November 2025
👋 Intro
Welcome to the November edition of CloudNative.Now - a monthly newsletter that covers all that has been happening in the cloud native world in the past month!
Lots has been going on this month! KubeCon brought a lot of activity and some great talks and announcements but we've also seen the (upcoming) retirement of ingress-nginx, some major releases of Helm and external-secrets and a Cloudflare outage that effected lots of the internet.
This months issue also includes all the recordings from not one, not two, not three but FOUR different conferences! 😮 That should keep y'all busy in the fast approaching winter nights.
As always, you’re invited to subscribe to the email newsletter or add the RSS feed to your favourite feed reader to make sure you don’t miss anything! And please help to spread the word and recommend this to your friends and network if you find the content useful! 💙
If you have any feedback or have any links you’d like to suggest please reach out on Bluesky or Mastodon! 💬
📰 News & Articles
- Kustomize logo design proposals - Kustomize
The Kustomize project is looking for a new logo. If you're feeling creative why not add your submission? - Tailscale Welcomes Kubernetes Co-Founder Joe Beda as Advisor - Joab Jackson
The Kubernetes co-founder will help bring Wireguard VPN's ease of use to solving complicated K8s networking patterns. - Announcing the 2025 Steering Committee Election Results - Arujjwal Negi
The 2025 Steering Committee Election is now complete. The Kubernetes Steering Committee consists of 7 seats, 4 of which were up for election in 2025. Incoming committee members serve a term of 2 years, and all members are elected by the Kubernetes Community. - Ingress NGINX Retirement: What You Need to Know - Tabitha Sable
If you haven't heard already - ingress-nginx is being retired due to lack of time and support for the maintainers of the project. This post outlines the current plan for maintenance and retirement. - Navigating the Ingress-nginx Archival: Why Now Is the Time to Move to Cilium - Isovalent
Following on from the above post, this post explains what the retirement means, compares your options, and shows how to migrate quickly to Cilium Ingress or adopt the Cilium Gateway API for advanced traffic management. - External Secrets Inc is winding down - External Secrets Inc
External Secrets Inc., the company set up to build out External Secrets, is winding down operations but its not just bad news. All of the (formerly) proprietary code is now open source (under the MIT License) so that all may benefit from what they've created. - Kubernetes v1.35 Sneak Peek - Aakanksha Bhende, Arujjwal Negi, Chad M. Crowell, Graziano Casto & Swathi Rao
A look at what we can expect from the upcoming Kubernetes v1.35 release expected to be released December 17th. - Gateway API 1.4: New Features - Beka Modebadze
The Kubernetes SIG Network community presented the General Availability release of Gateway API (v1.4.0)! Released on October 6, 2025, version 1.4.0 reinforces the path for modern, expressive, and extensible service networking in Kubernetes. - SRE math every engineer should know: a practical guide - Srivatsa RV
Curious how top engineers keep systems reliable? This guide breaks down the maths behind Site Reliability Engineering into simple, real-life examples whether it’s understanding error budgets, decoding percentiles, or making sense of dashboards. Perfect if you want to stop firefighting and start making data-driven, confident decisions on call. - A 2025 look at real-world Kubernetes version adoption - Rory McCune
Rory took a fresh look at the state of Kubernetes version adoption and things are looking generally pretty good. - Cloudflare outage on November 18, 2025 - Matthew Prince
Cloudflare suffered a service outage on November 18, 2025. The outage was triggered by a bug in generation logic for a Bot Management feature file causing many Cloudflare services to be affected. This post breaks down the cause and the steps taken to identify and fix the problem. - How Amazon Prepares for Black Friday: Predictive Modeling - Joab Jackson
As Black Friday approaches, two Amazon engineers shared secrets of how they ensure the shopping service stays up even under heavy duress.
🔒 Security
- ⚠️ Three runc CVE published
There's been 3 CVEs published against runc, all rated as "High". Please make sure you're updated!
- CVE-2025-31133 - container escape via "masked path" abuse due to mount race conditions
- CVE-2025-52881 - container escape and denial of service due to arbitrary write gadgets and procfs write redirects
- CVE-2025-52565 - container escape with malicious config due to /dev/console mount and related races - OpenSourceMalware.com - Community Threat Intelligence
A community database, API and collaboration platform to help identify and protect against open-source malware. - Fun-reliable side-channels for cross-container communication -
h4x0r
Some Linux Kernel exploits to allow for cross-container communication.
🧑🏫 Tutorials, Videos & Podcasts
- Preventing Kubernetes from Pulling the Pause Image from the Internet - Kyle Cascade
A look at how to block pulling the pause image from the internet - useful when deploying into airgapped or highly restricted environments. - Wrangling Kubernetes contexts - Natalie Klestrup Röijezon
If you use Kubernetes on a regular basis, you've probably came across the dreaded context. This post walks through how to manage your context. - 📺 Pixie: Instant Kubernetes Visibility with eBPF - Whitney Lee
Pixie lets you observe live traffic, system behavior, and app hotspots without touching the code, so teams can investigate issues the moment they appear. - 🎙️ Cows, Tech Careers, Working at Microsoft, and Even More About Cows, with Saad Ansari - Software Defined Talk
In this episode, Whitney and Coté speak with Saad Ansari, a product manager at Databricks, about his journey from working at Microsoft to co-founding a startup focused on creating sensors for monitoring cow behavior. - 📺 Kubernetes Community Days UK - Edinburgh, 2025
All the recordings from KCD UK last month are now available to watch on YoutTube. - 📺 Cloud Native Rejekts Atlanta 2025 - Tack 1 & Track 2
The livestream recordings from Cloud Native Rejekts in Atlanta are available to watch back on YouTube. - 📺 KubeCon+CloudNativeCon NA 2025
All recordings from KubeCon NA are now available to watch on YouTube. - 📺 Netflix’s Engineering Culture - The Pragmatic Engineer
What’s it like to work as a software engineer inside one of the world’s biggest streaming companies. - 📺 TalosCon 2025
Recordings from TalosCon are available to watch on YouTube. - 🎙️ Whitney goes to KubeCon - Software Defined Talk
This week, Whitney Lee joins Software Defined Talk to discuss KubeCon news, Coding Assistants, and conference tips. Plus, vegan food and note-taking recommendations.
🧰 Tools
- External-Secrets v1.0.0 (and v1.1.0) - external-secrets
External-secrets has made the jump to a v1.0.0 release! - Grafana Mimir 3.0 release: performance improvements, a new query engine, and more - Dimitar Dimitrov, Nick Pillitteri & Vladimir Varankin
Grafana Mimir 3.0 marks a new era for the open source time series database, delivering dramatic improvements in both reliability and performance. - Helm v4.0.0 - helm
This has been coming for a long time now and finally Helm v4 has been released for all to use! Lots of new features and fixes in this release.
🎤 Events and CFPs
Events
- 🇬🇧 ContainerDays London 2026 - 11th - 12th February, 2026
ContainerDays is coming to the UK for the first time next year and tickets are now available. I'll also be speaking so come say hi if you are there! 👋 - 🇨🇭 Cloud Native Zürich 2026 -11th June, 2026
Tickets are now available for Cloud Native Zürich
CFPs
- 🇮🇹 Cloud Native Days Italy 2026 - Deadline 6th March
💬 Social Post of the Month

🤷 Misc & Fun
- Linux Kernel Ported To WebAssembly - Demo Lets You Run It In Your Web Browser - Michael Larabel
Linux in your web browser!? 🤯 - stickertop.art
Discover a unique collection of laptops adorned with creative stickers from around the world. - Kubernetes Cluster Goes Mobile In Pet Carrier - Bryan Cockfield
If you were at KubeCon earlier this month you might have seen Justin walking around with a cluster running from a backpack!
✨ Feedback Form ✨
That's all for this month!
Thank you for reading! 💙
If you enjoyed this post, please spread the word and share with your friends.
~ Marcus 👋
Comments ()