Search results for: security audit


Cloud Native Computing Foundation announces Prometheus graduation

Posted on August 9, 2018

Widely-adopted open source monitoring and alerting tool used by cloud native leaders like DigitalOcean, Red Hat, SUSE, and Weaveworks SAN FRANCISCO, Calif., August 9, 2018 – The Cloud Native Computing Foundation® (CNCF®), which sustains open source…


Building a cloud native platform from the ground up with Kairos, k0rdent, and bindy

Posted on May 13, 2026 | Erick Bourgeois, Director & Head of Kubernetes Platform Engineering, RBC Capital Markets

As we shared in our earlier post on FluxCD, RBC Capital Markets has been on a deliberate journey to modernize our Kubernetes platform. GitOps with FluxCD gave us a solid deployment foundation. But as our platform grew,…


Announcing Kyverno release 1.18!

Posted on May 5, 2026 | Cortney Nickerson, Kyverno Contributor

We’re excited to announce the release of Kyverno 1.18, our first release since graduating within the Cloud Native Computing Foundation. This release builds on Kyverno’s growing role as a Kubernetes-native policy engine, with major investments in…


Securing GitHub Actions CI dependencies: Recipe card

Posted on May 4, 2026 | Marina Moore, Evan Anderson, and Sherine Khoury, CNCF Technical Advisory Group

Recipe GitHub Actions CI dependencies Target audience (the chef) Project maintainers and developers who need practical, concrete steps to efficiently secure CI dependencies within their GitHub Actions workflows Scope (ingredients) Dependencies within the GitHub Actions, Github…


Adobe

Posted on April 30, 2026

The challenge Flex CI & CD transformed software delivery at Adobe by making GitOps the foundation of how teams deploy and manage applications. We established Git as the source of truth, adopted declarative infrastructure and application…


From Ingress NGINX to Higress: migrating 60+ resources in 30 minutes with AI

Posted on April 23, 2026 | Tianyi Zhang, Alibaba

With the official retirement of Ingress NGINX that took place in March 2026, enterprise platform teams are facing an urgent security and compliance mandate. Remaining on a retired controller leaves critical infrastructure vulnerable to unpatched security…


Infosys Ltd. Client

Posted on April 9, 2026

The Challenge: Fragmented tooling and compliance risk at scale The client’s platform engineering team managed a sprawling cloud-native estate with over 1,000 GitLab projects, hundreds of Kubernetes workloads, Kafka streams, Databricks and Spark jobs, and Aurora…


GitOps policy-as-code: Securing Kubernetes with Argo CD and Kyverno

Posted on April 2, 2026 | Ivan Roussev, Igtix

A hands-on guide to deploying Kyverno with Argo CD and enforcing custom policies As Kubernetes environments develop, GitOps with Argo CD has become the standard for declarative, self-healing infrastructure. Yet without guardrails for your deployments, misconfigured,…


LLMs on Kubernetes Part 1: Understanding the threat model

Posted on March 30, 2026 | Nigel Douglas, CloudSmith

Let’s say you’ve got an LLM running on Kubernetes. Pods are healthy, logs are clean, users are chatting. Everything looks fine. But here’s the thing: Kubernetes is great at scheduling workloads and keeping them isolated. It…


The weight of AI models: Why infrastructure always arrives slowly

Posted on March 27, 2026 | Wenbo Qi (Dragonfly/ModelPack Maintainer), Chenyu Zhang (Harbor/ModelPack Maintainer) and Feynman Zhou (ORAS Maintainer and CNCF Ambassador)

As AI adoption accelerates across industries, organizations face a critical bottleneck that is often overlooked until it becomes a serious obstacle: reliably managing and distributing large model weight files at scale. A model’s weights serve as…