Week 30, Jul 20-26, 2026

This week: 45 releases, 176 news items.

👋 Welcome

This week in Cloud Native saw several project updates across networking, observability, and security. Noteworthy developments included HAMi becoming a CNCF incubating project, focusing on GPU resource scheduling for AI, and discussions around operating AI/ML workloads on Kubernetes. The community also addressed various bug fixes and stability improvements in core projects.

🚀 Notable Releases

Networking

  • Cilium v1.19.6 - Adds support for configuring Gateway access logs via spec.telemetry.accessLogs in CiliumGatewayClassConfig. Uses L3 sockets for solicited node multicast signaling in the L2 responder.
  • Cilium v1.18.12 - Introduces support for configuring Gateway access logs through spec.telemetry.accessLogs in CiliumGatewayClassConfig. Addresses incorrect policy denials for traffic to L7 load balanced services.
  • Cilium v1.17.18 - Fixes incorrect policy denials for traffic to L7 load balanced services. Resolves an issue where multi-pool IPAM did not wait for zero prealloc requests.
  • Envoyproxy v1.39.0 - Requires Bazel 8 for builds, which necessitates --enable_workspace and --noenable_bzlmod flags. Disables the Intel DLB connection balancer for all builds due to a broken source archive. Deprecates enforce_rsa_key_usage in TLS.
  • Kubernetes Gateway API v1.6.1 - Adjusts the port used in the TCPRouteMultipleRoutesAttachment conformance test. Ensures CleanupTestResources is respected for BackendTLSPolicy, TCPRouteMultipleRoutesAttachment, and UDPRouteMultipleRoutesAttachment.

Service Mesh

  • Istio 1.30.3 - A patch release providing stability updates.
  • Istio 1.29.6 - A patch release providing stability updates.
  • Kuma v2.14.1 - Updates the Go version to 1.26.4. Includes updates to kumahq/kuma-gui.

Observability

  • Jaeger v2.20.0 - Removes support for Elasticsearch v6. Promotes Elasticsearch rotation and index-cleaner feature gates to beta. Merges the jaegermcp extension into the jaegerquery extension.
  • Thanos v0.42.2 - Released due to broken base image SHAs, contains no functional changes.
  • Thanos v0.42.1 - Increases timeout values in the Shipper component of the Receiver to address an issue with previously set small timeouts.
  • Inspektor Gadget v0.54.1 - Fixes an issue in the OCI module to ensure the oci-store directory exists before locking.

Security

  • External-Secrets v2.8.0 - Corrects Barbican find semantics and adds documentation for property/extract.
  • External-Secrets helm-chart-2.8.0 - Provides the Helm chart for external secrets management.
  • Cosign v3.1.2 - The maintainers state this may be the final v3.1 release, with deprecated functionality slated for removal in v4. Migration to the bundle format is encouraged.
  • Cosign v2.6.4 - Backports OCI manifest fixes and enhances support for cosign attestation download when using a mix of older signatures and the bundle format.

CI/CD & Build

  • FluxCD v2.9.2 - Addresses a regression from v2.9.1 where Kustomizations with openapi.path referencing a URL failed reconciliation. Corrects several CRD field descriptions.
  • Dapr v1.17.11 - Fixes an issue preventing actor reminders and jobs from registering when their names or actor IDs contained characters such as | or @.
  • Backstage v1.53.0 - Removes the deprecated Server-Sent Events (SSE) MCP transport from @backstage/plugin-mcp-actions-backend, requiring MCP clients to use Streaming RPC.
  • Telepresence v2.30.1 - Includes installers with an option to run the root daemon as a system service, which removes the requirement for elevated privileges during use.
  • Telepresence v2.30.0 - Introduces installers that allow the root daemon to run as a system service, eliminating the need for elevated privileges when using Telepresence.

Cluster Management

  • KubeEdge v1.23.1 - A patch release. Refer to the CHANGELOG-1.23.md for specific details.
  • KubeEdge v1.22.2 - A patch release. Refer to the CHANGELOG-1.22.md for specific details.
  • KubeEdge v1.21.2 - A patch release. Refer to the CHANGELOG-1.21.md for specific details.
  • Kubernetes SIGs Cluster API v1.13.4 - Increases management cluster client QPS and Burst. Addresses a bug in the clusterctl v1.10 upgrade test related to the Kind image. Supports Kubernetes management clusters from v1.32.x to v1.36.x and workload clusters from v1.30.x to v1.36.x.
  • Kubernetes SIGs Cluster API v1.12.10 - Fixes a Kind image issue in the clusterctl v1.10 upgrade test. Corrects PrettyPrint behavior in WaitForCondition. Supports Kubernetes management clusters from v1.31.x to v1.35.x and workload clusters from v1.29.x to v1.35.x.

Configuration & Tooling

  • Meshery v1.0.59 - Logs human-readable summaries in SaveConnection debug lines. Improves environment assignment discoverability in the UI.
  • Meshery v1.0.58 - Updates meshery/schemas to v1.3.34 and v1.3.33. Records failed Kubernetes connections as error notifications. Renames Meshmodel API routes to /api/registry.
  • Meshery v1.0.57 - Updates websocket-driver. Adds parent capability to VPC and corrects relationship between EKS addon and cluster. Adopts meshery/schemas v1.3.32.
  • Meshery v1.0.56 - Adds the F5 BIG-IP Controller for Kubernetes model. Migrates Kubernetes connection and controller subscriptions from GraphQL to SSE/REST in both the CLI and UI.
  • LitmusChaos v3.31.0 - Fixes probe comparator type initialization from loaded probe data. Updates dependencies in graphql/server to address vulnerabilities.

Application Frameworks

  • KServe v0.18.1 - A patch release, includes a fix for Helm charts.
  • Fermyon Spin canary - This is a canary release of recent commits on the main branch and is not stable. It is intended for developers evaluating the latest features, some of which may not be fully implemented.

Database

  • CrateDB 6.4.1 - A patch release, refer to release notes for details.
  • CrateDB 6.3.6 - A patch release, refer to release notes for details.

📰 This Week in Cloud Native

This week, the Cloud Native landscape saw significant activity related to Artificial Intelligence (AI) and its integration with Kubernetes. HAMi, a project focused on efficient GPU sharing and resource scheduling for AI workloads, was accepted as a CNCF incubating project. Concurrently, discussions emerged around the optimal deployment unit for AI agents within Kubernetes, with considerations for running self-hosted Large Language Models (LLMs) using tools like vLLM. Kubernetes also saw the introduction of a Headlamp plugin for Kubeflow, aiming to streamline the operation of AI/ML workloads. Furthermore, the concept of “Agent Substrate” from Google was highlighted as a potential direction for future AI agent runtimes, alongside efforts to standardize AI agent infrastructure through initiatives like the x402 Foundation.

In infrastructure and platform engineering, there were updates from major cloud providers. AWS introduced self-managed Amazon S3 buckets for Lambda function code, which addresses storage limits and provides customers with more control over deployment artifacts. New enhanced AssetState dimensions for AWS Outposts capacity metrics were also released. Additionally, AWS announced the cessation of sales for its original 1U and 2U Outposts servers, directing customers towards Outposts Racks. A significant billing error was reported by Amazon Web Services, where some customers were shown astronomically high estimated costs due to a technical fault. The concept of cloud sovereignty and how architectural decisions influence cloud costs were also subjects of discussion.

Security and observability components also received attention. The CNCF blog highlighted OpAMP as a tool for operating OpenTelemetry at scale, facilitating remote management and configuration of collectors across diverse environments. Kubernetes provided guidance on building custom metrics exporters to expand beyond built-in CPU and memory metrics for scaling decisions. A security bulletin from Tailscale disclosed a vulnerability (TS-2026-009) where insecure argument handling in Tailscale SSH could permit root access. Microsoft open-sourced its legacy Comic Chat application, making its codebase publicly available.

💬 Community Buzz

Discussions on Hacker News this week included technical topics such as implementing Kubernetes within a MicroVM, benchmarking gRPC load balancing solutions on Kubernetes (Linkerd, Istio, Cilium), and recommendations for containerization and security of AI agents. Other technical subjects discussed involved building self-hosted personal finance applications, creating a local image compressor, and developing a pure Go immediate-mode GUI library without CGO.

📊 Numbers of the Week

  • Total stable releases: 35 across 21 projects
  • Top 3 projects by commits this week:
    1. meshery/meshery — 247 commits
    2. kubernetes/kubernetes — 244 commits
    3. cilium/cilium — 148 commits
  • Top 3 projects by merged pull requests this week:
    1. cilium/cilium — 131 merged PRs
    2. kubernetes/kubernetes — 129 merged PRs
    3. kumahq/kuma — 126 merged PRs

📚 View all articles from this week →