Veille Technologique

2026-05-06

27 feeds · 87 articles traités · 20 sélectionnés · gemma4:e2b · 2026-05-06T09:13:00.496Z

Divers

docker request truncation bug bypasses AuthZ plugins (CVE-2026-34040)

r/devops (Tier 1) · Publié : 2026-05-06 · 68.4/10

Docker v29.3.1 dropped in March with a fix for CVE-2026-34040 (CVSS 8.8) the bug is weird. Dockers middleware strips request bodies over ~1mb before AuthZ plugins see them but the daemon still processes the full thing. so the plugin evaluates an empty body, approves it, and the daemon runs whatever was actually in the request the AuthZ plugin and daemon are literally looking at different requests craft an oversized request, plugin sees nothing suspicious and approves it, daemon executes the full

Kubernetes v1.36: Declarative Validation Graduates to GA

Kubernetes Blog (Tier 1) · Publié : 2026-05-05 · 52.0/10

In Kubernetes v1.36, Declarative Validation for Kubernetes native types has reached General Availability (GA). For users, this means more reliable, predictable, and better-documented APIs. By moving to a declarative model, the project also unlocks the future ability to publish validation rules via OpenAPI and integrate with ecosystem tools like Kubebuilder. For contributors and ecosystem developers, this replaces thousands of lines of handwritten validation code with a unified, maintainable fram

nginx active health checks use pod ip as host header by default, causing 502s with strict backend validation

r/devops (Tier 1) · Publié : 2026-05-05 · 40.9/10

Universal 502 Bad Gateway responses across production API. Nginx ingress controller log: [error] 45#45: *1890201 no live upstreams while connecting to upstream, client: 10.1.4.55, server: api.prod.internal, request: "GET /v2/metrics HTTP/1.1", upstream: "http://api-backend". K8s endpoints showed api-backend pods as Running and 100% Ready. Assumed Nginx failed routing packets to pod IPs. Exec'd into Nginx pod, ran curl -I <pod-ip>:8080. TCP connection succeeded but r

How do you structure DevOps for personal projects?

r/devops (Tier 1) · Publié : 2026-05-05 · 37.3/10

I’ve been spinning up a lot more personal projects lately, partly thanks to our friend AI, and it made me reflect on how I structure the DevOps side of things. I wanted to start a discussion and see how others are setting up their local dev, CI/CD, deployment, and infrastructure for side projects or small personal apps. For my own projects, I usually start pretty simple. I tend to use a Makefile for common tasks like building, packaging, running, and deploying. From there, I’ll add more structur

We built a small tool to scan cloud environments (AWS / GCP / Azure)

r/devops (Tier 1) · Publié : 2026-05-05 · 31.4/10

Hey, I built a small tool to scan cloud environments (AWS / GCP / Azure) for: - security issues - cost inefficiencies - basic compliance gaps It runs directly in the browser (no agents), and only requires read-only access. I’m not storing credentials — the scan runs with what you provide and that's it. Honestly just looking for feedback from people running real workloads. If you want to try: https://cloudchecker.app Any feedback (good or bad) is appreciated. submitted by /u/Overa

How to handle pushback from team for any improvement?

r/devops (Tier 1) · Publié : 2026-05-05 · 27.6/10

I moved into a team around 6 months ago, they have been in production for more than 8 years. The Terraform code and Python scripts was never updated, looked like it was written by someone who learnt Python or Terraform yesterday. Long lived infra, ec2 instances which are never terminated, only stopped, even though they are doing blue-green deployment. ECS cluster had its plethora of issues. But hey, they have made it work for years. I have been trying to improve the Terraform code and Infra but

pocketos lost their prod db + backups to a cursor agent in 9 seconds. the ai isn’t the main story

r/devops (Tier 1) · Publié : 2026-05-05 · 27.1/10

been reading the pocketos incident and the takes feel off. everyone is focused on ai agent deleted a startup but if you remove the ai part, this is just infra failing hard: one api key had delete access to prod + backups backups were in the same railway env as prod no confirmation step before destructive actions ~30 hours of downtime, some data gone for good this could’ve been a bad script, leaked key, or someone half-asleep running a command. the agent just did it faster. the only actually new

How We Diagnosed a Hidden Scheduler Failure in a Docker Swarm Cluster Serving 2 Million Users

DZone DevOps (Tier 1) · Publié : 2026-05-05 · 26.3/10

Context: 120 Nodes, Strict SLAs, and Legacy Infrastructure Our team is responsible for the mobile backend infrastructure serving over 2 million registered users. The Docker Swarm cluster consists of 120 nodes: 5 manager nodes, 40 worker nodes, and the rest are infrastructure servers. The cluster runs about 50 services, totaling hundreds of replicas. We inherited Swarm from the previous contractor. The client is not yet ready to migrate to Kubernetes , and Swarm is currently sufficient for the cu

Is Single Pane of Glass a myth?

r/devops (Tier 1) · Publié : 2026-05-06 · 25.4/10

I feel like I've been chasing the 'Single Pane of Glass' (SPoG) for years, but the more I build towards it, the more fractured things feel.We have the 'big players' for metrics and logs, then specialized tools for traces, then a different dashboard for Kubernetes health, and maybe another for only incidents handling. Instead of a single pane, I just have a dozen different 'panes' open in Chrome, and each one is screaming at me with its own version of the truth.An aler

Dealing with AI in Devops

r/devops (Tier 1) · Publié : 2026-05-05 · 24.3/10

Hello guys, lately how are you dealing with pressure of AI , like I have been in the field for almost a decade and am a part of a team that is quickly adopting , like using AI agent to code Iac and frontier agents for debugging. All I feel is use AI to debug and plan future projects, and not using enough skills that I used earlier, and AI may be replacing soon, though we are the one who is implementing it . submitted by /u/Cloudy_Context07 [link] [comments]

Incredibuild Unveils Islo Sandbox to Isolate AI Coding Agents

DevOps.com (Tier 1) · Publié : 2026-05-05 · 21.9/10

Incredibuild this week developed a sandbox, dubbed Islo, that makes it possible to safely run artificial intelligence (AI) coding agents. Company CEO Shimon Hason said Islo provides an isolated execution environment that enables DevOps teams to limit access to sensitive data, codebases, resources and services. Each AI coding agent is then provided with its own […]

AI has a sprawling data problem. Airbyte has just launched a tool to fix it.

The New Stack (Tier 1) · Publié : 2026-05-05 · 21.4/10

Airbyte on Tuesday launched Airbyte Agents, a new service that precomputes and indexes a company’s business data, allowing AI agents The post AI has a sprawling data problem. Airbyte has just launched a tool to fix it. appeared first on The New Stack .

Kawaii - La GameCube découpée au scalpel qui tient dans la poche

Korben (Tier 1) · Publié : 2026-05-06 · 20.9/10

Mackie Kannard-Smith vient de sortir Kawaii , une GameCube qui tient dans un porte-clés avec une vraie carte mère Nintendo dedans. Pas d'émulation ni de Raspberry Pi déguisé mais juste du silicium d'origine charcuté à mort pour rentrer dans 60 × 60 × 15,8 mm ! Pour vous donner une idée, c'est plus petit qu'une Game Boy Color et c'est le boîtier en alu bleu anodisé qui fait office de dissipateur thermique passif.

Show HN: Explore color palettes inspired by 3000 master painter artworks

Hacker News (Tier 1) · Publié : 2026-05-05 · 20.5/10

I built PaletteInspiration.com, a browsable archive of color palettes pulled from artworks by 3,000+ master painters (Monet, Vermeer, Raphael, Van Gogh). Why I built it: every color palette generator I tried converged on the same five muted pastels. Painters spent centuries figuring out color and we mostly ignore that body of work when picking colors for digital design. Please share your feedback on the Color Harmony Explorer - drag the wheel to any color and it shows which hues master painters

wg-obfuscator - Faire passer WireGuard pour de la visioconf

Korben (Tier 1) · Publié : 2026-05-06 · 20.3/10

Si vous faites tourner WireGuard depuis un réseau filtré par DPI (Genre en Russie, Iran, Chine, et autres pays défenseurs de la libertéééé (non)), vous avez sans doute remarqué que les tunnels tombent rapidement. En effet, les signatures des protocoles et notamment du protocole WireGuard sont devenues facilement identifiables. Les filtres modernes de censure sont ainsi capable de les bloquer en quelques secondes. C'est pour ça que wg-obfuscator , sorti par Alexey Cluster (le dev derrière le mod

Should You Be Worried About Copy Fail Linux Exploitation?

It's FOSS (Tier 1) · Publié : 2026-05-06 · 19.4/10

It's been patched, but cloud and container users should update sooner than later.

Weeks of building cross-repo dependency mapping: Things I got wrong, things I'm still unsure about

r/devops (Tier 1) · Publié : 2026-05-05 · 19.3/10

Some time ago, I posted about cross-repo dependency visibility . The "if I change repo X, what else breaks?"-problem. The thread surprised me with how many people described the same pain, including around 6 who'd already built internal versions. After a while, I thought I’d try to built something around it, and now I'm at the part of the journey where I want to stress-test my assumptions before going further. Wanted to share a few things I changed my mind on, and a few I'm

Il démonte une caméra gimbal de drone Shahed-136 récupéré en Ukraine

Korben (Tier 1) · Publié : 2026-05-05 · 18.7/10

Un chercheur du nom de Michel a mis la main sur une caméra de surveillance issue d'un drone Shahed-136 abattu en Ukraine, et il en a fait un démontage très complet. Le Shahed-136, ce drone iranien que la Russie a adopté massivement et qu'elle modifie au fil des mois avec des charges utiles supplémentaires, embarque ici une caméra thermique pour les missions de nuit, montée sur un gimbal motorisé, le tout dans un boîtier qui tient dans la main.

For Managers: Is it a red flag for you if an applicant only stayed for less than 2 years at a job?

r/devops (Tier 1) · Publié : 2026-05-05 · 18.2/10

Hello all, I am currently working as an SRE on site. I am really working hard and trying to make an impact as much as possible. I am less than 2 years in to my current company and I believe I have contributed a lot in my team and have heavily influenced them on how we work. I do SRE tasks but I am more focused on creating automation projects. I have standardized our patch deployments, created an end to end pipeline for upgrading/rollback of the services our servers are running, I have also creat

Modularized Workflow Toggles for GitHub Actions

r/devops (Tier 1) · Publié : 2026-05-05 · 17.4/10

Im working on a project where all of the infrastructure and app packages are part of a monolithic deployment pattern. Right now its simple, pick the release or hotfix you want to deploy and deploy the full blown application, no limits. I've modularized one of the new applications we've built and see that it adds additional toggles, part of two build packages. I have to modularize 10 more packages and decouple the infrastructure associated. In order to maintain dependencies I plan to use

Généré par veille-auto · Modèle : gemma4:e2b