1_DevOps'ish

1_DevOps'ish

55008 bookmarks
Custom sorting
CNCF Firehose
CNCF Firehose
CNCF project releases aggregated in one place
·castrojo.github.io·
CNCF Firehose
Curiosity is the first-step in problem solving.
Curiosity is the first-step in problem solving.
Despite my best efforts, I have been wrong a lot over the years. I’ve been wrong about technology patterns (in 2014, I thought microservices would take over the world), I’ve been wrong about management techniques (I used to think systems thinking was the ultimate technique, but I’ve seen so many mistakes rooted in over-reliance on systems thinking), and a bunch of other stuff as well. Early on, I spent a lot of time thinking about how to be wrong less frequently. That’s a noble endeavor, and one I still aim to improve at today. However, a lot of the problems you encounter later in your career are deeply ambiguous, and it simply isn’t possible to eliminate bad outcomes. Some examples of this are:
·lethain.com·
Curiosity is the first-step in problem solving.
MCP Apps - Bringing UI Capabilities To MCP Clients
MCP Apps - Bringing UI Capabilities To MCP Clients
Today, we’re announcing that MCP Apps are now live as an official MCP extension. Tools can now return interactive UI components that render directly in the conversation: dashboards, forms, visualizations, multi-step workflows, and more. This is the first official MCP extension, and it’s ready for production. We proposed MCP Apps last November, building on the amazing work of MCP-UI and the OpenAI Apps SDK. We were excited to partner with both OpenAI and MCP-UI to create a shared open standard for providing affordances for developers to include UI components in their MCP clients.
·blog.modelcontextprotocol.io·
MCP Apps - Bringing UI Capabilities To MCP Clients
The Shape of Leadership
The Shape of Leadership
Leadership Lessons from Birds That Know When to Lead and When to Adapt
·mikefisher.substack.com·
The Shape of Leadership
Physicists employ AI labmates to supercharge LED light control
Physicists employ AI labmates to supercharge LED light control
A Sandia Labs paper published in Nature Communications shows how AI is advancing beyond a mere automation tool toward becoming a powerful engine for clear, comprehensible scientific discovery.
·newsreleases.sandia.gov·
Physicists employ AI labmates to supercharge LED light control
Brex and The Pros and Cons of Hubristic Fundraising
Brex and The Pros and Cons of Hubristic Fundraising
Capital One just announced it’s acquiring Brex for $5.15 billion.  An incredible, top 0.1% “exit” in less than 10 years from a category creator that created massive wealth and opportunities. …
·saastr.com·
Brex and The Pros and Cons of Hubristic Fundraising
Desk Setup January 2026
Desk Setup January 2026

Desk Setup, January 2026

https://chrisshort.net/desk-setup-january-2026/

There’s a metaphor out there that you should write about something if you are asked about it more than three times. I cannot count how many times folks ask about my setup, so I’ll capture it here. I also haven’t posted anything about my desk since we finished our basement, which includes my office. Actually the last time I wrote about this was five years ago, almost to the day.

Note: I may earn compensation for sales from links on this post through affiliate programs.

via Chris Short https://chrisshort.net/

January 27, 2026

·chrisshort.net·
Desk Setup January 2026
AWS European Sovereign Cloud (ESC): What to Know and Do | CSA
AWS European Sovereign Cloud (ESC): What to Know and Do | CSA
Overview of AWS European Sovereign Cloud (ESC): purpose, ownership, regional structure, security features, gaps, and practical recommendations for Europe.
·cloudsecurityalliance.org·
AWS European Sovereign Cloud (ESC): What to Know and Do | CSA
149 Million Usernames and Passwords Exposed by Unsecured Database
149 Million Usernames and Passwords Exposed by Unsecured Database
This “dream wish list for criminals” includes millions of Gmail, Facebook, banking logins, and more. The researcher who discovered it suspects they were collected using infostealing malware.
·wired.com·
149 Million Usernames and Passwords Exposed by Unsecured Database
CNCF: Kubernetes is 'foundational' infrastructure for AI
CNCF: Kubernetes is 'foundational' infrastructure for AI
From where the Cloud Native Computing Foundation sits, Kubernetes is no longer experimental but foundational. Soon, it will be essential to AI as well.
·thenewstack.io·
CNCF: Kubernetes is 'foundational' infrastructure for AI
Reclaiming underutilized GPUs in Kubernetes using scheduler plugins
Reclaiming underutilized GPUs in Kubernetes using scheduler plugins
GPUs are expensive; and yours are probably sitting idle right now. High-end GPUs (for example, NVIDIA A100-class devices) can cost $10,000+, and in a Kubernetes cluster running AI workloads…
·cncf.io·
Reclaiming underutilized GPUs in Kubernetes using scheduler plugins
Drowning in AI slop, cURL ends bug bounties
Drowning in AI slop, cURL ends bug bounties
Daniel Stenberg, founder and lead developer of cURL, has had enough of AI slop and is closing down its bug bounty program.
·thenewstack.io·
Drowning in AI slop, cURL ends bug bounties
Docker lazy loading at Grab: Accelerating container startup times
Docker lazy loading at Grab: Accelerating container startup times
Large container images were causing slow cold starts and poor auto-scaling for Grab's data platforms. This post explores how we implemented Docker image lazy loading with Seekable OCI (SOCI) technology, to achieve faster image pulls and startup times. The blog discusses how lazy loading works, the technology behind SOCI and eStargz, and finally how this configuration delivered a 60% improvement in download times.
·engineering.grab.com·
Docker lazy loading at Grab: Accelerating container startup times
Expose your local server to the public internet instantly | Glama
Expose your local server to the public internet instantly | Glama
pipenet is a tunneling tool that creates a secure connection between your local machine and the public internet. Run a single command, and you'll get a public URL that forwards traffic directly to your localhost.
·glama.ai·
Expose your local server to the public internet instantly | Glama
Last Week in Kubernetes Development - Week Ending January 18 2026
Last Week in Kubernetes Development - Week Ending January 18 2026

Week Ending January 18, 2026

https://lwkd.info/2026/20260122

Developer News

SIG Windows is nominating Yuanliang Zhang and Jose Valdes as the new co-chairs. Aravindh Puthiyaparambil and Mark Rossetti will be stepping down from their roles as co-chairs while Mark Rossetti will continue on as technical lead. Thank you for your service and congrats to the newly elected chairs!

Patrick Ohly has proposed to spin down WG Structured Logging since most of the work has moved to different SIGs now. Thanks everyone who has helped modernizing logging in Kubernetes!

The SIG Node KEP Wrangling program is looking for volunteers for the v1.36 release. Sign up if you’re interested to work with KEP authors and SIG leads to ensure that deadlines are met and KEPs progress in a timely manner for the v1.36 release. Please reach out in the #sig-node-wranglers channel in Slack if you have any questions.

Release Schedule

Next Deadline: PRR Freeze, February 4

Kubernetes v1.36 call for enhancements is open! If you want your KEP to go in the v1.36 cycle, talk to your SIG leads and get the lead-opted-in label. Make sure that your KEP meets the PRR freeze requirements before February 4th.

The January 2026 patch releases remain delayed since the Go team issued new security releases, and the team is now wrapping up the necessary updates before cutting the patches.

Featured PRs

136086: Graduate watch_list_duration_seconds to Beta

This PR graduates the watch_list_duration_seconds metric from Alpha to Beta, signaling stability and long-term support. The metric provides improved observability into watch list performance and is now suitable for broader production use and alerting.

136117: Add utilities to allow strategy.go files to enable DV native validations

This PR adds utilities that allow Kubernetes API strategy implementations to opt into Declarative Validation (DV) native rules. It strengthens API correctness by ensuring declarative validations are consistently enforced for new APIs while preserving feature gate semantics.

KEP of the Week

KEP-5295: Introducing KYAML, a safer, less ambiguous YAML subset / encoding

This KEP proposes introducing KYAML, a new kubectl output format that is a strict, safer subset of YAML designed to avoid common YAML pitfalls. KYAML is not whitespace-sensitive, making it easier to edit and patch reliably, especially in tools like Helm. The proposal also recommends making KYAML the standard format for Kubernetes documentation and examples. The motivation is to reduce errors caused by indentation, implicit type coercion, and other confusing YAML behaviors while still remaining compatible with existing YAML tooling.

This KEP graduated to beta in v1.35.

Other Merges

Fix log verbosity level in apiserver

client-go: fake client-go (i.e. anything using k8s.io/client-go/testing) now supports separate List+Watch calls

Drop TopologyAwareHints and ServiceTraficDistribution feature gates

kubeadm: waiting for etcd learner member to be started before promoting during ‘kubeadm join’

client-go: Informer resync processing improved handling of Resync handling

Fix scheduler_unschedulable_pods metric leak when pods fail PreEnqueue plugins

kubctl: Change the default debug profile from legacy to general

Add Declarative Validation to Workload API

kubectl: Fix deleting multiple StatefulSet pods to exit normally

Add the appProtocol field to the service describe output

kubelet: Fix data race in volume manager during concurrent pod unmount operations

client-go: Informers now update store state before calling handlers, ensuring handlers see consistent resource versions

Scheduler: PreBind plugins can now run in parallel to improve binding latency.

Promotions

watch_list_duration_seconds to beta

Version Updates

Go to 1.25.6

golang.org/x/crypto to v0.47.0

github.com/golang-jwt/jwt/v5 to v5.3.0

golang.org/x/net to v0.49.0

go.uber.org/zap to v1.27.1

github.com/godbus/dbus/v5 to v5.2.2

Subprojects and Dependency Updates

node-readiness-controller released v0.1.1 with initial implementation of the Node Readiness Controller

Controller-Runtime released v0.23.0. Highlights include subresource Apply support, conversion webhook implementation being possible outside of api packages, the PriorityQueue being enabled by default and enabling generic Validators and Defaulters in the webhook.

coreDNS v1.14.1 focuses on security fixes for vulnerabilities in older Go versions, improves proxy plugin performance with multiplexed connections, and includes documentation updates.

cluster-api v1.12.2 adds Kubernetes support up to v1.35.x, includes several ControlPlane, ClusterClass, and Runtime SDK fixes, and updates Go and core dependencies.

cluster-api v1.11.5 extends support to v1.34.x with targeted fixes in ControlPlane, ClusterClass, KCP permissions, and Runtime SDK cert rotation.

kompose v1.38.0 focuses on maintenance, with dependency updates, CI improvements, and bug fixes, including better macOS and Podman test compatibility.

openstack-cloud-controller-manager 2.34.2 and openstack-cinder-csi 2.34.2 update the Helm charts for the OpenStack Cloud Controller Manager and Cinder CSI driver, respectively.

Shoutouts

Josh Berkus: Kudos to @Swathi Rao for doing a great job organizing comms to publicize the NCO.

Swathi Rao: Shoutout to @Avni for reaching out to SIGs for good first issues and curating them. We got some great responses from 3 this month!

via Last Week in Kubernetes Development https://lwkd.info/

January 22, 2026 at 04:12AM

·lwkd.info·
Last Week in Kubernetes Development - Week Ending January 18 2026