Found 2591 posts
Community Post
OTel and mesh-derived metrics: A 2026 reference
If you already run an OpenTelemetry pipeline, you have good visibility into what your applications are doing. This blog post is about what you don’t see yet: the east-west traffic between your services, measured at the...
June 29, 2026 | Mesut Oezdil, DevOps Engineer (written on behalf of Buoyant)
Project Post
etcd-operator joins Cozystack with a new v1alpha2 API
The etcd-operator project, which develops an operator for deploying and maintaining etcd clusters on Kubernetes, has been donated to the Cozystack project. Alongside the donation, a from-scratch implementation of the operator has been published under a...
June 29, 2026 | Andrey Kolkov and Andrei Kvapil, Ænix
Member Post
Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes
Linux provides powerful kernel-level security mechanisms, seccomp, SELinux, and AppArmor, that restrict what containerized workloads can do. Each uses profiles that define permitted behavior, but writing, distributing, and maintaining those profiles by hand is tedious and...
June 26, 2026 | Sascha Grunert (Red Hat)
Member Post
Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next
This is the third and final post in a series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control and Part 2 covered dependency hardening. This post covers the last layer: keeping CI...
June 26, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)
Ambassador Post
Building a Cluster-Aware AI Agent with Kubernetes, Argo CD, and GitOps
A practical walkthrough of running a self-hosted, read-only AI agent inside a Kubernetes cluster, with the full CI/CD chain handled by GitHub Actions and Argo CD Image Updater. No data leaves the cluster, no cloud AI...
June 25, 2026 | Maryam Tavakkoli (CNCF Ambassador | Lead Cloud Engineer @ RELEX Solutions)
Community Post
From Awareness to Engineered Accessibility in Open Source
The open-source ecosystem thrives on a deceptively simple premise: anyone, anywhere, can show up and contribute. But that promise quietly breaks down at the edges. A contributor who needs written context before a synchronous call, or...
June 24, 2026 | Diana Todea (DevRel Engineer at VictoriaMetrics and Merge-Forward Neurodiversity chapter lead), and Ryan Etten (Senior Architect & Team Lead at Red Hat and Wisconsin CNCF chapter community organizer)
Project Maintainer Post
Building Jaeger’s ClickHouse backend: 8.6× compression on 10 million spans
As someone who’s been maintaining Jaeger, I’ve watched users request ClickHouse support consistently over the past few years. With Jaeger v2.18.0, we’ve finally delivered it. What excites me most isn’t just that ClickHouse is available—it’s that its architecture is...
June 23, 2026 | Mahad Zaryab, CNCF Jaeger Project Maintainer and Software Engineer at Meta
Ambassador Post
Agent Auth: A lawyer’s day in court
I’ve always thought about AI agents as microservices+. They need everything a traditional microservice needs, and: When thinking about agent auth, I found myself reflecting on a traffic lawyer I hired years ago after receiving a...
June 23, 2026 | Lin Sun, CNCF Ambassador
Community Post
Telemetry that matters: Designing sustainable, high-impact observability pipelines
As system architectures grow increasingly complex, the cloud-native community faces a subtle but pressing challenge: we are drowning in our own telemetry data. It is easier than ever to instrument an application and collect signals, but...
June 22, 2026 | Diana Todea - DevRel Engineer at VictoriaMetrics and Cloud Native Days Romania community organizer, Laura Luttmer - Principal Product Manager at Bindplane (Dynatrace), Antonio Jimenez Martinez - Tech Lead Software Engineer at Cisco ThousandEyes
Staff Post
Expanding CARE: Passing CKS can now extend your CKA certification
A few months ago, CNCF introduced the CARE Program — Certification Advancement & Recertification Experience — to make it easier for certified professionals to keep their credentials current as they continue growing their cloud native skills....
June 17, 2026 | Christophe Sauthier, Cloud Native Training and Certification Lead
Why cloud native belongs at the heart of agentic AI: Lessons from building a multi-agent security platform on Kubernetes
In March, I gave a talk at KubeCon + CloudNativeCon Europe 2026 in Amsterdam. After the session, the same questions kept coming up on the CNCF Slack and in person: why build agentic AI on cloud...
June 17, 2026 | Willem Berroubache, Lead Security Architect (Orange Innovation) and CNCF Golden Kubestronaut.
Community Post
From data residency to digital sovereignty: Architectural patterns for cloud native platforms
Over the past two years, digital sovereignty has evolved from a policy discussion into a practical platform engineering concern. The EU Data Act has been fully applicable since January 11, 2025. NIS-2 and DORA already shape...
June 16, 2026 | Hrittik Roy, CNCF Ambassador
Member Post
Improving Arm64 support in CNCF projects with OCI credits
In recent years, Arm64 has been taking the cloud service provider world by storm. Recent reports indicate that, as of the end of 2025, over 50% of new instances on AWS and over 33% on Azure...
June 15, 2026 | Dave Neary, Director of Developer Relations at Ampere Computing
Member Post
Securing CI/CD for an open source project: Locking down dependencies
Part two This is the second post in a three-part series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control: who can trigger builds and what code CI is allowed to execute. This...
June 12, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)
Project Post
Introducing Verifiable Execution in Dapr 1.18
Bringing attestation, provenance, and tamper-evident execution history to workflows and AI agents For years, the cloud native ecosystem has focused on making distributed systems resilient. Applications recover from failures. Services retry requests. Workflows survive crashes and...
June 11, 2026 | epower
Member Post
Solving secret sprawl in multi-account Kubernetes with External Secrets Operator
Infrastructure provisioning in Kubernetes has become increasingly automated, but secret management often remains a challenge as environments grow. Organizations commonly separate development, staging, and production workloads across clusters, namespaces, or cloud accounts to improve security and...
June 9, 2026 | Viktoria Bisova, DevOps Engineer, Itigix
Member Post
Breaking free of a single datacenter: Practical geo-distributed AI operations with the k0smos platforms
Breaking the single datacenter assumption Modern AI architectures are built on the assumption of centralized, homogeneous data centers. In reality, infrastructure is messy. For most organizations, compute resources are fragmented across private clouds, research environments, and...
June 8, 2026 | Prithvi Raj (Mirantis), Alexander Acker (Logsight.ai), and Soeren Becker (Logsight.ai)
Member Post
Benchmarking KubeVirt performance with virtbench
Organizations migrating VM estates from traditional hypervisors to KubeVirt often discover that many Kubernetes observability tools were originally designed around container workloads rather than VM-centric operational metrics. While KubeVirt schedules VMs as pods, the performance variables...
June 8, 2026 | Bob Glithero, Senior Technical Product Marketing Manager, Portworx by Everpure
Identity and Access Management Whitepaper
As cloud native architectures become more distributed, dynamic, and automated, identity increasingly becomes the new security perimeter. Traditional approaches to authentication and authorization struggle to keep pace with short-lived workloads, service-to-service communication, and zero-trust requirements. The...
June 4, 2026 | CNCF TAG Security and Compliance
Member Post
Securing CI/CD for an open source project: Controlling who runs what
Part one The last twelve months have been rough on the open source supply chain. Axios was compromised on npm and shipped a remote access trojan inside otherwise normal-looking releases. LiteLLM’s PyPI package was hijacked to...
June 4, 2026 | André Martins, Cilium maintainer and Software Engineer, Isovalent at Cisco and Feroz Salam, Cilium Security Team and a Security Engineer, Isovalent at Cisco.