1_r/devopsish

1_r/devopsish

54497 bookmarks
Custom sorting
DevOps Toolkit - Workload Identity - Feat. SPIFFE SPIRE and Athenz (You Choose! Ch. 3 Ep. 7) - https://www.youtube.com/watch?v=gYq591U8Dac
DevOps Toolkit - Workload Identity - Feat. SPIFFE SPIRE and Athenz (You Choose! Ch. 3 Ep. 7) - https://www.youtube.com/watch?v=gYq591U8Dac

Workload Identity - Feat. SPIFFE, SPIRE, and Athenz (You Choose!, Ch. 3, Ep. 7)

Generating Workload Identity - Choose Your Own Adventure: The Treacherous Trek to Security In this episode, we'll figure out ...

via YouTube https://www.youtube.com/watch?v=gYq591U8Dac

·youtube.com·
DevOps Toolkit - Workload Identity - Feat. SPIFFE SPIRE and Athenz (You Choose! Ch. 3 Ep. 7) - https://www.youtube.com/watch?v=gYq591U8Dac
Linux is a CNA
Linux is a CNA
As was recently announced, the Linux kernel project has been accepted as a CNA as a CVE Numbering Authority (CNA) for vulnerabilities found in Linux. This is a trend, of more open source projects taking over the half-hazard assignments of CVEs against their project by becoming a CNA so that no other group can assign CVEs without their involvment. Here’s the curl project doing much the same thing for the same reasons.
·kroah.com·
Linux is a CNA
Week Ending February 11 2024
Week Ending February 11 2024

Week Ending February 11, 2024

http://lwkd.info/2024/20240211

Developer News

The Contributor Summit is looking for volunteers and a few more pre-planned sessions; remember that KCS sessions need to target contributors.

Need a technical summer intern? We can still accept project proposals for the CNCF Google Summer of Code application if you get them in soon.

Release Schedule

Next Deadline: Docs Deadline for placeholder PRs, February 22nd

We are in Enhancements Freeze now, and currently have 84 opted-in, 56 tracked, and 28 removed features. If your feature missed the deadline, you need to file an Exception.

Patch releases, including a Go update, are due out this week for Valentine’s Day! This is likely to be the last patch release for Kubernetes 1.26. Tell your partner you love them by updating all their clusters.

Roses are red Violets are blue Golang’s outdated 1.26 is EOL too

KEP of the Week

KEP-3962: Mutating Admission Policies

This KEP introduces mutating admission policies, declared using CEL expressions, improving on mutating admission webhooks. It leverages the power of CEL object construction and Server Side Apply’s merge algorithms to allow in-process mutations.

Mutations are specified within a MutatingAdmissionPolicy resource, referencing parameter resources for configuration. Reinvocation will support it as well. Metrics and safety checks are being developed to ensure idempotence and deterministic final states. While limitations exist (e.g., no deletion), this feature offers a declarative and efficient way to perform common mutations, reducing complexity and improving performance.

This KEP was created in 2023, and is planned to reach its alpha milestone in v1.30 release.

Other Merges

ValidatingAdmissionPolicy supports variables in type checks

kubectl explain shows enum values if available

Wildcard events will get requeued

kubeadm: finalize phase uses auth context

Priority and Fairness allows ConcurrencyShares to be zero

Add porto support for vanity imports of the Kubernetes code

Promotions

CloudDualStackNodeIPs is GA

Deprecated

SecurityContextDeny admission plugin is removed; use PodSecurity instead

Version Updates

go to 1.21.7 in 1.26 through 1.29, and to 1.22 in 1.30

debian-base for images to bookworm 1.0.1

etcd to 3.5.12

Subprojects and Dependency Updates

kubespray to v2.22.2 Make kubernetes 1.26.13 the default version

via Last Week in Kubernetes Development http://lwkd.info/

February 11, 2024 at 05:00PM

·lwkd.info·
Week Ending February 11 2024
Introducing Video Game Module Powered by Raspberry Pi
Introducing Video Game Module Powered by Raspberry Pi
We're excited to announce the Video Game Module, our new product developed in collaboration with Raspberry Pi! The module is powered by the first chip designed by Raspberry Pi—the RP2040 microcontroller, the same as in the Raspberry Pi Pico board. We slightly overclocked the microcontroller so it could generate
·blog.flipper.net·
Introducing Video Game Module Powered by Raspberry Pi
New WiFi Authentication Vulnerabilities For Linux's IWD & WPA_Supplicant
New WiFi Authentication Vulnerabilities For Linux's IWD & WPA_Supplicant
Kicking off what may end up being a fairly busy Patch Tuesday are two WiFi authentication vulnerabilities being made public that affect Intel's IWD daemon as well as the WPA_Supplicant software -- between the two they are the most common solutions for wireless daemons on Linux systems.
·phoronix.com·
New WiFi Authentication Vulnerabilities For Linux's IWD & WPA_Supplicant
Backblaze Drive Stats for 2023
Backblaze Drive Stats for 2023
Read the 2023 Drive Stats Report and the latest insights on drive failure from Andy Klein. Read the 2023 Drive Stats Report and the latest insights on drive failure from Andy Klein.
·backblaze.com·
Backblaze Drive Stats for 2023
China is developing a new generation of communication satellites, which will become one of the important components of 6G communication network - IT Home (Chinese)
China is developing a new generation of communication satellites, which will become one of the important components of 6G communication network - IT Home (Chinese)
这种新一代通信卫星在一个数平方米的平面上既有可以通信的天线,又有可以把太阳能转换成卫星能源的太阳电池片,是一种相控阵天线和太阳翼一体化的通信卫星。
·ithome.com·
China is developing a new generation of communication satellites, which will become one of the important components of 6G communication network - IT Home (Chinese)
Using Finch to run Apache Airflow using mwaa-local-runner
Using Finch to run Apache Airflow using mwaa-local-runner
I show you how you can use the Finch to run Apache Airflow using the mwaa-local-runner tool, and how you can do this for your applications too As some of you may know, I have been creating content on Apache Airflow for a few years now. One of the open source projects that AWS has produced to make it easier for developers to get started with Apache Airflow, is mwaa-local-runner.
·blog.beachgeek.co.uk·
Using Finch to run Apache Airflow using mwaa-local-runner
How to Make Better Friends at Work
How to Make Better Friends at Work
Friendships at work can enrich us and our organizations if we cultivate these relationships thoughtfully.
·sloanreview.mit.edu·
How to Make Better Friends at Work