HashiCorp
Consul API gateway backport isolates failing routes
A backported fix stops a single misconfigured route from taking down an entire API gateway listener.
read --wire →
$ tail -f topics/go.log
Daily updates from Go and the cloud-native infrastructure written in it - Kubernetes, HashiCorp's stack, and the Go standard library.
21 updates across 3 projects this week.
One calm review of what shipped across Go - the commits, releases, and security advisories that matter. Every Monday, with security advisories same-day. Free, unsubscribe in one click.
We'll start you on the top Go projects - refine anytime. · Read a sample issue →
HashiCorp
A backported fix stops a single misconfigured route from taking down an entire API gateway listener.
read --wire →
Kubernetes
kube-state-metrics ships three new experimental PVC metrics for VolumeAttributesClass and kops adds initial Akamai firewall support.
read --wire →
Go
The Go compiler reorganizes its SSA rewrite packages and the net package fixes a data race in QUIC stream resets.
read --wire →
Go
golang/net fixes a data race in HTTP/3 by clearing the fast-path receive buffer when a stream is reset.
read --wire →
HashiCorp
HashiCorp's automated licensing review is adding or fixing copyright headers across multiple repositories, including go-changelog and vault-servicenow-credential-resolver.
read --wire →
Kubernetes
The most impactful merge today is the Spanish localization of the SIG Docs participation page, expanding contributor documentation to a wider audience.
read --wire →
HashiCorp
Routine maintenance landed, with no material API, security, or major-release change.
read --wire →
Kubernetes
The VPA Helm chart now manages CRDs as templates so upgrades keep them in sync, while kOps test infra adds full Amazon Linux 2027 support and minikube fixes a Hugo security break.
read --wire →
Go
Three crypto/x509 commits from Daniel McCarney align name-constraint handling with RFC 5280, restricting URI and email constraints to exact hosts and rejecting empty GeneralSubtrees sequences.
read --wire →
HashiCorp
The exec2 driver now reports actual RSS memory usage and fixes a sandboxing bug that silently blocked reads of /proc/self/mountinfo for approved workloads.
read --wire →
Kubernetes
kOps removes legacy PKI fallbacks that could wrongly trigger CA recreation, while Kubernetes publishing repos roll forward on structured-merge-diff v7, kube-openapi, and Go 1.27.
read --wire →
Go
TLS connections no longer pin record-sized buffers during blocked reads, and a compiler fix prevents linker drops that caused unreachable method panics.
read --wire →
HashiCorp
Two releases landed today: Terraform's TFE provider gains Site Auditor SAML management and drops the frozen go-tfe v1 client, while Consul fixes confirmed grpc and crypto vulnerabilities.
read --wire →
Kubernetes
Kubernetes' discovery API graduates declarative validation to stable, replacing hand-written validation, and kOps adds experimental support for Amazon Linux 2027.
read --wire →
Go
A runtime fix stops duplicate interface method table entries for plugins, while pkgsite skips symbol insertion for modules over 30,000 symbols to prevent timeout.
read --wire →
HashiCorp
Two notable changes: Consul patched security vulnerabilities in its UI dependencies, and terraform-provider-aws now lets you enable S3 Object Lock without replacing the bucket.
read --wire →
Kubernetes
A single apimachinery change bringing declarative validation to the Condition.Message field shipped this week to five core Kubernetes repositories.
read --wire →
Go
A runtime memory layout bug and a coordinated export-data protocol change landed today, the latter breaking changes that ripple across Go tools and analysis.
read --wire →
HashiCorp
Five fixes across the prewritten Terraform policy library address null-value errors and delete policies that could not be managed via Terraform.
read --wire →
Kubernetes
Kubernetes removed the PodSchedulingReadiness feature gate and rotated SIG Storage leadership while CI hardening shipped in the release repo.
read --wire →