Week 35, Aug 24-30, 2026

This week: 46 releases, 161 news items.

👋 Welcome

This week in Cloud Native saw significant updates across core projects, including multiple patch releases for networking and orchestration tools, and a focus on security enhancements. The Cloud Native Computing Foundation announced Kubeflow’s graduation, highlighting advancements in cloud native AI operations. Discussions also centered on the evolving landscape of AI agents and their security implications.

🚀 Notable Releases

Application Frameworks

  • Backstage v1.54.3 - Fixes the unintended removal of support for intrinsic string, number, array, Map, and Set methods in software templates.
  • Backstage v1.54.0 - Introduces stricter OAuth redirect URI allowlist matching in @backstage/plugin-auth-backend, which is a breaking change.
  • Spin canary - This is a canary release of recent commits from the main branch, intended for developers to try out the latest features, and is not stable.

Build

  • Meshery v1.0.68 - Fixes a fatal boot panic when seeding models under a pinned provider.
  • Meshery v1.0.67 - Fixes malformed doc comments and handles negative pagination page sizes.

Chaos Engineering

  • Chaos Mesh v2.8.4 - Includes bug fixes for Helm chart template rendering and dashboard UI RBAC Token Generator copy buttons, and addresses dashboard subpath serving.

Database

  • Crate 6.4.3 - A patch release; refer to the project’s release notes for a complete list of changes.

Messaging

  • Strimzi Kafka Operator 1.2.0 - Adds Apache Kafka 4.3.1 support and templated features. Upgrading to this version requires converting all custom resources to the v1 CRD API, as older v1beta2, v1beta1, and v1alpha1 APIs are no longer supported.

Networking

  • Cilium v1.20.1 - Overhauls Cluster Mesh documentation with updated introduction, load-balancing guidance, and Helm-first setup instructions. It also demotes stale ADS endpoint warnings.
  • Cilium v1.19.7 - Restores http-idle-timeout as the route idle timeout source, fixes a BPF verifier reject on pre-v5.12 kernels with IPv6 enabled, and addresses an agent warning on EKS ENI IPAM.
  • Cilium v1.18.13 - Adds support for VRRP and IGMP protocols in the host firewall. It also includes bug fixes for host firewall to tolerate unknown CT protocols and resolves abnormal IP allocation caused by hostnetwork pods.
  • CoreDNS v1.14.7 - Adds capabilities for ACME-managed TLS, topology-aware Kubernetes services, HTTP/2 forwarding, DNS-over-QUIC, and secondary zone management. It also delivers correctness and performance fixes across various handling components.
  • Kube-OVN v1.15.24 - Updates golang.org/x/net to v0.58.0, includes fixes for IPPool exclude-IP allocation, improves OVN-IC route consistency, and serializes KubeVirt E2E tests.

Observability

  • OpenTelemetry Collector v0.159.0 - Adds the pkg.exporterhelper.queueBatchEnabled feature gate, which, when enabled, sets batch::enabled to true in default queue configurations.
  • Prometheus v3.14.0 - Deprecates the stats query parameter of /api/v1/query and /api/v1/query_range for values other than true and all. The /api/v1/status/config endpoint now correctly displays empty separator and replacement fields in relabel configs when explicitly set.
  • Inspektor Gadget v0.55.1 - Addresses ELF/uprobe resource exhaustion by using a bounded streaming iterator for symbol parsing, capping USDT notes at 10,000, and size-checking debuginfod files. It also fixes fanotify issues in the runc/container hook.

Orchestration

  • Crossplane v2.4.0 - Introduces the ability to watch required resources and reconcile XRs immediately upon change, adds scale-to-zero functionality for safe-start capable providers, and provides vulnerability-scannable release artifacts.
  • Crossplane v2.3.5 - Corrects crank checksums for amd64 binaries, which had not matched since v2.2.0, resolving issues with install scripts or Dockerfiles that verified checksums.
  • Crossplane v2.2.5 - Corrects crank checksums for amd64 binaries, which had not matched since v2.2.0.
  • Crossplane v1.20.12 - Includes dependency security updates, bumping the Go toolchain to 1.25.13, go-git, and golang.org/x/mod to pick up upstream CVE fixes.
  • Kubernetes v1.36.4 - A patch release. Refer to the project’s CHANGELOG for specific updates.
  • Kubernetes v1.35.8 - A patch release. Refer to the project’s CHANGELOG for specific updates.
  • Kubernetes v1.34.11 - A patch release. Refer to the project’s CHANGELOG for specific updates.
  • Capsule v0.14.0 - Adds a global resource quota API, binds default owner clusterroles in strict RBAC mode, supports Kubernetes 1.36, and enables replicating resources upon namespace creation.

Security

  • Kyverno v1.19.0 - Limits intermediate certificates to mitigate CVE-2026-32280 and adds support for CLI cross-resource application.
  • Open Policy Agent v1.19.1 - Uses Go version 1.26.6 to build OPA, which fixes standard library vulnerabilities in code used by OPA’s HTTP handler and crypto builtins.
  • Keycloak 26.7.2 - Includes security fixes, notably addressing CVE-2026-45292 related to unbounded memory allocation in the OpenTelemetry Java SDK’s W3C Baggage Propagation.
  • SPIFFE/SPIRE v1.15.3 - Adds a Slurm workload attestor, an Azure Blob BundlePublisher plugin, and a trust_bundle_spiffe_workload_api agent configuration option. It also introduces disable_workload_api, disable_sds_api, and disable_kubelet_client agent options.
  • Sigstore Rekor v1.5.4 - Applies proactive hardening against malformed requests (GHSA-843x-px86-vq42) and improves handling of connection issues.
  • Kubewarden Controller v1.37.2 - Fixes a security bug by changing the unique internal identifier for policies. It also updates Rust and Go dependencies, including the Go Docker tag to v1.26.6.

Storage

  • Rook v1.20.6 - A patch release focusing on feature additions and bug fixes to the Ceph operator. Users are advised to upgrade due to Ceph CVE-2025-30156.
  • Rook v1.19.10 - A patch release focusing on feature additions and bug fixes to the Ceph operator. Users are advised to upgrade due to Ceph CVE-2025-30156.
  • Rook v1.20.5 - A patch release focusing on feature additions and bug fixes to the Ceph operator. Users are advised to upgrade due to Ceph CVE-2025-30156.
  • Rook v1.19.9 - A patch release focusing on feature additions and bug fixes to the Ceph operator. Users are advised to upgrade due to Ceph CVE-2025-30156.

📰 This Week in Cloud Native

The Cloud Native Computing Foundation (CNCF) announced Kubeflow’s graduation, indicating its adoption for automating AI and machine learning lifecycles on Kubernetes. This development underscores the growing integration of AI operations within the cloud native ecosystem. Concurrently, discussions emerged regarding the security of AI agents, covering aspects like sandboxing, identity management, prompt injection, and the challenges of large-scale refactoring with AI coding agents. Anthropic introduced Mythos 5 into its Claude Security vulnerability scanner, while Google’s AI coding agent demonstrated extended capabilities beyond its native IDE. Stripe acquired OpenRouter, a platform for managing LLM interactions, further signaling the commercialization and integration of AI services.

In the realm of security and compliance, the CNCF highlighted the importance of cloud native platform sovereignty, emphasizing multi-plane architectures beyond geographical regions. AWS detailed managed certificate authority rotation for Amazon EKS and encryption controls for Amazon ECS traffic, including VPC encryption and Service Connect TLS. Kyverno was discussed as a platform primitive rather than solely a security tool, suggesting its broader application in policy enforcement. Separately, Debian proposed a ban on AI-generated code contributions to its open-source projects, prompting discussion among developers and maintainers about the implications for open-source development.

Observability tools saw updates with a CNCF blog post detailing how OpenTelemetry can be used to convert slow queries into actionable reliability metrics. The topic of building smarter OpenSearch alerts also received attention. Furthermore, new CNCF mascots, Falkey for Falco and Ky for Kyverno, were introduced, expanding Phippy’s circle of cloud native friends. Kubernetes Community Days (KCDs) for H1 2027 were announced, providing opportunities for community engagement. GitHub reported processing 2.9 billion commits per month, with commentary noting the platform’s challenges in keeping pace with this volume. The discussion around Kubernetes at the edge identified fleet management as a potential solution for scaling and managing edge deployments.

💬 Community Buzz

Hacker News discussions this week included the operational aspects of Kubernetes, specifically how probes function, and new tools for Kubernetes management and security, such as Infra Lang for compiling to Kubernetes manifests, K7d for forking live clusters, K8s-audit for security checks, and KubeSentry for runtime threat detection. Topics related to Docker included reproducible ESP32 firmware development with Docker Sandboxes, API-first browser automation, and self-hosting databases and applications. Observability benchmarks comparing Prometheus, Mimir, and OpenObserve were discussed, alongside methods for vulnerability observability in Go services and leveraging OpenTelemetry traces for GenAI metrics. The impact of AI coding agents on developer identity, agent session management, and the security implications of AI agents also generated conversation.

📊 Numbers of the Week

  • Total stable releases: 34 across 12 projects
  • Top 3 projects by commits this week:
    1. meshery/meshery — 201 commits
    2. kubescape/kubescape — 132 commits
    3. cilium/cilium — 100 commits
  • Top 3 projects by merged pull requests this week:
    1. kubescape/kubescape — 132 merged PRs
    2. keycloak/keycloak — 116 merged PRs
    3. cilium/cilium — 90 merged PRs

📚 View all articles from this week →