<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Praveen Kumar</title>
    <description>The latest articles on DEV Community by Praveen Kumar (@pkbvs1806).</description>
    <link>https://dev.to/pkbvs1806</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F417223%2Ff571a3c5-ae05-47b5-9bad-39ce904164cd.png</url>
      <title>DEV Community: Praveen Kumar</title>
      <link>https://dev.to/pkbvs1806</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/pkbvs1806"/>
    <language>en</language>
    <item>
      <title>The OSI Model</title>
      <dc:creator>Praveen Kumar</dc:creator>
      <pubDate>Thu, 01 Oct 2026 02:38:04 +0000</pubDate>
      <link>https://dev.to/pkbvs1806/the-osi-model-17ib</link>
      <guid>https://dev.to/pkbvs1806/the-osi-model-17ib</guid>
      <description>&lt;h1&gt;
  
  
  The OSI Model
&lt;/h1&gt;




&lt;p&gt;Most OSI explanations fail because they teach you seven words to memorize. That's like teaching someone to drive by handing them a diagram of a car engine. You don't need the diagram. You need to &lt;strong&gt;feel&lt;/strong&gt; the clutch.&lt;/p&gt;

&lt;p&gt;By the end of this, OSI won't be a model you recall. It'll be the way you think.&lt;/p&gt;




&lt;h2&gt;
  
  
  Table of Contents
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The Real Model&lt;/li&gt;
&lt;li&gt;
Encapsulation: The One Concept That Unlocks Everything

&lt;ul&gt;
&lt;li&gt;The naming matters more than you think&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
The Layers, Done Properly

&lt;ul&gt;
&lt;li&gt;Layer 7 — Application&lt;/li&gt;
&lt;li&gt;Layer 6 — Presentation&lt;/li&gt;
&lt;li&gt;Layer 5 — Session&lt;/li&gt;
&lt;li&gt;Layer 4 — Transport&lt;/li&gt;
&lt;li&gt;Layer 3 — Network&lt;/li&gt;
&lt;li&gt;Layer 2 — Data Link&lt;/li&gt;
&lt;li&gt;Layer 1 — Physical&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Use Case Traces — Real Systems, Layer by Layer

&lt;ul&gt;
&lt;li&gt;4.1 Loading a YouTube video&lt;/li&gt;
&lt;li&gt;4.2 A single DNS lookup&lt;/li&gt;
&lt;li&gt;4.3 A multiplayer game tick&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Diagnostics: The OSI X-Ray

&lt;ul&gt;
&lt;li&gt;The tool map&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
System Design Through the OSI Lens

&lt;ul&gt;
&lt;li&gt;6.1 Where each layer lives in a modern stack&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The Master's Lens&lt;/li&gt;
&lt;li&gt;
Appendix: Quick Reference

&lt;ul&gt;
&lt;li&gt;The Seven Questions&lt;/li&gt;
&lt;li&gt;The Vocabulary Chain&lt;/li&gt;
&lt;li&gt;The Tool Map&lt;/li&gt;
&lt;li&gt;The Core Principle&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  The Real Model
&lt;/h2&gt;

&lt;p&gt;Forget "7 layers" for a second. Here's what OSI actually is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Every piece of data traveling across any network must answer seven questions, in order. OSI is just the ordered list of those questions.&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's it. Seven questions. Each one has a "layer" that answers it.&lt;br&gt;
&lt;/p&gt;

&lt;pre data-lang="mermaid"&gt;&lt;code&gt;graph TD

&amp;nbsp; &amp;nbsp; Q1["What does the user actually want?"] --&amp;gt; L7["7 · APPLICATION"]

&amp;nbsp; &amp;nbsp; Q2["How is this data represented?"] --&amp;gt; L6["6 · PRESENTATION"]

&amp;nbsp; &amp;nbsp; Q3["Is this part of an ongoing conversation?"] --&amp;gt; L5["5 · SESSION"]

&amp;nbsp; &amp;nbsp; Q4["Did it arrive, in order, intact?"] --&amp;gt; L4["4 · TRANSPORT"]

&amp;nbsp; &amp;nbsp; Q5["Which machine, across the world?"] --&amp;gt; L3["3 · NETWORK"]

&amp;nbsp; &amp;nbsp; Q6["Which device, on this local wire?"] --&amp;gt; L2["2 · DATA LINK"]

&amp;nbsp; &amp;nbsp; Q7["What physical signal carries it?"] --&amp;gt; L1["1 · PHYSICAL"]

&amp;nbsp; &amp;nbsp; style L7 fill:#ff6b6b,color:#fff

&amp;nbsp; &amp;nbsp; style L6 fill:#feca57,color:#000

&amp;nbsp; &amp;nbsp; style L5 fill:#48dbfb,color:#000

&amp;nbsp; &amp;nbsp; style L4 fill:#1dd1a1,color:#000

&amp;nbsp; &amp;nbsp; style L3 fill:#5f27cd,color:#fff

&amp;nbsp; &amp;nbsp; style L2 fill:#ff9ff3,color:#000

&amp;nbsp; &amp;nbsp; style L1 fill:#576574,color:#fff&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;Ask *&lt;strong&gt;&lt;em&gt;What problem does this layer solve?&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;

&lt;p&gt;Then each layer makes sense - it exists because without it, some problem can’t be solved.&lt;/p&gt;

&lt;p&gt;| Layer | Without it... |&lt;/p&gt;

&lt;p&gt;|-------|---------------|&lt;/p&gt;

&lt;p&gt;| L1 | Nothing physically moves |&lt;/p&gt;

&lt;p&gt;| L2 | Two devices on the same wire can't agree on who's talking |&lt;/p&gt;

&lt;p&gt;| L3 | You can never leave your local network |&lt;/p&gt;

&lt;p&gt;| L4 | You can't tell "arrived" from "lost," or "this app" from "that app" on the same machine |&lt;/p&gt;

&lt;p&gt;| L5 | Every request is a stranger; no conversations, no state |&lt;/p&gt;

&lt;p&gt;| L6 | Encryption, compression, encoding — all chaos |&lt;/p&gt;

&lt;p&gt;| L7 | Nothing meaningful happens |&lt;/p&gt;




&lt;h2&gt;
  
  
  Encapsulation: The One Concept That Unlocks Everything
&lt;/h2&gt;

&lt;p&gt;If you only take one thing from this blog, take this.&lt;/p&gt;

&lt;p&gt;When you send data, it doesn't jump across the network as is. It gets *&lt;strong&gt;&lt;em&gt;wrapped&lt;/em&gt;&lt;/strong&gt;*, layer by layer. Each layer adds its own header (sometimes a trailer) - metadata the receiving side will use to unwrap.&lt;br&gt;
&lt;/p&gt;

&lt;pre data-lang="mermaid"&gt;&lt;code&gt;graph LR

&amp;nbsp; &amp;nbsp; subgraph DOWN["Sender — Data flows DOWN"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A["Application data\&amp;lt;br/&amp;gt;\&amp;lt;i&amp;gt;Hello\&amp;lt;/i&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; B["+ TCP header\&amp;lt;br/&amp;gt;\&amp;lt;b&amp;gt;[Port | Seq | Hello]\&amp;lt;/b&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C["+ IP header\&amp;lt;br/&amp;gt;\&amp;lt;b&amp;gt;[IP | Port | Seq | Hello]\&amp;lt;/b&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D["+ Frame header/trailer\&amp;lt;br/&amp;gt;\&amp;lt;b&amp;gt;[MAC | IP | Port | Seq | Hello | CRC]\&amp;lt;/b&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; E["Physical bits\&amp;lt;br/&amp;gt;\&amp;lt;b&amp;gt;1010110100...\&amp;lt;/b&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A --&amp;gt; B --&amp;gt; C --&amp;gt; D --&amp;gt; E

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; subgraph UP["Receiver — Data flows UP"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; F["Bits arrive"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; G["Frame verified · MAC matched"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; H["Packet verified · IP matched"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I["Segment reassembled · ACK sent"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; J["Application reads \&amp;lt;i&amp;gt;Hello\&amp;lt;/i&amp;gt;"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; F --&amp;gt; G --&amp;gt; H --&amp;gt; I --&amp;gt; J

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; E -.-&amp;gt;|"The wire"| F

&amp;nbsp; &amp;nbsp; style DOWN fill:#ffeaa7

&amp;nbsp; &amp;nbsp; style UP fill:#55efc4&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;The genius of this design: *&lt;strong&gt;&lt;em&gt;each layer only needs to understand its own header.&lt;/em&gt;&lt;/strong&gt;* The IP layer doesn't care if you're sending JSON or a JPEG. TCP doesn't care if you're talking to Google or GF. This separation is why the internet scaled from 4 nodes to 5 billion devices without a redesign.&lt;/p&gt;

&lt;h3&gt;
  
  
  The naming matters more than you think
&lt;/h3&gt;

&lt;p&gt;Each layer's wrapped unit has a name — and these names are used in RFCs, tools, and incident reports. Learn them once:&lt;/p&gt;

&lt;p&gt;| Layer | Unit name | Typical size |&lt;/p&gt;

&lt;p&gt;|-------|-----------|--------------|&lt;/p&gt;

&lt;p&gt;| 7–5 | Data / Message | Application-defined |&lt;/p&gt;

&lt;p&gt;| 4 | Segment (TCP) · Datagram (UDP) | Up to ~1460 bytes payload |&lt;/p&gt;

&lt;p&gt;| 3 | Packet | Up to 65,535 bytes |&lt;/p&gt;

&lt;p&gt;| 2 | Frame | Up to 1500 bytes (MTU) |&lt;/p&gt;

&lt;p&gt;| 1 | Bit / Symbol | 1 or a few |&lt;/p&gt;

&lt;p&gt;When someone says "we're seeing packet loss," they mean L3. When they say "frame errors on the switch," that's L2. *&lt;strong&gt;&lt;em&gt;Vocabulary is diagnosis.&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;




&lt;h2&gt;
  
  
  The Layers, Done Properly
&lt;/h2&gt;

&lt;p&gt;I'm going to move through each layer with the same lens: *&lt;strong&gt;&lt;em&gt;what problem it solves, what protocols live there, what products you've heard of, and how it fails.&lt;/em&gt;&lt;/strong&gt;* Failure modes are the real education.&lt;/p&gt;

&lt;h3&gt;
  
  
  Layer 7 — Application
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;What does the user actually want to accomplish?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is where protocols that carry meaning live. HTTP, DNS, SMTP, SSH, FTP, gRPC, WebSocket, MQTT, and hundreds more. Each one is a *&lt;strong&gt;&lt;em&gt;contract&lt;/em&gt;&lt;/strong&gt;* — a shared language between two programs.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* Nginx, HAProxy, Cloudflare, AWS Application Load Balancer, Envoy, Kong.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* &lt;code&gt;502 Bad Gateway&lt;/code&gt; (upstream is broken), &lt;code&gt;504 Gateway Timeout&lt;/code&gt; (upstream is too slow), &lt;code&gt;404&lt;/code&gt; (the app says it doesn't exist), malformed JSON, rate-limit &lt;code&gt;429&lt;/code&gt;. Every HTTP status code is an L7 statement.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The subtle part most people miss:&lt;/em&gt;&lt;/strong&gt;* L7 is where &lt;strong&gt;business logic&lt;/strong&gt; becomes visible on the wire. A load balancer that "understands" HTTP can route &lt;code&gt;/api/v1/*&lt;/code&gt; to one service and &lt;code&gt;/images/*&lt;/code&gt; to another. An L4 balancer cannot do this — it never sees the URL. This distinction is worth millions in cloud bills.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 6 — Presentation
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;How is this data represented so both sides agree?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Encryption, compression, character encoding, serialization formats. TLS is the celebrity here, but so are JSON, Protobuf, MessagePack, JPEG, MP4, gzip, zstd, UTF-8.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* OpenSSL, BoringSSL, Let's Encrypt, Cloudflare's image resizing, Cloudinary, brotli.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* Expired certificates, TLS handshake failures, incompatible cipher suites, garbled text from encoding mismatch, images that render as broken icons.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Why this layer is quietly the most dangerous:&lt;/em&gt;&lt;/strong&gt;* A TLS misconfiguration takes down &lt;strong&gt;everything&lt;/strong&gt; above it. A compression bug can leak secrets (see CRIME, BREACH attacks). Presentation is where "it works" and "it's catastrophically insecure" look identical from the outside.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 5 — Session
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;Is this request part of an ongoing conversation, or a fresh start?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Session establishment, maintenance, teardown, and checkpointing. In practice, this layer is often absorbed into L7 (HTTP cookies, JWT) or L4 (TCP connections), but conceptually it's distinct: it's about *&lt;strong&gt;&lt;em&gt;state across multiple exchanges&lt;/em&gt;&lt;/strong&gt;*.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* Socket.io, gRPC streams, WebRTC, Auth0 sessions, Redis session stores, sticky-session load balancers.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* "Session expired, please log in again." Sticky-session routing sending a user to the wrong backend. WebRTC streams that reconnect on every network blip. A logout that doesn't invalidate the server-side session.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The design tension:&lt;/em&gt;&lt;/strong&gt;* Sessions are cheap to maintain and expensive to scale. Every horizontal-scaling architecture eventually confronts this — do you store sessions server-side (stateful) or push state to the client (stateless, JWT)? Both are L5 decisions with L4 and L7 consequences.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 4 — Transport
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;Did it arrive, in order, intact — and which application does it belong to?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the delivery layer. It's where *&lt;strong&gt;&lt;em&gt;ports&lt;/em&gt;&lt;/strong&gt;* live (so the same machine can run a web server, a database, and an SSH daemon simultaneously), and where *&lt;strong&gt;&lt;em&gt;reliability&lt;/em&gt;&lt;/strong&gt;* is decided.&lt;/p&gt;

&lt;p&gt;The two protagonists:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;TCP&lt;/em&gt;&lt;/strong&gt;* — connection-oriented, ordered, reliable, with flow control and congestion control. Used by HTTP/1.1, HTTP/2, SMTP, SSH, databases.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;UDP&lt;/em&gt;&lt;/strong&gt;* — fire-and-forget, minimal, no ordering, no retransmission. Used by DNS, VoIP, gaming, video streaming, and — crucially — QUIC.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;And then there's QUIC.&lt;/em&gt;&lt;/strong&gt;* This deserves its own sentence because it's quietly rewiring the internet. QUIC is a transport protocol built &lt;strong&gt;on top of&lt;/strong&gt; UDP that implements everything TCP does (reliability, ordering, congestion control) but with multiplexed streams, 0-RTT handshakes, and built-in TLS 1.3 encryption. HTTP/3 is QUIC. Google, Cloudflare, and Meta run it at massive scale. When you see a YouTube video start instantly, QUIC is often why.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* the Linux TCP stack, Cloudflare's quiche, Google's cronet, Nginx, Envoy, AWS Network Load Balancer.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* "Connection timed out" (TCP handshake never completed), "Connection reset by peer" (RST received), port blocked by a firewall, MTU black holes where large packets silently die.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Why this layer is the engineer's favorite:&lt;/em&gt;&lt;/strong&gt;* It's the last layer you can reason about &lt;strong&gt;purely&lt;/strong&gt; — without business logic, without user intent. If L4 is clean and L7 is broken, you know exactly where to look.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 3 — Network
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;Which machine, across the world, and what path gets us there?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;IP addresses, routing, path selection. This is where the internet actually &lt;strong&gt;is&lt;/strong&gt; an internet — a network of networks. BGP (Border Gateway Protocol) is the protocol that stitches together every ISP, every cloud, every content provider. When BGP has a bad day, countries disappear from the internet.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* Cisco, Juniper, Arista routers, AWS Transit Gateway, Google Cloud Interconnect, AWS Global Accelerator, any BGP-speaking AS.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* "Destination host unreachable," traceroute showing packets dying at a specific hop, asymmetric routing (traffic goes out one path, comes back another — often fine, sometimes catastrophic for firewalls), route flapping, BGP hijacks.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The uncomfortable truth:&lt;/em&gt;&lt;/strong&gt;* You don't control L3. The internet is a &lt;strong&gt;cooperative agreement&lt;/strong&gt; between thousands of autonomous systems, and any one of them can misconfigure their router and break your service for a country. This is why CDNs exist — to shorten the path and reduce the number of untrusted hands your packets pass through.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 2 — Data Link
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;Which device, on this local wire, should receive this?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;MAC addresses, framing, error detection (CRC), and local delivery. Every Ethernet frame, every WiFi frame, every VLAN tag lives here. This is the layer of switches, not routers.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* Arista and Cisco switches, WiFi access points, AWS VPC ENIs, Cumulus Linux, VLANs, VXLAN overlays, MPLS.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* MAC address flapping (a MAC appears on two switch ports — usually a loop), VLAN misconfiguration (traffic silently dropped), ARP storms, duplex mismatch (one side thinks it's full-duplex, the other half — slow but functional, the worst kind of bug).&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The layer everyone forgets until it's the problem:&lt;/em&gt;&lt;/strong&gt;* L2 issues are the hardest to diagnose because they're often &lt;strong&gt;silent&lt;/strong&gt;. A misconfigured VLAN doesn't throw an error. It just... doesn't deliver. You see packets leave, and nothing arrives. Wireshark is your only friend.&lt;/p&gt;




&lt;h3&gt;
  
  
  Layer 1 — Physical
&lt;/h3&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Solves:&lt;/em&gt;&lt;/strong&gt;* &lt;strong&gt;What physical signal carries this, and can the receiver tell 0 from 1?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Copper, fiber, radio. Voltages, wavelengths, modulation schemes. The dirt and the photons.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Real products:&lt;/em&gt;&lt;/strong&gt;* Corning and Prysmian fiber, Cat6/Cat7 cabling, DWDM optics (400G, 800G), Starlink's radio link, AWS Direct Connect, undersea cables.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;How it fails:&lt;/em&gt;&lt;/strong&gt;* Cable unplugged, fiber cut (a single backhoe in Virginia takes down half the internet — this has happened), signal attenuation over long distances, interference on wireless, bad SFP modules.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Why it still matters in a cloud world:&lt;/em&gt;&lt;/strong&gt;* The physical layer is where &lt;strong&gt;latency physics&lt;/strong&gt; lives. Light in fiber travels ~200,000 km/s. New York to London is ~5,600 km — so round-trip, that's ~56 ms &lt;strong&gt;minimum&lt;/strong&gt;, no matter how good your software is. Every CDN, every edge compute offering, every "multi-region active-active" architecture is fundamentally a negotiation with L1 latency.&lt;/p&gt;




&lt;h2&gt;
  
  
  Use Case Traces — Real Systems, Layer by Layer
&lt;/h2&gt;

&lt;p&gt;Theory is cheap. Let's walk through real flows and watch the layers dance.&lt;/p&gt;

&lt;h3&gt;
  
  
  4.1 Loading a YouTube video
&lt;/h3&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;sequenceDiagram

&amp;nbsp; &amp;nbsp; participant U as User

&amp;nbsp; &amp;nbsp; participant B as Browser

&amp;nbsp; &amp;nbsp; participant CF as CDN Edge

&amp;nbsp; &amp;nbsp; participant O as Origin

&amp;nbsp; &amp;nbsp; participant DB as Metadata DB

&amp;nbsp; &amp;nbsp; U-&amp;gt;&amp;gt;B: Click play

&amp;nbsp; &amp;nbsp; B-&amp;gt;&amp;gt;B: L7: Build HTTP/3 request

&amp;nbsp; &amp;nbsp; B-&amp;gt;&amp;gt;B: L6: TLS 1.3 (already cached session)

&amp;nbsp; &amp;nbsp; B-&amp;gt;&amp;gt;B: L4: QUIC stream over UDP

&amp;nbsp; &amp;nbsp; B-&amp;gt;&amp;gt;CF: L3: Route to nearest PoP (anycast)

&amp;nbsp; &amp;nbsp; CF-&amp;gt;&amp;gt;CF: L2/L1: Cache lookup

&amp;nbsp; &amp;nbsp; alt Cache hit

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CF--&amp;gt;&amp;gt;B: Video chunks (sub-50ms)

&amp;nbsp; &amp;nbsp; else Cache miss

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CF-&amp;gt;&amp;gt;O: Fetch from origin

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; O-&amp;gt;&amp;gt;DB: Metadata query

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DB--&amp;gt;&amp;gt;O: Result

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; O--&amp;gt;&amp;gt;CF: Video + cache it

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CF--&amp;gt;&amp;gt;B: Stream

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; B--&amp;gt;&amp;gt;U: Playing&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;*&lt;strong&gt;&lt;em&gt;What to notice:&lt;/em&gt;&lt;/strong&gt;* Every layer is doing something essential. The anycast routing at L3 sends you to the &lt;strong&gt;nearest&lt;/strong&gt; CDN edge — not the "correct" one in a DNS sense, just the geographically closest. QUIC at L4 gives you 0-RTT resumption so re-opening the tab doesn't cost a handshake. TLS at L6 is already negotiated. This is why YouTube feels instant.&lt;/p&gt;

&lt;h3&gt;
  
  
  4.2 A single DNS lookup
&lt;/h3&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;sequenceDiagram

&amp;nbsp; &amp;nbsp; participant C as Client

&amp;nbsp; &amp;nbsp; participant R as Recursive Resolver

&amp;nbsp; &amp;nbsp; participant Root as Root Server

&amp;nbsp; &amp;nbsp; participant TLD as .com TLD

&amp;nbsp; &amp;nbsp; participant Auth as Authoritative NS

&amp;nbsp; &amp;nbsp; C-&amp;gt;&amp;gt;R: Query: google.com? (UDP:53)

&amp;nbsp; &amp;nbsp; R-&amp;gt;&amp;gt;Root: Where is .com?

&amp;nbsp; &amp;nbsp; Root--&amp;gt;&amp;gt;R: Ask .com TLD

&amp;nbsp; &amp;nbsp; R-&amp;gt;&amp;gt;TLD: Where is google.com?

&amp;nbsp; &amp;nbsp; TLD--&amp;gt;&amp;gt;R: Ask Google's NS

&amp;nbsp; &amp;nbsp; R-&amp;gt;&amp;gt;Auth: Where is google.com?

&amp;nbsp; &amp;nbsp; Auth--&amp;gt;&amp;gt;R: 142.250.185.78 (TTL 300s)

&amp;nbsp; &amp;nbsp; R--&amp;gt;&amp;gt;C: 142.250.185.78 (cached)&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;*&lt;strong&gt;&lt;em&gt;What to notice:&lt;/em&gt;&lt;/strong&gt;* DNS is a &lt;strong&gt;recursive&lt;/strong&gt; protocol — each server only knows the next step, not the final answer. The 300-second TTL is the L7 contract that lets caching work. Without TTLs, every DNS query would hit the root servers, and the internet would collapse under its own weight.&lt;/p&gt;

&lt;h3&gt;
  
  
  4.3 A multiplayer game tick
&lt;/h3&gt;

&lt;p&gt;A 60-tick-per-second shooter sends ~60 UDP packets per second per player. Each packet contains: player position, velocity, actions.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;L4: UDP, not TCP.&lt;/em&gt;&lt;/strong&gt;* A lost position update 100ms ago is &lt;strong&gt;worthless&lt;/strong&gt;. Retransmitting it would delay the next update, making lag worse. UDP wins because stale data is worse than missing data.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;L3:&lt;/em&gt;&lt;/strong&gt;* The game server IP is often &lt;strong&gt;anycast&lt;/strong&gt; — the player connects to the nearest edge, which tunnels to the authoritative game server.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;L7:&lt;/em&gt;&lt;/strong&gt;* Custom binary protocol. JSON would be 10x too slow.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The lesson:&lt;/em&gt;&lt;/strong&gt;* "Reliable" isn't always better. Protocol choice is a &lt;strong&gt;product&lt;/strong&gt; decision, not a network one.&lt;/p&gt;




&lt;h2&gt;
  
  
  Diagnostics: The OSI X-Ray
&lt;/h2&gt;

&lt;p&gt;This is where OSI earns its keep. When something breaks, you don't guess — you *&lt;strong&gt;&lt;em&gt;walk the stack&lt;/em&gt;&lt;/strong&gt;*.&lt;br&gt;
&lt;/p&gt;

&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TD

&amp;nbsp; &amp;nbsp; START["Something is broken"] --&amp;gt; Q1{"Can you ping\&amp;lt;br/&amp;gt;the IP? (L3)"}

&amp;nbsp; &amp;nbsp; Q1 --&amp;gt;|No| L3["L3 issue\&amp;lt;br/&amp;gt;Routing · Firewall · IP conflict"]

&amp;nbsp; &amp;nbsp; Q1 --&amp;gt;|Yes| Q2{"Does the port\&amp;lt;br/&amp;gt;accept connections? (L4)"}

&amp;nbsp; &amp;nbsp; Q2 --&amp;gt;|No| L4["L4 issue\&amp;lt;br/&amp;gt;Port closed · Firewall · TCP stack"]

&amp;nbsp; &amp;nbsp; Q2 --&amp;gt;|Yes| Q3{"Does DNS\&amp;lt;br/&amp;gt;resolve? (L7)"}

&amp;nbsp; &amp;nbsp; Q3 --&amp;gt;|No| L7a["L7 issue\&amp;lt;br/&amp;gt;Resolver · Records · TTL"]

&amp;nbsp; &amp;nbsp; Q3 --&amp;gt;|Yes| Q4{"Does TLS\&amp;lt;br/&amp;gt;handshake? (L6)"}

&amp;nbsp; &amp;nbsp; Q4 --&amp;gt;|No| L6["L6 issue\&amp;lt;br/&amp;gt;Cert · Cipher · SNI"]

&amp;nbsp; &amp;nbsp; Q4 --&amp;gt;|Yes| Q5{"Does the API\&amp;lt;br/&amp;gt;return 200? (L7)"}

&amp;nbsp; &amp;nbsp; Q5 --&amp;gt;|No| L7b["L7 issue\&amp;lt;br/&amp;gt;App · DB · Downstream"]

&amp;nbsp; &amp;nbsp; Q5 --&amp;gt;|Yes| DONE["Working"]

&amp;nbsp; &amp;nbsp; style START fill:#ff7675,color:#fff

&amp;nbsp; &amp;nbsp; style DONE fill:#55efc4

&amp;nbsp; &amp;nbsp; style L3 fill:#fdcb6e

&amp;nbsp; &amp;nbsp; style L4 fill:#fdcb6e

&amp;nbsp; &amp;nbsp; style L6 fill:#fdcb6e

&amp;nbsp; &amp;nbsp; style L7a fill:#fdcb6e

&amp;nbsp; &amp;nbsp; style L7b fill:#fdcb6e&lt;/code&gt;&lt;/pre&gt;



&lt;h3&gt;
  
  
  The tool map
&lt;/h3&gt;

&lt;p&gt;| Layer | Tool | What it tells you |&lt;/p&gt;

&lt;p&gt;|-------|------|-------------------|&lt;/p&gt;

&lt;p&gt;| L7 | &lt;code&gt;curl -v&lt;/code&gt;, browser DevTools, &lt;code&gt;dig&lt;/code&gt;, &lt;code&gt;nslookup&lt;/code&gt; | App response, DNS resolution |&lt;/p&gt;

&lt;p&gt;| L6 | &lt;code&gt;openssl s_client&lt;/code&gt;, Wireshark (with keylog) | TLS handshake, cert validity |&lt;/p&gt;

&lt;p&gt;| L5 | &lt;code&gt;ss&lt;/code&gt;, &lt;code&gt;netstat&lt;/code&gt;, app logs | Session state, connection count |&lt;/p&gt;

&lt;p&gt;| L4 | &lt;code&gt;nc&lt;/code&gt;, &lt;code&gt;nmap&lt;/code&gt;, &lt;code&gt;tcpdump&lt;/code&gt;, &lt;code&gt;ss&lt;/code&gt; | Port reachability, retransmits |&lt;/p&gt;

&lt;p&gt;| L3 | &lt;code&gt;ping&lt;/code&gt;, &lt;code&gt;traceroute&lt;/code&gt;, &lt;code&gt;mtr&lt;/code&gt;, &lt;code&gt;ip route&lt;/code&gt; | Path, latency, packet loss |&lt;/p&gt;

&lt;p&gt;| L2 | &lt;code&gt;arp -a&lt;/code&gt;, &lt;code&gt;ifconfig&lt;/code&gt;, switch CLI | MAC, frame errors |&lt;/p&gt;

&lt;p&gt;| L1 | &lt;code&gt;ethtool&lt;/code&gt;, OTDR, cable tester | Link status, signal quality |&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The two golden rules of troubleshooting:&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Bottom-up&lt;/em&gt;&lt;/strong&gt;* when you suspect infrastructure (start at L1, walk up).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Top-down&lt;/em&gt;&lt;/strong&gt;* when you suspect the app (start at L7, walk down).&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Most production incidents are resolved faster with top-down, because the app is &lt;strong&gt;usually&lt;/strong&gt; the culprit. But when the app looks fine and nothing works, bottom-up is the only path.&lt;/p&gt;




&lt;h2&gt;
  
  
  System Design Through the OSI Lens
&lt;/h2&gt;

&lt;p&gt;Here's where OSI stops being a networking concept and becomes an *&lt;strong&gt;&lt;em&gt;architecture tool&lt;/em&gt;&lt;/strong&gt;*.&lt;/p&gt;

&lt;h3&gt;
  
  
  6.1 Where each layer lives in a modern stack
&lt;/h3&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;graph TB

&amp;nbsp; &amp;nbsp; subgraph CLIENT["Client Tier"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C1["Mobile / Browser"]

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; subgraph EDGE["Edge Tier · L7"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; E1["CDN · Cloudflare / Akamai"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; E2["WAF · DDoS Protection"]

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; subgraph LB["Load Balancing Tier"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; L1["L7 LB · AWS ALB"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; L2["L4 LB · AWS NLB"]

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; subgraph APP["Application Tier"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A1["Service A · gRPC"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A2["Service B · REST"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A3["Service C · GraphQL"]

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; subgraph DATA["Data Tier"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D1["PostgreSQL"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D2["Redis"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D3["Kafka"]

&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D4["Vector DB"]

&amp;nbsp; &amp;nbsp; end

&amp;nbsp; &amp;nbsp; CLIENT --&amp;gt; EDGE --&amp;gt; LB --&amp;gt; APP --&amp;gt; DATA

&amp;nbsp; &amp;nbsp; style CLIENT fill:#ff7675,color:#fff

&amp;nbsp; &amp;nbsp; style EDGE fill:#fdcb6e

&amp;nbsp; &amp;nbsp; style LB fill:#74b9ff

&amp;nbsp; &amp;nbsp; style APP fill:#55efc4

&amp;nbsp; &amp;nbsp; style DATA fill:#a29bfe&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The critical design question at each tier:&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Edge (L7):&lt;/em&gt;&lt;/strong&gt;* Do you need request-aware routing, or just fast termination? Cloudflare vs. plain DNS.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Load balancer (L4 vs. L7):&lt;/em&gt;&lt;/strong&gt;* L4 LBs are faster and protocol-agnostic but blind to HTTP semantics. L7 LBs see everything but cost more CPU. Most architectures use both — L4 at the edge, L7 inside.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;App tier (L7):&lt;/em&gt;&lt;/strong&gt;* REST for public APIs (cacheable, human-readable), gRPC for internal services (fast, typed, streaming), GraphQL when clients need flexibility.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Data tier (L4):&lt;/em&gt;&lt;/strong&gt;* Databases speak their own protocols over TCP. Connection pooling is an L4 concern. Kafka is its own protocol entirely.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  The Master's Lens
&lt;/h2&gt;

&lt;p&gt;You've read the layers, the traces, the diagnostics, the designs. Here's how to &lt;strong&gt;use&lt;/strong&gt; all of it.&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;When something breaks, ask:&lt;/em&gt;&lt;/strong&gt;* Which layer's &lt;strong&gt;question&lt;/strong&gt; is being answered wrong?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;User can't reach the site → L7 DNS? L3 routing? L4 port? L1 link?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Latency is high → L3 path? L4 retransmits? L6 handshake? L7 app code?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Data is corrupted → L2 CRC? L6 encoding? L7 serialization?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Security incident → L6 TLS misconfig? L7 injection? L3 spoofing?&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;When you design a system, ask:&lt;/em&gt;&lt;/strong&gt;* What layer does each component operate at, and what does that buy me?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;L4 load balancer: fast, protocol-blind.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;L7 load balancer: slower, HTTP-aware.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;L6 sidecar: encryption without app changes.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;L7 service mesh: retries, tracing, traffic shifting.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;When you scale, ask:&lt;/em&gt;&lt;/strong&gt;* Which layer is the bottleneck?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;More traffic → L4/L7 horizontal scaling.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;More regions → L3 routing, L4 replication.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;More GPU → L1 bandwidth, L2 topology.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;More services → L7 API design, L6 security.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;*&lt;strong&gt;&lt;em&gt;The final insight:&lt;/em&gt;&lt;/strong&gt;* OSI is not a test you pass. It's a *&lt;strong&gt;&lt;em&gt;shared vocabulary&lt;/em&gt;&lt;/strong&gt;* that lets a student, an SRE, an architect, and a CTO argue about the same problem without talking past each other. Every incident postmortem, every design review, every "why is this slow" conversation becomes clearer when everyone agrees on which layer they're discussing.&lt;/p&gt;

&lt;p&gt;That's the mastery. Not memorizing seven words — *&lt;strong&gt;&lt;em&gt;seeing seven questions, always, in every system you touch.&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;




&lt;h2&gt;
  
  
  Appendix: Quick Reference
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The Seven Questions
&lt;/h3&gt;

&lt;p&gt;| # | Question | Layer |&lt;/p&gt;

&lt;p&gt;|---|----------|-------|&lt;/p&gt;

&lt;p&gt;| 1 | What does the user want? | L7 · Application |&lt;/p&gt;

&lt;p&gt;| 2 | How is the data represented? | L6 · Presentation |&lt;/p&gt;

&lt;p&gt;| 3 | Is this an ongoing conversation? | L5 · Session |&lt;/p&gt;

&lt;p&gt;| 4 | Did it arrive, intact, in order? | L4 · Transport |&lt;/p&gt;

&lt;p&gt;| 5 | Which machine, globally? | L3 · Network |&lt;/p&gt;

&lt;p&gt;| 6 | Which device, locally? | L2 · Data Link |&lt;/p&gt;

&lt;p&gt;| 7 | What physical signal? | L1 · Physical |&lt;/p&gt;

&lt;h3&gt;
  
  
  The Vocabulary Chain
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;
Data → Segment/Datagram → Packet → Frame → Bits

(L7-5) &amp;nbsp; &amp;nbsp; &amp;nbsp;(L4) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(L3) &amp;nbsp; &amp;nbsp;(L2) &amp;nbsp; (L1)

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  The Tool Map
&lt;/h3&gt;

&lt;p&gt;| Layer | Tools |&lt;/p&gt;

&lt;p&gt;|-------|-------|&lt;/p&gt;

&lt;p&gt;| L7 | &lt;code&gt;curl&lt;/code&gt;, &lt;code&gt;dig&lt;/code&gt;, DevTools |&lt;/p&gt;

&lt;p&gt;| L6 | &lt;code&gt;openssl&lt;/code&gt;, Wireshark |&lt;/p&gt;

&lt;p&gt;| L5 | &lt;code&gt;ss&lt;/code&gt;, &lt;code&gt;netstat&lt;/code&gt; |&lt;/p&gt;

&lt;p&gt;| L4 | &lt;code&gt;nc&lt;/code&gt;, &lt;code&gt;nmap&lt;/code&gt;, &lt;code&gt;tcpdump&lt;/code&gt; |&lt;/p&gt;

&lt;p&gt;| L3 | &lt;code&gt;ping&lt;/code&gt;, &lt;code&gt;traceroute&lt;/code&gt;, &lt;code&gt;mtr&lt;/code&gt; |&lt;/p&gt;

&lt;p&gt;| L2 | &lt;code&gt;arp&lt;/code&gt;, &lt;code&gt;ifconfig&lt;/code&gt; |&lt;/p&gt;

&lt;p&gt;| L1 | &lt;code&gt;ethtool&lt;/code&gt;, OTDR |&lt;/p&gt;

&lt;h3&gt;
  
  
  The Core Principle
&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;*&lt;strong&gt;&lt;em&gt;Encapsulate going down. Decapsulate going up. Every hop. Every time. Everywhere.&lt;/em&gt;&lt;/strong&gt;*&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;&lt;strong&gt;If you made it here, you don't need to "study OSI" anymore. You already see it.&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;On Github:&lt;br&gt;
&lt;a href="https://github.com/pkbvs1806/B2B/blob/main/Networking/OSI_Layers.md" rel="noopener noreferrer"&gt;https://github.com/pkbvs1806/B2B/blob/main/Networking/OSI_Layers.md&lt;/a&gt;&lt;/p&gt;

</description>
      <category>networking</category>
      <category>cloud</category>
      <category>devops</category>
      <category>career</category>
    </item>
    <item>
      <title>Microsoft Azure Sentinel</title>
      <dc:creator>Praveen Kumar</dc:creator>
      <pubDate>Tue, 02 May 2023 14:59:21 +0000</pubDate>
      <link>https://dev.to/pkbvs1806/microsoft-azure-sentinel-7i5</link>
      <guid>https://dev.to/pkbvs1806/microsoft-azure-sentinel-7i5</guid>
      <description>&lt;p&gt;IF you are working as SOC or DevSecOps in Cloud environments, we are need to ensure and highly responsible for security management capabilities.&lt;/p&gt;

&lt;p&gt;Here some is the topic like &lt;strong&gt;SIEM&lt;/strong&gt; (Security Information and Event Management) &lt;strong&gt;SOAR&lt;/strong&gt; (Security Orchestration and Automated Response).&lt;/p&gt;

&lt;p&gt;For above topics like SIEM and SOAR we have Microsoft Azure Sentinel in Public cloud is of the right solution to manage with minimal Administrations and flexible pricing model&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM&lt;/strong&gt; - Tool that an organization uses to &lt;strong&gt;collect, analyze, and perform security operations&lt;/strong&gt; on its computer systems. Those systems can be hardware appliances, applications, or both&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Log management&lt;/strong&gt;: The ability to collect, store, and query the log data from resources within your environment&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Alerting&lt;/strong&gt;: A proactive look inside the log data for potential security incidents and anomalies&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Visualization&lt;/strong&gt;: Graphs and dashboards that provide visual insights into your log data&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Incident management&lt;/strong&gt;: The ability to create, update, assign, and investigate incidents that have been identified&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Querying data&lt;/strong&gt;: A rich query language, similar to that for log management, that you can use to query and understand your data&lt;/p&gt;

&lt;p&gt;Microsoft Sentinel in General term, cloud-native SIEM system used by SOC to &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fm1ossdkl9ts6fur367j1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fm1ossdkl9ts6fur367j1.png" alt=" " width="742" height="691"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Getting insights across by collecting data&lt;/li&gt;
&lt;li&gt;Detect and investigate threat by using &lt;strong&gt;advanced built in Machine Learning and Microsoft threat Intelligence&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Automate response by using playbooks and natively incorporates Azure Logic Apps and Log Analytics which enhances its capabilities&lt;/li&gt;
&lt;li&gt;Unlike an traditional Sentinel &lt;strong&gt;no worries about installation in servers or on premises&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Microsoft Sentinel is a service that you deploy in Azure. You can get &lt;strong&gt;up and running with Sentinel in just a few minutes&lt;/strong&gt; in the Azure portal&lt;/p&gt;

&lt;p&gt;Four Stages of Sentinel&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Collect (Visibility)&lt;/li&gt;
&lt;li&gt;Detect (Analytics, Hunting)&lt;/li&gt;
&lt;li&gt;Investigate (Incidents)&lt;/li&gt;
&lt;li&gt;Respond (Automations)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fre82fdgk6ox11gi3toe3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fre82fdgk6ox11gi3toe3.png" alt=" " width="800" height="195"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Collect Data&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;collect data on all users, devices, applications, and infrastructure both on-premises and across multiple cloud environments. It can easily connect to security sources out of the box&lt;/li&gt;
&lt;li&gt;There are several connectors available for Microsoft solutions that provide real-time integration&lt;/li&gt;
&lt;li&gt;It also includes built-in connectors for third-party products and services (non-Microsoft Solutions)
&lt;strong&gt;Data connectors&lt;/strong&gt; are many
    * Syslog
    * Common Event Format (CEF)
    * Trusted Automated eXchange of Indicator Information (TAXII) (for threat intelligence)
    * Azure
    * AWS&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbgp7xoz0rer20ox8n1nz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbgp7xoz0rer20ox8n1nz.png" alt=" " width="800" height="471"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Detect Threats&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;can detect threats and minimizes false positives by using analytics and threat intelligence drawn directly from Microsoft. Azure * * Analytics plays a major role in correlating alerts into incidents identified by the security team&lt;/li&gt;
&lt;li&gt;It provides built-in templates directly out-of-the-box to create threat detection rules and automate threat responses&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Investigation Suspicious Activities&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;can investigate and hunt suspicious activities across the environment. It helps reduce noise and hunt for security threats&lt;/li&gt;
&lt;li&gt;Use Artificial Intelligence to proactively identify threats before an alert  trigger across the protected assest to detect suspicious activities&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Respond&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;can react smoothly and respond quickly to built-in orchestration incidents, and common and frequent tasks can easily be converted into automation&lt;/li&gt;
&lt;li&gt;capable of creating simplified security orchestration with playbook&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Major Key Components we can utilize in Sentinel&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data connectors&lt;/strong&gt;&lt;br&gt;
(we have seen above)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Log retention&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdqhjnh32s0as5z7udq4g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdqhjnh32s0as5z7udq4g.png" alt=" " width="800" height="403"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;After it's been ingested into Microsoft Sentinel, your data is stored by using Log Analytics&lt;/li&gt;
&lt;li&gt;KQL is a rich query language that gives you the power to dive into and gain insights from our data&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Workbooks&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0a8xk8lmyzz40ch6isrw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0a8xk8lmyzz40ch6isrw.png" alt=" " width="800" height="433"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;can use workbooks to visualize your data within Microsoft Sentinel. Think as a Dashboard&lt;/li&gt;
&lt;li&gt;Each component in the dashboard is built by using an underlying KQL query of your data&lt;/li&gt;
&lt;li&gt;can use the built-in workbooks within Microsoft Sentinel and edit them to meet your own needs, or create your own workbooks from scratch&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Analytics alerts&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxyczyqgsit6wyvefsb8j.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxyczyqgsit6wyvefsb8j.png" alt=" " width="800" height="473"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;As far as now we have, you have your logs and some data visualization&lt;/li&gt;
&lt;li&gt;Now it's great time to have some proactive analytics across your data, so you're notified when something suspicious occurs&lt;/li&gt;
&lt;li&gt;can enable built-in analytics alerts within your Sentinel workspace&lt;/li&gt;
&lt;li&gt;There are many types alerts are there. Can also create custom, scheduled alerts from scratch&lt;/li&gt;
&lt;li&gt;Other alerts are built on machine-learning models that are proprietary to Microsoft&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Threat hunting&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Feorbyloffe0ahq58epm0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Feorbyloffe0ahq58epm0.png" alt=" " width="799" height="475"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;there are some built-in hunting queries that they can use&lt;/li&gt;
&lt;li&gt;can also create their own queries&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Incidents and investigations&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F585h292jhohlxdo9xhfp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F585h292jhohlxdo9xhfp.png" alt=" " width="799" height="346"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;when an alert that you've enabled is triggered, Incident will be ceated&lt;/li&gt;
&lt;li&gt;you can do standard incident management tasks like changing status or assigning incidents to individuals for investigation&lt;/li&gt;
&lt;li&gt;Microsoft Sentinel also has investigation functionality, so you can visually investigate incidents by mapping entities across log data along a timeline&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Automation playbooks&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3nwnh88hl1blns9x3s5h.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3nwnh88hl1blns9x3s5h.png" alt=" " width="800" height="470"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;With the ability to respond to incidents automatically now you can automate some of your security operations and make your SOC more productive&lt;/li&gt;
&lt;li&gt;Sentinel allows you to create automated workflows, or playbooks, in response to events and functionality could be used for incident management, enrichment, investigation, or remediation. This capabilities are often referred to as security orchestration, automation, and response (SOAR)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Continue......&lt;/p&gt;

</description>
      <category>azure</category>
      <category>devsecops</category>
      <category>sentinel</category>
      <category>cloudcomputing</category>
    </item>
    <item>
      <title>Robusta Installation</title>
      <dc:creator>Praveen Kumar</dc:creator>
      <pubDate>Wed, 26 Apr 2023 16:59:29 +0000</pubDate>
      <link>https://dev.to/pkbvs1806/robusta-installation-b4k</link>
      <guid>https://dev.to/pkbvs1806/robusta-installation-b4k</guid>
      <description>&lt;p&gt;Robusta is the CNCF member, Which is &lt;strong&gt;open source&lt;/strong&gt; and used on monitoring layer for Kubernetes and automations. Provides &lt;strong&gt;valuable insights into Kubernetes clusters&lt;/strong&gt; and integrates with various monitoring and alerting tools Commonly used with Prometheus but not limited.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffl1so98wp8vziut2jjsn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffl1so98wp8vziut2jjsn.png" alt=" " width="799" height="382"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;First as the source of truth to check parent website for updated templates &lt;a href="https://docs.robusta.dev/master/installation.html" rel="noopener noreferrer"&gt;https://docs.robusta.dev/master/installation.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Installation steps&lt;br&gt;
There are few ways of installations like Robusta cli and docker, Currently we are using Robusta CLI&lt;/p&gt;

&lt;p&gt;By default, on Linux and mac you have python install or else check and install python before the Robusta.&lt;/p&gt;

&lt;p&gt;Step 1 : &lt;br&gt;
$ helm repo add robusta &lt;a href="https://robusta-charts.storage.googleapis.com" rel="noopener noreferrer"&gt;https://robusta-charts.storage.googleapis.com&lt;/a&gt; &amp;amp;&amp;amp; helm repo update&lt;/p&gt;

&lt;p&gt;$ pip install -U robusta-cli --no-cache&lt;br&gt;
(check the python version, coz Python 3.7 and higher is required)&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fh011vihk6hw5x03yp02c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fh011vihk6hw5x03yp02c.png" alt=" " width="800" height="186"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Step 2 : Robusta configurations required sink (automations in place to handle alerts in your Kubernetes cluster by sending them to sinks with added enrichments that tell you what is happening in your cluster. It also suggests common fixes that give us better alerts)&lt;br&gt;
Sinks Available : &lt;a href="https://docs.robusta.dev/master/catalog/sinks/index.html" rel="noopener noreferrer"&gt;https://docs.robusta.dev/master/catalog/sinks/index.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;$ robusta gen-config&lt;/p&gt;

&lt;p&gt;will ask for y or n popup, once y is been choosed on browser ask to add on channel slack.&lt;/p&gt;

&lt;p&gt;It will create the generated_values.yaml in current path&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fipm07o0y482f3t7px451.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fipm07o0y482f3t7px451.png" alt=" " width="799" height="320"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd24q94yi8q8r7h4sqldv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd24q94yi8q8r7h4sqldv.png" alt=" " width="800" height="83"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Step 3 : Run the following commands to install Helm charts&lt;/p&gt;

&lt;p&gt;$ helm install robusta robusta/robusta -n your_namespace -f ./generated_values.yaml \&lt;br&gt;
    --set clusterName=&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4objtbglsk0ohk93jeeh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4objtbglsk0ohk93jeeh.png" alt=" " width="799" height="160"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Step 4 : To check the deployments on robusta&lt;/p&gt;

&lt;p&gt;$ kubectl get pods -n your_namespace&lt;br&gt;
$ robusta logs&lt;/p&gt;

&lt;p&gt;Step 5 : To check the Robusta create some error like crashing pod&lt;/p&gt;

&lt;p&gt;$ kubectl apply -f &lt;a href="https://gist.githubusercontent.com/robusta-lab/283609047306dc1f05cf59806ade30b6/raw" rel="noopener noreferrer"&gt;https://gist.githubusercontent.com/robusta-lab/283609047306dc1f05cf59806ade30b6/raw&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;$ kubectl get pods -n your_namespace&lt;/p&gt;

&lt;p&gt;Step 6 : Use Robusta UI that we enabled in Step 2 option&lt;/p&gt;

&lt;p&gt;URL : &lt;a href="https://platform.robusta.dev/" rel="noopener noreferrer"&gt;https://platform.robusta.dev/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Two options to choose like Google and Azure, provide the mail id which is given in Step 2&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7lv5gqmtueez9qiap9ze.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7lv5gqmtueez9qiap9ze.png" alt=" " width="800" height="513"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Continue......&lt;/p&gt;

</description>
      <category>devops</category>
      <category>kubernetes</category>
      <category>robusta</category>
      <category>monitoring</category>
    </item>
  </channel>
</rss>
