Kubernetes
KOPS HARDENS CCM SCHEDULING, DRA GPU DRIVER SHIPS v0.4.1
Cloud-controller-manager pods across five cloud providers now tolerate all node taints, eliminating a class of scheduling failures on heavily tainted control planes.
read --wire →
$ tail -f topics/infra.log
Daily updates from the platform-engineering layer - Kubernetes, Terraform, Linux, Arch, and the tools that run production.
42 updates across 6 projects this week.
One calm review of what shipped across Infrastructure - the commits, releases, and security advisories that matter. Every Monday, with security advisories same-day. Free, unsubscribe in one click.
We'll start you on the top Infrastructure projects - refine anytime. · Read a sample issue →
Kubernetes
Cloud-controller-manager pods across five cloud providers now tolerate all node taints, eliminating a class of scheduling failures on heavily tainted control planes.
read --wire →
Go
The gopls language server has a mystery crash in its frob decoder that defenders are now treating as a hardware fault scenario, while the crypto team closes two SSH attack surfaces that silently drain memory and corrupt terminal output.
read --wire →
Linux
The kernel's input drivers got critical OOB access patches while NTB pulled in device removal fixes, as Linus opens the 7.2 merge window.
read --wire →
Arch Linux
A new kernel patch ships with unprivileged namespace isolation hardening, AMD display deadlock fixes, and UDP buffer handling corrections.
read --wire →
Kubernetes
New contributor joins kubernetes org while documentation teams push major localization updates and test infrastructure hardens Windows support.
read --wire →
Linux
Four subsystem pull requests landed overnight addressing hardware state machine corruption, heap leaks in audio sequencer core, and variable overflow bugs that could cause device misconfiguration.
read --wire →
Arch Linux
Two kernel releases landed overnight with the same critical fix: a new sysctl that disables unprivileged namespace cloning, closing a known local privilege escalation vector.
read --wire →
HashiCorp
Both the Podman driver and Autoscaler are publishing nightly snapshots, giving you a chance to validate upcoming changes before they land in stable releases.
read --wire →
Kubernetes
Kubernetes operations is moving away from direct Role comparisons to helper methods, preparing the infrastructure for supporting additional control plane types beyond the current master/worker split.
read --wire →
Go
golang/tools cut goimports execution time from seconds to subseconds by leveraging the module cache index that gopls already builds.
read --wire →
Linux
The kernel's SMB server implementation got a major protocol compliance overhaul after smbtorture exposed significant divergence from spec, while filesystems and power management shore up edge cases before the 7.2 release.
read --wire →
Arch Linux
Arch's package signing infrastructure absorbed a breaking change in the pgp crate that required immediate adjustments to Ed25519 key handling.
read --wire →
HashiCorp
Boundary's Kubernetes validation just got real - switching from KIND binaries to actual versioned nodes means the chart now proves it works on the K8s versions you're actually running.
read --wire →
Kubernetes
Kops now ships native Karpenter EC2NodeClass and NodePool support while kube-proxy eliminates its cadvisor dependency by reading CPU topology directly from cpuset.
read --wire →
Go
Go's crypto/autocert library ships a critical data race fix while the tools team systematically hardens Plan 9 support across gopls and the standard library.
read --wire →
Linux
Linux 7.2-rc1 merges critical SMB client and server patches alongside a major FUSE refactor that separates transport and filesystem layers for the first time.
read --wire →
Arch Linux
Three HLS plugins and xmonad-extras pushed to extra-staging-x86_64 in coordinated rebuild, while alpm.rs regenerates its FFI layer against bindgen 0.72.1.
read --wire →
HashiCorp
The Python Terraform Enterprise SDK can now automatically populate related resources when you request them with ?include= parameters, eliminating manual data assembly in your TFE integrations.
read --wire →
Kubernetes
Kops now lets you run dedicated API server nodes separate from control plane workers, solving a years-old load balancer problem that sent traffic to both when you only wanted one.
read --wire →
Go
Go 1.27 RC1 is available now [ref:11], and the vulnerability database just sealed two fresh CVEs while patching an insufficient fix from last month [ref:1] [ref:2] [ref:3].
read --wire →