DevOps’ish

Cloud Native, DevOps, Open Source, AI, tech industry news, culture, and the ‘ish between. A newsletter by Chris Short.

Subscribe to DevOps'ish

No spam, ever. Unsubscribe anytime.

DevOps'ish 312: Nobody won the token race, rsync outrage, dev goes scorched earth on vibe coders, and more

Most teams quarantine flaky tests. We fix them. A flake fails, someone hits retry, it passes, you merge. The bug doesn’t go away. Mendral runs in your CI, reproduces the flake in a sandbox, finds the actual race or timing bug, and opens the fix PR. No quarantines, no skip annotations, no ignore list growing month over month. SPONSORED Eliminating Kubernetes Image Signature Replication - The Kubernetes project tore out a resource-intensive signature replication pipeline and replaced it with a simple routing approach that points all signature requests to a single canonical region. Less infra, same trust chain. From Kubernetes Dashboard to Headlamp: Understanding the Transition - The Kubernetes Dashboard is archived. Headlamp is the successor, and this post maps familiar workflows to the new tool while walking through multi-cluster visibility, application-centric views, and the plugin extension model. Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware - Attackers compromised the CI/CD pipeline behind the @redhat-cloud-services npm namespace and poisoned over 30 packages with malware that runs automatically on npm install. It hoovers up GitHub tokens, cloud credentials, Kubernetes tokens, SSH keys, and more – then disguises its exfil traffic as calls to api.anthropic.com to blend into org logs. If you run anything from that scope, audit your environments now. ...

June 7, 2026 · 6 min · Chris Short

DevOps'ish 311: Poisoned Repos, Hallucinating Executives, and More

Make smarter application decisions with Azure Copilot Migration Agent (Sponsor) Stop guessing what to modernize. This playbook from Microsoft’s Azure Copilot Migration Agent team gives you strategies to decide what to re-platform, refactor, and what to leave as is. Try it yourself — download a copy today. Reconciling the Past: Correcting Records for Unfixed Kubernetes CVEs - The Kubernetes Security Response Committee will correct CVE records on June 1, 2026 for three long-standing unfixed vulnerabilities that represent architectural design trade-offs rather than code bugs, with remediation approaches provided for cluster admins. Nvidia to spend $150 billion a year in Taiwan, ’epicentre’ of AI revolution, says CEO - Jensen Huang announced Nvidia will commit roughly $150 billion annually to Taiwan operations and break ground on a new 4,000-person Taipei headquarters called Constellation, up from just $10-15 billion a year five years ago. Tech CEOs are apparently suffering from AI psychosis - Box CEO Aaron Levie argues that tech executives have become dangerously disconnected from practical AI implementation realities, leading them to overestimate productivity gains and justify mass layoffs on automation assumptions that don’t hold up. ...

May 31, 2026 · 5 min · Chris Short

DevOps'ish 310: The Breaches Are Coming From Inside the Extension Store

GitHub Confirms Internal Breach via Poisoned VS Code Extension - Official statement from GitHub confirming TeamPCP’s breach of approximately 3,800 internal repositories via the backdoored Nx Console VS Code extension; the malicious version was pulled in 18 minutes, credentials rotated, and no customer data appears to have been affected. NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability - A critical heap buffer overflow in NGINX dating back to 2008 can be exploited via the rewrite and set directives to achieve remote code execution – yes, 18 years. Fragnesia Made Public As Latest Linux Local Privilege Escalation Vulnerability - Hot on the heels of Dirty Frag, Fragnesia is now public as a similar LPE in Linux’s ESP/XFRM code with a logic bug allowing arbitrary byte writes into the kernel page cache – proof-of-concept code already out there. AI Just Found Another Linux Zero-Day and Security Researchers Are Freaking Out - CVE-2026-46333, a privilege escalation flaw in the Linux kernel’s ptrace subsystem, is stoking greater concern about AI tools compressing the timeline from discovery to exploitation. ...

May 24, 2026 · 6 min · Chris Short

DevOps'ish 309: Dirty Pages All the Way Down, The Cloud Is Hot, and more

The Linux kernel vulnerabilities are coming in hot and heavy. I don’t think I’ve ever updated a kernel due to security issues this frequently before. I fear CopyFail, Dirty Frag, and Fragnesia are the tip of a much bigger iceberg below the surface. There will be more, and they could come very quickly as more flaws in the kernel’s page cache logic are discovered, as more and more eyeballs focus on this exploit vector. As always, build safety into your systems and processes to make upgrades and reboots as painless as possible. Stay safe out there. How to migrate your paging tool without breaking your team Most teams treat a paging tool migration as a like-for-like swap. Mistake. Paging is ~10% of incident management. The other 90% (triage, comms, postmortems) is where teams actually break. SPONSORED Fleet-Scale Kubernetes: An Operating Model for Homogeneous Clusters with Decoupled Capacity - The case for managing fleets of many small, homogeneous Kubernetes clusters with decoupled capacity provisioning through a standardized autoscaler contract, rather than trying to scale individual clusters or unify across specialized cluster types. ...

May 17, 2026 · 7 min · Chris Short

DevOps'ish 308: Actively Exploited, Actively Litigated, Actively Dead

Build Real-Time Voice Agents with 90ms Latency Voxtral TTS streams natively, handles arbitrarily long generations, and slots into any STT + LLM stack. Clone any voice in 9 languages from a 3-second sample—no fine-tuning required. Pair with Voxtral Transcribe for end-to-end speech-to-speech. Get started with Voxtral TTS! SPONSORED IaCConf 2026: AI, IaC, and platform engineering It’s 2026. Platform engineering is shifting. Your users aren’t just developers anymore. They’re AI agents. Plan for it. Join IaCConf 2026 to hear from the people building this shift on May 14th at 11 am ET. SPONSORED Cloud Native Days Romania Two days of cloud native talks, hands-on workshops, and strong community momentum - 18–19 May at the Radisson Blu, Bucharest. Join developers, platform engineers, DevOps practitioners, engineering leaders, and cloud enthusiasts for the 3rd edition of Romania’s community-driven Cloud Native Days, bringing practical Kubernetes use cases and modern cloud native systems to the stage. CNCF Project Antrea Compromised in Daring GitHub Attack - The Antrea open-source Kubernetes project was attacked via its Jenkins integration on May 2 by an unknown threat actor who opened a malicious pull request, claimed root on the Jenkins controller, and taunted maintainers. All thanks to the Trivy vulnerability. ...

May 10, 2026 · 6 min · Chris Short