An sshd_config snippet turning password authentication off and requiring publickey

Secure SSH on your first VPS before the bots find it

A step-by-step SSH hardening guide for a first VPS on the RHEL 10 family (AlmaLinux, Rocky, CentOS Stream). Key-only authentication, no root login, brute-force limits, a safe port move, and SELinux left enforcing, with every command shown and the lockout traps called out.

September 9, 2026 · 23 min · widnyana
Terragrunt and OpenTofu provisioning VMware vSphere virtual machines from a golden template

Provisioning vSphere VMs with Terragrunt and OpenTofu

I used to build VMs by hand. Click through the wizard, guess an IP, forget which VLAN it went on, and a month later nobody remembers why vm-1042 exists. This post is the replacement: OpenTofu + Terragrunt cloning from a golden template on vSphere, driven by a least-privilege SSO user. Everything here survived a real production estate, including the parts that cost me actual debugging time: the permission model in vCenter is full of silent traps, and I’ll point at every one of them. ...

August 29, 2026 · 18 min · widnyana
Port

Introducing kubectl-ports: Easily List Exposed Ports in Kubernetes

As a Kubernetes user, have you ever found yourself digging through resource definitions or running multiple commands just to find out what ports are exposed by your pods and services? It can be a tedious process. That’s why I created kubectl-ports, a handy kubectl plugin that retrieves the exposed ports information and presents it in a clean, readable table format. What is kubectl-ports? kubectl-ports is a tool that leverages the kube-rs SDK to retrieve information about running pods in a Kubernetes cluster. It filters out the relevant port details from each pod and prints the final result in an easy-to-read table. No more combing through verbose output or chaining together multiple commands! ...

October 10, 2024 · 3 min · widnyana