Arch Linux
Yanked wnaf crate forces signstar dependency bump
Signstar's dependency on wnaf moves to 0.14.1 after 0.14.0 was yanked, while package updates land across Arch's extra repo.
read --wire →
$ tail -f topics/infra.log
Daily updates from the platform-engineering layer - Kubernetes, Terraform, Linux, Arch, and the tools that run production.
42 updates across 6 projects this week.
One calm review of what shipped across Infrastructure - the commits, releases, and security advisories that matter. Every Monday, with security advisories same-day. Free, unsubscribe in one click.
We'll start you on the top Infrastructure projects - refine anytime. · Read a sample issue →
Arch Linux
Signstar's dependency on wnaf moves to 0.14.1 after 0.14.0 was yanked, while package updates land across Arch's extra repo.
read --wire →
HashiCorp
The exec2 driver now reports actual RSS memory usage and fixes a sandboxing bug that silently blocked reads of /proc/self/mountinfo for approved workloads.
read --wire →
Kubernetes
kOps removes legacy PKI fallbacks that could wrongly trigger CA recreation, while Kubernetes publishing repos roll forward on structured-merge-diff v7, kube-openapi, and Go 1.27.
read --wire →
Go
TLS connections no longer pin record-sized buffers during blocked reads, and a compiler fix prevents linker drops that caused unreachable method panics.
read --wire →
CachyOS
CachyOS Linux ships 7.2.3-2 for the main branch, adding early Apple T2 CPU offlining and the new t2bce driver stack, while cachy-update rolls out to v4.2.1.
read --wire →
Linux
The mm hotfixes pull for 7.3 rc2 fixes a secretmem workaround that lets unprivileged users evade RLIMIT_MEMLOCK.
read --wire →
Arch Linux
The Arch Linux kernel v7.2.3-arch1 adds a sysctl option to disable unprivileged user namespaces, while package updates land for ImageMagick, Sundials, and a rewrite of the Hyprland wayland stack.
read --wire →
HashiCorp
Two releases landed today: Terraform's TFE provider gains Site Auditor SAML management and drops the frozen go-tfe v1 client, while Consul fixes confirmed grpc and crypto vulnerabilities.
read --wire →
Kubernetes
Kubernetes' discovery API graduates declarative validation to stable, replacing hand-written validation, and kOps adds experimental support for Amazon Linux 2027.
read --wire →
Go
A runtime fix stops duplicate interface method table entries for plugins, while pkgsite skips symbol insertion for modules over 30,000 symbols to prevent timeout.
read --wire →
CachyOS
CachyOS packaged Mesa 26.2.2-2, limine 12.7.0-1, and Go 1.27.1-1, continuing its rolling-release cadence.
read --wire →
Linux
Linux's rc2 pulls a hardening fix that disables randstruct when Rust is enabled, and two Omarchy lifecycle bugs could lock sessions or stall installs.
read --wire →
Arch Linux
buildbtw containers now start an SSH agent and point libgit2 at /root key paths, while Arch extra updates land libcerf, libde265, and bup.
read --wire →
HashiCorp
Two notable changes: Consul patched security vulnerabilities in its UI dependencies, and terraform-provider-aws now lets you enable S3 Object Lock without replacing the bucket.
read --wire →
Kubernetes
A single apimachinery change bringing declarative validation to the Condition.Message field shipped this week to five core Kubernetes repositories.
read --wire →
Go
A runtime memory layout bug and a coordinated export-data protocol change landed today, the latter breaking changes that ripple across Go tools and analysis.
read --wire →
CachyOS
CachyOS Settings 1.4.0 and key package refreshes shipped across the distribution's packaging repos today.
read --wire →
Linux
Linux 7.3-rc2 pulls ksmbd and cifs fixes that prevent data corruption and tighten security descriptor handling.
read --wire →
Arch Linux
Arch Linux package state updates remove gst-thumbnailers and talhelper, while archinstall reverts an archiso workflow fix and buildbtw adds a buildspaces listing endpoint.
read --wire →
HashiCorp
Five fixes across the prewritten Terraform policy library address null-value errors and delete policies that could not be managed via Terraform.
read --wire →