
    <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
      <channel>
        <title>Luca Cavallin</title>
        <link>https://www.lucavallin.com/blog/tags/containers</link>
        <description>
      Platform Engineer at Xebia, focused on AI platform engineering - the infrastructure behind reliable, observable, scalable AI and cloud-native workloads. I work primarily in Go and Google Cloud, with deep experience in Kubernetes, containers, and end-to-end observability - and a strong interest in networking and lower-level systems work in Rust. My current focus is the platform layer beneath AI: inference serving infrastructure on Kubernetes, AI gateway and MCP connectivity, agentic workload orchestration, and end-to-end observability for GenAI systems.

      My broader experience is full-stack: strong on backend, with solid frontend and mobile knowledge. I contribute to open source, write on my blog, and pick up the occasional talk, training, or meetup when something interesting comes up. I&#39;m a Google Developer Expert (GDE) and a CNCF Ambassador.

      For a deeper dive, see my blog. If you&#39;re new to open source, check out Verto.sh. For mentorship, I&#39;m on Mentorcruise. Outside of work, activities like photography, motorcycling, playing a handpan and cleaning litterboxes keep me occupied 🐈.
    </description>
        <language>en-us</language>
        <managingEditor>Luca Cavallin</managingEditor>
        <webMaster>Luca Cavallin</webMaster>
        <lastBuildDate>Tue, 10 Mar 2026 00:00:00 GMT</lastBuildDate>
        <atom:link href="https://www.lucavallin.com/blog/tags/containers/feed.xml" rel="self" type="application/rss+xml"/>
        
    <item>
      <guid>https://www.lucavallin.com/blog/containers-are-not-automatically-secure</guid>
      <title>Containers Are Not Automatically Secure</title>
      <link>https://www.lucavallin.com/blog/containers-are-not-automatically-secure</link>
      <description>Containers changed how we package and ship software, but they did not rewrite the basic security rules. Trust boundaries, privilege, and attack surface are all still there. That was probably the main thing I learned while digging into container security, partly from Liz Rice&#39;s Container Security and partly from spending time with the Linux pieces underneath.</description>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>linux</category><category>containers</category><category>security</category>
    </item>
  
    <item>
      <guid>https://www.lucavallin.com/blog/kubernetes-networking-from-packets-to-pods</guid>
      <title>Kubernetes Networking from Packets to Pods</title>
      <link>https://www.lucavallin.com/blog/kubernetes-networking-from-packets-to-pods</link>
      <description>Kubernetes networking doesn&#39;t have to be a black box. This guide breaks it down, starting from the fundamentals of Linux networking and container isolation. We then dive into the complete Kubernetes model, explaining everything from Pod IPs and CNI plugins to Services, NetworkPolicy, and Ingress, providing a clear end-to-end map of how connectivity works in your cluster.</description>
      <pubDate>Tue, 01 Jul 2025 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>kubernetes</category><category>networking</category><category>containers</category><category>linux</category>
    </item>
  
    <item>
      <guid>https://www.lucavallin.com/blog/kubefm-podcast-lucavallin-barco-containers-from-scratch-in-c</guid>
      <title>I&#39;m on the KubeFM Podcast Talking About &quot;Linux Containers From Scratch&quot;</title>
      <link>https://www.lucavallin.com/blog/kubefm-podcast-lucavallin-barco-containers-from-scratch-in-c</link>
      <description>KubeFM recently invited me to talk about my project &quot;barco: Linux Containers From Scratch in C&quot;. In this episode, I talk about why Linux containers don&#39;t exist, how to use cgroups and namespaces to isolate a process, how to secure the container with seccomp and capabilities, and how to make the right syscall from C to build your own container engine. Thank you, KubeFM, for having me!</description>
      <pubDate>Wed, 24 Jan 2024 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>podcast</category><category>containers</category><category>linux</category><category>cloud-native</category><category>cncf</category><category>kubernetes</category>
    </item>
  
    <item>
      <guid>https://www.lucavallin.com/blog/barco-linux-containers-from-scratch-in-c</guid>
      <title>barco: Linux Containers From Scratch in C.</title>
      <link>https://www.lucavallin.com/blog/barco-linux-containers-from-scratch-in-c</link>
      <description>A straightforward C implementation of a container runtime, built from the ground up to explore containers and the Linux Kernel.</description>
      <pubDate>Sun, 17 Sep 2023 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>c</category><category>linux</category><category>containers</category><category>cncf</category>
    </item>
  
    <item>
      <guid>https://www.lucavallin.com/blog/club-cloud-stories-news-from-around-the-cloud</guid>
      <title>Club Cloud Stories #2 - News from Around the Cloud</title>
      <link>https://www.lucavallin.com/blog/club-cloud-stories-news-from-around-the-cloud</link>
      <description>The latest news from around the cloud: Club Cloud Stories #2 is here! Luca Cavallin &amp; Jacco Kulman – joined by special guest Antoni Tzavelas (Google Cloud Course Creator and DevOps enthusiast) – are going to discuss: &quot;CloudFormation: Quick Retry&quot;, &quot;Google Cloud IoT Core 101&quot;, &quot;Step Functions: Power Up&quot;, &quot;What is GitOps?&quot;, &quot;Inspect Traffic Between Subnets in a VPC&quot;, &quot;Rust on CloudFlare Workers&quot;.</description>
      <pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>cloud</category><category>club-cloud</category><category>containers</category><category>podcast</category>
    </item>
  
    <item>
      <guid>https://www.lucavallin.com/blog/club-cloud-stories-first-episode-antoni-tzavelas-mark-van-holsteijn</guid>
      <title>Club Cloud Stories #1 - The First Episode with Antoni Tzavelas &amp; Mark van Holsteijn</title>
      <link>https://www.lucavallin.com/blog/club-cloud-stories-first-episode-antoni-tzavelas-mark-van-holsteijn</link>
      <description>In this first episode of Club Cloud Stories, hosts Luca Cavallin and Jacco Kulman welcome two guests: Antoni Tsavelas and Mark van Holsteijn. They discuss the latest cloud developments as well as a special reaper package to stop containers from running.</description>
      <pubDate>Tue, 19 Oct 2021 00:00:00 GMT</pubDate>
      <author>Luca Cavallin</author>
      <category>cloud</category><category>club-cloud</category><category>containers</category><category>podcast</category>
    </item>
  
      </channel>
    </rss>
  