👋 Welcome
This week in Cloud Native saw significant developments in AI integration, with new tools and projects focusing on AI agent management and infrastructure. The Kubernetes ecosystem received updates across various projects, enhancing security, networking, and application orchestration. Additionally, the CNCF reported on community growth and upcoming events.
🚀 Notable Releases
CI/CD
- Argo CD v3.4.6 - This patch release provides installation manifests.
- Argo CD v3.3.13 - This patch release provides installation manifests.
Security
- cert-manager v1.21.1 - Fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, resolves log spam and dropped Secret informer events, and addresses Issuers getting stuck atReady=Falsewhen an ACME DNS-01 solver Secret is created after the Issuer. - Open Policy Agent (OPA) v1.19.0 - Fixes a SQL injection vector in the Compile API, adds stricter safety checking for Rego assignments, replaces
wasmtime-gowithwazerofor a cgo-free WebAssembly runtime, and introduces a newstrings.split_nbuilt-in function. - Kubewarden Controller v1.37.0 - Adds support for context-aware policies when using the
kwctl benchcommand and fixes an issue where stale audit reports were deleted by label selector instead of write-set.
Networking
- Cilium v1.20.0 - This release includes over 2,660 new commits. Users of legacy Mutual Authentication, Envoy Go extensions, Kafka-aware policies, or the
cilium.io/v2alpha1 CiliumNodeConfigAPI may need to take action during upgrade. - Kube-OVN v1.15.20 - Fixes an issue in MetalLB where internal underlay VIP traffic was not preserved and adds functionality to infer pod subnet from named IPPool.
- Kube-VIP v1.2.2 - Updates
k8s.io/client-gofrom0.36.1to0.36.2and bumps other Go dependencies.
Registry
- Dragonfly v2.5.1 - Introduces scheduler features for handling local cache in peer registration and upgrading, and implements a sharded keymutex in the peer manager. It also adds capacity and rolling window fields to snapshot statistics for peer piece cost tracking.
Orchestration
- KEDA v2.20.2 - Introduces a dedicated
HPAActivecondition onScaledObjectthat mirrors the HPA’sScalingActivestatus, which prevents theReadycondition from flipping toFalsedue to transient HPA metric gaps. - Karmada v1.18.2 - This patch release includes bug fixes and improvements.
- Karmada v1.17.5 - This patch release includes bug fixes and improvements.
- Karmada v1.16.8 - This patch release includes bug fixes and improvements.
- Volcano v1.15.1 - Upgrades
golang.org/x/cryptofromv0.49.0tov0.53.0for SSH security fixes. Supports both the newvnpus.configswrapper and legacy array formats for HAMi Ascend vNPU configuration, and recovers from a PVC informer race inaddPod. - Volcano v1.14.4 - Registers PreFilter plugins to skip no-op predicate filters, treats Succeeded pods as ready for job dependencies, fixes potential scheduler panic caused by nil pointers, and honors
NeedContinueAllocatingafter PrePredicate failures. - Project Capsule v0.13.11 - Improves performance by removing duplicate client calls from all admission paths and corrects tenant ownership resolution with deduplication.
Observability
- Prometheus v3.13.2 - Bumps
golang.org/x/texttov0.39.0(addressing CVE-2026-56852) andgoogle.golang.org/grpctov1.82.1(addressing GHSA-hrxh-6v49-42gf). Fixes a PromQL bug by preallocating the active query tracker file to prevent SIGBUS crashes when the data disk is full. - Thanos v0.42.4 - This release contains no functional changes and addresses broken base image SHAs.
- Thanos v0.42.3 - Fixes a bug to ensure that Receive on shutdown creates a new block and uploads it, preserving previous upload behavior.
Storage
- Rook v1.20.3 - This patch release for the Ceph operator adds toolbox repository and tag settings to Helm, supports multisite CR in the
rook-ceph-clusterchart, and enables custom NFS server ports. It also deduplicates external MGR endpoints in EndpointSlice and pool growth prediction series. - Rook v1.19.8 - This patch release for the Ceph operator updates the Go text module, changes object bucket policy modification to clobber instead of merge, reveals swallowed errors on CephFS reconcile, and ensures volume attachment deletion during unmount.
Build & Container Tools
- Backstage v1.53.1 - Fixes issues where errors in TypeScript configuration schema definitions no longer prevent applications from building or starting, logging them as warnings instead.
- KubeVirt v1.9.0 - This is a promotion of release candidate
v1.9.0-rc.2, incorporating 1653 changes from 108 contributors. - Telepresence v2.31.2 - This release provides updated installation artifacts.
- Telepresence v2.31.1 - This release provides updated installation artifacts.
- Buildah v1.45.0 - Bumps Buildah to
v1.45.0-devandoc/selinuxtov1.15.0. Adds aFollowSymlinkoption toAddAndCopyOptionsto allow disabling the dereference of symlinks. - Skopeo v1.24.0 - Introduces new
skopeo copyoptions:--remove-list-signaturesand--strip-removed-platforms.
Messaging
- NATS Server v2.14.4 - Updates Go version to
1.26.5and various dependencies. The Raft transport layer has been decoupled for improved testing, and the JetStream disk concurrency semaphore has been increased to 4096 slots. - NATS Server v2.12.14 - Updates Go version to
1.25.12and various dependencies. The Raft transport layer has been decoupled for improved testing, and the JetStream disk concurrency semaphore has been increased to 4096 slots.
Service Mesh
- Kuma v2.14.2 - Bumps the
corednsdependency and includes security updates. Adds a pluggable per-route metadata provider to the API server. - Kuma v2.13.10 - Bumps
coredns,golang.org/x/net,golang.org/x/text, andgoogle.golang.org/grpcdependencies. - Kuma v2.12.14 - Bumps
coredns,golang.org/x/net,golang.org/x/text, andgoogle.golang.org/grpcdependencies. - Kuma v2.11.18 - Bumps
coredns,golang.org/x/text, andgoogle.golang.org/grpcdependencies, and includes security updates. - Kuma 2.9.19 - Bumps
coredns,golang.org/x/text, andgoogle.golang.org/grpcdependencies, and includes security updates. - Kuma v2.7.29 - Bumps
coredns,golang.org/x/net,golang.org/x/text, andgoogle.golang.org/grpcdependencies.
📰 This Week in Cloud Native
This week, the Cloud Native landscape saw a concentrated focus on Artificial Intelligence and its integration with existing infrastructure. The CNCF announced that Kubeflow is advancing its cloud native capabilities for AI workloads and highlighted Subaru’s adoption of cloud native infrastructure to accelerate AI development, which reduced AI container image pull times by 60x. The CoHDI project was accepted into the CNCF Sandbox, aiming to evolve Kubernetes into composable disaggregated infrastructures, a development relevant for AI deployments. News also covered Gartner’s projection that AI is the largest infrastructure project globally, alongside Meta and BlackRock’s plans for a 1-GW data center in Texas, and Nvidia’s negotiations for a substantial guarantee for OpenAI’s access to a 10-Gigawatt data center. OpenAI also reduced API costs, while Amazon reportedly scaled back several of its Nova AI models to focus on a few frontier models. Discussions emerged around designing APIs for AI agents, the security implications of AI-generated software, and approaches to building AI SRE teams.
In the Kubernetes ecosystem, new tools and operational insights were shared. The CNCF published guidance on scaling Kubernetes pods with KEDA based on Amazon SQS queue depth and introduced KubeElasti’s ProbeResponse to prevent health checks from unintentionally scaling services back up from a scale-to-zero state. A sneak peek into Kubernetes v1.37 outlined upcoming features, deprecations, and removals. Additionally, an article explained the internal workings of the controller-runtime cache, and Amazon EKS was noted for its efforts in simplifying and securing cluster lifecycle management during upgrades. A CNCF blog post also detailed runtime supply chain verification using the Node Resource Interface (NRI) for enhanced container security.
Security updates were prominent, with several projects addressing vulnerabilities and strengthening practices. OPA v1.19.0 fixed a SQL injection vulnerability, and Prometheus v3.13.2 included dependency bumps to address CVEs in golang.org/x/text and google.golang.org/grpc. Volcano v1.15.1 upgraded golang.org/x/crypto to incorporate SSH security fixes. Discussions also covered privilege escalation in AWS EKS and the application of Kyverno policies for Kubernetes cluster security. The importance of managing DNS as infrastructure was highlighted, and CISA released a guide to help federal agencies securely use open-source software.
Community and platform developments also occurred. The CNCF reported that Japan’s Cloud Native community has reached nearly 1 million developers, with a significant increase in AI developers leveraging cloud native technologies. The foundation also announced the schedule for the debut Observability Summit Europe. Lima v2.2 was released, adding support for Windows guests and TPM 2.0 emulation, expanding its capabilities for running virtual machines.
💬 Community Buzz
Hacker News discussions this week centered on the tooling and infrastructure for AI agents, including Kubernetes Custom Resource Definitions (CRDs) for agent runtimes, specialized control planes for AI workloads, and local sandbox environments. Other topics included Kubernetes clients focused on application views, methods for securing Kubernetes clusters with policy engines, and the operational aspects of distributed databases like CloudNativePG.
📊 Numbers of the Week
- Total stable releases: 35 across 22 projects
- Top 3 projects by commits this week:
- meshery/meshery — 152 commits
- telepresenceio/telepresence — 94 commits
- cilium/cilium — 90 commits
- Top 3 projects by merged pull requests this week:
- cilium/cilium — 100 merged PRs
- envoyproxy/envoy — 72 merged PRs
- kubescape/kubescape — 68 merged PRs