2026-04-29
27 feeds · 104 articles traités · 20 sélectionnés · gemma4:e2b · 2026-04-29T09:14:45.511Z
DZone DevOps (Tier 1) · Publié : 2026-04-28 · 72.9/10
Editor’s Note: The following is an article written for and published in DZone’s 2026 Trend Report, Security by Design: AI Defense, Supply Chain Security, and Security-First Architecture in Practice . DevSecOps means security is part of software delivery from the beginning, where security is built into planning, coding, building, testing, releasing, and operations. As pipelines become faster and more automated, security checks should run inside the CI/CD pipeline and be enforceable across d
r/devops (Tier 1) · Publié : 2026-04-29 · 50.7/10
Basically as the title says, I am stuck on which direction I should go for. I have been in the infrastructure side for about 8 years, was working as data center tech/lead for 5 years, then 3 years ago got into Infrastructure engineering. I am pretty much the virtualization guy at my work for vSphere. We have VMs running in Azure that I maintain at a base level, giving permissions, creating subs/vaults. I have also recently gotten into the K8s side as well using Openshift Containerization as our
Korben (Tier 1) · Publié : 2026-04-29 · 50.5/10
PS5-Linux est là !! Andy Nguyen, le security engineer alias theflow0, vient de publier le hack qui transforme une PS5 Phat (les modèles originaux, pas les Slim ni les Pro) en PC 100% Linux. Et le truc cool c'est que ça marche désormais sur les firmwares 3.xx et 4.xx, et pas seulement sur les premières consoles oubliées dans leur boîte ! Pour rappel, en mars dernier, Andy Nguyen avait fait tourner GTA 5 Enhanced en ray tracing sur sa PS5 , mais l'exploit était limité aux firmwares 1.xx et 2.xx, d
r/devops (Tier 1) · Publié : 2026-04-28 · 49.7/10
High-Level Architecture About six months ago I was managing infrastructure across several environments and ran into a consistent limitation. I couldn't find a clean way to provide per-environment observability with real isolation without duplicating the entire monitoring stack. Dashboard variables solved for presentation, not security, and any admin could still access everything. Spinning up separate Prometheus instances fixed isolation, but at the cost of operational overhead and fragmentat
r/devops (Tier 1) · Publié : 2026-04-29 · 43.6/10
Hi everyone, I’m relatively new to GitHub as a DevOps platform, especially its Actions and workflows. I do have solid experience with Azure DevOps pipelines (both YAML and designer-based), tasks, and build runners (self-hosted and managed). I recently joined a team that uses GitHub Enterprise for their project, so I need to learn GitHub Actions and workflows quickly. I found Scott Sauber’s course “ From Zero to Hero: GitHub Actions ” on Dometrain. It has a 4.6 rating, but costs £90. There’s a 40
Kubernetes Blog (Tier 1) · Publié : 2026-04-28 · 43.0/10
Staleness in Kubernetes controllers is a problem that affects many controllers, and is something may affect controller behavior in subtle ways. It is usually not until it is too late, when a controller in production has already taken incorrect action, that staleness is found to be an issue due to some underlying assumption made by the controller author. Some issues caused by staleness include controllers taking incorrect actions, controllers not taking action when they should, and controllers ta
OpenTelemetry Blog (Tier 1) · Publié : 2026-04-28 · 41.1/10
This report presents findings from the OpenTelemetry Japanese Community Survey, conducted to understand the current landscape of OTel awareness, adoption, and community engagement among developers and engineers in Japan. The survey targeted practitioners across roles such as development, SRE, DevOps, and Platform Engineering, distributed through CNCF community channels and Japanese social platforms like X (formerly Twitter), Qiita , and Zenn. The goal was to develop data-driven strategies that c
DZone DevOps (Tier 1) · Publié : 2026-04-28 · 37.4/10
There is a specific kind of frustration reserved for Java developers who have just containerized their application. You spend hours optimizing your Spring Boot microservice, ensuring your logic is sound and that your tests pass. You wrap it in a Docker container, push it to the registry, and deploy. Then the reality sets in. Your image is 800MB, your startup time is 40 seconds, and during load testing, the container is killed silently by the OS. In my recent work, migrating a monolithic Java app
Grafana Blog (Tier 1) · Publié : 2026-04-28 · 36.9/10
To simulate real user behavior, performance tests often rely on API keys, tokens, or credentials to interact with real systems. But as your testing suite grows, this sensitive data can start to sprawl across scripts, configs, and environments, increasing the risk of exposure and making tests harder to manage and maintain. To address this challenge, we’re rolling out secrets management for Grafana Cloud k6 , the fully managed performance testing platform powered by k6 OSS. Secrets management allo
r/devops (Tier 1) · Publié : 2026-04-29 · 36.0/10
New hire,1 months into devops,no prior exp. Lets just say im the only devops in the company. I am tasked to unit test some projects inside our remote repo(inside on prem azure devops server). I do unit testing, goes fine. And then it had some errors during unit testing,missing dependencies. I know what im doing is not best practice, but all i did was copy the missing dependency from location A to location B, and now the testing is green. I did inform my superior,before doing this,but she said sh
Grafana Blog (Tier 1) · Publié : 2026-04-28 · 36.0/10
The way you write code is changing, which means the way you observe your systems and respond to issues needs to change, too. Engineers today spend much of their day working via command line, as agentic tools like Cursor and Claude Code have become highly effective at handling many day-to-day engineering tasks. This greatly accelerates code generation, but it doesn't solve for the context switching that comes when you have to jump into another tool that's not part of this new, faster workflow. Mo
DZone DevOps (Tier 1) · Publié : 2026-04-28 · 35.8/10
We moved our monolithic Java application to Kubernetes last year. The promise was scalability and resilience. The reality was a series of silent failures during deployments. Users reported dropped connections every time we pushed a new version. Our monitoring showed zero downtime, but the customer experience told a different story. Requests vanished into the void during rolling updates. We spent weeks chasing network ghosts before finding the root cause. The issue was not the network. It was how
r/devops (Tier 1) · Publié : 2026-04-29 · 32.5/10
Hola a todos! Llevo 2 años trabajando con Terragrunt y quería conocer su opinión sobre la transición de Terraform a OpenTofu. Entiendo que desde el cambio de licencia de HashiCorp en 2023 (de MPL a BSL), mucha gente empezó a plantearse alternativas. En mi caso uso Terraform como backend de Terragrunt, así que técnicamente el cambio sería mínimo — solo reemplazar el binario. ¿Alguien ya hizo la migración? ¿Valió la pena o fue más dolor de cabeza de lo esperado? ¿O simplemente se quedaron con Terr
Hacker News (Tier 1) · Publié : 2026-04-28 · 29.4/10
https://aws.amazon.com/bedrock/openai/ https://www.aboutamazon.com/news/aws/bedrock-openai-models https://openai.com/index/openai-on-aws/ https://x.com/amazon/status/2049178618639839427 Comments URL: https://news.ycombinator.com/item?id=47939320 Points: 271 # Comments: 88
r/devops (Tier 1) · Publié : 2026-04-29 · 28.2/10
Not looking for the big flashy stuff like we switched to Kubernetes or we rolled out a new observability platform. I mean the small, almost boring changes that ended up having an outsized impact on how your team actually works day to day. A few examples of what I am talking about. Standardizing commit message formats so changelogs practically write themselves. Adding a lightweight incident template in Notion that takes two minutes to fill out. Enforcing a rule that every alert must link to a run
r/devops (Tier 1) · Publié : 2026-04-28 · 28.2/10
Is it just me, or is the current state of AI Agents for DevOps basically just R͏AG over documentation with a fancy U͏I? I’ve been sitting through demos lately where the promise is autonomous incident response, but when you peel back the hood, the logic is almost always: \- scrape docs, \- summarize a runbook, \- open a Jira ticket with the summary. That’s not an ag͏ent, that’s just a faster way to read. In a real production environment, I don’t need an AI to tell me what the docs say - I need it
Korben (Tier 1) · Publié : 2026-04-28 · 27.4/10
478 binaires Unix peuvent servir à devenir root sur un système mal configuré. C'est ce que recense GTFOBins , le projet open source monté par Emilio Pinna et Andrea Cardaci, qui est devenu LE bookmark obligatoire de tout pentester Linux. Ce ne sont pas des exploits, hein, mais juste des fonctions parfaitement légitimes de programmes installés partout, et qui dans le bon contexte (genre un bit SUID oublié, qui fait tourner un binaire avec les droits du propriétaire, souvent root) permettent de sp
Korben (Tier 1) · Publié : 2026-04-29 · 25.9/10
" GitHub n'est plus un endroit pour faire du travail sérieux. " C'est signé Mitchell Hashimoto, le créateur de HashiCorp, de Vagrant ou plus récemment de Ghostty, et l'utilisateur numéro 1299 de la plateforme depuis février 2008. Et quand un mec qui a passé 18 ans à pousser du code presque tous les jours sur Github annonce qu'il se casse, bah ça vaut clairement le coup de comprendre pourquoi. L'annonce est tombée hier : Ghostty , le terminal en Zig pour macOS et Linux va quitter la pla
Korben (Tier 1) · Publié : 2026-04-29 · 25.5/10
Vous avez déjà voulu créer une appli desktop qui tourne sur Linux, Mac et Windows en même temps ? En Rust, c'était un peu compliqué jusqu'ici. Heureusement, Slint , créé par la société allemande SixtyFPS GmbH, propose une solution sympa ! L'idée, c'est de décrire votre interface dans des petits fichiers .slint (un genre de mini HTML/CSS pour appli native), et de brancher ça à du Rust, du C++, du JavaScript ou du Python. Comme ça, vous codez le visuel d'un côté, la logique de l'autre.
r/devops (Tier 1) · Publié : 2026-04-29 · 25.3/10
I recently joined a company and inherited an AWS setup that uses a single CloudFront distribution with 3 alternate domain names and 3 origins. Set up looks like this: 2 origins are S3 buckets hosting frontend applications 1 origin is an Application Load Balancer connected to backend apps running on EC2 Different domains point to the same CloudFront distribution Example: app1.company.com → S3 frontend app2.company.com → S3 frontend api.company.com → ALB backend In my previous company, we used sep
Généré par veille-auto · Modèle : gemma4:e2b