Our take on Build & Deploy at Devoxx France 2024
Translated from the French original, first published on dev.to, on the onepoint blog, written with @cfarges and @jtama.
Written in 2024: some details may have changed since.

After our colleagues’ write-ups, here is ours on the Build & Deploy track of Devoxx France 2024.
And as every year, the least we can say is that there was plenty to choose from, with dozens of talks on how to package and deploy our applications! Without further ado, here are the topics in this category that stood out to @cfarges, @jtama and me.
GatewayAPI, 10 ans de maturation pour une nouvelle API Kubernetes (GatewayAPI, 10 years in the making for a new Kubernetes API)
This year, Kévin Davin came to talk to us about the Gateway API. <3
With quite a bit of hindsight, the verdict is clear: the Ingress resource is not enough. It takes on too many responsibilities, isn’t specific enough, leaves each implementation free to make different choices for the same problem (poor portability), and doesn’t provide enough features either.
The Gateway API is role-oriented, with several kinds:
- The GatewayClass:: For the provider, the one who knows the network
- The Gateway :: For the cluster operator, the one who knows the cluster 🤷
- The GRPCRoute / HTTPRoute:: For developers, the ones who know the applications.
Each person has their own skills, knowledge, responsibilities, and kind.
This API goes far enough to overlap significantly with some of the features offered by service meshes (including traffic splitting).
Replay
Multi Kubernetes, Multi Régions, Au-secours ! (Multi Kubernetes, Multi Region, Help!)
Through a REX (experience report) built around a fictional company, Aurélien Moreau and Nicolas Lavacry present the needs of their new company: CASDAL. It has 2 markets, one in the US and one in France. How do you host this application?
We then learn how to deploy a Kubernetes environment across several regions, and why several clusters are needed to keep latency low, since Kubernetes doesn’t like latency when a continent separates its nodes. Their flawlessly executed demo takes us behind the scenes and shows the tools and methods to guarantee quality of service, low latency and data integrity!
Notre dépendance à l’Open Source est effrayante. SLSA, SBOM et Sigstore à la rescousse (Our dependency on Open Source is scary. SLSA, SBOM and Sigstore to the rescue)
This very interesting talk shows how much we rely on third-party software and dependencies in our applications, over which we have no control. Does that mean we should use them without checking their integrity, leaving room for a middleman to inject malicious code during a packaging step of our application?
Abdellfetah Sghiouar then presents tools we can rely on to guarantee the traceability of our applications, such as cosign to sign our images before deploying them to our cluster, or SBOMs to list every package used in our application.
Au cœur de la ruche eBPF! (Inside the eBPF hive!)
I had heard about eBPF several times without really knowing what it was. So this talk was an opportunity for me to dig into the subject! Although very technical, Mohammed Aboullaite clearly explained how a kernel module works and how eBPF has evolved. I don’t think I’ll be writing my own kernel module tomorrow, but I now better understand all the “hype” around it and the value eBPF brings by making it easier to distribute a new module, with native performance and the same level of security.
Le cauchemar des attaquants : une infrastructure sans secret (An attacker’s nightmare: a secretless infrastructure)
Thibault Lengagne shows us how to use Vault and Boundary to get rid of most passwords
in our environments while keeping a “Secure by design” approach and full traceability of every access to application components.
With a Zero-Credentials architecture, each user has a single password that gives access, through Boundary,
to our applications. Combining Boundary and Vault makes it possible to create temporary credentials and keep full traceability of access, from development environments all the way to production.
Thibault shows us an architecture and the best practices that go with these concepts. Through several short demos, we start wanting to roll this out in our own environments, especially as our teams keep growing.
No more endless password rotations: we have one access, and the rest is handled by the policies defined in our infrastructure’s source code.
Check-list ultime pour rendre vos app cloud native (The ultimate checklist to make your apps cloud native)
In this talk, Katia Himeur goes over the various contexts that may lead us to move our applications to the “cloud”.
She reminds us that the definition of “cloud” can vary widely depending on who you’re talking to. The complexity, the plethora of available solutions (over 2,000 tools in the CNCF landscape, for example) and the diversity of providers must all be taken into account in a cloud project, whether for a new application
or for migrating an existing one.
Part methodology, part experience report, Katia’s talk is a goldmine of information and inspiration on how to approach this kind of project.
The points she covers are as much about people as about technology, including team onboarding and change management. The main pain points of these projects are addressed: could this be the ultimate recipe?
Final words
Thanks to @onepoint for allowing us to take part in this special event every year!
Feel free to check out the other articles our colleagues published on the other tracks!
Read our full series of articles on Devoxx: