October 2025
 
            👋 Intro
Welcome to the October edition of CloudNative.Now - a monthly newsletter that covers all that has been happening in the cloud native world in the past month!
This month seems to have flow by! How is it Halloween already!? 👻
I managed to attend one of my favourite cloud native conferences this month - Kubernetes Community Days UK - this time hosted in wonderful Edinburgh for the first time. It was great to see so many lovely friends, both new and old. I also had the pleasure of not only seeing my teammates giving a talk to a full room but also watching so many of my dear friends giving amazing talks throughout the two days. 💙
As always, you’re invited to subscribe to the email newsletter or add the RSS feed to your favourite feed reader to make sure you don’t miss anything! And please help to spread the word and recommend this to your friends and network if you find the content useful! 💙
If you have any feedback or have any links you’d like to suggest please reach out on Bluesky or Mastodon! 💬
📰 News & Articles
- Follow Up - Preventing Upgrade Failures from etcd v3.5 to v3.6 -  Benjamin Wang & Josh Berkus
 Additional scenarios have been identified and fixed that may cause upgrade failures when moving from etcd v3.5 to v3.6. This post contains details, the fix, and additional workarounds.
- GitHub Will Prioritize Migrating to Azure Over Feature Development - Frederic Lardinois
 GitHub is working on migrating all of its infrastructure to Azure, even though this means it'll have to delay some feature development. Not super happy about this news.
- Migrating From Cluster Autoscaler to Karpenter v0.32 - Isaac Kiptanui
 A guide to switching Cluster Autoscaler for Karpenter's newer NodePool and EC2NodeClass setup and how to save money while you're at it.
- The State of CI/CD in 2025: Key Insights from the Latest JetBrains Survey - Olga Bedrina
 What's the most popular CI/CD tool in 2025? How many companies use AI in their workflows? Find answers to these and other questions in this blog post, based on the latest JetBrains survey.
- Fidelity Investments Shares Its Migration Story from Terraform to OpenTofu - James Humphries
 A G&A with Fidelity Investments about their migration from Terraform to OpenTofu
- Engineering Reality Report - Chainguard
 A software engineer’s reality moving into 2026: what engineers want to do, and what they have to do
- Ulysses’ Odyssey: Lessons for Platform Engineering - William Rizzo
 Is your platform engineering journey facing monsters like technical debt or integration complexity? Learn how to navigate these challenges.
- k8s-1m Overview - Ben Chess
 An effort to create a fully functional Kubernetes cluster with 1 million active nodes.
- Spotlight on Policy Working Group - Arujjwal Negi 
 In the complex world of Kubernetes, policies play a crucial role in managing and securing clusters. But have you ever wondered how these policies are developed, implemented, and standardized across the Kubernetes ecosystem? To answer that, let's take a look back at the work of the Policy Working Group.
- 📗 Container Security - Liz Rice
 Grab a free copy of Liz Rice's book "Container Security" thanks to Isovalent.
- The Challenges of Uniting VMs and Containers on a Single Platform - Dean Lewis
 The idea of running VMs and containers on one platform is appealing, but there are real-world obstacles to making it happen.
- Highlights from CNCF’s first Open Observability Summit - Dotan Horovits
 Dotan covers all the highlights from the first Open Observability Summit.
- 7 Common Kubernetes Pitfalls (and How I Learned to Avoid Them) - Abdelkoddous Lhajouji
 A practical guide to some of the most common pitfalls and mistakes that folks make when working with Kubernetes.
- Why Modern IPv6 Failed This Massive Kubernetes Networking Test - Steven J. Vaughan-Nichols
 Deutsche Telekom pushes the limits of Kubernetes, containers and networks in its satellite network simulation.
🔒 Security
- Beyond Namespaces: Why Kubernetes Needs Real Workload Isolation - Lewis Denham-Parry
 To build secure, resilient infrastructure, we need to reset the conversation. Namespaces are valuable, but they don’t isolate. This post from Lewis takes a look at how we can take things further.
- OWASP Kubernetes Top 10 2025 Survey
 Kubernetes SIG Security Docs subproject is starting an update of the OWASP Kubernetes Top 10 and as such want to canvas ideas on what should be included.
- Wiz Finds Critical Redis RCE Vulnerability: CVE‑2025‑49844 - Benny Isaacs & Nir Brakha
 A 13‑year Redis flaw (CVE‑2025‑49844) allows attackers to escape Lua sandbox and run code on hosts. See Wiz Research’s analysis and mitigations.
🧑🏫 Tutorials, Videos & Podcasts
- Build Java Containers with Jib - Chainguard
 In this tutorial, you'll learn how to build minimal Java containers using Jib and Chainguard base images
- A Practical Guide to Kubernetes Stateful Backup and Recovery - Adetokunbo Ige
 Explore methods, tools and best practices for protecting data in databases, memory caches, storage systems and other stateful applications.
- Kube Mysteries: The Invisible Pod | Challenge - Márk Sági-Kazár
 Did you know that pods can become invisible? Can you figure out how?
- 📺 Flagger on Kubernetes: Progressive Delivery and Canary Deployments - Whitney Lee
 Deploying fast is easy; deploying safely is hard. Instead of swapping Kubernetes resources by hand or hoping a rollout won’t break users, Flagger runs the release process itself.
- 📺 How to Run the Simplest Talos Linux Cluster on Oracle Cloud - Gerhard Lazu
 Join Gerhard as they explore the "why" behind Kubernetes and Talos, and then get hands-on with a step-by-step guide to getting your own single-node cluster up and running.
- 🎙️ The Making of Flux: The Rewrite - KubeFM
 The Making of Flux: The Rewrite
- 🎙️ How We Integrated Native macOS Workloads with Kubernetes - KubeFM
 How Testkube integrated native macOS workloads with Kubernetes.
- 📺 Platform Engineering: Asking "Why"? with Evelyn Osman - Rawkode Academy
 This episode had some long conversations about Arc Bash and the future of scripting as well as platforms and the rise and fall of Kubernetes.
- 🎙️ Cloud Native Compass | Flatcar Linux: A Modern OS for the Always-On Infrastructure - David Flanagan
 Flatcar Linux: A Modern OS for the Always-On Infrastructure. In this episode, they dive deep into Flatcar Linux, an immutable Linux distribution designed for always-on infrastructures.
- 📺 Kubernetes 1.34: Security, Performance, and DRA Go GA - The Landscape - Sylvain Kalache
 Vyom Yadav, Kubernetes Release Team Lead and Software Engineer at Canonical, joins Sylvain Kalache to discuss what’s new in Kubernetes 1.34. With over 58 enhancements, this release focuses on maturing Kubernetes.
- 📺 Pixie: Instant Kubernetes Visibility with eBPF - Whitney Lee
 Pixie lets you observe live traffic, system behavior, and app hotspots without touching the code, so teams can investigate issues the moment they appear.
🧰 Tools
- Announcing Flux 2.7 GA
 Flux v2.7.0 has been released! Here you will find highlights of new features and improvements in this release.
- CNCF Project Level Updates
 There's been several projects this month that have either being adopted by the CNCF or have been promoted to a new level:
- Introducing Headlamp Plugin for Karpenter - Scaling and Visibility - René Dudfield & Anirban Singha
 Headlamp is an open‑source, extensible Kubernetes SIG UI project designed to let you explore, manage, and debug cluster resources.
 Karpenter is a Kubernetes Autoscaling SIG node provisioning project that helps clusters scale quickly and efficiently. It launches new nodes in seconds, selects appropriate instance types for workloads, and manages the full node lifecycle, including scale-down.
 The new Headlamp Karpenter Plugin adds real-time visibility into Karpenter’s activity directly from the Headlamp UI.- Headlamp Plugins
 Following on from the above, Headlamp have a new, fancy plugins website.
 
- Headlamp Plugins
- Spotter - Madhu Akula
 Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations, and compliance violations across your Kubernetes clusters, manifests, and CI/CD pipelines.
- Secure and Free MinIO Chainguard Containers - Chainguard
 MinIO pulled its free images—but Chainguard has you covered. Get zero-CVE, continuously built MinIO and MinIO Client containers, free and secure from Chainguard.
🎤 Events and CFPs
Events
- 🇳🇱 KubeCon + CloudNativeCon Europe - 23rd – 26th March, 2026
 Tickets for KubeCon EU are on sale and the early bird pricing ends November 19th! If you're planning to attend and want to save some $$$ be sure to get your ticket soon.- KubeTrain: Travel to KubeCon by Train
 If you are planning to attend KubeCon be sure to check out KubeTrain. The coolest way to get to the conference with all your cloud native friends. They are also looking for sponsors.
 
- KubeTrain: Travel to KubeCon by Train
- 🇩🇪 CNS Munich - 29th – 30th June, 2026
 Cloud Native Summit Munich have a date locked in for next year and are now looking for sponsors.
- 🇺🇸 KubeCon + CloudNativeCon North America 2026 - 9th – 12th November, 2026
 The location for KubeCon NA 2026 has changed! Due to issues with the venue it will no longer be in LA but instead back in Salt Lake City.
CFPs
- 🇳🇱 Maintainer Summit: KubeCon + CloudNativeCon Europe 2026 - Deadline 14th December
💬 Social Post of the Month

🤷 Misc & Fun
- A Gift for the Open Source Community: Chainguard’s CVE-Free Raspberry Pi Images (Beta) - Dustin Kirkland
 Chainguard has created the first-ever CVE-free, vulnerability-free Raspberry Pi image.
- Cursed Knowledge - Immich
 Cursed knowledge Immich have learned as a result of building their product that they wish they never knew.
- Compute Cuter
 A cute computer environment can bring you joy! Here are some great resources to help make your computing cuter! ✿
- I am sorry, but everyone is getting syntax highlighting wrong - Nikita Prokopov
 A very interesting article about syntax highlighting but I did find that the suggested approach didn't work for me.
✨ Feedback Form ✨
That's all for this month! 
Thank you for reading! 💙
If you enjoyed this post, please spread the word and share with your friends.
~ Marcus 👋
 
                    
Comments ()