👋 Welcome
This week saw significant activity in the Cloud Native landscape, with numerous project releases focusing on security, performance, and AI integration. Key updates include Kubernetes Gateway API advancements, new tools for AI agent deployment and observability, and several security vulnerability fixes across various projects.
🚀 Notable Releases
- Argo CD v3.5.0 - Introduces version 3.5.0 of Argo CD, with install manifests available for non-HA and HA deployments.
- CRI-O v1.36.3 - A patch release containing bug fixes and uncategorized changes since v1.36.2.
- CRI-O v1.35.6 - A patch release containing bug fixes and uncategorized changes since v1.35.5.
- CRI-O v1.34.11 - A patch release containing uncategorized changes since v1.34.10.
- Dapr Runtime v1.17.12 - Updates Go to version 1.26.5 to address known vulnerabilities and fixes an issue where input bindings were not activated when the application was slow to respond to the subscription discovery probe.
- Dapr Runtime v1.16.18 - Fixes an issue where input bindings were not activated when the application was slow to respond to the subscription discovery probe.
- Flux v2.9.4 - A patch release providing fixes for Flux controllers, including source-watcher tarball extraction, glob expansion limits,
ImageUpdateAutomationrefspecs, notification-controller HTTP request limits, and Helm repository index loading. - OpenTelemetry Collector v0.158.0 - Introduces a new
queuebatchprocessor to replace the legacybatchprocessorand adds first-class extended type aliases tocmd/mdatagen. - Keycloak 26.7.1 - Includes security fixes, specifically addressing CVE-2026-9793, which concerns a JWE request object bypass of
requestObjectSignatureAlgenforcement in OIDC. - KServe v0.20.0 - Adds model-based routing gates and model status reporting for LLMInferenceService, alongside documentation updates for LLMInferenceService conditions.
- OpenCost v1.121.1 - Adds Athena query result reuse configuration for AWS and includes NAT gateway cost metrics in scrapes.
- OpenFGA v1.18.3 - Fixes an issue in the experimental
weighted_graph_checkwhere it intermittently returnedfalsefor specific recursive TTU relations. - OpenFGA v1.18.2 - Extends experimental
weighted_graph_checkdiagnostic logging to coverwildcard_with_exclusionanduserset_with_exclusionshapes. - External Secrets Helm Chart v2.9.0 - Provides updates for external secrets management for Kubernetes.
- External Secrets v2.9.0 - Provides general updates and bug fixes, including a fix for Conjur installation timeouts in the Helm chart.
- Inspektor Gadget v0.55.0 - Adds initial GPU telemetry support via a userspace daemon and expands eBPF operator support for map pinning, non-destructive map iteration, and
ebpf.SockOps/ebpf.SkSKB. - Kube-OVN v1.15.22 - Updates Helm charts to use
kubeovn/kube-ovn:v1.15.22-dpdkfor hybrid DPDK deployments and fixes IPv6 neighbor cache refreshing. - Kube-OVN v1.15.21 - Adds support for bandwidth quantities in
vpc-egress-gatewayand includes a fix for recovering from invalid raft headers inovn-central. - Kubewarden Controller v1.37.1 - Includes updates to Rust and Go dependencies, and adds a CI check for
questions.yamlsynchronization withvalues.yaml. - Meshery v1.0.65 - Contains general updates including documentation improvements and fixes for CLI golden test failures.
- Meshery v1.0.64 - Includes updates to
iterate-prmode, dependency bumps, and fixes for response body leaks in remote authentication. - Fermyon Spin Canary - A canary release containing recent commits from the main branch, intended for developers to test the latest features.
- Sigstore Cosign v3.1.3 - Resolves GHSA-fx35-mq7g-6g98, a verification bypass vulnerability, and adds auto-detection of default digest algorithm for public keys.
- Sigstore Cosign v2.6.5 - Backports the GHSA-fx35-mq7g-6g98 verification bypass fix to the v2.6.x branch.
- CrateDB 6.4.2 - A maintenance release providing bug fixes and improvements.
- CrateDB 6.3.7 - A maintenance release providing bug fixes and improvements.
- K3s v1.36.3+k3s1 - Updates Kubernetes to v1.36.3 and includes a breaking change for Traefik chart v40.x, which alters the
kubernetesIngressNginxprovider name tokubernetesIngressNGINX. - K3s v1.35.7+k3s1 - Updates Kubernetes to v1.35.7 and includes a breaking change for Traefik chart v40.x, which alters the
kubernetesIngressNginxprovider name tokubernetesIngressNGINX. - K3s v1.34.10+k3s1 - Updates Kubernetes to v1.34.10 and includes a breaking change for Traefik chart v40.x, which alters the
kubernetesIngressNginxprovider name tokubernetesIngressNGINX. - K3s v1.33.13+k3s2 - Updates Kubernetes to v1.33.13 and includes a breaking change for Traefik chart v40.x, which alters the
kubernetesIngressNginxprovider name tokubernetesIngressNGINX. - Trivy v0.73.0 - A new stable release with various updates and improvements.
📰 This Week in Cloud Native
The Cloud Native community saw significant developments this week, particularly around the integration of AI agents and enhanced Kubernetes capabilities. The Kubernetes Global Balancer (K8gb) has advanced to a CNCF incubating project, signaling its growing role in cloud-native global server load balancing. Kubernetes Gateway API reached v1.6, with TCPRoute and UDPRoute graduating to Standard, expanding its capabilities for managing network traffic. Discussions also highlighted Kubernetes Dynamic Resource Allocation (DRA) as a method for improving GPU scheduling and resource sharing, addressing previous limitations with device plugin interfaces. Observability for AI agents and the tracking of Kubernetes inference costs were also noted, with OpenCost 1.121.0 introducing inference cost tracking.
Security remains a prominent theme, with new analyses of “Shadow AI” in CI/CD pipelines, outlining potential threats from AI tools integrated into development workflows without corresponding security architecture. The Cortex project completed a security audit by OSTIF, focusing on its long-term, multi-tenant storage for Prometheus. Several reports detailed cloud security incidents, including a Metabase 0-day vulnerability leading to a data breach for a laptop manufacturer, and an npm supply chain attack that exploited provenance attestations. Concerns were also raised regarding the potential for US government-mandated “kill switches” for critical IT services provided by US companies.
In broader cloud and platform engineering news, the general availability of Azure DevOps Remote MCP Server was announced, enabling AI assistants to securely access Azure DevOps projects. AWS introduced Dogwood for runtime verification of AI agents and announced support for Agent Plugins, an open standard for portable agent extensions. AWS also detailed how Amazon EKS Auto Mode detects and repairs node failures and provided guidance on extending Amazon ECS Express Mode. The financial implications of building internal platforms and the adoption of AI tools within engineering teams were also subjects of discussion, including metrics on AI productivity and the challenges of measuring its impact.
💬 Community Buzz
Discussions on Hacker News this week centered on tools for deploying and managing AI agents in Kubernetes environments, such as Curie and Hoplite, and local-first coding agent workbenches like Isolade. Other topics included Kubernetes debugging tools like Deployah and OpsCart, Docker Sandboxes for isolated AI agent execution, and methods for running GitHub Actions locally in microVMs. There was also interest in a pure-Go PII detection tool and an open-weight background removal model.
📊 Numbers of the Week
- Total stable releases: 31 across 19 projects
- Top 3 projects by commits this week:
- meshery/meshery — 239 commits
- backstage/backstage — 192 commits
- kubescape/kubescape — 124 commits
- Top 3 projects by merged pull requests this week:
- kubescape/kubescape — 124 merged PRs
- cilium/cilium — 99 merged PRs
- kumahq/kuma — 97 merged PRs