August 2026
👋 Intro
Welcome to the August edition of CloudNative.Now - a monthly newsletter that covers all that has been happening in the cloud native world in the past month!
As mentioned in last months issue I spent the start of this month celebrating my birthday in 🇯🇵 Tokyo! It was incredible! I had such a wonderful time - could have spent the whole month there easily. I managed to do a bunch of shopping (Donki was an experience), visit Disneyland, explore the Poképark, visit some temples and shrines, go hunting for Poké Lids and even managed to check out the unicorn Gundam (as seen above) before it was permanently removed. I already want to go back and explore more of Japan - such an amazing country.
Tomorrow I'm heading out to 🇩🇪 Hamburg for ContainerDays where I'll be giving a talk with Márk first thing Wednesday morning. If you're going to be there please do come say hi if you see me. 👋
And if that wasn't enough - on 29th September I'll be at 🇧🇬 KCD Sofia where not only will I be giving a talk (with Márk again) but I'll be hosting the event! I'm so excited! This will be my first time hosting a conference and I cannot wait! Tickets are still available and I highly recommend you grab one if you're able to make it. I'm positive it's going to be an amazing event! 💙
As always, you’re invited to subscribe to the email newsletter or add the RSS feed to your favourite feed reader to make sure you don’t miss anything! And please help to spread the word and recommend this to your friends and network if you find the content useful! 💙
If you have any feedback or have any links you’d like to suggest please reach out on Bluesky or Mastodon! 💬
📰 News & Articles
- Kubernetes v1.37: Garhwal - Kubernetes
Similar to previous releases, the release of Kubernetes v1.37 introduces new Stable, Beta, and Alpha features. The consistent delivery of high-quality releases underscores the strength of the development cycle and the vibrant support from our community. This release consists of 67 enhancements. - How Kubernetes probes work - Sam Rose
Learn how probes work interactively on simulated Kubernetes clusters running in your browser. This is a truly incredible blog post with fantastic interactive demos. Well worth a read through! - Selective drift correction with ignore rules - Dipti Pai
Let external controllers like HPA and cert-manager manage specific fields without fighting Flux drift correction. - On building scalable control planes - Dr Werner Vogels
Zak van der Merwe has spent his entire career at AWS building control planes. First for EC2 and now for DSQL. On the surface, the control plane looks quite boring: it records what should exist and reconciles that with what actually does. Nobody leaves school dreaming of building one, but Zak will be the first to tell you that if you like solving hard problems in distributed systems, there are few better places to be. It’s where many of those hard problems converge, and where the decisions you make determine whether a service survives its own growth. - Kubernetes upgrades don’t have to break things: How EKS is making cluster lifecycle management simpler and safer - Spyros Angelopoulos & Vikram Venkataraman
Discover how AWS EKS simplifies Kubernetes upgrades with automated Upgrade Insights, 7-day Version Rollback, and AI-driven operations. - Pushing container images to China: what we learned the hard way - Giant Swarm
Why container pushes to China take 30 minutes, and how Giant Swarm cut it to under 2 with a split push through Singapore. - Pulling multi-gigabyte container images in seconds on Amazon EKS - Sri Saran Balaji Vellore Rajakumar & Neelendra Bhandari
Speed up large ML container image pulls on Amazon EKS from minutes to seconds using parallel download and unpack in containerd. - CNCF Announces Graduation of Cloud Native Buildpacks, Advancing the Standard for Container Builds - CNCF
The Cloud Native Computing Foundation (CNCF) has announced the graduation of Cloud Native Buildpacks, an open-source toolkit that automates the creation of OCI-compliant container images directly from application source code. - How to Pretty-Print Your Kubernetes YAML as KYAML and Why You'd Want To - Kashish Verma
YAML has been the standard way to write Kubernetes manifests for years. Every example, tutorial, and configuration file you come across is written in it. The problem isn't that YAML is a bad format. It's that YAML gives you a lot of choices, and not all of them are equally good for writing Kubernetes manifests. Some features make files harder to read, some are easy to misuse and others can lead to surprising behavior. - The Kubernetes Noisy Neighbour Problem Is Actually a Permissions Problem - Abby Bangser
Giving every team direct Kubernetes API access to build custom controllers creates a noisy neighbour problem. Here's the abstraction that avoids it. - We turned off Pub/Sub and nobody noticed - Patrick Hamann & Mike Fisher
Incident.io's entire event-driven platform ran through a single message broker, which made it a single point of failure. So they added a second one. This is the story of building an event load balancer, the queueing theory behind it, and the chaos test where they turned off Pub/Sub in production and nobody noticed. - Lightweight Dragonfly Deployment: P2P Distribution Without the Database Stack - Wenbo Qi
Dragonfly speeds up file and container image distribution using peer-to-peer (P2P) technology, but a standard installation deploys several components and dependencies.
Dragonfly supports a lightweight deployment model that removes the Manager, MySQL, and Redis. The Scheduler serves as the sole coordination component, allowing you to install the entire setup with a single Helm command. This post explains how the lightweight architecture operates and demonstrates how to run it in a localkindcluster. - Kyverno is a platform primitive, not a security tool - Koray Oksay
Where does Kyverno live in your organization? I don’t mean which cluster! On which team’s slide deck does it show up? Whose budget line? For most companies Koray's talked to, the answer is security. But is that the right fit? - Talos Linux CAPI Providers Move to Community - Sterling Koch
Sidero Labs is moving the Talos Linux Cluster API providers to community maintenance. The code stays open source and nothing breaks. - AWS deprecated this EKS auth method. 81% of clusters still run it. - Yannick Struyf & Aarthi Mahesh
Kubernetes security requires fleet-wide policies, hardened clusters, and continuous compliance as legacy controls and AI workloads expand enterprise risks. - The post-VMware playbook: what to move first, what to leave for last - Manuel Gawert
The post-VMware playbook: what to move first, what to leave for last, and what each option costs in risk, time, and money. - The August 17 outage, and the work ahead - Vlad Fedorov
GitHub posts an update on the August 17 outage and the steps they're taking to improve reliability.
🔒 Security
- Tailscale in the Hugging Face intrusion: The good news and the bad news - Avery Pennarun
An AI agent used a stolen Tailscale auth key at Hugging Face. Workload identity federation, flow logs, and safer defaults could have reduced the risk. - My Homelab Got Hacked - A Postmortem - Phillip
A postmortem on the hack of Phillip's self-hosted Forgejo instance and a reminder to patch your software.
I love this kind of thing - more of this please! - Using the API server proxy to bypass network policies - Rory McCune
Rory explores how Kubernetes attackers can bypass network policies in multi-tenant clusters by leveraging the API server proxy.
🧑🏫 Tutorials, Videos & Podcasts
- Let's Learn About the OpenTelemetry GenAI Normalizer - Adriana Villela
Adriana talks about LLM observability with standardized OTel AI semantic conventions - 📺 What Is Keycloak? Open Source Identity and Access Management - Whitney Lee
Remember when every website had its own username and password? Different rules, different logins, no way to share identity between applications. That pain drove the creation of standards like OpenID Connect (OIDC), as well as tools like Keycloak that let you run your own identity and access management system. - 🎙️ Progressive Delivery, with Heidi Waterhouse - Software Defined Talk
Whitney and Coté talk with Heidi Waterhouse, co-author of the book Progressive Delivery. - Optimizing Kubernetes pods for reliability with topology spread constraints - Andre Newman
Topology spread constraints let you determine how Kubernetes spreads pod replicas across failure domains, such as availability zones and regions. This blog explains how they work, how to configure them, and how to scan for missing constraints.
🧰 Tools
- Introducing Flux Mirror - Leigh Capili
Declarative mirroring for container images, Helm charts, and OCI artifacts, with signature verification, provenance policies, and minimum artifact age. - Gateway API v1.6: TCPRoute and UDPRoute Graduate to Standard - Beka Modebadze & Ricardo Katz
Gateway API has become the standard for modern, role-oriented, and expressive service networking in Kubernetes. In previous releases, Gateway API established a production-grade foundation for HTTP and TLS layer 7 traffic. With version 1.6.0, Gateway API takes a major step forward by expanding standard layer 4 protocol routing and introducing cleaner API boundaries for experimental innovation. - kiac: Local Kubernetes on Apple's container framework - Saiyam Pathak
Local Kubernetes on Apple's container framework - every node is its own lightweight VM. Metrics, storage, and LoadBalancer included. - prow-github-actions: Slash commands, jobs, and chat-ops for Github actions inspired by Kubernetes Prow ⚓️ - CNCF
Slash commands, jobs, and chat-ops for Github actions inspired by Kubernetes Prow. - KubeElasti: Kubernetes-native scale-to-zero with zero traffic loss, no code changes, and direct integration with kubernetes resources - KubeElasti
Kubernetes-native scale-to-zero with zero traffic loss, no code changes, and direct integration with kubernetes resources
🎤 Events and CFPs
Events
- 🇩🇪 ContainerDays Hamburg - September 2 → 4
I'm going to be speaking here on the 2nd. If you're about please do come say hi to me! 👋 - 🇧🇬 KCD Sofia - September 29
I'm going to be speaking at and hosting this one! 😮 I'm so excited! Really hope I can see some of y'all there! - 🇺🇸 KubeCon NA Schedule - November 9 → 12
The schedule for KubeCon + CloudNativeCon North America is now live. - 🌐 Announcing H1 2027 KCDs
The KCD's for the first half of 2027 have been announced.
CFPs
- 🇪🇸 KubeCon + CloudNativeCon Europe 2027 - Deadline 11th October
💬 Social Post of the Month

🤷 Misc & Fun
- PGSimCity · How PostgreSQL Works, in 3D - Nik Samokhvalov
An independent, non-commercial educational visualization of PostgreSQL internals. Not affiliated with Electronic Arts. - Three Weeks at the Company - Artem Hrechanychenko
Three Weeks at the Company is a DevOps career simulator that tasks players with interviewing for a role and attempting to survive their first three weeks on the job. Can you last 3 weeks? - Crafting QR Codes: A deep dive into QR code art - Kyle Zheng
Truly beautiful deep dive into creating beautiful QR codes.
✨ Feedback Form ✨
That's all for this month!
Thank you for reading! 💙
If you enjoyed this post, please spread the word and share with your friends.
~ Marcus 👋
Comments ()