Veille Technologique — Bilan hebdomadaire

Semaine 2026-W27 · du 2026-06-29 au 2026-07-05

27 feeds · 184 articles traités · 40 sélectionnés · gemma4:e2b · 2026-06-29T08:26:44.688Z

Divers

Grafana 13.1 release: observability as code updates, extending Grafana Assistant across more data sources, and more

Grafana Blog (Tier 1) · Publié : 2026-06-24 · 88.5/10

Earlier this year, Grafana 13 laid the groundwork for making it easier and faster than ever to turn your data into actionable insights. With our latest minor release, Grafana 13.1, we're building on that foundation, expanding observability as code, bringing Grafana Assistant to more data sources, and streamlining the everyday workflows teams rely on to visualize, analyze, and act on their data. Below are just some of the highlights from Grafana 13.1. If you want to explore all the latest updates

Post-incident review for TanStack npm supply chain ransom incident: No unauthorized access to customer production systems

Grafana Blog (Tier 1) · Publié : 2026-06-23 · 84.7/10

On May 27, we completed our internal investigation of the recent TanStack supply chain ransom incident and confirmed our initial findings: The incident was strictly limited to Grafana Labs' GitHub environment. There was no unauthorized access to customer production systems, and the Grafana Cloud platform was not affected. For an additional, independent audit, we engaged Mandiant, a leader in cybersecurity and incident response. We provided them with API access to Grafana Labs' log environment to

Transitioning from 6.5 years in IT Infra to DevOps. I built an end-to-end GitOps pipeline on Azure & some Python automation. Looking for architectural roasts.

r/devops (Tier 1) · Publié : 2026-06-25 · 68.0/10

​Hey everyone, ​I’ve spent the last 6.5+ years deep in traditional IT infrastructure—managing servers, troubleshooting production environments, and obsessing over strict uptime. Over the last several months, I’ve been pivoting into Cloud/DevOps to learn how to build and automate from scratch. ​Instead of just grinding multiple-choice certs, I treated my homelab like a production environment. I’d love some brutal, honest feedback on my setup from the seniors here. ​Project 1: End-to-End GitOps on

Introducing the Cluster API plugin for Headlamp

Kubernetes Blog (Tier 1) · Publié : 2026-06-25 · 64.6/10

Headlamp is an open-source, extensible Kubernetes SIG UI project designed to let you explore, manage, and debug cluster resources directly from a browser. Cluster API (CAPI) is a Kubernetes sub-project that brings declarative, Kubernetes-style APIs to cluster lifecycle management. It lets platform teams provision, upgrade, and manage the lifecycle of Kubernetes clusters using standard Kubernetes objects stored and reconciled in a management cluster. Managing Cluster API resources has historicall

DevOps or SAP Basis? Feeling stuck at a career crossroads

r/devops (Tier 1) · Publié : 2026-06-26 · 63.4/10

I've been working in IT infrastructure for several years, mainly on Linux systems, databases, production support, and enterprise applications. Recently, I've been thinking seriously about where I should specialize next, but I'm genuinely torn between two paths: DevOps and SAP Basis . DevOps seems to have a huge ecosystem with skills like Docker, Kubernetes, CI/CD, cloud, automation, and SRE. It feels like a path with plenty of opportunities across industries and good long-term growth

Open source maintainership in the age of AI

Kubernetes Blog (Tier 1) · Publié : 2026-06-26 · 62.2/10

AI has really changed the game around software development. More people are leveraging AI than ever to contribute patches to projects they use. To me, this is a good thing as more folks will contribute patches rather than fork or not fix them. The main problem is that AI has made generating code fast but there has been very little improvement in maintaining code bases. In this post, we will highlight the ways the Kubernetes community is adapting to the world of AI assisted coding. The first step

Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes

CNCF Blog (Tier 1) · Publié : 2026-06-26 · 56.5/10

Linux provides powerful kernel-level security mechanisms, seccomp, SELinux, and AppArmor, that restrict what containerized workloads can do. Each uses profiles that define permitted behavior, but writing, distributing, and maintaining those profiles by hand is tedious and...

Terraform MCP server: Four real-world AI infrastructure patterns

HashiCorp Blog (Tier 1) · Publié : 2026-06-26 · 55.1/10

Discover how Terraform MCP Server helps AI agents make better infrastructure decisions using trusted organizational context and guardrails.

Deploy Boundary on Kubernetes with official Helm charts

HashiCorp Blog (Tier 1) · Publié : 2026-06-25 · 54.6/10

HashiCorp Boundary now offers official Helm charts for deploying controllers and workers on Kubernetes. Learn which chart fits your deployment model and how to get started.

Boundary 1.0 releases RDP session recording and improved management

HashiCorp Blog (Tier 1) · Publié : 2026-06-25 · 50.1/10

Boundary 1.0 releases with support for RDP session recording and a preview ahead towards securing AI agent access in a brave new agentic world.

Inspect Volcano workloads faster with Headlamp

Kubernetes Blog (Tier 1) · Publié : 2026-06-25 · 48.5/10

Volcano is a cloud native batch scheduler for Kubernetes, built for high-performance computing, AI/ML, and other batch workloads. Headlamp is an extensible Kubernetes web UI. With its plugin system, Headlamp can surface APIs and workflows beyond the built-in Kubernetes resources. The Volcano plugin brings core Volcano resources into Headlamp so you can inspect workload state, queue behavior, and gang scheduling details in one place. Kubernetes was originally designed around long-running services

From Phishing to Vishing: Why DevSecOps Must Rethink Communication Security

DevOps.com (Tier 1) · Publié : 2026-06-26 · 43.9/10

Key Takeaways: Vishing is the new frontline threat: Attackers are shifting from emails to phone-based scams, using AI and social engineering to bypass traditional security controls. DevSecOps must expand its scope: Securing code is no longer enough; communication channels like voice, chat, and messaging must be integrated into threat models and security pipelines. Human and […]

Update on Project Yellow Olive: I added Kubernetes Deployment challenges to my Pokemon Yellow inspired TUI game

r/devops (Tier 1) · Publié : 2026-06-25 · 42.4/10

Hello r/devops , Disclosure: I’m the creator of Project Yellow Olive, a Pokémon-inspired terminal game for learning Kubernetes. I’ve posted about this before, but I wanted to share a more technical update because I recently added a Deployments chapter. The new chapter focuses on: scaling replicas understanding ReplicaSets rollout status rollback scenarios debugging failed deployments blue/green and canary-style deployment concepts The idea is to make Kubernetes practice feel less like memorising

Kubernetes teams trust automation to ship code but not to touch CPU, and AI is raising the stakes

The New Stack (Tier 1) · Publié : 2026-06-23 · 41.3/10

Kubernetes teams automate deployments without thinking about it. CI/CD pipelines fire dozens of times a day, autoscaling adjusts replicas in The post Kubernetes teams trust automation to ship code but not to touch CPU, and AI is raising the stakes appeared first on The New Stack .

Building a Cluster-Aware AI Agent with Kubernetes, Argo CD, and GitOps

CNCF Blog (Tier 1) · Publié : 2026-06-25 · 41.1/10

A practical walkthrough of running a self-hosted, read-only AI agent inside a Kubernetes cluster, with the full CI/CD chain handled by GitHub Actions and Argo CD Image Updater. No data leaves the cluster, no cloud AI...

HCP Vault Dedicated introduces cluster disaster recovery (public preview)

HashiCorp Blog (Tier 1) · Publié : 2026-06-25 · 38.0/10

Cluster DR for HCP Vault Dedicated (public preview) enables DR drills at the cluster level, so teams can simulate cluster failures and prove failover readiness.

Mentor help for DevOps

r/devops (Tier 1) · Publié : 2026-06-29 · 37.5/10

Hello, I currently have 4 years of experience ( bits and pieces in everything ) most in DevOps. Some in vulnerability fixes etc.. Started out fresh out of college. Got into a decent team old tech but good team. Kept working for a while and felt I could do it in IT. On my request I went to a different team which was DevOps work(still work for old sometimes). Started out fine , I learnt many things I started delivering good works in short spans. Enjoyed the time. I felt intimidated many times beca

devops browser game that uses AI to argue with you on your decisions unless you are confident

r/devops (Tier 1) · Publié : 2026-06-27 · 37.3/10

hi all I built a browser game where you argue with AI on a given challenge/scenario and it rates your responses. right now the scenarios are about devops/engineering, but I am planning to add interview kit, from 0 to hero, etc... how it is different from just using chatgpt: when you ask chatgpt for a scenario and then give your answer, it mostly agrees with you. it wants to be nice, so even if your answer is bad it says "good point" and you walk away thinking you did well. it also does

DevOps: watching builds all day?

r/devops (Tier 1) · Publié : 2026-06-27 · 37.1/10

I'm not primarily a devops engineer, but whenever I do devops stuff, I realize I'm usually waiting for builds to complete and I can't easily switch to another task when things are building because something might actually happen that requires attention. How do full-time devops engineer handle this? I'm genuinely curious. I feel like most of the day is spend watching builds go through. submitted by /u/tammoton [link] [comments]

practical knowledge resources and roadmaps for linux

r/devops (Tier 1) · Publié : 2026-06-28 · 36.1/10

what roadmaps and useful material do you suggest for taking my linux knowledge to the next level if im not focusing on certs and just wanna improve my usable linux knowledge in dev/network field. i already work with linux and have somewhat beginner knowledge but just wanted to improve it in a funcinal/practical/applied way submitted by /u/Muted-Way3474 [link] [comments]

DevOps culture stuff

r/devops (Tier 1) · Publié : 2026-06-25 · 36.0/10

I know that DevOps has become a role now and I'm cool with that. There are a typical set of tasks we do that employers need done, so why not? But what has become of the culture part of DevOps? Shift left. Fail fast. Break down silos. Etc. Have we achieved all those things and so we don't need to talk about them anymore? When people ask "How do I learn DevOps" do we just assume they'll pick up on the culture stuff on the job? Has the culture stuff moved to other tech managem

Advancing AI agent security in Vault

HashiCorp Blog (Tier 1) · Publié : 2026-06-24 · 33.3/10

HashiCorp Vault Enterprise advances AI agent security with recent enhancements now available in public preview.

Starting new chapter as DevOps manager

r/devops (Tier 1) · Publié : 2026-06-26 · 32.1/10

Hear me out. After 20+ years of working as senior individual contributor and technical lead, I am moving into DevOps management. I am joining new organisation, so I am at a disadvantage of not knowing absolutely anyone. It’s in banking. Team of ~10. I am both most senior DevOps manager and engineer, so I hold authority in both, at least as far as Platform Engineering goes. What would your advice be in how to handle 1st day, 1st week, 1st month? submitted by /u/Motor_Interest9817 [lin

What should I do if higher ups think in silos?

r/devops (Tier 1) · Publié : 2026-06-27 · 32.0/10

I work in a European gov company for some years now and I really like it there. In my previous roles as DevOps engineer in different product teams I did my best to automate stuff within the boundaries of my team. 2-3 months ago I switched role to plattform engineer. During the interview for this new role HR asked me why I think they should choose me for the position. I answered that apart of being experienced with all the devops tooling I worked already in three product teams in this company and

Spotlight on WG Device Management

Kubernetes Blog (Tier 1) · Publié : 2026-06-24 · 29.7/10

The rising popularity of AI, Edge, and Telecommunications workloads on Kubernetes has led to new requirements for hardware management. We now need hardware specification beyond CPU time and memory allocations. This includes allocating GPUs, TPUs, network interfaces, and other hardware, sometimes after pod start and occasionally through time-sharing. Efficiently managing this specialized hardware is the mission of the Device Management Working Group . Their cornerstone project, Dynamic Resource A

Terraform / OpenTofu vs Pulumi

r/devops (Tier 1) · Publié : 2026-06-25 · 29.3/10

You have a chance to plan and implement IaC on a project from scratch In what case you will choose Pulumi over Terraform/OpenTofu? My thoughts about this: 1. Pulumi gives possibility to manage more complex logic in infra, conditions, loops, reusable 2. More human readable (compare to HCL), good for involving developers in IaC 3. Creating abstract objects like “testEnvForQa”, that can be parametrized, instead of pack of terraform modules submitted by /u/Informal-Tea755 [link] [c

Trust in Rust: Foundation debuts official training to tackle steep learning curve

The New Stack (Tier 1) · Publié : 2026-06-25 · 28.2/10

The Rust Foundation on Thursday announced the launch of the Rust Foundation Trusted Training (RFTT) program, a new formal accreditation The post Trust in Rust: Foundation debuts official training to tackle steep learning curve appeared first on The New Stack .

See your serverless: introducing the Headlamp plugin for Knative

Kubernetes Blog (Tier 1) · Publié : 2026-06-25 · 27.4/10

Headlamp is an open-source, extensible Kubernetes SIG UI project designed to let you explore, manage, and debug cluster resources. Knative brings serverless workloads to Kubernetes, handling traffic routing, autoscaling, and revision management so teams can deploy and iterate without fighting infrastructure. But operating Knative workloads day-to-day can be difficult, there's still a lot of jumping between the kn CLI, kubectl , and the Kubernetes UI to get a full picture of what's running. We bu

Les flux RSS c'est la vie !

Korben (Tier 1) · Publié : 2026-06-28 · 27.4/10

J'aime bien lire les articles de l'EFF (l'Electronic Frontier Foundation, la Quadrature du Net des américains quoi...) et là ils viennent de publier un truc qui m'a fait plaisir : un vrai plaidoyer pour la défense du RSS . Vous connaissez mon avis là-dessus et c'est vrai que depuis que Google a signé l'arrêt de mort de cette techno au profit d'algo à la con type Discover , y'a énormément moins de monde qui l'utilise. Et je trouve ça triste.

JaiLIP - L'image piégée qui débride les IA qui voient

Korben (Tier 1) · Publié : 2026-06-28 · 27.3/10

Md Jueal Mia et Hadi Amini, deux chercheurs de Florida International University , ont mis au point une méthode qu'ils ont baptisée JaiLIP qui permet de forger une image capable de contourner les garde-fous des LLM pour les jailbreaker. Pour cela, ils utilisent 2 techniques en simultanée. La première dit à l'image « reste identique à l'originale, qu'aucun humain ne voie la moindre différence » et la seconde dit « pousse le modèle à cracher la réponse interdite ». Ainsi, en poussant ces 2 curseurs

La faille d'Amazon Q : ouvrir un projet suffisait à se faire voler ses accès au cloud

Korben (Tier 1) · Publié : 2026-06-27 · 26.7/10

Amazon Q, l'assistant de programmation dopé à l'IA que propose Amazon, pouvait se faire piéger d'une manière aussi simple qu'embarrassante. Petit rappel pour situer. Amazon Q se greffe dans Visual Studio Code, l'éditeur de code de Microsoft que les développeurs utilisent au quotidien, et sert à écrire ou corriger du code à votre place. Des chercheurs de Wiz, une société spécialisée dans la sécurité du cloud, ont découvert que cet assistant exécutait des commandes cachées à la simple ouverture d'

To all former DevOps Engineers

r/devops (Tier 1) · Publié : 2026-06-24 · 26.6/10

What made you switch from DevOps to your current role? Do you regret leaving DevOps or are you happy that you made the switch? Genuinely interested if other roles are worth getting into. submitted by /u/Noisy_Farts [link] [comments]

Don't Wrap OpenTelemetry — You're Probably Hurting More Than Helping

OpenTelemetry Blog (Tier 1) · Publié : 2026-06-24 · 26.4/10

There’s a pattern I’ve seen across many teams adopting OpenTelemetry, and it’s well-intentioned every single time. An engineer wants to make things easier for the team. They build a thin abstraction over the OTel API — an IMetric interface, a TelemetryHelper class, a MetricsWrapper module — and ship it as the team’s standard. “Just use this,” they say. “It’s simpler.” The intention is genuine. The outcome is usually not good.

GBCYouTube - YouTube en direct sur une Game Boy Color

Korben (Tier 1) · Publié : 2026-06-28 · 26.2/10

Un bidouilleur du nom de Throaty Mumbo a décidé de s'attaquer à la Game Boy Color (sortie en 1998, ça ne nous rajeunit pas) pour y faire tourner YouTube ! Et du vrai YouTube hein, en streaming, sur 160x144 pixels. Ça s'appelle GBCYoutube et je vous explique tout en détail... Ce qu'il a fait en fait, c'est se bricoler une cartouche maison avec dedans, un microcontrôleur RP2350B (le cerveau du Raspberry Pi Pico 2) qui fait tourner le lecteur, et une puce ESP32-C6 qui sert juste de pont WiFi. Vous

What are DevOps interviews like?

r/devops (Tier 1) · Publié : 2026-06-25 · 25.2/10

I’ve been working full time for a year, but during that year I’ve been “motivated” to use Claude code to do basic code and while I understand the code, I forgot how to write code and never was a fan of memorizing leetcode to land a position. 2 days ago I got a call about an interview for a DevOps position and while all my friends who have had interviews never had an actual coding question given, but rather all scenarios and system design, I read online that a lot of interviews still put you on t

How AI Is Transforming DevOps and Cloud Engineering

DevOps.com (Tier 1) · Publié : 2026-06-26 · 24.9/10

While AI is often associated with chatbots or generative models, one of its most significant impacts is happening behind the scenes — within DevOps and cloud engineering.

SRE Weekly Issue #523

SRE Weekly (Tier 1) · Publié : 2026-06-29 · 23.8/10

View on sreweekly.com A message from our sponsor, Buildkite: More places to run, more scale to manage and maintain, usually means more blind spots; not here. Buildkite’s control plane holds the live state of every job, agent and queue, regardless of throughput size. See what’s running, what’s waiting and why with immediate insight → https://buildkite.com/platform/pipelines/ […]

Game Porting Toolkit 4 - Les jeux Windows enfin fluides sur Mac

Korben (Tier 1) · Publié : 2026-06-26 · 23.8/10

Il y a deux ans, Apple lâchait le Game Porting Toolkit en jurant ses grands dieux qu'on pourrait faire tourner des jeux Windows sur un Mac Apple Silicon. À l'époque je vous disais que le gaming Windows sur Mac, c'était donc plié. Hé bien la version 4.0 vient de sortir en bêta, et cette fois les chiffres donnent raison à cette promesse ! La nouvelle version du traducteur maison de GPTK (baptisé D3DMetal 4) transforme dorénavant le DirectX 12 des jeux en Metal 4, le moteur graphique d'Apple.

BioPass - Déverrouiller son Linux avec sa tronche et son doigt

Korben (Tier 1) · Publié : 2026-06-26 · 23.7/10

Contrairement à ce que dit Yann Barthès, on n'est pas tous égaux face à la canicule. Et l'autre truc face auquel on n'est pas tous égaux non plus, c'est le déverrouillage biométrique de son ordi. On les connaît les Linuxiens qui regardent avec jalousie leur collègue sous Windows qui déverrouille sa machine d'un simple coup d’œil à la webcam. Eux, ils sont obligés de taper leur mot de passe de 56 caractères et ça leur fout la rage, alors ils vont sur Reddit pour dire du mal de tous ceux qui n'ont

Containers and Internal Certificate Authorities

r/devops (Tier 1) · Publié : 2026-06-25 · 22.9/10

Hi, We are in the process of deploying an internal PKI, and as such issuing our in house Certificate Authority. One problem which have arisen is how to handle this inside of containers and I'm curious to see how the folks in this subreddit handled it. I've asked this question to a couple of LLMs but so far none of the solutions seem very viable. The one that so far seems the most reliable is building your own golden base images for our various needs and injecting the CA straight into the

Généré par veille-auto · Modèle : gemma4:e2b