Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes
Linux provides powerful kernel-level security mechanisms, seccomp, SELinux, and AppArmor, that restrict what containerized workloads can do. Each uses profiles that define permitted behavior, but writing, distributing, and maintaining those profiles by hand is tedious and…
In March, I gave a talk at KubeCon + CloudNativeCon Europe 2026 in Amsterdam. After the session, the same questions kept coming up on the CNCF Slack and in person: why build agentic AI on cloud…
Inspektor Gadget: Results from the first security audit
Inspektor Gadget, the open source eBPF-based toolkit for Kubernetes observability and Linux host inspection, has completed its first independent security audit. The audit was coordinated by the Open Source Technology Improvement Fund (OSTIF), funded by the…
Modern software delivery is no longer constrained by application code — it is constrained by the platform that runs it. This article presents the design of a cloud-native Internal Developer Platform (IDP) built on Kubernetes and…
Kubernetes 1.36 adds native GPU scheduling via Workload Aware Scheduling and DRA, plus stable fine-grained Kubelet authorization. Ryota Sawada, Release Lead, explains what changed.
Cloud Native Live: Falco’s Nest & the Evolution of Runtime Security
Falco, the Cloud Native Runtime Security project, is constantly evolving to meet the demands of modern cloud environments. This livestream dives into the latest advancements and strategic direction of the project, with a focus on two…
Techzine: “Kubernetes v1.36 enhances security and AI support”
The Kubernetes project has released version 1.36 with 70 improvements, comprising 18 stable features, 25 beta features, and 25 alpha features. The release focuses primarily on improved access control, visibility into hardware failures, and native support…
Efficiently Connected: “Runtime Security Meets AI as Kubernetes Extends to Agent Workloads”
Kubescape 4.0 introduces enterprise-grade runtime threat detection, Kubernetes-native security storage, and new capabilities to both secure AI agents and enable them to analyze cluster security posture.
KubeCon + CloudNativeCon Europe 2026 in Amsterdam opened on a note that felt almost too perfect.