
Day 2 OTel-Shop: Shipping Three Go Services to k3d
Day 2 of OTel-Shop: three Go services got real handlers and routes, packed into lean containers, and landed on the local k3d cluster. All green.
Where We Left Off
Yesterday was all about foundations: the cluster came up, the database got seeded, and a fake trace made it all the way to Jaeger. Nice view, empty rooms. Day 2's mission was simple to say out loud: put actual services inside that beautiful infrastructure.
What Got Built Today
Here's the haul:
- Gave all three services their shapes and starter brains — models for checkout, inventory lookup, and payment, each wired into clean routes.
- Kept the front door consistent: every service answers
/health, which doubles as Kubernetes' way of asking "you good?" (readiness and liveness probes are hooked up to it). - Wrote multi-stage container recipes: a chunky builder stage does the compiling, then the final image starts from literally nothing and carries one small binary. Lean is lovely.
- Rolled the whole packaging flow into a single script: build with Podman, hand over to Docker, import into the cluster. One command instead of a ritual.
- Added deployment and service manifests so each app gets its own address inside the cluster, plus fixed door numbers on my laptop to reach them from outside.
- Finished the day poking everything with curl like an impatient customer. Everything answered politely.
A taste of what worked straight from the host:
- A checkout request returned a shiny new order id with status
paid. - Asking about product A123 reported ten units in stock.
- A payment call happily declared success.
- Sloppy requests (empty fields, negative numbers) got polite 400 rejections instead of mystery errors.
One honest note: the smarts are intentionally shallow right now. Inventory isn't really reading the database yet, and checkout doesn't call its friends. Those are the next episodes.
The Container Shuffle
The day's plot twist happened at the handover between tools. Podman built the images perfectly, but when they crossed into the Docker side they picked up an extra localhost/ prefix on their names. The cluster import step then looked at those names, shrugged, and refused everything.
Five minutes of head-scratching later, the fix was one extra retag step in the script. Classic. The lesson generalizes nicely though: when two tools meet at a boundary, naming conventions are where things go sideways — not the actual work.
Lessons Learned
Four takeaways from today:
- Start-from-nothing images are underrated. A runtime with zero extras has almost nothing that can rot, need patching, or surprise you at 2am.
- Automate the boring handoffs immediately. The build-to-cluster chain only bit me once because it became a script right after — future me says thanks.
- Poke from the outside. Testing through the public ports like a real client tells you what actually matters; testing only from inside would have felt deceptively fine.
- Health checks are cheap insurance. Wiring probes took minutes and already keeps rollouts honest — a pod only counts as ready when it truly answers.
Conclusion
Day 2 ends with three services running in the cluster, every endpoint answering correctly from my laptop, and the whole ship-and-deploy loop scripted. The foundation phase is officially behind us; from here on it's behavior, wiring, and telemetry.
Tomorrow the services start talking — first inventory meets the database for real, then checkout learns to orchestrate its neighbors. See you there.
Repo is here: https://github.com/stayrelevantid/otel-shop
Diskusi & Komentar
Day 1 OTel-Shop: Setting Up k3d, Jaeger & Postgres
Next ArticleDay 3 OTel-Shop: Services Start Talking via HTTP
Artikel Terkait
Hari 35: Rego Policy Pertama — Wajib Resource Limits
Tulis Rego policy pertama untuk Gatekeeper: Pod/Deployment tanpa resource limits dan requests ditolak. 4 violation rules, enforcementAction deny, 0 violations.
Hari 5: Trivy SCA Scan Nemukan 4 CVE di Golang API
Hari kelima 60 hari DevSecOps! Scan dependensi Go pakai Trivy dan nemukan 4 CVE termasuk 1 CRITICAL — termasuk library deprecated jwt-go.
Hari 8: Semgrep SAST Scan Temukan Kode Tidak Aman
Hari kedelapan 60 hari DevSecOps! Install Semgrep, buat kode insecure (MD5), dan scan ketemu 2 finding — MD5 weak hash dan HTTP server tanpa TLS.