Veille Technologique — Bilan hebdomadaire

Semaine 2026-W23 · du 2026-06-01 au 2026-06-07

27 feeds · 180 articles traités · 40 sélectionnés · gemma4:e2b · 2026-06-01T08:25:28.912Z

Divers

Reconciling the Past: Correcting Records for Unfixed Kubernetes CVEs

Kubernetes Blog (Tier 1) · Publié : 2026-05-26 · 102.0/10

The Kubernetes project relies on transparency to empower cluster administrators and security researchers. One important way we do that is by publishing CVE records into the Common Vulnerabilities and Exposures database. As part of our ongoing effort to mature the official Kubernetes CVE Feed , we have identified some discrepancies. CVE records for a few older, unfixed issues incorrectly include a fixed version field. The Kubernetes Security Response Committee (SRC) will correct the affected CVE

Feeling Stuck in My DevOps Career After 7 Years – Looking for Advice

r/devops (Tier 1) · Publié : 2026-05-31 · 90.8/10

Hi everyone, I'm based in India and have around 7 years of experience. My skills include Java, Python, AWS, Terraform, Linux, CI/CD, Jenkins, Kubernetes, Docker, and automation testing tools like Selenium. My career has taken a few unexpected turns. I started in a CI/CD-focused role and later got an excellent opportunity to work on DevOps projects where I built and managed pipelines from scratch. Unfortunately, that project ended, and I was moved into automation testing for a couple of years

Zero-Downtime Deployments for Java Apps on Kubernetes

DZone DevOps (Tier 1) · Publié : 2026-05-29 · 62.6/10

This article provides a comprehensive guide to achieving zero-downtime deployments for Java-based applications on Kubernetes.  We cover deployment strategies, Kubernetes primitives, Java-specific considerations, session state handling, database migrations, traffic shifting techniques, CI/CD pipelines, GitHub Actions, Jenkins with automated rollbacks, observability (Prometheus, Grafana, Jaeger), Helm/ArgoCD examples, testing strategies (canary analysis, chaos, smoke tests), and troubleshooti

We moved from Azure to Hetzner and why you should too

r/devops (Tier 1) · Publié : 2026-05-30 · 57.7/10

2,5 years ago Azure generously offered us a Startup credit, we were already on Azure so we said why not. At that time our compute needs were way lower than now, yet we were given very large amount of credits. Once first year was up Azure kept pushing us to use more of their managed services. At some point we got an email and It was quite hard to convince them not to terminate our account since it was not "vendor locked enough" for them e.g. we didn't use their proprietary Services/

Full security scanner coverage of your codebase in minutes

GitLab Blog (Tier 1) · Publié : 2026-05-26 · 54.5/10

Across the industry, every CI/CD platform faces the same challenge: As organizations grow, manually configuring scanners to run across every pipeline definition file isn't scalable. AI is accelerating how fast teams ship code, and with this comes more projects, more pipelines, and more surface area to secure. What starts as a deliberate security decision becomes inherited configuration that nobody owns, coverage that was never backfilled, and gaps that are invisible until they aren't. Se

A deep dive into Kubernetes Gateway API

r/devops (Tier 1) · Publié : 2026-05-29 · 49.6/10

I’ve published a deep dive into Kubernetes Gateway API. The blog post covers: how Kubernetes ingress patterns evolved from Service resources to Ingress and now Gateway API why the Ingress API is limited for modern teams how Gateway API works: GatewayClass , Gateway , 5x Routes , policies, ReferenceGrant , and more what to do if you are still running the deprecated NGINX Ingress Controller how I would think about picking a Gateway API implementation: Envoy Gateway, Istio, kgateway, Traefik, NGINX

Do you still manually maintain docker-compose files across projects, or do you have a better workflow now?

r/devops (Tier 1) · Publié : 2026-05-30 · 49.2/10

Hey everyone, I’ve been building a lot of side projects over the years, and I keep running into the same annoying pattern around Docker setups. Every time I start a new project, I usually end up: copying a docker-compose file + Dockerfile + configs from another project tweaking it for the new use case sometimes asking AI to help speed things up, but it still needs a lot of fixing afterward then debugging small inconsistencies between environments It works, but it feels repetitive and time-consum

Docker Hardened Images Are Free Now — Here's What You Still Need to Build

DZone DevOps (Tier 1) · Publié : 2026-05-27 · 49.1/10

The Problem Isn't the Image Hardened container images are no longer niche. Docker open-sourced major portions of the tooling behind Docker Hardened Images under Apache 2.0 in late 2025. Chainguard and Google's distroless variants sit in the same space. The pitch across all three: fewer packages, smaller attack surface, dramatically lower CVE counts. The pitch is accurate. It is also incomplete. Most container security failures are not image failures. They are governance failures:

Systems Architect / DevOps MS Student looking for home lab collaborators and architecture feedback (GitHub enclosed)

r/devops (Tier 1) · Publié : 2026-05-31 · 45.7/10

Hey everyone, ​I’m a Systems Engineer focusing heavily on cloud-native infrastructure, platforms, and systems architecture. Day-to-day at work, I deal with production infrastructure management, Kubernetes orchestration, container deployments, and system cutovers. ​On the academic side, I’m currently finishing up my Master’s in Software Engineering with a specialization in DevOps Engineering. ​While work and school keep me busy, my real sandbox is my home lab. I treat it like a mini-enterprise en

DevOps and Platform Engineering Readiness Checklist: Everything Needed for a Scalable, Secure, High-Velocity Delivery Platform

DZone DevOps (Tier 1) · Publié : 2026-05-27 · 45.1/10

Editor’s Note: The following is an article written for and published in DZone’s 2026 Trend Report,  Platform Engineering and DevOps: How Internal Platforms, Developer Experience, and Modern DevOps Practices Accelerate Software Delivery . High-performing engineering organizations don’t scale through heroics. They scale through repeatable platform capabilities backed by evidence. This checklist reflects the shift from tool‑centric DevOps to product‑oriented platform engineering, focused on sc

What exactly do you do as an SRE?

r/devops (Tier 1) · Publié : 2026-05-31 · 44.5/10

I've tried multiple times to understand what this role entails but couldn't wrap my head around it. The question really popped when I was taking the SAA practice exam and I found myself really enjoying the gears in my brain working on what to do and why do it and I started searching. I work as a DevOps engineer and with how AI basically does everything and I just oversee it, I lost the appeal and enjoyment and want something where my brain would work again and the AI usage isn't too

Building a cloud native internal developer platform with Kubernetes, GitOps, and supply chain security

CNCF Blog (Tier 1) · Publié : 2026-05-29 · 43.9/10

Modern software delivery is no longer constrained by application code — it is constrained by the platform that runs it. This article presents the design of a cloud-native Internal Developer Platform (IDP) built on Kubernetes and...

Preparing for new devops job

r/devops (Tier 1) · Publié : 2026-05-30 · 41.6/10

Hey guys, in 5 months I will start a new job as devops / cloud Engineer for an it consultant company. Currently I am hired as software engineer. My main task should be software developing but I am more involved in devops / platform Engineering stuff : maintaining CI /CD Pipeline, AWS Infrastructure ( That's why I made the transition ). During the next months I want to deep dive into more topics like k8 or terrarform so I can start the new job more prepared. Do you have any suggestions for to

One Query, Four GPUs: Tracing a Distributed Training Stall Across Nodes

DZone DevOps (Tier 1) · Publié : 2026-05-25 · 37.6/10

TL;DR A single straggling node held up a 4-node distributed training job. We found it by fanning out one SQL query to all four nodes and getting the answer in under a second. This is distributed GPU training debugging with eBPF – no central service, no Prometheus, no time-series database, just the same single-binary agent already running on each machine. The Problem We Kept Hitting We’ve been building Ingero — an eBPF agent that traces CUDA API calls and host kernel events to explain GPU latency

Questions for the cloud engineering crowd

r/devops (Tier 1) · Publié : 2026-05-31 · 36.8/10

Quick context: After working in DevOps, I realized I don’t enjoy writing pipelines and basic scripting and I enjoy designing and understanding low-level and high-level, getting across multiple domains and so I enjoyed both reliability and cloud, but cloud got my eye more. Now recently I’ve been studying to take the SAA cert and was really enjoying how the gears in my brain started working again, as with the introduction of AI, most of my work became provisioning the AI to do what I want and modi

Product-Led Software Delivery: Intelligent Platforms for DevOps at Scale

DZone DevOps (Tier 1) · Publié : 2026-05-25 · 36.6/10

Editor’s Note: The following is an article written for and published in DZone’s 2026 Trend Report,  Platform Engineering and DevOps: How Internal Platforms, Developer Experience, and Modern DevOps Practices Accelerate Software Delivery . Recent advances in tooling and automation have moved DevOps beyond a collection of siloed frameworks and tools toward a more unified delivery model. But the sprawl of disconnected tools and the cognitive load of constant context switching have also created

Linux va enfin faire tourner le GA100 de NVIDIA avec un pilote 100% libre

Korben (Tier 1) · Publié : 2026-05-29 · 35.6/10

Petite victoire pour le logiciel libre. Avec la prochaine version du noyau Linux, la 7.2, le pilote Nouveau va enfin prendre en charge le GA100 de NVIDIA. Pour situer, Nouveau, c'est le pilote graphique libre développé par la communauté pour faire fonctionner les cartes NVIDIA sans dépendre du pilote propriétaire maison. Le GA100, lui, n'est pas une carte de gamer. C'est la puce qui anime l'A100, l'accélérateur que NVIDIA vend par camions entiers aux data centers pour entraîner les IA et faire t

Reduce supply chain risk with SBOM-based dependency scanning

GitLab Blog (Tier 1) · Publié : 2026-05-26 · 35.5/10

Third-party code dominates most codebases, and four recent supply chain incidents show how a single compromised package can ripple into every project that depends on it. AI is compounding this problem: Research suggests nearly half of AI-generated code contains vulnerabilities . Traditional dependency scanners, including GitLab's Gemnasium analyzer, were engineered to answer one question: Which of my declared packages have known CVEs? When dependency trees weren’t as deep and release cycles

Vendor neutrality isn’t magic: A hard look at the OpenTelemetry ecosystem

The New Stack (Tier 1) · Publié : 2026-05-29 · 33.0/10

The OpenTelemetry (OTel) ecosystem provides us not only with a standard data format and transport mechanism for generating, processing, and The post Vendor neutrality isn’t magic: A hard look at the OpenTelemetry ecosystem appeared first on The New Stack .

SRE Weekly Issue #519

SRE Weekly (Tier 1) · Publié : 2026-06-01 · 31.8/10

View on sreweekly.com A message from our sponsor, BigPanda: What if you could predict which changes will cause incidents? BigPanda analyzes every change, including ones marked safe, to surface the real risk and impact before deployment. Next time, routine changes don’t become your next P1. See BigPanda for SREs The Problem with AI-Generated Post-Incident Reviews […]

Why Linux creator Linus Torvalds gets angry hearing “99% of code is AI”

The New Stack (Tier 1) · Publié : 2026-05-29 · 30.9/10

During his keynote at the recent Open Source Summit North America, Linux and Git creator Linus Torvalds did not mince The post Why Linux creator Linus Torvalds gets angry hearing “99% of code is AI” appeared first on The New Stack .

Consul 2.0 improves flexibility, control, and scalability

HashiCorp Blog (Tier 1) · Publié : 2026-05-27 · 30.4/10

Consul 2.0 enhancements include multi-port for service mesh, CyberArk Workload Identity Manager, cluster rate limiting, and auto-scaling for API gateway.

Building a DevOps-Ready Internal Developer Platform: A Hands-On Guide to Golden Paths, Self-Service, and Automated Delivery Pipelines

DZone DevOps (Tier 1) · Publié : 2026-05-28 · 29.6/10

Editor’s Note: The following is an article written for and published in DZone’s 2026 Trend Report,  Platform Engineering and DevOps: How Internal Platforms, Developer Experience, and Modern DevOps Practices Accelerate Software Delivery . The role of the enterprise developer has become more complex over time as organizations adopt new technologies and tools, often without retiring their old ones. Add high staff turnover and increasing time and cost pressure, and developers are confronted wit

FOSS Weekly #26.22: Win for Linux, Firefox New AI Feature, AMD Betrayal, Rust Linux Commands and More

It's FOSS (Tier 1) · Publié : 2026-05-28 · 29.3/10

Linux gets some relief in the absurd OS-level age verification law fiasco.

Agentic SRE: The Next Frontier of Reliability

DevOps.com (Tier 1) · Publié : 2026-05-29 · 29.0/10

Agentic SRE is the evolution of site reliability engineering where AI agents help observe systems, reason over telemetry and take bounded operational actions under human-defined guardrails.

I made a roadmap for 3 months, to land a job as Junior DevOps Engineer

r/devops (Tier 1) · Publié : 2026-05-30 · 28.8/10

Thank you all in advance for any feedback and suggestions. I am a Cruise Ship IT for 4 years and I want to land on a remote DevOps job after my contract because I am done with ships and I want a stable life. I am already familiar with Domain Controllers, servers, helpdesk, on-site support, firewalls, monitoring and logging. I am currently on AZ-900 certificate and I am positive about completing the exam and getting it in a week. Later on I will start on AZ-104 which will take a fair amount of ti

Debugging the undebuggable: building observability into probabilistic AI systems

The New Stack (Tier 1) · Publié : 2026-05-28 · 28.0/10

Debugging used to be straightforward: A service failed, you checked the logs, followed the stack trace, and fixed the bug. The post Debugging the undebuggable: building observability into probabilistic AI systems appeared first on The New Stack .

Interview as an SRE

r/devops (Tier 1) · Publié : 2026-06-01 · 27.9/10

Hey, I need help regarding finding SRE jobs. I am 10 years experienced and have been an SRE since last 5 years. I recently lost a job and now when I see the interview market it has drastically changed. If you have interviewed recently, would you be able to help me what is actually working for interviews in 2026 for SRE's. submitted by /u/Lost_Question_1996 [link] [comments]

BadHost - Un caractère et votre agent IA passe à l'ennemi

Korben (Tier 1) · Publié : 2026-05-28 · 27.3/10

Les chercheurs de X41 D-Sec viennent de divulguer une faille critique baptisée BadHost (CVE-2026-48710) dans Starlette, le framework Python qui sert de fondation à FastAPI, vLLM , LiteLLM et une grande partie des serveurs MCP basés sur FastAPI. 325 millions de téléchargements par semaine, et il suffit d'injecter un seul caractère dans le header HTTP "Host" pour contourner les contrôles d'accès path-based qui lisent "request.url.path" dont autant dire que beaucoup de déploieme

Agentic coding is only as good as its context

GitLab Blog (Tier 1) · Publié : 2026-05-28 · 26.9/10

Every week, another coding agent demo shows a prompt turning into a pull request in under five minutes. These demos often highlight a narrow use case not yet in production, and they skip everything that happens after the commit. The pull request doesn’t include a link to the issue it was supposed to fix. The CI/CD pipeline fails because the agent didn't know about a recently added linter rule. A security scan flags a dependency the agent pulled in without checking the project's approved

AI is shipping code faster than security was built to handle

The New Stack (Tier 1) · Publié : 2026-05-29 · 26.7/10

Snyk has entered the AI-powered penetration testing market with a new product it says addresses the gap in how enterprises The post AI is shipping code faster than security was built to handle appeared first on The New Stack .

The Kubernetes integration tax: Prometheus, Cilium and production reality

CNCF Blog (Tier 1) · Publié : 2026-05-28 · 26.4/10

I still remember the first time we lost sleep over something that wasn’t a bug. It was a Tuesday. Grafana dashboards showed blank panels for Cilium network metrics. Hubble was working fine — DNS visibility, TCP...

Un développeur de malware oublie son propre token GitHub dans le code

Korben (Tier 1) · Publié : 2026-05-28 · 25.2/10

Voilà qui est rigolo. Un développeur malveillant a essayé de voler les fichiers sensibles des utilisateurs de Claude (l'assistant IA d'Anthropic, concurrent d'OpenAI sur les modèles de langage) en uploadant un package npm piégé. Sauf que dans son code, il a laissé son propre token d'authentification GitHub privé. Les chercheurs n'ont eu qu'à le récupérer pour remonter jusqu'à lui. Le package s'appelait mouse5212-super-formatter. Il se présentait comme un utilitaire interne de synchronisation de

Why Enterprise AI Infrastructure Is Becoming a DevOps Problem

DevOps.com (Tier 1) · Publié : 2026-05-29 · 25.1/10

Most enterprise AI projects start with retrieval. You connect Jira, Confluence, SharePoint, and Slack. Maybe a few internal databases nobody has touched in five years. You tune embeddings, optimize chunking, wire up a vector database, and convince yourself you’ve built an AI-powered knowledge system. Then the model server crashes. And suddenly, you discover the uncomfortable […]

How Jaeger is evolving to trace AI agents with OpenTelemetry

CNCF Blog (Tier 1) · Publié : 2026-05-26 · 24.9/10

As software architectures evolve, observability tools must adapt. When the industry moved to microservices, distributed tracing became a necessity. Jaeger emerged as a core tool for engineers to understand those fragmented systems. Now, as organizations integrate...

When Architecture Diagrams Stop Scaling

r/devops (Tier 1) · Publié : 2026-05-30 · 24.6/10

Interesting engineering write-up from Netflix on maintaining a real-time service topology in a large microservices ecosystem. The takeaway for me: observability isn't just about metrics, traces, and logs—understanding service relationships is equally critical as systems scale. Curious how others approach dependency mapping in production environments. https://netflixtechblog.com/from-silos-to-service-topology-why-netflix-built-a-real-time-service-map-0165ba13a7bc submitted by /u/m

The agentic identity crisis: Why your security isn’t ready for the AI revolution

The New Stack (Tier 1) · Publié : 2026-05-28 · 23.9/10

The transition from traditional web applications to agentic ecosystems is more than a change in the UI; it is a The post The agentic identity crisis: Why your security isn’t ready for the AI revolution appeared first on The New Stack .

Teams using opentelemetry in production

r/devops (Tier 1) · Publié : 2026-05-29 · 23.7/10

What's something you still can't easily answer even with traces? I mean an actual question that still takes time to investigate despite having logs, metrics & traces available. I want to understand where observability still falls short in practice. submitted by /u/outgrownman [link] [comments]

GPU autoscaling on Kubernetes with KEDA: Building an external scaler

CNCF Blog (Tier 1) · Publié : 2026-05-27 · 23.6/10

If you run GPU workloads on Kubernetes — vLLM, Triton, training jobs, or the newer agentic inference stacks — you’ve probably hit a familiar problem: the default autoscaling path still reasons about CPU and memory, while...

Did I just shoot myself in the foot

r/devops (Tier 1) · Publié : 2026-05-30 · 23.4/10

Hi everyone, I am looking for a reality check on a negotiation I just attempted. I’m an early career engineer and currently juggling two very different offers: Offer A (The Summer program): A 3 month Devops contract at a well known big AI company. It pays exceptionally well. However, there is no guarantee of a permanent role after the 3 months. I also already successfully negotiated pushing the start date back a month so I could finish up my current job, meaning I'd be starting in July. I am

Généré par veille-auto · Modèle : gemma4:e2b