Skip to content

Archive

Operations

7 articles
Python 09 Sep 2026 10 min read

Reload Process Environment Variables with Python 3.14

Python applications often treat environment variables as if every read goes straight to the operating system. In CPython, that mental model is incomplete. os.environ is a mapping captured when the os module is first imported, normally during interpreter startup. If the process environment later changes through something outside that mapping, Python’s cached view can become stale. Python 3.14 adds os.reload_environ() for the unusual cases where an application really needs to refresh that view.

Python 09 Sep 2026 11 min read

Attach pdb to Running Python Processes in Python 3.14

A Python service can misbehave without crashing. A worker may loop unexpectedly, a request may remain in an odd state, or a long-running process may hold data that is difficult to reproduce in a development environment. Historically, using pdb in that situation usually required planning ahead. You could add breakpoint() to the code, start the program under the debugger, or restart it with extra instrumentation. Those approaches are useful, but they do not help much when the interesting state already exists inside a running process.

Linux 02 Sep 2026 5 min read

Inspect Process Isolation with Linux Namespaces

Containers rely on several Linux kernel features, but namespaces provide much of the process-level isolation people notice first. They let different groups of processes see different views of resources such as process IDs, mounts, hostnames, and network interfaces. You do not need a container runtime to inspect namespaces. Standard Linux tools and /proc expose the relationships directly. What a namespace changes A namespace virtualizes one class of global system resource.

Linux 01 Sep 2026 5 min read

Linux Network Troubleshooting with ip, ss, dig, and curl

When a Linux service is “unreachable,” the failure can be in several different layers: the local interface, routing, a listening socket, DNS, a firewall, TLS, or the application itself. Randomly restarting services makes diagnosis harder. A better approach is to move from local state outward and identify the first layer that does not behave as expected. 1. Confirm the interface and address Start with the addresses configured on the host:

Linux 01 Sep 2026 5 min read

Harden systemd Services with Security Directives

A systemd unit can do more than start and restart a process. It can also define a security boundary around the service by restricting filesystem access, Linux capabilities, namespaces, privilege changes, and resource consumption. These controls do not replace application security, but they can reduce the damage caused by a compromised or misbehaving process. Start from the service’s real requirements Hardening works best when it is based on what the process actually needs.

Linux 01 Sep 2026 4 min read

Find Hidden Linux Disk Usage with df, du, and lsof

A Linux filesystem can report 95% usage in df while du appears to account for much less. The tools are not contradicting each other: they measure different things. df asks the filesystem about allocated blocks. du walks visible directory entries and sums blocks reachable through those paths. The gap between those views points to several useful troubleshooting cases. Start with the filesystem view Check filesystems and their types: df -hT Identify the mount that is actually full. Do not immediately scan recursively from /; container mounts, network filesystems, and bind mounts can make that slow and misleading.

Cloud Computing 01 Sep 2026 5 min read

Blue-Green Deployments for Safer Zero-Downtime Releases

A blue-green deployment keeps two production-capable application environments. One serves live traffic while the other receives the new release. After validation, traffic is switched to the candidate environment. The pattern can make rollback fast, but it does not automatically make a release safe. Database changes, background jobs, caches, and external side effects can still make an old version incompatible with the new state. The basic release sequence Assume blue is currently live and green will run the new version.