Search results for: security audit


Building a Scalable, Flexible, Cloud-Native GenAI Platform with Open Source Solutions

Posted on August 28, 2025 | Takeshi Yoneda, Envoy Maintainer and Open Source Software Engineer at Tetrate | Erica Hughberg, Envoy AI Gateway Maintainer at Tetrate | Alexa Griffith, Senior Software Engineer at Bloomberg

AI workloads are complex, and unmanaged complexity kills velocity. Your architecture is the key to mastering it. As generative AI (GenAI) becomes foundational to modern software products, developers face a chaotic new reality, juggling different APIs…


PaC and AI

Posted on August 12, 2025 | Jon Zeolla, Founder at Zenable and CNCF Ambassador | Pedro Ignácio, Senior Platform Engineer at Itaú Unibanco

In part three of this series on Policy as Code, we’ll look at the intersection between PaC and AI coding assistants. AI coding tools have fundamentally changed software development. “Vibe coding” or chat-based coding, where you…


Automating EKS CIS Compliance with Kyverno and KubeBench

Posted on August 4, 2025 | Yugandhar Suthari | Security Engineer at Cisco

A practical approach to implementing CIS security controls using CNCF cloud native tools. Introduction: The Challenge of EKS Compliance at Scale  Maintaining CIS Benchmarks compliance for Amazon EKS across multiple clusters is a common challenge in…


PaC in the Cloud Native Landscape

Posted on August 1, 2025 | Jon Zeolla, Founder at Zenable and CNCF Ambassador | Pedro Ignácio, Senior Platform Engineer at Itaú Unibanco

This is post 2 out of 3 with an Introduction to Policy as Code preceding this. Kubernetes continues to grow, but it has already become the main component of cloud native architectures. Maintaining your cluster is…


Kgateway – The Next-Gen Gateway for Kubernetes, AI, and Agents

Posted on July 23, 2025 | Craig Box - Senior Director of Developer Relations at Solo.io | CNCF Governing Board

Kgateway may be new to the CNCF, but it’s not new to the market: it was born as “Gloo” in 2018, a project to provide modern API management within Kubernetes. Gloo built a large user base…


From YAML to Intelligence: The Evolution of Platform Engineering 

Posted on July 22, 2025 | Prithvi Raj (CNCF Ambassador, Community Manager at Mirantis

The next big thing in the platform engineering ecosystem as they say is AI Agents for Platform Engineering. How to build them, how to run them on Kubernetes, best practices, the journey from microservices to microagents,…


Why Policy as Code is a Game Changer for Platform Engineers

Posted on July 8, 2025 | Jim Bugwadia, co-founder and CEO of Nirmata

Originally posted on Nirmata’s blog. Platform engineers, let’s talk about a fundamental shift that’s revolutionizing how we build and manage internal developer platforms: Policy as Code (PaC). This isn’t just another buzzword; it’s the key to…


GitOps in 2025: From Old-School Updates to the Modern Way

Posted on June 9, 2025 | Gerardo Lopez and Saloni Narang

1. Introduction: Why Everyone’s Talking About GitOps in 2025 It’s 2025, and building software is more cloud-driven than ever. Cloud computing offers incredible speed and flexibility, but it also brings complexity. Companies are expected to ship…


Announcing Kyverno Release 1.14!

Posted on May 14, 2025

TL;DR We are excited to announce the release of Kyverno 1.14.0, marking a significant milestone in our journey to make policy management in Kubernetes more modular, streamlined, and powerful. This release introduces two new policy types…


10 Years in Cloud Native: TOC Restructures Technical Groups

Posted on May 7, 2025 | Karena Angell, Chair, CNCF Technical Oversight Committee

The CNCF Technical Oversight Committee (TOC) is the technical governing body responsible for maintaining the technical vision of the CNCF. At the time the CNCF was founded in 2015 and as of 2016, there were four…