic authentication
- OAuth2/OIDC Authentication provider for web SSO
- OAuth Application Portal/Gateway allowing easy access to linked applications
- Linux/UNIX integration with offline authentication
- SSH key distribution to Linux/UNIX systems
- RADIUS for network and VPN authentication
- Read only LDAPS gateway for Legacy Systems
- Complete CLI tooling for Administration
- User Self Service via the WebUI
External References
authentik is an IdP (Identity Provider) and SSO (Single Sign On) platform that is built with security at the forefront of every piece of code, every feature, with an emphasis on flexibility and versatility.
With authentik, site administrators, application developers, and security engineers have a dependable and secure solution for authentication in almost any type of environment. There are robust recovery actions available for the users and applications, including user profile and password management. You can quickly edit, deactivate, or even impersonate a user profile, and set a new password for new users or reset an existing password.
You can use authentik in an existing environment to add support for new protocols, so introducing authentik to your current tech stack doesn't present re-architecting challenges. We support all of the major providers, such as OAuth2, SAML, LDAP, and SCIhttps://docs.goauthentik.io/M, so you can pick the protocol that you need for each application.
We offer two versions of authentik: the forever-free open source project upon which everything is built, and our open core, source available Enterprise version, with a Support center and additional features.
Authelia is an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role of information security in providing multi-factor authentication and single sign-on (SSO) for your applications via a web portal. Authelia is an OpenID Connect 1.0 Provider which is OpenID Certified™ allowing comprehensive integrations, and acts as a companion for common reverse proxies.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
I’ve been using NixOS for a while now, primarily to provision my personal and work Mac systems. While Nix can be complex and sometimes challenging to debug, I’ve enjoyed its unique approach to system configuration. However, I haven’t explored much beyond that scope. For some time, I’ve become particularly interested in using it for containers, as NixOS offers compelling features—reproducibility, declarative configuration, and reliable upgrades—which, in theory, make it an excellent choice. How well this theory holds up is something I’m eager to explore further. In this post, I’m documenting my steps for installing NixOS on Proxmox, my chosen virtual environment solution for my home server, as deploying NixOS onto my home server should help me further explore using it for configuring my containers

