<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Cloud Native with Carlos Santana]]></title><description><![CDATA[Kubernetes and Cloud Native News, Assets, and Skills]]></description><link>https://news.santana.dev</link><image><url>https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659</url><title>Cloud Native with Carlos Santana</title><link>https://news.santana.dev</link></image><generator>Substack</generator><lastBuildDate>Fri, 17 Apr 2026 06:12:48 GMT</lastBuildDate><atom:link href="https://news.santana.dev/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Carlos Santana]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[csantanapr@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[csantanapr@substack.com]]></itunes:email><itunes:name><![CDATA[Carlos Santana]]></itunes:name></itunes:owner><itunes:author><![CDATA[Carlos Santana]]></itunes:author><googleplay:owner><![CDATA[csantanapr@substack.com]]></googleplay:owner><googleplay:email><![CDATA[csantanapr@substack.com]]></googleplay:email><googleplay:author><![CDATA[Carlos Santana]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Newsletter of Carlos Santana - Issue #41]]></title><description><![CDATA[Change is never easy but should not be scary; pushing yourself to get out of the comfort zone is one way to deal with impostor syndrome.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-41-1267436</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-41-1267436</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Wed, 27 Jul 2022 02:10:25 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Change is never easy but should not be scary; pushing yourself to get out of the comfort zone is one way to deal with impostor syndrome.</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.cncf.io/blog/2022/07/20/cilium-1-12-ga-cilium-service-mesh-and-other-major-new-features-for-enterprise-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cilium 1.12 GA: Cilium Service Mesh and other major new features for enterprise Kubernetes </a>&#8212; <a href="https://www.cncf.io/blog/2022/07/20/cilium-1-12-ga-cilium-service-mesh-and-other-major-new-features-for-enterprise-kubernetes/">www.cncf.io</a></strong></p><p>The Cilium Project is excited to announce the general availability of Cilium 1.12.</p><p><strong><a href="https://www.solo.io/blog/exploring-cilium-layer-7-capabilities-compared-to-istio/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Exploring Cilium Layer 7 Capabilities Compared to Istio </a>&#8212; <a href="https://www.solo.io/blog/exploring-cilium-layer-7-capabilities-compared-to-istio/">www.solo.io</a></strong></p><p>Learn about the differences between Layer 7 security in Cilium vs. Layer 7 security in Istio</p><p><strong><a href="https://www.cncf.io/blog/2022/07/26/how-to-apply-gitops-to-everything-with-crossplane-and-flux/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to apply GitOps to everything with Crossplane and Flux </a>&#8212; <a href="https://www.cncf.io/blog/2022/07/26/how-to-apply-gitops-to-everything-with-crossplane-and-flux/">www.cncf.io</a></strong></p><p><strong><a href="https://blog.bytebytego.com/p/diagram-as-code?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Diagram as Code </a>&#8212; <a href="https://blog.bytebytego.com/p/diagram-as-code">blog.bytebytego.com</a></strong> 6 different ways to turn code into beautiful architecture diagrams</p><p><strong><a href="https://aws.amazon.com/blogs/aws/amazon-prime-day-2022-aws-for-the-win/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Amazon Prime Day 2022 </a>&#8212; <a href="https://aws.amazon.com/blogs/aws/amazon-prime-day-2022-aws-for-the-win/">aws.amazon.com</a></strong></p><p>SQS 70.5 million messages per second</p><p><strong><a href="https://www.graplsecurity.com/post/kernel-pwning-with-ebpf-a-love-story?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kernel Pwning with eBPF: a Love Story </a></strong>We cover the basics of eBPF and the verifier component, which is supposed to make sure the code is safe to run.</p><h2>Assets</h2><p><strong><a href="https://github.com/awslabs/git-secrets?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - awslabs/git-secrets</a> &#8212; <a href="https://github.com/awslabs/git-secrets">github.com</a></strong></p><p>Prevents you from committing secrets</p><p><strong><a href="https://github.com/trufflesecurity/trufflehog?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - trufflesecurity/trufflehog</a> &#8212; <a href="https://github.com/trufflesecurity/trufflehog">github.com</a></strong></p><p>Find credentials all over the place.</p><p><strong><a href="https://canarytokens.org/generate?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Know. Before it matters</a> &#8212; <a href="https://canarytokens.org/generate">canarytokens.org</a></strong></p><p>Canarytokens is a free tool that helps you discover you&#8217;ve been breached by having attackers announce themselves.</p><p><strong><a href="https://github.com/cloudscape-design/components?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AWS Console open source: React components for Cloudscape Design System</a> &#8212; <a href="https://github.com/cloudscape-design/components">github.com</a></strong></p><p>React components for Cloudscape Design System.</p><h2>Skills</h2><p><strong><a href="https://r.bluethl.net/how-to-design-better-apis?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to design better APIs</a> &#8212; <a href="https://r.bluethl.net/how-to-design-better-apis">r.bluethl.net</a></strong> 15 language-agnostic, actionable tips on REST API design</p><p><strong><a href="https://learncsdesign.medium.com/an-overview-of-distributed-caching-e426781d1ff0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">An Overview of Distributed Caching </a>&#8212; <a href="https://learncsdesign.medium.com/an-overview-of-distributed-caching-e426781d1ff0">learncsdesign.medium.com</a></strong></p><p>CPUs that run your applications have fast, multilevel hardware caches to reduce main memory access times. S</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #40]]></title><description><![CDATA[Hello folks, after taking a break this summer I'm back with my mojo collecting the best resources on cloud native. Don't forget to join me every Friday to discuss a Kubernetes book in our BookClub, this week we are discussing Chapter 8 "Policy" from the Hacking Kubernetes book.Hope you're not melting with this hot summer, stay hydrated.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-40-1222185</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-40-1222185</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Thu, 14 Jul 2022 23:34:36 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello folks, after taking a break this summer I'm back with my mojo collecting the best resources on cloud native.</p><p>Don't forget to join me every Friday to discuss a Kubernetes book in our <a href="https://www.santana.dev/book-club">BookClub</a>, this week we are discussing Chapter 8 "Policy" from the Hacking Kubernetes book.</p><p>Hope you're not melting with this hot summer, stay hydrated.</p><div><hr></div><h2>News</h2><p><strong><a href="https://asankov.dev/blog/2022/07/11/demystifying-the-kubernetes-iceberg-part-8/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Demystifying the Kubernetes Iceberg: Part 8 | Anton Sankov's Blog</a> &#8212; <a href="https://asankov.dev/blog/2022/07/11/demystifying-the-kubernetes-iceberg-part-8/">asankov.dev</a></strong> Kubernetes is like an iceberg. You learn the basics, only to see there is a lot more to learn. The more you learn, the more you see there is to know. This series of articles explains all the concepts listed in the "Kubernetes Iceberg" diagram by Flant.</p><p><strong><a href="https://kubernetespodcast.com/episode/185-writing/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Podcast from Google: Episode 185 - Writing, Learning and Tech, with Ian Miell</a> &#8212; <a href="https://kubernetespodcast.com/episode/185-writing/">kubernetespodcast.com</a></strong> Ian Miell is a partner at consultancy Container Solutions, and an author of books on Bash, Git, Terraform and Docker. He explains to Craig how writing - whether runbooks, blog posts, training courses, or "real" books, can help you learn and make your team more effective.</p><p><strong><a href="https://blog.coinbase.com/operating-efficiently-at-scale-e6e2378d3d4?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Operating efficiently at scale. By Brian Armstrong, CEO and Co-founder | by Coinbase | Jul, 2022 | The Coinbase Blog</a> &#8212; <a href="https://blog.coinbase.com/operating-efficiently-at-scale-e6e2378d3d4">blog.coinbase.com</a></strong> As companies scale, they usually slow down and become less efficient. It takes more dollars, more people and more time to get anything done. Coordination headwinds increase, vetocracies emerge, risk&#8230;</p><p><strong><a href="https://slsa.dev/blog/2022/06/slsa-github-workflows?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">SLSA &#8226; General Availability of SLSA 3 Go native builder for GitHub Actions</a> &#8212; <a href="https://slsa.dev/blog/2022/06/slsa-github-workflows">slsa.dev</a></strong> A couple of months ago, Google and GitHub demonstrated how to generate non-forgeable SLSA 3 provenance for packages/binaries created via GitHub Actions (1, 2). Since then, we&#8217;ve been working hard to turn the reference example into a production-ready system for everyone to use. Today, we&#8217;re announcing the v1 release of the trusted builders that can be used in GitHub Actions and verification tools.</p><p><strong><a href="https://www.cidersecurity.io/blog/research/optimizing-ci-cd-credential-hygiene-a-comparison-of-ci-cd-solutions?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Optimizing CI/CD Credential Hygiene - A Comparison of CI/CD Solutions - Cider Security Site</a> &#8212; <a href="https://www.cidersecurity.io/blog/research/optimizing-ci-cd-credential-hygiene-a-comparison-of-ci-cd-solutions">www.cidersecurity.io</a></strong> Attackers are always on the lookout to gain access to credentials, which are a critical asset to protect and are widespread throughout the organization.</p><p><strong><a href="https://www.docker.com/blog/use-cases-and-tips-for-using-the-busybox-docker-official-image?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Use Cases and Tips for Using the BusyBox Docker Official Image - Docker</a> &#8212; <a href="https://www.docker.com/blog/use-cases-and-tips-for-using-the-busybox-docker-official-image">www.docker.com</a></strong> The BusyBox Docker Official Image can help jumpstart your next Linux development project. Learn about use cases, best practices, and setup, here.</p><p><strong><a href="https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Minimal Container Images: Towards a More Secure Future</a> &#8212; <a href="https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future">blog.chainguard.dev</a></strong> This post walks through the typical approaches in this space &#8212; minimal distributions, scratch and &#8220;distroless&#8221; &#8212; finishing with a look at Chainguard&#8217;s new, improved version of distroless.</p><p><strong><a href="https://www.infoworld.com/article/3664052/why-mercedes-benz-runs-on-900-kubernetes-clusters.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Why Mercedes-Benz runs on 900 Kubernetes clusters | InfoWorld</a> &#8212; <a href="https://www.infoworld.com/article/3664052/why-mercedes-benz-runs-on-900-kubernetes-clusters.html">www.infoworld.com</a></strong> The German automaker runs a massive fleet of Kubernetes clusters to support a wide range of project teams around the world. &#8216;For us, managing Kubernetes is not that hard.&#8217;</p><h2>Assets</h2><p><strong><a href="https://github.com/infracost/infracost?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - infracost/infracost: Cloud cost estimates for Terraform in pull requests&#128176;&#128201; Love your cloud bill!</a> &#8212; <a href="https://github.com/infracost/infracost">github.com</a></strong> Cloud cost estimates for Terraform in pull requests&#128176;&#128201; Love your cloud bill! - GitHub - infracost/infracost: Cloud cost estimates for Terraform in pull requests&#128176;&#128201; Love your cloud bill!</p><p><strong><a href="https://github.com/chainguard-dev/hello-melange-apko?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Showing how to go from source code to container image using melange+apko</a> &#8212; <a href="https://github.com/chainguard-dev/hello-melange-apko">github.com</a></strong></p><p>Demo app duplicated in 5 languages (Go/JavaScript/Python/Ruby/Rust) showing how to go from source code to container image using melange+apko</p><p><strong><a href="https://github.com/fonoster/fonoster?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - fonoster/fonoster: &#128640; The open-source alternative to Twilio</a> &#8212; <a href="https://github.com/fonoster/fonoster">github.com</a></strong> &#128640; The open-source alternative to Twilio. Contribute to fonoster/fonoster development by creating an account on GitHub.</p><p><strong><a href="https://github.com/mingrammer/diagrams?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - mingrammer/diagrams: Diagram as Code for prototyping cloud system architectures</a> &#8212; <a href="https://github.com/mingrammer/diagrams">github.com</a></strong> :art: Diagram as Code for prototyping cloud system architectures - GitHub - mingrammer/diagrams: Diagram as Code for prototyping cloud system architectures</p><h2>Skills</h2><p><strong><a href="https://thenewstack.io/living-with-kubernetes-12-commands-to-debug-your-workloads?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Living with Kubernetes: 12 Commands to Debug Your Workloads &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/living-with-kubernetes-12-commands-to-debug-your-workloads">thenewstack.io</a></strong> Kubernetes can&#8217;t fix broken code. But if your container won&#8217;t start or the application gets intermittent errors, here&#8217;s where you can start.</p><p><strong><a href="https://inlets.dev/blog/2022/06/24/fixing-kubectl-port-forward.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Fixing the Developer Experience of Kubernetes Port Forwarding &#8211; Inlets &#8211; The Cloud Native Tunnel</a> &#8212; <a href="https://inlets.dev/blog/2022/06/24/fixing-kubectl-port-forward.html">inlets.dev</a></strong> Alex shows you some of the frustrations of using kubectl for port-forwarding and how to fix the developer experience.</p><p><strong><a href="https://developer.okta.com/blog/2022/06/22/terraform-eks-microservices?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Deploy Java Microservices on Amazon EKS Using Terraform and Kubernetes | Okta Developer</a> &#8212; <a href="https://developer.okta.com/blog/2022/06/22/terraform-eks-microservices">developer.okta.com</a></strong> Deploy a cloud-native Java microservice stack on Amazon EKS using Terraform and Kubernetes.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #39]]></title><description><![CDATA[I hope everyone got their KubeCon NA CFP submitted. The Kubernetes leads and chairs are currently reviewing all these great CFP ideas my heart &#10084;&#65039; goes out to them for volunteering their time in this great community. Please be empathetic if you don't get selected, as these great individuals are doing their best to choose a minimal set of talks they are allowed.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-39-1207210</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-39-1207210</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 13 Jun 2022 19:14:01 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I hope everyone got their KubeCon NA CFP submitted. The Kubernetes leads and chairs are currently reviewing all these great CFP ideas my heart &#10084;&#65039; goes out to them for volunteering their time in this great community. Please be empathetic if you don't get selected, as these great individuals are doing their best to choose a minimal set of talks they are allowed.</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.coinbase.com/scaling-container-technologies-at-coinbase-with-kubernetes-de18efa9389f?gi=5f335169c202&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Scaling Container Technologies at Coinbase with Kubernetes </a>&#8212; <a href="https://blog.coinbase.com/scaling-container-technologies-at-coinbase-with-kubernetes-de18efa9389f?gi=5f335169c202">blog.coinbase.com</a></strong> Tl;dr: Our recent evaluation of Kubernetes underscored its suitability for scaling Coinbase into the future. In the past, a migration to Kubernetes raised concerns due to the operational burden of&#8230;</p><p><strong><a href="https://thenewstack.io/chainguard-secure-software-supply-chain-images-arrive?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Chainguard Secure Software Supply Chain Images Arrive</a> &#8212; <a href="https://thenewstack.io/chainguard-secure-software-supply-chain-images-arrive">thenewstack.io</a></strong></p><p>Chainguard Images, are container base images designed for a secure software supply chain.</p><p><strong><a href="https://akuity.io/blog/how-to-manage-kubernetes-secrets-gitops/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to manage Kubernetes secrets with GitOps? | Akuity</a> &#8212; <a href="https://akuity.io/blog/how-to-manage-kubernetes-secrets-gitops/">akuity.io</a></strong> How to manage Kubernetes secrets with GitOps? Your guide on selecting a proper method.</p><p><strong><a href="https://blog.argoproj.io/breaking-changes-in-argo-cd-2-4-29e3c2ac30c9?gi=7e606aa9f933&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Breaking Changes in Argo CD 2.4. </a>&#8212; <a href="https://blog.argoproj.io/breaking-changes-in-argo-cd-2-4-29e3c2ac30c9?gi=7e606aa9f933">blog.argoproj.io</a></strong></p><p>Argo CD 2.4 includes some awesome improvements and also gave the Argo CD team an opportunity to clean up some tech debt.</p><p><strong><a href="https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">PyPI package 'keep' mistakenly included a password stealer</a> &#8212; <a href="https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/">www.bleepingcomputer.com</a></strong> PyPI packages 'keep,' 'pyanxdns,' 'api-res-py' were found to&nbsp;contain&nbsp;a&nbsp;password-stealer and a backdoor due to the presence of malicious 'request' dependency within some&nbsp;versions.</p><p><strong><a href="https://blog.envoyproxy.io/introducing-envoy-gateway-ad385cc59532?gi=88099feb7663&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing Envoy Gateway. Today we are thrilled to announce Envoy</a> &#8212; <a href="https://blog.envoyproxy.io/introducing-envoy-gateway-ad385cc59532?gi=88099feb7663">blog.envoyproxy.io</a></strong> Today we are thrilled to announce Envoy Gateway, a new member of the Envoy Proxy family aimed at significantly decreasing the barrier to entry when using Envoy for API Gateway (sometimes known as&#8230;</p><p><strong><a href="https://www.jeli.io/blog/oops-that-almost-happened/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Oops, That Almost Happened - Jeli</a> &#8212; <a href="https://www.jeli.io/blog/oops-that-almost-happened/">www.jeli.io</a></strong></p><p>At this point you&#8217;ve seen all the reasons why learning from incidents is good for you and your org.</p><p><strong><a href="https://github.blog/2022-06-06-github-brings-supply-chain-security-features-to-the-rust-community/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub brings supply chain security features to the Rust community | The GitHub Blog</a> &#8212; <a href="https://github.blog/2022-06-06-github-brings-supply-chain-security-features-to-the-rust-community/">github.blog</a></strong> The Rust community can now discover, report, and prevent security vulnerabilities.</p><p><strong><a href="https://blog.sigstore.dev/introducing-gitsign-9fd3f1b682aa?gi=8da0a0520447&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing Gitsign. Keyless Git commit signing </a>&#8212; <a href="https://blog.sigstore.dev/introducing-gitsign-9fd3f1b682aa?gi=8da0a0520447">blog.sigstore.dev</a></strong></p><p>With Gitsign, we aim to bring the best of Sigstore to Git with &#8220;keyless&#8221; signing and transparency log support&nbsp;</p><p><strong><a href="https://www.newyorker.com/magazine/2022/06/13/the-surreal-case-of-a-cia-hackers-revenge?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The Surreal Case of a&nbsp;C.I.A. Hacker&#8217;s Revenge | The New Yorker</a> &#8212; <a href="https://www.newyorker.com/magazine/2022/06/13/the-surreal-case-of-a-cia-hackers-revenge">www.newyorker.com</a></strong> A hot-headed coder is accused of exposing the agency&#8217;s hacking arsenal. Did he betray his country because he was pissed off at his colleagues?</p><p><strong><a href="https://hectormrejia.medium.com/scalable-self-hosted-runner-system-for-github-actions-509052905817?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Scalable self-hosted runner system for GitHub actions </a>&#8212; <a href="https://hectormrejia.medium.com/scalable-self-hosted-runner-system-for-github-actions-509052905817">hectormrejia.medium.com</a></strong></p><p>Hello everyone! This article is intended for organizations that develop on private repositories and the minutes available from GitHub are not enough for their CI/CD needs.</p><h2>Assets</h2><p><strong><a href="https://github.com/iovisor/bcc?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - iovisor/bcc: </a>&#8212; <a href="https://github.com/iovisor/bcc">github.com</a></strong></p><p>BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more -</p><p><strong><a href="https://github.com/kubeshop/testkube?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kubeshop/testkube: &#9784;&#65039; </a>&#8212; <a href="https://github.com/kubeshop/testkube">github.com</a></strong> &#9784;&#65039; Kubernetes-native framework for test definition and execution - GitHub - kubeshop/testkube: &#9784;&#65039; Kubernetes-native framework for test definition and execution</p><p><strong><a href="https://github.com/redhat-developer/vscode-didact?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - redhat-developer/vscode-didact</a> &#8212; <a href="https://github.com/redhat-developer/vscode-didact">github.com</a></strong></p><p>Framework and tools for providing interactive tutorials with active links that call VS Code commandson markdown</p><p><strong><a href="https://docs.cilium.io/en/stable/gettingstarted/encryption-wireguard/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">WireGuard Transparent Encryption &#8212; Cilium 1.11.5 documentation</a></strong> This guide explains how to configure Cilium with transparent encryption of traffic between Cilium-managed endpoints using WireGuard&#174;.</p><p><strong><a href="https://reproducible-builds.org/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Reproducible Builds </a>&#8212; <a href="https://reproducible-builds.org/">reproducible-builds.org</a></strong> Reproducible builds are a set of software development practices that create an independently-verifiable path from source to binary code.</p><p><strong><a href="https://pypi.org/project/reprotest/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">reprotest &#183; PyPI</a> &#8212; <a href="https://pypi.org/project/reprotest/">pypi.org</a></strong> Build packages and check them for reproducibility.</p><h2>Skills</h2><p><strong><a href="https://tailscale.com/blog/how-nat-traversal-works/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How NAT traversal works &#183; Tailscale</a> &#8212; <a href="https://tailscale.com/blog/how-nat-traversal-works/">tailscale.com</a></strong> In this post, we&#8217;ll talk about how to establish a peer-to-peer connection between two machines, in spite of all the obstacles in the way.</p><p><strong><a href="https://blog.alexellis.io/troubleshooting-on-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Troubleshoot Applications on Kubernetes</a> &#8212; <a href="https://blog.alexellis.io/troubleshooting-on-kubernetes/">blog.alexellis.io</a></strong> Learn how to troubleshoot applications on Kubernetes. Because if it's not working, wouldn't it be great if you could find out why and fix it yourself?</p><p><strong><a href="https://go.dev/blog/supply-chain?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How Go Mitigates Supply Chain Attacks - The Go Programming Language</a> &#8212; <a href="https://go.dev/blog/supply-chain">go.dev</a></strong> Go tooling and design help mitigate supply chain attacks at various stages.</p><p><strong><a href="https://blog.jimmyray.io/kubernetes-workload-identity-with-aws-sdk-for-go-v2-927d2f258057?gi=9553ceb463d3&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Workload Identity with AWS SDK for Go v2 | by Jimmy Ray | Jun, 2022 | Medium</a> &#8212; <a href="https://blog.jimmyray.io/kubernetes-workload-identity-with-aws-sdk-for-go-v2-927d2f258057?gi=9553ceb463d3">blog.jimmyray.io</a></strong> In the context of Cloud Service Providers (CSP), a Kubernetes workload identity is the concept of pods assuming authenticated principals, to perform operations using CSP services. When using Amazon&#8230;</p><p><strong><a href="https://raesene.github.io/blog/2022/06/11/escaping-the-nested-doll-with-tailscale/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Escaping the Nested Doll with Tailscale</a> &#8212; <a href="https://raesene.github.io/blog/2022/06/11/escaping-the-nested-doll-with-tailscale/">raesene.github.io</a></strong></p><p>I came across a scenario recently (for a workshop in Kubecon) where I needed to access a GUI application deployed in a KinD cluster running in an EC2 instance on AWS, from my laptop.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #38]]></title><description><![CDATA[Hi, I'm back with a new newsletter this week after a break traveling to Spain for KubeCon. Was very fantastic to get to see in person all the amazing technologists I interact with in open source.We resume the Kubernetes BookClub this week, we are reading the Hacking Kubernetes book and will discuss Chapter 3 on June 3rd. If you want to join get an invite here https://www.santana.dev/book-club]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-38-1172452</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-38-1172452</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Fri, 03 Jun 2022 02:15:21 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi, I'm back with a new newsletter this week after a break traveling to Spain for KubeCon. Was very fantastic to get to see in person all the amazing technologists I interact with in open source.</p><p>We resume the Kubernetes BookClub this week, we are reading the Hacking Kubernetes book and will discuss Chapter 3 on June 3rd. If you want to join get an invite here <a href="https://www.santana.dev/book-club">https://www.santana.dev/book-club</a></p><div><hr></div><h2>News</h2><p><strong><a href="https://concerned.tech/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Letter in Support of Responsible Fintech Policy</a> &#8212; <a href="https://concerned.tech/">concerned.tech</a></strong> Dear Members of Senate Finance Committee...</p><p><strong><a href="https://techcrunch.com/2022/06/02/chainguard-raises-50m-to-guard-supply-chains/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Chainguard raises $50M Series A for supply chain security &#8211; TechCrunch</a> &#8212; <a href="https://techcrunch.com/2022/06/02/chainguard-raises-50m-to-guard-supply-chains/">techcrunch.com</a></strong> Software supply chain startup Chainguard today announced that it has raised a $50 million Series A led by Sequoia.</p><p><strong><a href="https://www.cncf.io/blog/2022/05/18/announcing-the-refreshed-cloud-native-security-whitepaper/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Announcing the Refreshed Cloud Native Security Whitepaper | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/blog/2022/05/18/announcing-the-refreshed-cloud-native-security-whitepaper/?utm_source=pocket_mylist">www.cncf.io</a></strong> The CNCF Security Technical Advisory Group (TAG) has just released a refreshed Cloud Native Security Whitepaper v2 to help educate the community about best&#8230;</p><p><strong><a href="https://chipsandcheese.com/2022/05/29/graviton-3-first-impressions/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Graviton 3: First Impressions &#8211; Chips and Cheese</a> &#8212; <a href="https://chipsandcheese.com/2022/05/29/graviton-3-first-impressions/?utm_source=pocket_mylist">chipsandcheese.com</a></strong></p><p>In late May of 2022, AWS released Graviton 3 to the general public. Graviton 3 was the first ARM CPU to introduce the SVE instruction set to a widely accessible server CPU.</p><p><strong><a href="https://blog.getambassador.io/kubecon-eu-2022-summary-cloud-novices-golden-paths-and-software-supply-chains-f38d34b0c5a4?gi=a9b6add6de08&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">KubeCon EU 2022 Summary: Cloud Novices, Golden Paths, and Software Supply Chains | by Daniel Bryant | May, 2022 | Ambassador Labs</a> &#8212; <a href="https://blog.getambassador.io/kubecon-eu-2022-summary-cloud-novices-golden-paths-and-software-supply-chains-f38d34b0c5a4?gi=a9b6add6de08">blog.getambassador.io</a></strong> Summary of KubeCon EU 2022 in Valencia, with a focus on cloud education, golden paths and platform engineering, and security and software supply chains</p><p><strong><a href="https://www.nojones.net/posts/breaking-into-cloudsec?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Breaking Into Cloud Security - Nick Jones</a></strong></p><p>Cloud security is an area of the industry with some of the biggest skill shortages.</p><p><strong><a href="https://thenewstack.io/what-made-golang-so-popular-the-languages-creators-look-back/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">What Made GoLang So Popular? The Language&#8217;s Creators Look Back &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/what-made-golang-so-popular-the-languages-creators-look-back/?utm_source=pocket_mylist">thenewstack.io</a></strong></p><p>Since the day it was open sourced in 2009, the Go programming language has consistently grown in popularity.</p><p><strong><a href="https://iximiuz.com/en/posts/how-to-start-programming-in-go-for-devops/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">How To Start Programming In Go: Advice For Fellow DevOps Engineers</a> &#8212; <a href="https://iximiuz.com/en/posts/how-to-start-programming-in-go-for-devops/?utm_source=pocket_mylist">iximiuz.com</a></strong> "Starting programming", "Starting programming in Go", and "Starting programming Kubernetes controllers in Go" are there different challenges with the exponentially increasing level of complexity.</p><p><strong><a href="https://www.digitalocean.com/blog/introducing-digitalocean-functions-serverless-computing?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Introducing DigitalOcean Functions: A powerful serverless computing solution</a> &#8212; <a href="https://www.digitalocean.com/blog/introducing-digitalocean-functions-serverless-computing?utm_source=pocket_mylist">www.digitalocean.com</a></strong> DigitalOcean is committed to providing products that serve developers throughout their journey, and access to serverless computing has been one of the most popular requests from DigitalOcean users ...</p><p><strong><a href="https://engineering.atspotify.com/2022/05/the-open-future/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">The Open Future : Spotify Engineering</a> &#8212; <a href="https://engineering.atspotify.com/2022/05/the-open-future/?utm_source=pocket_mylist">engineering.atspotify.com</a></strong> Spotify&#8217;s official technology blog</p><p><strong><a href="https://www.cncf.io/reports/kubernetes-annual-report-2021/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Annual Report 2021 | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/reports/kubernetes-annual-report-2021/">www.cncf.io</a></strong> This is a summary of the Kubernetes project&#8217;s contributor community and activities. This report documents both quantitative measures of community health&#8230;</p><p><strong><a href="https://blog.chainguard.dev/announcing-chainguard-images/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing the First Images Designed for a Secure Software Supply Chain</a> &#8212; <a href="https://blog.chainguard.dev/announcing-chainguard-images/">blog.chainguard.dev</a></strong> We&#8217;re building a suite of products with the goal of simplifying security for all developers.</p><p><strong><a href="https://github.blog/2022-05-26-npm-security-update-oauth-tokens/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">npm security update: Attack campaign using stolen OAuth tokens | The GitHub Blog</a> &#8212; <a href="https://github.blog/2022-05-26-npm-security-update-oauth-tokens/?utm_source=pocket_mylist">github.blog</a></strong> npm's impact analysis of the attack campaign using stolen OAuth tokens and additional findings.</p><p><strong><a href="https://cloud.redhat.com/blog/red-hat-releases-open-source-stackrox-to-the-community?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Red Hat Releases Open Source StackRox to the Community</a> &#8212; <a href="https://cloud.redhat.com/blog/red-hat-releases-open-source-stackrox-to-the-community?utm_source=pocket_mylist">cloud.redhat.com</a></strong></p><p>Today, Red Hat is excited to announce that Red Hat Advanced Cluster Security for Kubernetes (RHACS) is now open sourced as StackRox.</p><p><strong><a href="https://blog.kintone.io/entry/2022/03/08/170206?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Five Things to Prepare for Cgroup v2 with Kubernetes - Kintone Engineering Blog</a> &#8212; <a href="https://blog.kintone.io/entry/2022/03/08/170206?utm_source=pocket_mylist">blog.kintone.io</a></strong></p><p>By Daichi Sakaue (@yokaze) Above all the effort of the community, Kubernetes is now ready to run with cgroup v2.</p><p><strong><a href="https://thenewstack.io/jetstack-helps-turn-security-policies-into-actions?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Jetstack Helps Turn Security Policies into Actions &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/jetstack-helps-turn-security-policies-into-actions">thenewstack.io</a></strong> Jetstack, a cloud native security company, has released its Jetstack software supply chain toolkit -- a comprehensive, web-based interactive program for securing software supply chains.</p><h2>Assets</h2><p><strong><a href="https://ttl.sh/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">ttl.sh | An anonymous &amp; ephemeral (and free) Docker image registry</a></strong> An anonymous &amp; ephemeral (and free) Docker image registry.</p><p><strong><a href="https://github.com/chainguard-dev/ssc-reading-list?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - chainguard-dev/ssc-reading-list: A reading list for software supply-chain security.</a> &#8212; <a href="https://github.com/chainguard-dev/ssc-reading-list">github.com</a></strong> A reading list for software supply-chain security. - GitHub - chainguard-dev/ssc-reading-list: A reading list for software supply-chain security.</p><p><strong><a href="https://github.com/fjogeleit/trivy-operator-polr-adapter?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports</a> &#8212; <a href="https://github.com/fjogeleit/trivy-operator-polr-adapter?utm_source=pocket_mylist">github.com</a></strong> Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports - GitHub - fjogeleit/trivy-operator-polr-adapter: Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports</p><p><strong><a href="https://github.com/ContainerSolutions/delayed-jobs-operator?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">GitHub - ContainerSolutions/delayed-jobs-operator</a> &#8212; <a href="https://github.com/ContainerSolutions/delayed-jobs-operator?utm_source=pocket_mylist">github.com</a></strong> Contribute to ContainerSolutions/delayed-jobs-operator development by creating an account on GitHub.</p><p><strong><a href="https://github.com/iovisor/bcc?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">GitHub - iovisor/bcc: BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more</a> &#8212; <a href="https://github.com/iovisor/bcc?utm_source=pocket_mylist">github.com</a></strong> BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more - GitHub - iovisor/bcc: BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more</p><h2>Skills</h2><p><strong><a href="https://developers.redhat.com/e-books/getting-gitops-practical-platform-openshift-argo-cd-and-tekton?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Getting GitOps: A practical platform with OpenShift, Argo CD, and Tekton | Red Hat Developer</a> &#8212; <a href="https://developers.redhat.com/e-books/getting-gitops-practical-platform-openshift-argo-cd-and-tekton">developers.redhat.com</a></strong> A practical guide through the jungle of modern development with Kubernetes, with a focus on application distribution via continuous integration/continuous delivery (CI/CD) and GitOps on Red Hat OpenShift.</p><p><strong><a href="https://medium.com/jaegertracing/introducing-native-support-for-opentelemetry-in-jaeger-eb661be8183c?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing native support for OpenTelemetry in Jaeger | by Yuri Shkuro | JaegerTracing | May, 2022 | Medium</a> &#8212; <a href="https://medium.com/jaegertracing/introducing-native-support-for-opentelemetry-in-jaeger-eb661be8183c">medium.com</a></strong> The latest Jaeger v1.35 release introduced the ability to receive OpenTelemetry trace data via the OpenTelemetry Protocol (OTLP), which all OpenTelemetry SDKs are required to support. This is a&#8230;</p><p><strong><a href="https://blog.pragmaticengineer.com/typical-migration-approaches/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Migrations Done Well: Typical Migration Approaches - The Pragmatic Engineer</a> &#8212; <a href="https://blog.pragmaticengineer.com/typical-migration-approaches/?utm_source=pocket_mylist">blog.pragmaticengineer.com</a></strong> A guide for executing migrations well, at both small and large scales.</p><p><strong><a href="https://systemd.io/CGROUP_DELEGATION/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">Control Group APIs and Delegation</a></strong> Intended audience: hackers working on userspace subsystems that require direct cgroup access, such as container managers and similar.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #37]]></title><description><![CDATA[KubeCon EU 2022 is next week May 16th; check out the schedule, KubeCon NA CFP is open until May 27th. Get those talks submitted!If you plan to be at KubeConEU at Valencia and see me, don't be a stranger and come say hello and let's take a selfie together. I missed selfies at conferences &#128557;]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-37-1162062</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-37-1162062</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 10 May 2022 02:01:31 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/">KubeCon EU 2022</a> is next week May 16th; check out the schedule, <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/">KubeCon NA CFP</a> is open until May 27th. Get those talks submitted!</p><p>If you plan to be at KubeConEU at Valencia and see me, don't be a stranger and come say hello and let's take a selfie together. I missed selfies at conferences &#128557;</p><div><hr></div><h2>News</h2><p><strong><a href="https://kubernetes.io/blog/2022/05/03/kubernetes-1-24-release-announcement/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes 1.24: Stargazer | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2022/05/03/kubernetes-1-24-release-announcement/">kubernetes.io</a></strong></p><p>Authors: Kubernetes 1.24 Release Team We are excited to announce the release of Kubernetes 1.24, the first release of 2022! This release consists of 46 enhancements:</p><p><strong><a href="https://blog.cloudflare.com/introducing-the-wintercg/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A Community Group for Web-interoperable JavaScript runtimes</a> &#8212; <a href="https://blog.cloudflare.com/introducing-the-wintercg/">blog.cloudflare.com</a></strong> Cloudflare is excited to be a part of the launch of the Web-interoperable Runtimes Community Group, a new effort that brings contributors from Cloudflare Workers, Deno, and Node.js together to collaborate on common Web platform API standards.</p><p><strong><a href="https://blog.argoproj.io/argo-cd-v2-4-release-candidate-d1a0eef6b908?gi=aa75c6e4549a&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Argo CD v2.4 release candidate</a> &#8212; <a href="https://blog.argoproj.io/argo-cd-v2-4-release-candidate-d1a0eef6b908?gi=aa75c6e4549a">blog.argoproj.io</a></strong> It has been three months since the v2.3 release. A perfect time for a new release candidate that brings a set of fantastic Argo CD improvements! More than 80 contributors worked hard on building new&#8230;</p><p><strong><a href="https://isovalent.com/blog/post/2022-05-03-servicemesh-security/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Next-Generation Mutual Authentication with Cilium Service Mesh</a> &#8212; <a href="https://isovalent.com/blog/post/2022-05-03-servicemesh-security/">isovalent.com</a></strong> Introduction to Mutual Authentication with Cilium &amp; Cilium Service Mesh</p><p><strong><a href="https://kubesimplify.com/the-secret-gems-behind-building-container-images-enter-buildkit-and-docker-buildx?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The secret gems behind building container images, Enter: BuildKit &amp; Docker Buildx</a> &#8212; <a href="https://kubesimplify.com/the-secret-gems-behind-building-container-images-enter-buildkit-and-docker-buildx">kubesimplify.com</a></strong> In this post, we discussed various things about Buildkit, its internals, how to interact with BuildKit and its benefits in container image building. Feel fr</p><p><strong><a href="https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins - FIDO Alliance</a> &#8212; <a href="https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/">fidoalliance.org</a></strong> Faster, easier and more secure sign-ins will be available&nbsp;to consumers across leading devices and platforms&nbsp; Mountain View, California, MAY 5, 2022&nbsp; &#8211; In a joint effort to make the web [&#8230;]</p><p><strong><a href="https://sanjimoh.medium.com/kubernetes-gateway-api-a-successor-to-existing-kubernetes-ingress-19bb3bebbb74?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Gateway API &#8212; A successor to existing Kubernetes Ingress! </a>&#8212; <a href="https://sanjimoh.medium.com/kubernetes-gateway-api-a-successor-to-existing-kubernetes-ingress-19bb3bebbb74">sanjimoh.medium.com</a></strong> The Ingress resource created a diverse ecosystem of Ingress controllers which were used across hundreds of thousands of clusters in a standardised &amp; consistent way that helped users to adopt&#8230;</p><p><strong><a href="https://fly.io/blog/logbook-2022-05-05/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Logbook - 2022-05-05 &#183; Fly</a> &#8212; <a href="https://fly.io/blog/logbook-2022-05-05/">fly.io</a></strong> What's new at Fly,io</p><h2>Assets</h2><p><strong><a href="https://github.com/stern/stern?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - stern/stern: &#9096; Multi pod and container log tailing for Kubernetes </a>&#8212; <a href="https://github.com/stern/stern">github.com</a></strong></p><p>&#9096; Multi pod and container log tailing for Kubernetes</p><p><strong><a href="https://github.com/Shopify/kubeaudit?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - Shopify/kubeaudit: kubeaudit helps you audit your Kubernetes clusters against common security controls</a> &#8212; <a href="https://github.com/Shopify/kubeaudit">github.com</a></strong> kubeaudit helps you audit your Kubernetes clusters against common security controls - GitHub - Shopify/kubeaudit: kubeaudit helps you audit your Kubernetes clusters against common security controls</p><p><strong><a href="https://github.com/go-gitea/gitea?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - go-gitea/gitea: Git with a cup of tea, painless self-hosted git service</a> &#8212; <a href="https://github.com/go-gitea/gitea">github.com</a></strong> Git with a cup of tea, painless self-hosted git service - GitHub - go-gitea/gitea: Git with a cup of tea, painless self-hosted git service</p><p><strong><a href="https://github.com/controlplaneio/kubesec?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - controlplaneio/kubesec: Security risk analysis for Kubernetes resources</a> &#8212; <a href="https://github.com/controlplaneio/kubesec">github.com</a></strong> Security risk analysis for Kubernetes resources. Contribute to controlplaneio/kubesec development by creating an account on GitHub.</p><h2>Skills</h2><p><strong><a href="https://blog.chainguard.dev/sigstore-the-local-way/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">sigstore, the local way</a> &#8212; <a href="https://blog.chainguard.dev/sigstore-the-local-way/">blog.chainguard.dev</a></strong></p><p>If you've been following the Chainguard blog, you might ask yourself: how do I run the open-source sigstore stack on my machine?</p><p><strong><a href="https://blog.chainguard.dev/auto-sboms-with-ko/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Automatic SBOMs with ko</a> &#8212; <a href="https://blog.chainguard.dev/auto-sboms-with-ko/">blog.chainguard.dev</a></strong></p><p>For those unfamiliar with ko, it &#8220;is a simple, fast container image builder for Go applications;&#8221; its objective is to enable developers to stop worrying about containers and focus on their application.&nbsp;</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #36]]></title><description><![CDATA[We conducted a Kubernetes Release Shadow program on Twitter Spaces where you can listen to the recording of what each area of the release team is composed of and how you can become a shadow. I will be leading up Release Notes v1.25 and we are still accepting shadow applications until May 6th. This newsletter edition is heavier on assets than news since I suspect a lot of projects and companies are holding their announcements for KubeConEU the week of May 16th.If you are using Knative in your company I'm conducting user interviews for the User Experience Working Group, please reach out by volunteering your time for a short and simple interview.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-36-1152180</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-36-1152180</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 02 May 2022 18:30:01 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We conducted a Kubernetes Release Shadow program on <a href="https://twitter.com/csantanapr/status/1519867101976178698">Twitter Spaces</a> where you can <a href="https://twitter.com/i/spaces/1dRKZleNdzVJB">listen to the recording</a> of what each area of the release team is composed of and how you can become a shadow.</p><p>I will be leading up Release Notes v1.25 and we are still accepting shadow applications until May 6th.</p><p>This newsletter edition is heavier on assets than news since I suspect a lot of projects and companies are holding their announcements for KubeConEU the week of May 16th.</p><p>If you are using Knative in your company I'm conducting user interviews for the User Experience Working Group, please reach out by <a href="https://twitter.com/csantanapr/status/1521149572776665090">volunteering your time for a short and simple interview</a>.</p><div><hr></div><h2>News</h2><p><strong><a href="https://thenewstack.io/chainguard-enforce-software-supply-chain-security-for-k8s?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Chainguard Enforce: Software Supply Chain Security for K8s &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/chainguard-enforce-software-supply-chain-security-for-k8s">thenewstack.io</a></strong></p><p>Zero-trust security company Chainguard has shipped the beta release of Chainguard Enforce, its first product</p><p><strong><a href="https://twitter.com/csantanapr/status/1519867101976178698?s=20&amp;t=T57Jnp2rnN6CKdoHM7z0ww&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Release Shadow Program Twitter Space</a> &#8212; <a href="https://twitter.com/csantanapr/status/1519867101976178698?s=20&amp;t=T57Jnp2rnN6CKdoHM7z0ww">twitter.com</a></strong></p><p>Listen to the recording of the Twitter Space with members of the Kubernetes Release Team v1.25 <a href="https://twitter.com/i/spaces/1dRKZleNdzVJB">https://twitter.com/i/spaces/1dRKZleNdzVJB</a></p><p><strong><a href="https://medium.com/graalvm/graalvm-22-1-developer-experience-improvements-apple-silicon-builds-and-more-b7ac9a0f6066?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">New GraalVM 22.1: Developer experience improvements, Apple Silicon builds, and more</a> &#8212; <a href="https://medium.com/graalvm/graalvm-22-1-developer-experience-improvements-apple-silicon-builds-and-more-b7ac9a0f6066">medium.com</a></strong></p><p>Today we&#8217;re releasing GraalVM 22.1! This release brings new features and lots of improvements &#8212;</p><p><strong><a href="https://aws.amazon.com/blogs/containers/addressing-latency-and-data-transfer-costs-on-eks-using-istio/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Addressing latency and data transfer costs on EKS using Istio</a> &#8212; <a href="https://aws.amazon.com/blogs/containers/addressing-latency-and-data-transfer-costs-on-eks-using-istio/">aws.amazon.com</a></strong></p><p>Data transfer charges are often overlooked when operating Amazon Elastic Kubernetes Service (Amazon EKS) clusters; understanding these charges would help reduce cost</p><p><strong><a href="https://www.civo.com/learn/installing-an-apache-kafka-cluster-on-kubernetes-using-strimzi-and-gitops?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Installing an Apache Kafka cluster on Kubernetes using Strimzi and GitOps &#8211; Civo.com</a> &#8212; <a href="https://www.civo.com/learn/installing-an-apache-kafka-cluster-on-kubernetes-using-strimzi-and-gitops">www.civo.com</a></strong> Strimzi is a Kubernetes operator which acts as a dedicated SRE for running Apache Kafka on Kubernetes</p><p><strong><a href="https://servicemesh.es/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">servicemesh.es | Service Mesh Comparison</a> &#8212; <a href="https://servicemesh.es/">servicemesh.es</a></strong> Service Mesh Feature Comparison &#8212; including Istio, Linkerd 2, AWS App Mesh, Consul, Maesh, Kuma, Open Service Mesh (OSM)</p><p><strong><a href="https://cloud.google.com/blog/products/containers-kubernetes/exploring-container-security-vulnerability-management-in-open-source-kubernetes?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Exploring container security: Vulnerability management in open-source Kubernetes</a> &#8212; <a href="https://cloud.google.com/blog/products/containers-kubernetes/exploring-container-security-vulnerability-management-in-open-source-kubernetes">cloud.google.com</a></strong> The Kubernetes Privacy Security Committee follows these steps when a vulnerability is reported.</p><p><strong><a href="https://opensource.com/article/22/4/kubernetes-policies-config-datree?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Prevent Kubernetes misconfigurations during development with this open source tool</a> &#8212; <a href="https://opensource.com/article/22/4/kubernetes-policies-config-datree">opensource.com</a></strong> Explore how the principles behind open source--collaboration, transparency, and rapid prototyping--are proven catalysts for innovation.</p><h2>Assets</h2><p><strong><a href="https://github.com/kubernetes-sigs/security-profiles-operator?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - The Kubernetes Security Profiles Operator</a> &#8212; <a href="https://github.com/kubernetes-sigs/security-profiles-operator">github.com</a></strong> The Kubernetes Security Profiles Operator. Contribute to kubernetes-sigs/security-profiles-operator development by creating an account on GitHub.</p><p><strong><a href="https://github.com/collabora/k8s-socketcan?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - SocketCAN Kubernetes device plugin</a> &#8212; <a href="https://github.com/collabora/k8s-socketcan">github.com</a></strong> SocketCAN Kubernetes device plugin. Contribute to collabora/k8s-socketcan development by creating an account on GitHub.</p><p><strong><a href="https://github.com/kinvolk/inspektor-gadget?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - Collection of gadgets for debugging and introspecting Kubernetes applications using BPF</a> &#8212; <a href="https://github.com/kinvolk/inspektor-gadget">github.com</a></strong> Collection of gadgets for debugging and introspecting Kubernetes applications using BPF - GitHub - kinvolk/inspektor-gadget: Collection of gadgets for debugging and introspecting Kubernetes applications using BPF</p><p><strong><a href="https://github.com/containers/oci-seccomp-bpf-hook?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - OCI hook to trace syscalls and generate a seccomp profile</a> &#8212; <a href="https://github.com/containers/oci-seccomp-bpf-hook">github.com</a></strong> OCI hook to trace syscalls and generate a seccomp profile - GitHub - containers/oci-seccomp-bpf-hook: OCI hook to trace syscalls and generate a seccomp profile</p><p><strong><a href="https://github.com/aquasecurity/tracee-test-kernels?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - Kernels for testing ebpf</a> &#8212; <a href="https://github.com/aquasecurity/tracee-test-kernels">github.com</a></strong> Kernels for testing tracee CO-RE feature. Contribute to aquasecurity/tracee-test-kernels development by creating an account on GitHub.</p><h2>Skills</h2><p><strong><a href="https://thebeautifultruth.org/life/mental-health/self-care-is-not-the-solution-for-burnout/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Self-Care is Not the Solution for Burnout &#8212; The Beautiful Truth</a> &#8212; <a href="https://thebeautifultruth.org/life/mental-health/self-care-is-not-the-solution-for-burnout/">thebeautifultruth.org</a></strong> Psychologist Justin D. Henderson makes the case that we need to address the systemic and cultural dimensions of burnout.</p><p><strong><a href="https://github.com/cncf/tag-observability/blob/main/whitepaper.md?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">TAG Observability Whitepaper</a> &#8212; <a href="https://github.com/cncf/tag-observability/blob/main/whitepaper.md">github.com</a></strong></p><p>This paper aims to get you quickly started with different kinds of observability you might need to work within the cloud-native world.</p><p><strong><a href="https://wuestkamp.medium.com/ckad-scenarios-kubectl-contexts-pod-resources-configmap-access-306701b2f9d9?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CKAD Scenarios Kubectl-Contexts | Pod-Resources | ConfigMap Access</a> &#8212; <a href="https://wuestkamp.medium.com/ckad-scenarios-kubectl-contexts-pod-resources-configmap-access-306701b2f9d9">wuestkamp.medium.com</a></strong> In the CKAD exam you need to breath kubectl. Kubectl is a client for the Kubernetes Apiserver and allows you to perform all kinds of operations. A kubectl context contains connection information to a&#8230;</p><p><strong><a href="https://iximiuz.com/en/posts/you-dont-need-an-image-to-run-a-container/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">You Don't Need an Image To Run a Container</a> &#8212; <a href="https://iximiuz.com/en/posts/you-dont-need-an-image-to-run-a-container/">iximiuz.com</a></strong> How to run container without an image? Why do you need container images? What problems container images solve?</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #35]]></title><description><![CDATA[This week we start a new book, "Hacking Kubernetes," in the Kubernetes Book Club, Istio is joining CNF following the steps of Knative, and Elon Musk is buying Twitter today and taking it private.It is only Monday, and there is so much going on already.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-35-1141546</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-35-1141546</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 26 Apr 2022 07:00:04 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This week we start a new book, "Hacking Kubernetes," in the <a href="https://twitter.com/csantanapr/status/1518576480527306753">Kubernetes Book Club</a>, <a href="https://twitter.com/csantanapr/status/1518641973644742656">Istio is joining CNF</a> following the steps of Knative, and <a href="https://www.bloomberg.com/news/articles/2022-04-26/musk-seals-44-billion-deal-even-he-wasn-t-sure-would-succeed">Elon Musk is buying Twitter</a> today and taking it private.</p><p>It is only Monday, and there is so much going on already.</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.sigstore.dev/dont-panic-a-playbook-for-handling-account-compromise-with-sigstore-ee299dca5144?gi=9eb81fd2cfe7&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Don&#8217;t Panic: A Playbook for Handling Account Compromise with Sigstore</a> &#8212; <a href="https://blog.sigstore.dev/dont-panic-a-playbook-for-handling-account-compromise-with-sigstore-ee299dca5144?gi=9eb81fd2cfe7">blog.sigstore.dev</a></strong></p><p>Despite your best efforts, you may no longer trust artifacts, keys, or identities when signing software.</p><p><strong><a href="https://www.coss.community/jj/oss-capital-announcement-200m-for-an-open-future-38n0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">OSS Capital Announcement: $200M For An Open Future - COSS Community</a> &#8212; <a href="https://www.coss.community/jj/oss-capital-announcement-200m-for-an-open-future-38n0">www.coss.community</a></strong> Today, OSS Capital is thrilled to publicly announce our first and second funds with $200M dedicated... Tagged with coss, funding, vc, opencore.</p><p><strong><a href="https://istio.io/latest/blog/2022/istio-has-applied-to-join-the-cncf/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Istio has applied to become a CNCF project</a></strong></p><p>The Istio project is pleased to announce its intention to join the&nbsp;<a href="https://cncf.io/">Cloud Native Computing Foundation</a>&nbsp;(CNCF).&nbsp;</p><p><strong><a href="https://events.istio.io/istiocon-2022/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Welcome to IstioCon 2022!</a> &#8212; <a href="https://events.istio.io/istiocon-2022/">events.istio.io</a></strong></p><p>IstioCon is the community conference for the industry&#8217;s most popular service mesh.</p><p><strong><a href="https://codefresh.io/about-gitops/how-to-model-your-gitops-environments-and-promote-releases-between-them/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Model Your Gitops Environments and Promote Releases between Them</a> &#8212; <a href="https://codefresh.io/about-gitops/how-to-model-your-gitops-environments-and-promote-releases-between-them/">codefresh.io</a></strong> Learn how to model your GitOps environments using different folders on the same Git branch, and how to handle environment promotion.</p><p>Time to patch nginx-ingress controllers to fix 2 recent critical CVEs, <a href="https://github.com/kubernetes/ingress-nginx/issues/8502">CVE-2021-25745</a> and <a href="https://github.com/kubernetes/ingress-nginx/issues/8503">CVE-2021-2576</a> they allow any user with ingress permissions to access the service account secret token of the main shared controller.</p><p><a href="https://uploads-ssl.webflow.com/6228fdbc6c97145dad2a9c2b/624e2337f70386ed568d7e7e_chainguard-all-about-that-base-image.pdf">Chainguard Whitepaper All About That Bade Image</a></p><p><strong><a href="http://heidloff.net/articles/resources-to-build-kubernetes-operators/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Resources to build Kubernetes Operators</a></strong> Resources to build Kubernetes Operators</p><p><strong><a href="https://marcusnoble.co.uk/2022-01-20-restricting-cluster-admin-permissions/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">'Restricting cluster-admin Permissions' by Marcus Noble</a> &#8212; <a href="https://marcusnoble.co.uk/2022-01-20-restricting-cluster-admin-permissions/">marcusnoble.co.uk</a></strong></p><p>Generally, and by default, operators of the cluster are assigned to the cluster-admin ClusterRole.</p><p><strong><a href="https://www.solo.io/blog/ebpf-for-service-mesh/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">eBPF for Service Mesh? Yes, but Envoy Proxy is here to stay - Solo</a> &#8212; <a href="https://www.solo.io/blog/ebpf-for-service-mesh/">www.solo.io</a></strong> Our goal here at Solo.io is to bring valuable solutions to our customers around application networking and service connectivity. Back in October, we announced our plans to enhance our enterprise [&#8230;]</p><p><strong><a href="https://webamp.org/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Webamp &#183; Winamp 2 in your browser</a> &#8212; <a href="https://webamp.org/">webamp.org</a></strong> Winamp 2.9 reimplemented in HTML5 and JavaScript</p><p><strong><a href="https://theintercept.com/2022/04/22/anomaly-six-phone-tracking-zignal-surveillance-cia-nsa/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">American Phone-Tracking Firm Demo&#8217;d Surveillance Powers by Spying on CIA and NSA</a> &#8212; <a href="https://theintercept.com/2022/04/22/anomaly-six-phone-tracking-zignal-surveillance-cia-nsa/">theintercept.com</a></strong> Anomaly Six, a secretive government contractor, claims to monitor the movements of billions of phones around the world and unmask spies with the press of a button.</p><p><strong><a href="https://github.blog/2022-04-22-removing-the-stigma-of-a-cve/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Removing the stigma of a CVE | The GitHub Blog</a> &#8212; <a href="https://github.blog/2022-04-22-removing-the-stigma-of-a-cve/">github.blog</a></strong> Do you worry that a CVE will hurt the reputation of your project? In reality, CVEs are a tracking number, and nothing more. Here's how we think of them at GitHub.</p><h2>Assets</h2><p><strong><a href="https://github.com/kubernetes-sigs/scheduler-plugins?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kubernetes-sigs/scheduler-plugins: Repository for out-of-tree scheduler plugins based on scheduler framework.</a> &#8212; <a href="https://github.com/kubernetes-sigs/scheduler-plugins">github.com</a></strong> Repository for out-of-tree scheduler plugins based on scheduler framework. - GitHub - kubernetes-sigs/scheduler-plugins: Repository for out-of-tree scheduler plugins based on scheduler framework.</p><p><strong><a href="https://github.com/backube/volsync?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - backube/volsync: Asynchronous data replication for Kubernetes volumes</a> &#8212; <a href="https://github.com/backube/volsync">github.com</a></strong> Asynchronous data replication for Kubernetes volumes - GitHub - backube/volsync: Asynchronous data replication for Kubernetes volumes</p><p><strong><a href="https://github.com/twitter/the-algorithm?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">twitter/the-algorithm &#183; GitHub</a> &#8212; <a href="https://github.com/twitter/the-algorithm">github.com</a></strong></p><p>Future home of twitter algorithm</p><h2>Skills</h2><p><strong><a href="https://dev.to/kcdchennai/building-functions-with-knative-and-tekton-php?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Building functions with Knative and Tekton - DEV Community</a></strong> Knative was recently accepted as a CNCF incubation project and there are so many exciting things... Tagged with knative, functions, tekton, faas.</p><p><strong><a href="https://cloud.redhat.com/blog/how-to-bring-your-own-scheduler-into-openshift-with-the-secondary-scheduler-operator?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Bring your own Scheduler into OpenShift with the Secondary Scheduler Operator</a> &#8212; <a href="https://cloud.redhat.com/blog/how-to-bring-your-own-scheduler-into-openshift-with-the-secondary-scheduler-operator">cloud.redhat.com</a></strong> The Kubernetes scheduler is an enterprise grade stable component in Kubernetes that decides where to place the incoming pods by a two step operation of filtering and scoring.</p><p><strong><a href="https://blog.argoproj.io/best-practices-for-multi-tenancy-in-argo-cd-273e25a047b0?gi=e0f0531d2f65&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Best Practices for Multi-tenancy in Argo CD | by Dan Garfield | Argo Project</a> &#8212; <a href="https://blog.argoproj.io/best-practices-for-multi-tenancy-in-argo-cd-273e25a047b0?gi=e0f0531d2f65">blog.argoproj.io</a></strong> This blogpost is co-authored by Dan Garfield and Jesse Suen. Special thanks to Alexander Matyushentsev, Jann Fischer, Henrik Blixt, and the amazing community for all their hard work in making Argo CD&#8230;</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #34]]></title><description><![CDATA[Hello Peeps &#128075;, I'm back home from some PTO traveling to New York City with my family and friends. We ate so much pizza &#127829;, cheesecake &#127856;, and bagels &#129391; that now I have to double my time on the treadmill &#127939;Some news around Kubernetes, The Release team 1.24 is working very hard to get a quality build out the door, but due to a bug in golang the final 1.24 release date was moved to May 3rd &#9202; I'm the new release notes lead for 1.25 and the shadow application is open for people to apply. &#128640;]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-34-1120434</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-34-1120434</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 19 Apr 2022 02:38:44 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello Peeps &#128075;, I'm back home from some PTO traveling to New York City with my family and friends. We ate so much pizza &#127829;, cheesecake &#127856;, and bagels &#129391; that now I have to double my time on the treadmill &#127939;</p><p>Some news around Kubernetes, The Release team 1.24 is working very hard to get a quality build out the door, but due to a bug in golang the <a href="https://groups.google.com/a/kubernetes.io/g/dev/c/9IZaUGVMnmo">final 1.24 release date was moved to May 3rd</a> &#9202;</p><p>I'm the new release notes lead for 1.25 and the <a href="https://groups.google.com/a/kubernetes.io/g/dev/c/vn8ZkMXjPpc">shadow application is open for people to apply.</a> &#128640;</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.chainguard.dev/the-principle-of-ephemerality/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The Principle of Ephemerality</a> &#8212; <a href="https://blog.chainguard.dev/the-principle-of-ephemerality/">blog.chainguard.dev</a></strong> TL;DR: Everything that can be ephemeral, should be ephemeral.</p><p><strong><a href="https://www.talos.dev/v1.0/introduction/what-is-new/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What's New in Talos 1.0 | Talos Linux</a></strong> List of new and shiny features in Talos Linux.</p><p><strong><a href="https://medium.com/@bitterwinsome/3-cloudops-companies-that-want-you-to-destroy-kubernetes-in-prod-f1feed6bcaed?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">3 CloudOps Companies That Want You To Destroy Kubernetes in Prod | by Molly Sheets | Apr, 2022 | Medium</a> &#8212; <a href="https://medium.com/@bitterwinsome/3-cloudops-companies-that-want-you-to-destroy-kubernetes-in-prod-f1feed6bcaed">medium.com</a></strong> In the last month, I investigated the portfolios of newer companies in devops and liveops because I had a hunch something interesting was happening in the world of reliability &#8212; is chaos engineering&#8230;</p><p><strong><a href="https://kubernetes.io/blog/2022/04/07/upcoming-changes-in-kubernetes-1-24/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Removals and Deprecations In 1.24 | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2022/04/07/upcoming-changes-in-kubernetes-1-24/">kubernetes.io</a></strong></p><p><strong><a href="https://vedcraft.com/architecture/cloud-native-is-the-new-architecture-mantra-for-core-banking-solutions?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cloud Native Is The New Architecture Mantra For Core Banking Solutions</a> &#8212; <a href="https://vedcraft.com/architecture/cloud-native-is-the-new-architecture-mantra-for-core-banking-solutions">vedcraft.com</a></strong> Cloud Native technologies are in mainstream adoption and Cloud native is the new architecture mantra for core banking solutions. Read more.</p><p><strong><a href="https://github.blog/2022-04-07-slsa-3-compliance-with-github-actions/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Achieving SLSA 3 Compliance with GitHub Actions and Sigstore for Go modules | The GitHub Blog</a> &#8212; <a href="https://github.blog/2022-04-07-slsa-3-compliance-with-github-actions/">github.blog</a></strong> Learn how to build packages with SLSA 3 provenance using GitHub Actions.</p><p><strong><a href="https://blog.kubecost.com/blog/measuring-argo-workflows-with-kubecost/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Measuring Argo Workflow Costs with Kubecost -</a></strong> Learn how you can use Argo and Kubecost together to optimize your Kubernetes workflows and gain insights and visibility into your cloud costs.</p><p><strong><a href="https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators</a> &#8212; <a href="https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/">github.blog</a></strong></p><p>On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI</p><p><strong><a href="https://www.vladionescu.me/posts/scaling-containers-on-aws-in-2022/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Scaling containers on AWS in 2022 :: Vlad Ionescu</a> &#8212; <a href="https://www.vladionescu.me/posts/scaling-containers-on-aws-in-2022/">www.vladionescu.me</a></strong> Comparing how fast containers scale up in 2022 using different orchestrators on AWS</p><p><strong><a href="https://medium.com/@percenuage/my-adventure-with-helm-as-gitops-in-a-distributed-architecture-6a6fdc6f11bd?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">My adventure with Helm as GitOps in a distributed architecture | by Axel Gendillard | Feb, 2022 | Medium</a> &#8212; <a href="https://medium.com/@percenuage/my-adventure-with-helm-as-gitops-in-a-distributed-architecture-6a6fdc6f11bd">medium.com</a></strong> The &#8220;DevOps&#8221; community has brought me useful knowledge since I started my career. Now it&#8217;s my turn to give back to the community. I would like to share some of my experience about Helm configuration&#8230;</p><p><strong><a href="https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">An update to Raspberry Pi OS Bullseye - Raspberry Pi</a> &#8212; <a href="https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/">www.raspberrypi.com</a></strong> Over the years, we have gradually ramped up the security of Raspberry Pi OS. Here's Simon Long to tell you what has changed.</p><p><strong><a href="https://www.docker.com/blog/announcing-docker-sbom-a-step-towards-more-visibility-into-docker-images/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing Docker SBOM: A step towards more visibility into Docker images - Docker</a></strong> Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version announcements!</p><p><strong><a href="https://medium.com/containers-101/best-practices-for-argo-cd-8253bcd31897?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Argo CD Best Practices | Container Hub</a> &#8212; <a href="https://medium.com/containers-101/best-practices-for-argo-cd-8253bcd31897">medium.com</a></strong> Discover key best practices for Argo CD that allow you to leverage GitOps easily within your deployment workflow.</p><p><strong><a href="https://www.tutorialworks.com/difference-docker-containerd-runc-crio-oci/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The differences between Docker, containerd, CRI-O and runc - Tutorial Works</a> &#8212; <a href="https://www.tutorialworks.com/difference-docker-containerd-runc-crio-oci/">www.tutorialworks.com</a></strong> Let&#8217;s answer the question of Docker vs CRI-O, and other common questions about different container runtimes.</p><p><strong><a href="https://enterprisersproject.com/article/2022/4/reduce-technical-debt?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">9 reasons you have technical debt and how to reduce it | The Enterprisers Project</a> &#8212; <a href="https://enterprisersproject.com/article/2022/4/reduce-technical-debt">enterprisersproject.com</a></strong> Don&#8217;t let technical debt hinder your organization&#8217;s digital transformation. Here are nine leading causes and a four-step strategy to overcome technical debt</p><p><strong><a href="https://security.googleblog.com/2022/04/improving-software-supply-chain.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google Online Security Blog: Improving software supply chain security with tamper-proof builds</a> &#8212; <a href="https://security.googleblog.com/2022/04/improving-software-supply-chain.html">security.googleblog.com</a></strong> Posted by Asra Ali and Laurent Simon, Google Open Source Security Team (GOSST) Many of the recent high-profile software attacks that have al...</p><p><strong><a href="https://aws.amazon.com/blogs/aws/announcing-aws-lambda-function-urls-built-in-https-endpoints-for-single-function-microservices/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing AWS Lambda Function URLs: Built-in HTTPS Endpoints for Single-Function Microservices</a> &#8212; <a href="https://aws.amazon.com/blogs/aws/announcing-aws-lambda-function-urls-built-in-https-endpoints-for-single-function-microservices/">aws.amazon.com</a></strong></p><h2>Assets</h2><p><strong><a href="https://www.ibm.com/cloud/blog/using-fio-to-tell-whether-your-storage-is-fast-enough-for-etcd?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Using Fio to Tell Whether Your Storage is Fast Enough for Etcd | IBM</a> &#8212; <a href="https://www.ibm.com/cloud/blog/using-fio-to-tell-whether-your-storage-is-fast-enough-for-etcd">www.ibm.com</a></strong> The short story: fio and etcd</p><p><strong><a href="https://github.com/kris-nova/kaar?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kris-nova/kaar</a> &#8212; <a href="https://github.com/kris-nova/kaar">github.com</a></strong> Kubernetes Application Archive. Contribute to kris-nova/kaar development by creating an account on GitHub.</p><p><strong><a href="https://tauri.studio/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Build smaller, faster, and more secure desktop applications with a web frontend | Tauri Studio</a> &#8212; <a href="https://tauri.studio/">tauri.studio</a></strong> Tauri is a framework for building tiny, blazing fast binaries for all major desktop platforms. Developers can integrate any front-end framework that compiles to HTML, JS and CSS for building their user interface.</p><p><strong><a href="https://github.com/disneystreaming/ssm-helpers?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - disneystreaming/ssm-helpers</a> &#8212; <a href="https://github.com/disneystreaming/ssm-helpers">github.com</a></strong> Help manage AWS systems manager with helpers. Contribute to disneystreaming/ssm-helpers development by creating an account on GitHub.</p><p><strong><a href="https://github.com/patrickdappollonio/tabloid?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - patrickdappollonio/tabloid</a> &#8212; <a href="https://github.com/patrickdappollonio/tabloid">github.com</a></strong> tabloid is a simple command line tool to parse and filter column-based CLI outputs from commands like kubectl or docker - GitHub - patrickdappollonio/tabloid: tabloid is a simple command line tool to parse and filter column-based CLI outputs from commands like kubectl or docker</p><p><strong><a href="https://fwa.dev/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Functional Web App (FWA)</a></strong> The Functional Web App (FWA) is an architectural pattern for building dynamic web applications and APIs.</p><p><strong><a href="https://github.com/CaravanaCloud/task-tree?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - CaravanaCloud/task-tree</a> &#8212; <a href="https://github.com/CaravanaCloud/task-tree">github.com</a></strong> Automating maintenance and troubleshooting tasks for Cloud Computing - GitHub - CaravanaCloud/task-tree: Automating maintenance and troubleshooting tasks for Cloud Computing</p><h2>Skills</h2><p><strong><a href="https://kube.events/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes events | Kube Events</a> &#8212; <a href="https://kube.events/">kube.events</a></strong> Curated meetups, conferences, training and webinars on Kubernetes</p><p><strong><a href="https://developers.redhat.com/articles/2022/04/05/automate-cicd-pull-requests-argo-cd-applicationsets?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Automate CI/CD on pull requests with Argo CD ApplicationSets | Red Hat Developer</a> &#8212; <a href="https://developers.redhat.com/articles/2022/04/05/automate-cicd-pull-requests-argo-cd-applicationsets">developers.redhat.com</a></strong> Use Argo CD's ApplicationSets and pull request generator with Tekton and Red Hat OpenShift tools to bring GitOps workflows into your CI/CD processes.</p><p><strong><a href="https://kubesimplify.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">New Kube blog site</a> &#8212; <a href="https://kubesimplify.com/">kubesimplify.com</a></strong> On a mission to teach cloud native to everyone.</p><p><strong><a href="https://medium.com/@charled.breteche/securing-grafana-with-keycloak-sso-d01fec05d984?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Securing Grafana with Keycloak SSO </a>&#8212; <a href="https://medium.com/@charled.breteche/securing-grafana-with-keycloak-sso-d01fec05d984">medium.com</a></strong> In this story i will show how to deploy and configure Keycloak in a local Kubernetes cluster, then deploy Grafana and use the Keycloak instance for authentication and authorization. I already wrote&#8230;</p><p><strong><a href="https://learnk8s.io/kubernetes-long-lived-connections?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Load balancing and scaling long-lived connections in Kubernetes</a> &#8212; <a href="https://learnk8s.io/kubernetes-long-lived-connections">learnk8s.io</a></strong> Kubernetes doesn't load balance long-lived connections and some Pods might receive more requests than others. Learn how to fix that.</p><p><strong><a href="https://cloud.google.com/blog/topics/developers-practitioners/deploy-coloring-page-generator-minutes-cloud-run?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Deploy a coloring page generator in minutes with Cloud Run</a></strong> In this post, you'll see how to create an image processing service and make it available online using minimal resources.</p><p><strong><a href="https://contribute.cncf.io/maintainers/github/templates/recommended/reviewing/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">HowTo: Make a Reviewing Guide | CNCF Contributors</a></strong></p><p><strong><a href="https://nuvalence.io/blog/modeling-analyzing-lambda-vs-fargate-breakeven?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Modeling &amp; Analyzing Lambda vs. Fargate Breakeven &#8212; Nuvalence</a> &#8212; <a href="https://nuvalence.io/blog/modeling-analyzing-lambda-vs-fargate-breakeven">nuvalence.io</a></strong></p><p><strong><a href="https://containerjournal.com/editorial-calendar/hardening-kubernetes-multi-cluster-environments/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Hardening Kubernetes Multi-Cluster Environments - Container Journal</a> &#8212; <a href="https://containerjournal.com/editorial-calendar/hardening-kubernetes-multi-cluster-environments/">containerjournal.com</a></strong> Increased visibility into all Kubernetes platforms and tighter RBAC is necessary to keep cloud-native architecture safe and secure.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #33]]></title><description><![CDATA[Last week we finished the book Container Security by Liz Rice, and this week we started a new book Kubernetes Security by Michale Hausenblas and Liz Rice. If You want to see the following books we will be reading and discussing, check out the Kubernetes Book Club. If you are a new person to open source and want to participate in Google Summer of Code (GSOC) this year with one of the CNCF projects, including Kubernetes, Knative, and many others, I hosted a Twitter Space you can listen to the recording.PS: If you plan to attend KubeCon and KnativeCon, I'm giving two talks. Please don't be shy, say hi, and take a selfie with me &#129303;]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-33-1108611</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-33-1108611</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 05 Apr 2022 01:34:04 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Last week we finished the book <strong><a href="https://twitter.com/csantanapr/status/1509863460913438723">Container Security</a></strong> by <a href="https://twitter.com/lizrice">Liz Rice</a>, and this week we started a new book <strong><a href="https://twitter.com/csantanapr/status/1510688253913047050">Kubernetes Security</a></strong> by <a href="https://twitter.com/mhausenblas">Michale Hausenblas</a> and Liz Rice. If You want to see the following books we will be reading and discussing, check out the <a href="https://www.santana.dev/book-club">Kubernetes Book Club</a>.</p><p>If you are a new person to open source and want to participate in Google Summer of Code (GSOC) this year with one of the CNCF projects, including Kubernetes, Knative, and many others, I hosted a <a href="https://twitter.com/csantanapr/status/1509607399514071040">Twitter Space</a> you can listen to the recording.</p><p>PS: If you plan to attend KubeCon and KnativeCon, I'm giving two talks. Please don't be shy, say hi, and take a selfie with me &#129303;</p><div><hr></div><h2>News</h2><p><strong><a href="https://opensource.com/article/22/3/virtual-kubernetes-clusters-new-model-multitenancy?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Virtual Kubernetes clusters: A new model for multitenancy | Opensource.com</a> &#8212; <a href="https://opensource.com/article/22/3/virtual-kubernetes-clusters-new-model-multitenancy">opensource.com</a></strong> Try vcluster, an open source implementation that tackles certain aspects of typical namespace- and cluster-based isolation models.</p><p><strong><a href="https://aws.amazon.com/blogs/containers/amazon-eks-now-supports-kubernetes-1-22/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Amazon EKS now supports Kubernetes 1.22 | Amazon Web Services</a> &#8212; <a href="https://aws.amazon.com/blogs/containers/amazon-eks-now-supports-kubernetes-1-22/">aws.amazon.com</a></strong></p><p>Amazon EKS, Amazon EKS Distro, and Amazon EKS Anywhere&nbsp;can now run Kubernetes version 1.22.</p><p><strong><a href="https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Spring4Shell: The zero-day RCE in the Spring Framework explained | Snyk</a> &#8212; <a href="https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/">snyk.io</a></strong> Security resources like Lunasec, Rapid7 and Praetorian confirmed that the vulnerability is real, and in the meantime Spring has already released a new version</p><p><strong><a href="https://grafana.com/blog/2022/03/30/announcing-grafana-mimir/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing Grafana Mimir, the most scalable open source TSDB in the world | Grafana Labs</a> &#8212; <a href="https://grafana.com/blog/2022/03/30/announcing-grafana-mimir/">grafana.com</a></strong> Our new open source project allows you to scale to 1 billion metrics and beyond.</p><p><strong><a href="https://go.dev/blog/supply-chain?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How Go Mitigates Supply Chain Attacks - The Go Programming Language</a></strong> Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.</p><p><strong><a href="https://blog.getambassador.io/is-platform-engineering-the-new-devops-or-sre-472ed97a1885?gi=61fdbd83cb3c&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Is Platform Engineering the New DevOps or SRE? | by Daniel Bryant | Mar, 2022 | Ambassador Labs</a> &#8212; <a href="https://blog.getambassador.io/is-platform-engineering-the-new-devops-or-sre-472ed97a1885?gi=61fdbd83cb3c">blog.getambassador.io</a></strong> Almost every day we hear about another organization building an internal developer platform or developer control plane. We&#8217;re not alone in observing this trend in platform engineering; when Humanitec&#8230;</p><p><strong><a href="https://kubernetes.io/docs/tasks/configure-pod-container/migrate-from-psp/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Migrate from PodSecurityPolicy to PodSecurity Admission Controller (Updated)</a> &#8212; <a href="https://kubernetes.io/docs/tasks/configure-pod-container/migrate-from-psp/">kubernetes.io</a></strong></p><p>This page describes the process of migrating from PodSecurityPolicies to the built-in PodSecurity admission controller.</p><p><strong><a href="https://aquasecurity.github.io/trivy/v0.25.1/docs/sbom/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Trivy new SBOM subcommand</a></strong></p><p>Comprehensive Vulnerability Scanner Trivy currently supports SBOM formats.</p><p><strong><a href="https://kubernetes.io/blog/2021/12/22/kubernetes-in-kubernetes-and-pxe-bootable-server-farm/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes-in-Kubernetes and the WEDOS PXE bootable server farm | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2021/12/22/kubernetes-in-kubernetes-and-pxe-bootable-server-farm/">kubernetes.io</a></strong></p><p>Author: Andrei Kvapil (WEDOS) When you own two data centers, thousands of physical servers, virtual machines and hosting for hundreds of thousands sites, Kubernetes can actually simplify the management of all these things.</p><p><strong><a href="https://planetscale.com/blog/generics-can-make-your-go-code-slower?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Generics can make your Go code slower</a> &#8212; <a href="https://planetscale.com/blog/generics-can-make-your-go-code-slower">planetscale.com</a></strong> Go 1.18 is here, and with it, the first release of the long-awaited implementation of Generics is finally ready for production usage. Generics are a frequently requested feature that has been highly contentious throughout the Go community.</p><p><strong><a href="https://kubernetes.io/blog/2022/03/31/ready-for-dockershim-removal/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Is Your Cluster Ready for v1.24? | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2022/03/31/ready-for-dockershim-removal/">kubernetes.io</a></strong></p><p>Author: Kat Cosgrove Way back in December of 2020, Kubernetes announced the deprecation of Dockershim.</p><p><strong><a href="https://blog.crunchydata.com/blog/announcing-postgres-container-apps-easy-deploy-postgres-apps?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing Postgres Container Apps: Easy Deploy Postgres Apps</a></strong> With Postgres Container Apps you can, from directly inside Postgres with a simple function call, spin up a container that is running right alongside your Postgres database!</p><h2>Assets</h2><p><strong><a href="https://consoledonottrack.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Console Do Not Track (DNT)</a></strong></p><p>This is a proposal for a single, standard environment variable that plainly and unambiguously expresses LACK OF CONSENT by a user of that software to&nbsp;<strong>any</strong>&nbsp;of the following:</p><p><strong><a href="https://github.com/rothgar/bashScheduler?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes scheduler written in less than 100 lines of bash</a> &#8212; <a href="https://github.com/rothgar/bashScheduler">github.com</a></strong> Kubernetes scheduler written in less than 100 lines of bash :grimacing: :laughing: - GitHub - rothgar/bashScheduler: Kubernetes scheduler written in less than 100 lines of bash</p><p><strong><a href="https://github.com/aws-containers/kubectl-detector-for-docker-socket?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A Kubectl plugin that can detect if any of your workloads or manifest files are mounting the docker.sock volume</a> &#8212; <a href="https://github.com/aws-containers/kubectl-detector-for-docker-socket">github.com</a></strong></p><p>A Kubectl plugin that can detect if any of your workloads or manifest files are mounting the docker.sock</p><p><strong><a href="https://github.com/instrumenta/kubeval?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Validate your Kubernetes configuration files, supports multiple Kubernetes versions</a> &#8212; <a href="https://github.com/instrumenta/kubeval">github.com</a></strong> Validate your Kubernetes configuration files, supports multiple Kubernetes versions - GitHub - instrumenta/kubeval: Validate your Kubernetes configuration files, supports multiple Kubernetes versions</p><p><strong><a href="https://github.com/yannh/kubeconform?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A FAST Kubernetes manifests validator, with support for Custom Resources!</a> &#8212; <a href="https://github.com/yannh/kubeconform">github.com</a></strong> A FAST Kubernetes manifests validator, with support for Custom Resources! - GitHub - yannh/kubeconform: A FAST Kubernetes manifests validator, with support for Custom Resources!</p><h2>Skills</h2><p><strong><a href="https://matrix.org/blog/2022/03/30/technical-faq-on-the-digital-markets-act/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Technical FAQ on the Digital Markets Act | Matrix.org</a> &#8212; <a href="https://matrix.org/blog/2022/03/30/technical-faq-on-the-digital-markets-act/">matrix.org</a></strong> We've been flooded with questions about the DMA since it was announced last week, and have spotted some of the gatekeepers jumping to the wrong conclusions about what it might entail. Just in case you don't want to wade through yesterday's sprawling blog post, we've put together a quick FAQ to cover the most important points based on our understanding.</p><p><strong><a href="https://www.parca.dev/docs/binary?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Parca from Binary | Parca</a></strong></p><p>Parca is a continuous profiling project for applications and infrastructure. It helps you save money, improve performance and understand incidents better.</p><p><strong><a href="https://medium.com/@lizrice/finding-an-intro-to-maths-for-cryptography-cc97ad6b04?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Finding an intro to maths for cryptography | by Liz Rice | Medium</a> &#8212; <a href="https://medium.com/@lizrice/finding-an-intro-to-maths-for-cryptography-cc97ad6b04">medium.com</a></strong> If you&#8217;re looking for an introduction to the mathematics that make cryptography work, perhaps this list might help. I&#8217;m currently writing a book about Container Security for O&#8217;Reilly Media, and one&#8230;</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #32]]></title><description><![CDATA[April starts this week, and you know what that means? 1Q22 is over, and you have to reflect on what you achieved in 25% of the year.&#160;I hope the war ends soon; writing this phrase is surreal.Talking about surreal, this is how   actors felt at the Oscars this Sunday.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-32-1096830</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-32-1096830</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 29 Mar 2022 01:19:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/01w7viEZzXQ" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>April starts this week, and you know what that means? 1Q22 is over, and you have to reflect on what you achieved in 25% of the year.&nbsp;</p><p><a href="https://twitter.com/POTUS/status/1508177941963984901">I hope the war ends soon</a>; writing this phrase is surreal.</p><p>Talking about surreal, this is how actors felt at the <a href="https://twitter.com/Variety/status/1508585165232214019">Oscars this Sunday</a>.</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.goreleaser.com/goreleaser-and-software-supply-chain-security-e8917b26924b?gi=8f7e5a469709&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GoReleaser And Software Supply Chain Security | by developer-guy | Mar, 2022 | GoReleaser</a> &#8212; <a href="https://blog.goreleaser.com/goreleaser-and-software-supply-chain-security-e8917b26924b?gi=8f7e5a469709">blog.goreleaser.com</a></strong> Before talking about the security of the software supply chains, we should mention what should come to our minds first when we are talking about software supply chains. In most basic terms, you can&#8230;</p><p><strong><a href="https://www.caffeinatedwonders.com/2022/03/28/new-ssh-server?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing Caddy-SSH</a></strong></p><p>Pure-Go, general-purpose SSH server</p><p><strong><a href="https://medium.com/@butkovic/favoring-podman-over-docker-desktop-33368e031ba0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Favoring Podman over Docker Desktop | by Peter Butkovic | Mar, 2022 | Medium</a> &#8212; <a href="https://medium.com/@butkovic/favoring-podman-over-docker-desktop-33368e031ba0">medium.com</a></strong> Since the announcement, that docker desktop won&#8217;t be available for free for the bigger organizations, I&#8217;ve been looking for the open source alternative with smooth migration option. Podman did a&#8230;</p><p><strong><a href="https://www.kubermatic.com/blog/get-the-best-of-both-worlds-with-the-kkp-2-19-cni-strategy/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Get the Best of Both Worlds With the KKP 2.19 CNI Strategy</a> &#8212; <a href="https://www.kubermatic.com/blog/get-the-best-of-both-worlds-with-the-kkp-2-19-cni-strategy/">www.kubermatic.com</a></strong> Find out how you can expect greater control and flexibility by selecting a CNI plugin with KKP 2.19.</p><p><strong><a href="https://opensource.com/article/19/5/shortcomings-rootless-containers?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The shortcomings of rootless containers | Opensource.com</a> &#8212; <a href="https://opensource.com/article/19/5/shortcomings-rootless-containers">opensource.com</a></strong> Explore how the principles behind open source--collaboration, transparency, and rapid prototyping--are proven catalysts for innovation.</p><p><strong><a href="https://www.redhat.com/en/blog/understanding-root-inside-and-outside-container?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Understanding root inside and outside a container</a> &#8212; <a href="https://www.redhat.com/en/blog/understanding-root-inside-and-outside-container">www.redhat.com</a></strong> Do you run your containers as root, or as a regular user? It&#8217;s such a deceptively simple question. You might be tempted to answer too quickly. Is the threat model really crystal clear in your mind? I have a suspicion that it might not be.</p><p><strong><a href="https://justi.cz/security/2018/11/14/gvisor-lpe.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Privilege Escalation in gVisor, Google's Container Sandbox</a></strong> tl;dr gVisor is Google&#8217;s sandboxing technology for containers running less-than-fully-trusted code. It&#8217;s a Golang reimplementation of the Linux kernel that r...</p><p><strong><a href="https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">containerd CRI plugin: Insecure handling of image volumes &#183; Advisory &#183; containerd/containerd &#183; GitHub</a> &#8212; <a href="https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7">github.com</a></strong> GitHub is where people build software. More than 73 million people use GitHub to discover, fork, and contribute to over 200 million projects.</p><h2>Assets</h2><p><strong><a href="https://github.com/box/kube-exec-controller?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - box/kube-exec-controller: </a>&#8212; <a href="https://github.com/box/kube-exec-controller">github.com</a></strong></p><p>An admission controller service and kubectl plugin to handle container drift in K8s clusters -</p><p><strong><a href="https://github.com/genuinetools/bane?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - genuinetools/bane: Custom &amp; better AppArmor profile generator for Docker containers.</a> &#8212; <a href="https://github.com/genuinetools/bane">github.com</a></strong> Custom &amp; better AppArmor profile generator for Docker containers. - GitHub - genuinetools/bane: Custom &amp; better AppArmor profile generator for Docker containers.</p><p><strong><a href="https://github.com/lizrice/running-with-scissors?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - lizrice/running-with-scissors: Resources from my KubeCon + CloudNativeCon keynote</a> &#8212; <a href="https://github.com/lizrice/running-with-scissors">github.com</a></strong> Resources from my KubeCon + CloudNativeCon keynote - GitHub - lizrice/running-with-scissors: Resources from my KubeCon + CloudNativeCon keynote</p><p><strong><a href="https://rootlesscontaine.rs/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Rootless Containers | Rootless Containers</a></strong> Rootless Containers</p><p><strong><a href="https://kubernetes.io/docs/tasks/administer-cluster/kubelet-in-userns/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Running Kubernetes Node Components as a Non-root User | Kubernetes</a> &#8212; <a href="https://kubernetes.io/docs/tasks/administer-cluster/kubelet-in-userns/">kubernetes.io</a></strong></p><p>FEATURE STATE: Kubernetes v1.22 [alpha] This document describes how to run Kubernetes Node components such as kubelet, CRI, OCI, and CNI without root privileges, by using a user namespace.</p><p><strong><a href="https://kubernetes.io/docs/reference/using-api/deprecation-guide/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Deprecated API Migration Guide | Kubernetes</a> &#8212; <a href="https://kubernetes.io/docs/reference/using-api/deprecation-guide/">kubernetes.io</a></strong></p><p>As the Kubernetes API evolves, APIs are periodically reorganized or upgraded. in v1.</p><p><strong><a href="https://aws.github.io/aws-eks-best-practices/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introduction - EKS Best Practices Guides</a></strong></p><p>Welcome to the EKS Best Practices Guides.</p><h2>Skills</h2><p><strong><a href="https://gibsonbiddle.medium.com/hacking-your-product-management-career-cce227a9c39a?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Hacking Your Product Leader Career | by Gibson Biddle | Medium</a> &#8212; <a href="https://gibsonbiddle.medium.com/hacking-your-product-management-career-cce227a9c39a">gibsonbiddle.medium.com</a></strong> A few years ago, I watched an Olympic gymnast deliver a speech, &#8220;How to Score a Perfect Ten.&#8221; He gave his talk while doing his pommel horse routine! He vaulted onto the horse, did a series of moves&#8230;</p><p><strong><a href="https://gvisor.dev/docs/architecture_guide/performance/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">gVisor Performance Guide</a></strong></p><p>gVisor is designed to provide a secure, virtualized environment while preserving key benefits of containerization, such as small fixed overheads and a dynamic resource footprint.</p><p><strong><a href="https://opensource.com/business/13/11/selinux-policy-guide?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Your visual how-to guide for SELinux policy enforcement | Opensource.com</a> &#8212; <a href="https://opensource.com/business/13/11/selinux-policy-guide">opensource.com</a></strong> Explore how the principles behind open source--collaboration, transparency, and rapid prototyping--are proven catalysts for innovation.</p><div id="youtube2-01w7viEZzXQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;01w7viEZzXQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/01w7viEZzXQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://github.com/genuinetools/contained.af?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - genuinetools/contained.af</a> &#8212; <a href="https://github.com/genuinetools/contained.af">github.com</a></strong> A stupid game for learning about containers, capabilities, and syscalls. - GitHub - genuinetools/contained.af: A stupid game for learning about containers, capabilities, and syscalls.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #31]]></title><description><![CDATA[I'm back from PTO, went to Orlando and visit Kubernete World, Where all Conditions come True (Eventually &#128517;)I'm helping plan KnativeCon and the Kubernetes Contributor Summit for KubeCon EU, I hope to be in Spain during May to finally meet some of my Cloud Native peeps in person.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-31-1085403</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-31-1085403</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 22 Mar 2022 00:17:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/N6iNLZi42MA" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I'm back from PTO, went to Orlando and visit<strong> <a href="https://twitter.com/csantanapr/status/1503807929518075904">Kubernete World</a></strong><a href="https://twitter.com/csantanapr/status/1503807929518075904">, Where all Conditions come True</a> (Eventually &#128517;)</p><p>I'm helping plan KnativeCon and the Kubernetes Contributor Summit for KubeCon EU, I hope to be in Spain during May to finally meet some of my Cloud Native peeps in person.</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.theregister.com/2022/03/15/cr8escape_container_runtime_bug/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes container runtime CRI-O has make-me-root flaw &#8226; The Register</a> &#8212; <a href="https://www.theregister.com/2022/03/15/cr8escape_container_runtime_bug/">www.theregister.com</a></strong> Cr8escape priv-escalation bug opens the door to cluster takeovers</p><p><strong><a href="https://blog.chainguard.dev/sigstore-the-local-way/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">sigstore, the local way</a> &#8212; <a href="https://blog.chainguard.dev/sigstore-the-local-way/">blog.chainguard.dev</a></strong> If you've been following the Chainguard blog, you might ask yourself: how do I run the open-source sigstore stack on my machine? While sigstore is often deployed using Kubernetes, it is flexible enough to run nearly anywhere: from a Raspberry Pi to an IBM mainframe. This article will demonstrate how</p><p><strong><a href="https://news.yahoo.com/senate-passes-bill-making-daylight-193310141.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Senate votes to make daylight saving time permanent</a> &#8212; <a href="https://news.yahoo.com/senate-passes-bill-making-daylight-193310141.html">news.yahoo.com</a></strong> The Senate approved legislation Tuesday that would make daylight saving time permanent in the U.S. starting next year.</p><p><strong><a href="https://guillaumeben.xyz/defender-containers.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Guillaume's Security Notebook</a></strong> In this article, we will explore and test Defender for Containers against a vulnerable environment and see what it can detects or prevent and how we can leverage it to make our Kubernetes workloads safer.</p><p><strong><a href="https://medium.com/codex/explore-client-go-informer-patterns-4415bb5f1fbd?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Explore client-go Informer Patterns | by Stefanie Lai | CodeX | Feb, 2022 | Medium</a> &#8212; <a href="https://medium.com/codex/explore-client-go-informer-patterns-4415bb5f1fbd">medium.com</a></strong> In platform development, our cluster runs operators involving multiple teams and various GCP resources, for querying which we often need to write various code including but not limited to bash&#8230;</p><p><strong><a href="https://www.cncf.io/blog/2019/08/06/open-sourcing-the-kubernetes-security-audit/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Open sourcing the Kubernetes security audit | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/blog/2019/08/06/open-sourcing-the-kubernetes-security-audit/">www.cncf.io</a></strong> Last year, the Cloud Native Computing Foundation (CNCF) began the process of performing and open sourcing third-party security audits for its projects in order&#8230;</p><p><strong><a href="https://about.gitlab.com/blog/2022/03/17/want-a-better-devops-career-learn-the-business/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Want a better DevOps career? Learn the business | GitLab</a> &#8212; <a href="https://about.gitlab.com/blog/2022/03/17/want-a-better-devops-career-learn-the-business/">about.gitlab.com</a></strong> A better DevOps career starts with a thorough understanding of business. Here's how to get started.</p><p><strong><a href="https://go.dev/doc/go1.18?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Go 1.18 Release Notes - The Go Programming Language</a></strong> Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.</p><p><strong><a href="https://blog.chainguard.dev/slsa-vs-software-supply-chain-attacks/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">SLSA vs. Software Supply Chain Attacks</a> &#8212; <a href="https://blog.chainguard.dev/slsa-vs-software-supply-chain-attacks/">blog.chainguard.dev</a></strong> Past Attacks and How SLSA Helps</p><p><strong><a href="https://www.eficode.com/blog/the-future-of-kubernetes-and-why-developers-should-look-beyond-kubernetes-in-2022?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The future of Kubernetes &#8211; and why developers should look beyond Kubernetes in 2022</a></strong> Kubernetes is ubiquitous in container orchestration, and its popularity has yet to weaken. This does, however, not mean that evolution in the container orchestration space is at a stand-still.</p><p><strong><a href="https://www.cncf.io/blog/2022/03/15/backstage-project-joins-the-cncf-incubator/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Backstage project joins the CNCF Incubator | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/blog/2022/03/15/backstage-project-joins-the-cncf-incubator/">www.cncf.io</a></strong> The CNCF Technical Oversight Committee (TOC) has voted to accept Backstage as a CNCF incubating project. Backstage is an open platform for building developer&#8230;</p><p><strong><a href="https://dev.to/stack-labs/introduction-to-taskfile-a-makefile-alternative-h92?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introduction to Taskfile: a Makefile alternative - DEV Community</a> &#8212; <a href="https://dev.to/stack-labs/introduction-to-taskfile-a-makefile-alternative-h92">dev.to</a></strong> Easier and simpler than Makefile. Tagged with automation, make, productivity.</p><p><strong><a href="https://www.theverge.com/2022/3/16/22980693/google-docs-gmail-draft-smart-canvas-chips?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google Docs update lets you draft emails and send them to Gmail with a click - The Verge</a> &#8212; <a href="https://www.theverge.com/2022/3/16/22980693/google-docs-gmail-draft-smart-canvas-chips">www.theverge.com</a></strong> Google is rolling out a new feature in its Docs that&#8217;s designed to make it easier to draft emails. It&#8217;s accessible via the @ menu in Google Docs.</p><p><strong><a href="https://www.csoonline.com/article/3410278/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The biggest data breach fines, penalties, and settlements so far | CSO Online</a> &#8212; <a href="https://www.csoonline.com/article/3410278/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html">www.csoonline.com</a></strong> Hacks and data thefts, enabled by weak security, cover-ups or avoidable mistakes have cost these companies a total of nearly $1.3 billion and counting.</p><p><strong><a href="https://linuxfoundation.org/wp-content/uploads/LF-Equality-Statement-7.pdf?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">LINUF FOUNDATION</a></strong></p><p>STATEMENT AGAINST TEXAS DISCRIMINATION</p><p><strong><a href="https://marcofranssen.nl/secure-your-software-supply-chain-using-sigstore-and-github-actions?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Secure your software supply chain using Sigstore and GitHub actions - Marco Franssen</a></strong></p><p>With the rise of software supply chain attacks it becomes more important to secure our software supply chains.</p><p><strong><a href="https://www.linkedin.com/posts/tim-seagren-7876aa112_sops-git-sigstore-activity-6910723090570240000-sDXg?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Tim Seagren on LinkedIn: #sops #git #sigstore | 11 comments</a> &#8212; <a href="https://www.linkedin.com/posts/tim-seagren-7876aa112_sops-git-sigstore-activity-6910723090570240000-sDXg">www.linkedin.com</a></strong> In the past 48 hours, the DoD Platform One Ironbank Pipelines and Operations (POPs) team has made two huge strides forward in the areas of day-to-day operations... 11 comments on LinkedIn</p><p><strong><a href="https://www.openssl.org/news/secadv/20220315.txt?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">OpenSSL Security Advisory [15 March 2022]</a></strong></p><p>Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778)</p><p><strong><a href="https://sessionize.com/cdk-day-2022?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CDK Day 2022: Call for Speakers/Papers @ Sessionize.com</a> &#8212; <a href="https://sessionize.com/cdk-day-2022">sessionize.com</a></strong> A Cloud Development Kit (CDK) is a developer tool built on the open source Constructs model. We now have multiple CDKs in AWS CDK, CDK for Terraform, ...</p><h2>Assets</h2><p><strong><a href="https://github.com/madhuakula/kubernetes-goat?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - madhuakula/kubernetes-goat: Kubernetes Goat &#128016; is a "Vulnerable by Design" </a>&#8212; <a href="https://github.com/madhuakula/kubernetes-goat">github.com</a></strong></p><p>Kubernetes Goat &#128016; is a "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security &#128272;security &#128272;</p><p><strong><a href="https://github.com/kubearmor/KubeArmor?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">GitHub - kubearmor/KubeArmor: Cloud-native Runtime Security Enforcement System</a> &#8212; <a href="https://github.com/kubearmor/KubeArmor?utm_source=pocket_mylist">github.com</a></strong> Cloud-native Runtime Security Enforcement System. Contribute to kubearmor/KubeArmor development by creating an account on GitHub.</p><p><strong><a href="https://github.com/magnologan/cncf-security-audits?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - magnologan/cncf-security-audits: List of all previous CNCF Project's Security Audit Reports</a> &#8212; <a href="https://github.com/magnologan/cncf-security-audits">github.com</a></strong> List of all previous CNCF Project's Security Audit Reports - GitHub - magnologan/cncf-security-audits: List of all previous CNCF Project's Security Audit Reports</p><p><strong><a href="https://github.com/go-task/task/releases?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Releases &#183; go-task/task &#183; GitHub</a> &#8212; <a href="https://github.com/go-task/task/releases">github.com</a></strong> A task runner / simpler Make alternative written in Go - Releases &#183; go-task/task</p><h2>Skills</h2><h2>Introducing apko &amp; melange</h2><div id="youtube2-N6iNLZi42MA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;N6iNLZi42MA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/N6iNLZi42MA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://www.linuxfoundation.org/research/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Research - Linux Foundation</a> &#8212; <a href="https://www.linuxfoundation.org/research/">www.linuxfoundation.org</a></strong> Expert guidance to manage open technology projects and put you on the path to success</p><p><strong><a href="https://stripe.com/guides/equity-for-employees?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Stripe: Equity for employees</a> &#8212; <a href="https://stripe.com/guides/equity-for-employees">stripe.com</a></strong> Understand the mechanics, decisions, and trade-offs related to issuing equity to employees</p><p><strong><a href="https://training.linuxfoundation.org/blog/success-story-cloud-engineer-bootcamp-enables-a-music-teacher-to-become-a-devops-engineer/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Success Story: Cloud Engineer Bootcamp Enables a Music Teacher to Become a DevOps Engineer - Linux Foundation - Training</a> &#8212; <a href="https://training.linuxfoundation.org/blog/success-story-cloud-engineer-bootcamp-enables-a-music-teacher-to-become-a-devops-engineer/">training.linuxfoundation.org</a></strong> Michael Rossiter was a long time Linux enthusiast working as a music teacher in the north of England. He had dreamed of a role working in IT, but wasn&#8217;t sure...</p><p><strong><a href="https://dev.to/aurelievache/learning-go-by-examples-part-2-create-an-http-rest-api-server-in-go-1cdm?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Learning Go by examples: part 2 - Create an HTTP REST API Server in Go - DEV Community</a> &#8212; <a href="https://dev.to/aurelievache/learning-go-by-examples-part-2-create-an-http-rest-api-server-in-go-1cdm">dev.to</a></strong> Serie of article in order to learn Golang language by concrete applications as example. Tagged with go, beginners, api, tutorial.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #30]]></title><description><![CDATA[Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and SkillsThis week I will be hosting the Kubernetes Office Hours again, this time will be learning about SIG-Docs]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-30-1075018</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-30-1075018</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 14 Mar 2022 17:42:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!E9mI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fff18ef17-5dbf-466f-a030-2c6b932ebff5_1200x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories <strong>News</strong>, <strong>Assets</strong>, and <strong>Skills</strong></p><p>This week I will be hosting the <a href="https://youtu.be/KJMka1ZzVUQ">Kubernetes Office Hours</a> again, this time will be learning about <a href="https://github.com/kubernetes/community/tree/master/sig-docs#docs-special-interest-group">SIG-Docs</a></p><div><hr></div><h2>News</h2><p><strong><a href="https://www.cncf.io/announcements/2022/03/09/cloud-native-computing-foundation-unveils-schedule-for-kubecon-cloudnativecon-europe-2022%EF%BF%BC/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cloud Native Computing Foundation Unveils Schedule for KubeCon + CloudNativeCon Europe 2022 | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/announcements/2022/03/09/cloud-native-computing-foundation-unveils-schedule-for-kubecon-cloudnativecon-europe-2022%EF%BF%BC/">www.cncf.io</a></strong> Back in-person in Valencia, Spain in May, technology enthusiasts will meet to share and educate around cloud native innovation SAN FRANCISCO, Calif. &#8211; March 9&#8230;</p><p><strong><a href="https://www.redhat.com/en/blog/red-hat-co-founded-project-knative-accepted-cncf-incubating-project?sc_cid=701f2000000tyBjAAI&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Red Hat co-founded project Knative accepted as CNCF incubating project</a> &#8212; <a href="https://www.redhat.com/en/blog/red-hat-co-founded-project-knative-accepted-cncf-incubating-project?sc_cid=701f2000000tyBjAAI">www.redhat.com</a></strong></p><p>This begins a new chapter in the evolution of a leading containerized serverless platform.</p><p><strong><a href="https://github.com/kubernetes-sigs/kind/releases/tag/v0.12.0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Release v0.12.0 &#183; kubernetes-sigs/kind </a>&#8212; <a href="https://github.com/kubernetes-sigs/kind/releases/tag/v0.12.0">github.com</a></strong> Kubernetes IN Docker - local clusters for testing Kubernetes - Release v0.12.0 &#183; kubernetes-sigs/kind</p><p><strong><a href="https://www.mandiant.com/company/press-release/mgc?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google to Acquire Mandiant | Mandiant</a> &#8212; <a href="https://www.mandiant.com/company/press-release/mgc">www.mandiant.com</a></strong> Your description for this link...</p><p><strong><a href="https://thenewstack.io/software-supply-chain-security-tearing-down-the-silos?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Software Supply Chain Security: Tearing Down the Silos &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/software-supply-chain-security-tearing-down-the-silos">thenewstack.io</a></strong> Both application and infrastructure security are required to keep a cloud native system safe. A single solution can integrate both to foil hackers.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/giltayar/status/1501962345119207426&quot;,&quot;full_text&quot;:&quot;By now, some of you may have heard about the new proposal to be suggested to the TC39 committee. This innocent sounding title is for a proposal that suggests adding some level of typing to the JavaScript language.\n\n<a class=\&quot;tweet-url\&quot; href=\&quot;https://github.com/giltayar/proposal-types-as-comments\&quot;>github.com/giltayar/propo&#8230;</a>\n\n&#129525;&quot;,&quot;username&quot;:&quot;giltayar&quot;,&quot;name&quot;:&quot;Gil Tayar&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Thu Mar 10 16:45:02 +0000 2022&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:45,&quot;like_count&quot;:132,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{&quot;url&quot;:&quot;https://github.com/giltayar/proposal-types-as-comments&quot;,&quot;image&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ff18ef17-5dbf-466f-a030-2c6b932ebff5_1200x600.png&quot;,&quot;title&quot;:&quot;GitHub - tc39/proposal-type-annotations: ECMAScript proposal for type syntax that is erased - Stage 1&quot;,&quot;description&quot;:&quot;ECMAScript proposal for type syntax that is erased - Stage 1 - GitHub - tc39/proposal-type-annotations: ECMAScript proposal for type syntax that is erased - Stage 1&quot;,&quot;domain&quot;:&quot;github.com&quot;},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p><strong><a href="https://medium.com/streamotion-tech-blog/visualising-the-cost-of-kubernetes-ca64f642de8c?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Visualising the Cost of Kubernetes | by Mitchell Rowling | Streamotion Tech Blog | Mar, 2022 | Medium</a> &#8212; <a href="https://medium.com/streamotion-tech-blog/visualising-the-cost-of-kubernetes-ca64f642de8c">medium.com</a></strong> Containerisation is still an emerging technology in many organisations across the world and Here at Streamotion, the adoption of containers has promoted rapid acceleration of our journey of Kayo&#8230;</p><p><strong><a href="https://www.eficode.com/blog/the-future-of-kubernetes-and-why-developers-should-look-beyond-kubernetes-in-2022?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The future of Kubernetes &#8211; and why developers should look beyond Kubernetes in 2022</a></strong> Kubernetes is ubiquitous in container orchestration, and its popularity has yet to weaken. This does, however, not mean that evolution in the container orchestration space is at a stand-still.</p><p><strong><a href="https://blog.aquasec.com/cve-2022-0847-dirty-pipe-linux-vulnerability?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Dirty Pipe Linux Vulnerability: Overwriting Files in Container Images</a></strong> CVE-2022-0847 Dirty Pipe in the Linux kernel allows users on Linux hosts running containerized applications to modify files in container images on the host</p><h2>Assets</h2><p><strong><a href="https://github.com/cert-manager/istio-csr?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - cert-manager/istio-csr: istio-csr is an agent that allows for Istio workload and control plane components to be secured using cert-manager.</a> &#8212; <a href="https://github.com/cert-manager/istio-csr">github.com</a></strong> istio-csr is an agent that allows for Istio workload and control plane components to be secured using cert-manager. - GitHub - cert-manager/istio-csr: istio-csr is an agent that allows for Istio workload and control plane components to be secured using cert-manager.</p><p><strong><a href="https://redpanda.com/cloud/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cloud Managed Redpanda | A Kafka alternative</a> &#8212; <a href="https://redpanda.com/cloud/">redpanda.com</a></strong> Choose a fully managed solution or bring your own cloud. Pay only for what you use. Infinite data retention. Global read replicas.</p><p><strong><a href="https://tmate.io/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">tmate &#8226; Instant terminal sharing</a></strong> Your description for this link...</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/mattklein123/status/1501648655907835905&quot;,&quot;full_text&quot;:&quot;It's been a journey for Envoy Mobile, but after significant progress we are starting to see traction across the industry. As such, we are now hosting a public community meeting for those that want to learn more about the project. Join us! &#128640;\n\n<a class=\&quot;tweet-url\&quot; href=\&quot;https://github.com/envoyproxy/envoy-mobile#community-meeting\&quot;>github.com/envoyproxy/env&#8230;</a>&quot;,&quot;username&quot;:&quot;mattklein123&quot;,&quot;name&quot;:&quot;Matt Klein&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Wed Mar 09 19:58:33 +0000 2022&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:15,&quot;like_count&quot;:44,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{&quot;url&quot;:&quot;https://github.com/envoyproxy/envoy-mobile#community-meeting&quot;,&quot;image&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/07936339-5d80-4121-bd6a-9da4afc3d510_1200x600.png&quot;,&quot;title&quot;:&quot;GitHub - envoyproxy/envoy-mobile: Client HTTP and networking library based on the Envoy project for iOS, Android, and more.&quot;,&quot;description&quot;:&quot;Client HTTP and networking library based on the Envoy project for iOS, Android, and more. - GitHub - envoyproxy/envoy-mobile: Client HTTP and networking library based on the Envoy project for iOS, ...&quot;,&quot;domain&quot;:&quot;github.com&quot;},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p><strong><a href="https://blog.baeke.info/2022/01/31/kubernetes-workload-identity-with-aks/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Workload Identity with AKS &#8211; baeke.info</a> &#8212; <a href="https://blog.baeke.info/2022/01/31/kubernetes-workload-identity-with-aks/">blog.baeke.info</a></strong> When you run a workload, no matter how simple or complex, you often need to access protected resources in both a secure and manageable way. Often, a resource's security is integrated with an identity store. Azure resources, for instance, can be secured with roles assigned to Azure Active Directory (AAD) users, groups, or service principals.&#8230;</p><h2>Skills</h2><p>Join the Monthly Kubernetes Office Hours this Wednesday, March 16th, with hosts <a href="https://twitter.com/csantanapr">@csantanapr</a> and <a href="https://twitter.com/rawkode">@rawkode</a></p><p>This month is SIG-Docs edition with guest <a href="https://twitter.com/Divya_Mohan02">@Divya_Mohan02</a></p><div id="youtube2-KJMka1ZzVUQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;KJMka1ZzVUQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/KJMka1ZzVUQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cloud-native-live-optimizing-istio-with-ebpf/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">See Cloud Native Live: Optimizing Istio with eBPF at CNCF CNCF Online Programs</a> &#8212; <a href="https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cloud-native-live-optimizing-istio-with-ebpf/">community.cncf.io</a></strong> CNCF CNCF Online Programs presents Cloud Native Live: Optimizing Istio with eBPF | Mar 16, 2022. Find event and ticket information.</p><div id="youtube2-KOh43en5dEY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;KOh43en5dEY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/KOh43en5dEY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://blog.devgenius.io/best-practice-and-cheat-sheet-for-rest-api-design-6a6e12dfa89f?gi=fa913c35becb&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Principles &amp; Best practices of REST API Design | by Love Sharma | Dev Genius</a> &#8212; <a href="https://blog.devgenius.io/best-practice-and-cheat-sheet-for-rest-api-design-6a6e12dfa89f?gi=fa913c35becb">blog.devgenius.io</a></strong> This best-practices article intends for developers interested in creating RESTful Web services that provide high reliability and consistency across multiple service suites; following these&#8230;</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #29]]></title><description><![CDATA[Thank you to all you that recently joined my weekly newsletter, welcome to this issue #29 as always I tried to categorize the resources into News, Assets, and Skills.If you wonder how can you help with the conflict in Ukraine there are many organizations you can donate to, and also encourage your employer to donate to help the large number of refugees.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-29-1049761</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-29-1049761</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Tue, 08 Mar 2022 02:51:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kHiC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fmedia%2FFNBhklkXIAwgvLx.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Thank you to all you that recently joined my weekly newsletter, welcome to this issue #29 as always I tried to categorize the resources into <strong>News</strong>, <strong>Assets</strong>, and <strong>Skills</strong>.</p><p>If you wonder how can you help with the conflict in Ukraine there are many organizations you can donate to, and also encourage your employer to donate to help the large number of refugees.</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.cncf.io/blog/2022/03/02/knative-accepted-as-a-cncf-incubating-project/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Knative accepted as a CNCF incubating project | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/blog/2022/03/02/knative-accepted-as-a-cncf-incubating-project/">www.cncf.io</a></strong> The CNCF Technical Oversight Committee (TOC) has voted to accept Knative as a CNCF incubating project. Knative is an open source, Kubernetes-based platform for&#8230;</p><p><strong><a href="https://www.infoq.com/podcasts/liz-rice-ebpf/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Liz Rice on Programming the Linux Kernel with eBPF, Cilium and Service Meshes</a> &#8212; <a href="https://www.infoq.com/podcasts/liz-rice-ebpf/">www.infoq.com</a></strong> Charles Humble discusses eBPF, a way of making the Linux kernel programmable, with Liz Rice.</p><p><strong><a href="https://thenewstack.io/using-machine-learning-to-actively-secure-cloud-native-apps?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Using Machine Learning to Actively Secure Cloud Native Apps &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/using-machine-learning-to-actively-secure-cloud-native-apps">thenewstack.io</a></strong> It's not enough to simply ward off threats. Tigera's Calico Cloud now uses machine learning to actively find and mitigate vulnerabilities.</p><p><strong><a href="https://blog.chainguard.dev/introducing-apko-bringing-distroless-nirvana-to-alpine-linux/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing apko: bringing distroless nirvana to Alpine Linux</a> &#8212; <a href="https://blog.chainguard.dev/introducing-apko-bringing-distroless-nirvana-to-alpine-linux/">blog.chainguard.dev</a></strong></p><p>Earlier today, Chainguard released version 0.1 of our apko tool.&nbsp;This tool allows for the composition of so-called &#8220;distroless&#8221; images from APK-based software distributions, such as Alpine Linux, using a declarative configuration.&nbsp;</p><p><strong><a href="https://thenewstack.io/acquisitions-are-good-for-the-developer-ecosystem?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Acquisitions Are Good for the Developer Ecosystem &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/acquisitions-are-good-for-the-developer-ecosystem">thenewstack.io</a></strong> A look at Mirantis' acquisition of Docker Enterprise and Lens, and the benefits to the developer and Kubernetes ecosystem that it's created in the past two years.</p><p><strong><a href="https://batuhan-apaydin-11378.medium.com/buildkit-machine-a-brand-new-project-to-enable-building-pushing-container-images-without-requiring-f8a899fd0cd0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">buildkit-machine: A brand new project to enable building/pushing container images without requiring a Docker Daemon based on BuildKit | by developer-guy | Mar, 2022 | Medium</a> &#8212; <a href="https://batuhan-apaydin-11378.medium.com/buildkit-machine-a-brand-new-project-to-enable-building-pushing-container-images-without-requiring-f8a899fd0cd0">batuhan-apaydin-11378.medium.com</a></strong> In the previous blog post, we talked about a brand new toolkit (lima + nerdctl + rancher-desktop) that we can use to work with container images, and in that blog post, we mentioned the&#8230;</p><p><strong><a href="https://podman.io/releases/2022/02/22/podman-release-v4.0.0.html?_hsenc=p2ANqtz-9d8EFhMcgAARzIrGghTUZBwZWhl4jouprVNWJDIzWwyXy08mtYzAXyKWvJnwkjLdQ1YiTqiGLUEwfMbNFtSf1ikcVgxQ&amp;_hsmi=205746218&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_content=205746218&amp;utm_medium=email&amp;utm_source=hs_email">Podman v4.0.0 Released</a></strong></p><p>Podman v4.0.0, a brand-new major release, is now available. Podman 4.0 is one of our most significant releases ever, featuring over 60 new features.</p><p><strong><a href="https://github.com/argoproj/argo-cd/releases/tag/v2.3.0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">ArgoCD v2.3.0 Released </a>&#8212; <a href="https://github.com/argoproj/argo-cd/releases/tag/v2.3.0">github.com</a></strong> Declarative continuous deployment for Kubernetes. Contribute to argoproj/argo-cd development by creating an account on GitHub.</p><p><strong><a href="https://nicovibert.com/2022/02/21/exploring-ebpf-part-3-hubble/?_hsenc=p2ANqtz-_Lss3KoXp934t7SuNU01gbsw_PSF_g7BfCDrexXkGFc_OgeisXkNgv50c8fbt6ZRR7CRrKG66lCpYM6qt9i73M8hhBQA&amp;_hsmi=205746218&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_content=205746218&amp;utm_medium=email&amp;utm_source=hs_email">Exploring eBPF &#8211; Part 3: Getting Started with Hubble</a> &#8212; <a href="https://nicovibert.com/2022/02/21/exploring-ebpf-part-3-hubble/?_hsenc=p2ANqtz-_Lss3KoXp934t7SuNU01gbsw_PSF_g7BfCDrexXkGFc_OgeisXkNgv50c8fbt6ZRR7CRrKG66lCpYM6qt9i73M8hhBQA&amp;_hsmi=205746218&amp;utm_content=205746218&amp;utm_medium=email&amp;utm_source=hs_email">nicovibert.com</a></strong> Welcome to the third post in my eBPF series: in my first post, I introduced eBPF and walked through how to use a sample code, in the second post, I talked about Cilium, an eBPF-based networking plugin for Kubernetes. In this third post, we're going to jump straight from the previous post and leverage Cilium's&#8230;</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/csantanapr/status/1499806512016936963&quot;,&quot;full_text&quot;:&quot;A prototype of the minikube GUI &#128640;\n<span class=\&quot;tweet-fake-link\&quot;>@minikube_dev</span>  team is looking for feedback from the community\nstart, stop, and delete multiple clusters. It also allows you to access the Kubernetes Dashboard and SSH into the cluster (currently Linux only) with the click of a button. &quot;,&quot;username&quot;:&quot;csantanapr&quot;,&quot;name&quot;:&quot;Carlos Santana&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Mar 04 17:58:32 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FNBhklkXIAwgvLx.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/Jkvq0ZpDNV&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:15,&quot;like_count&quot;:78,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p><strong><a href="https://blog.suborbital.dev/launching-sat-beta-1-still-tiny-still-mighty?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Suborbital Launching Sat Beta-1: Still tiny, still mighty</a> &#8212; <a href="https://blog.suborbital.dev/launching-sat-beta-1-still-tiny-still-mighty">blog.suborbital.dev</a></strong> Today we're happy to announce that our open source WebAssembly edge compute server Sat is now in beta! We've spent the past few months testing, refining, and simplifying it to enable some essential cloud computing use-cases. Best of all, the original...</p><p><strong><a href="https://cloud.google.com/blog/products/application-development/google-cloud-cli-declarative-export-preview?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Build your perfect Google Cloud infrastructure using Terraform and the gcloud CLI</a> &#8212; <a href="https://cloud.google.com/blog/products/application-development/google-cloud-cli-declarative-export-preview">cloud.google.com</a></strong> Learn more about how declarative export allows you to export the current state of your infrastructure into a descriptive file compatible with Terraform.</p><p><strong><a href="https://www.timescale.com/blog/year-of-the-tiger-110-million-to-build-the-future-of-data-for-developers-worldwide/?utm_campaign=2022-funding&amp;utm_medium=social&amp;utm_source=timescaledb">Year of the Tiger: $110 million to build the future of data for developers worldwide</a> &#8212; <a href="https://www.timescale.com/blog/year-of-the-tiger-110-million-to-build-the-future-of-data-for-developers-worldwide/?utm_campaign=2022-funding&amp;utm_medium=social&amp;utm_source=timescaledb">www.timescale.com</a></strong> Timescale just raised $110 million in our Series C, led by Tiger Global alongside all existing investors: Benchmark, New Enterprise Associates, Redpoint Ventures, Icon Ventures, and Two Sigma Ventures.</p><h2>Assets</h2><p><strong><a href="https://github.com/marketplace/actions/debuggging-with-tmate?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Debuggging with tmate &#183; Actions &#183; GitHub Marketplace &#183; GitHub</a> &#8212; <a href="https://github.com/marketplace/actions/debuggging-with-tmate">github.com</a></strong> Debug your GitHub Actions Environment</p><p><strong><a href="https://killercoda.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Killercoda Interactive Environments</a> &#8212; <a href="https://killercoda.com/">killercoda.com</a></strong> Interactive E-learning CKS Kubernetes Security</p><p><strong><a href="https://github.com/aquasecurity/tfsec?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - aquasecurity/tfsec: Security scanner for your Terraform code</a> &#8212; <a href="https://github.com/aquasecurity/tfsec">github.com</a></strong> Security scanner for your Terraform code. Contribute to aquasecurity/tfsec development by creating an account on GitHub.</p><p><strong><a href="https://github.com/Seagate/CORTX?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - Seagate/cortx: CORTX Community Object Storage is 100% open source object storage uniquely optimized for mass capacity storage devices.</a> &#8212; <a href="https://github.com/Seagate/CORTX">github.com</a></strong> CORTX Community Object Storage is 100% open source object storage uniquely optimized for mass capacity storage devices. - GitHub - Seagate/cortx: CORTX Community Object Storage is 100% open source object storage uniquely optimized for mass capacity storage devices.</p><p><strong><a href="https://github.com/lightrun-platform/koolkits?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - lightrun-platform/koolkits: &#129520; Opinionated, language-specific, batteries-included debug container images for Kubernetes.</a> &#8212; <a href="https://github.com/lightrun-platform/koolkits">github.com</a></strong> &#129520; Opinionated, language-specific, batteries-included debug container images for Kubernetes. - GitHub - lightrun-platform/koolkits: &#129520; Opinionated, language-specific, batteries-included debug container images for Kubernetes.</p><p><strong><a href="https://developers.cloudflare.com/1.1.1.1/setup/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter#1111-for-families">DNS for Families with Cloudflare 1.1.1.1</a></strong></p><p>Use 1.1.1.2 Use the following DNS resolvers to block malicious content. And 1.1.1.3 to block malware and adult content</p><p><strong><a href="https://github.com/lowlighter/metrics?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - lowlighter/metrics: &#128202; An infographics generator with 30+ plugins and 200+ options to display stats about your GitHub account and render them as SVG, Markdown, PDF or JSON!</a> &#8212; <a href="https://github.com/lowlighter/metrics">github.com</a></strong> &#128202; An infographics generator with 30+ plugins and 200+ options to display stats about your GitHub account and render them as SVG, Markdown, PDF or JSON! - GitHub - lowlighter/metrics: &#128202; An infographics generator with 30+ plugins and 200+ options to display stats about your GitHub account and render them as SVG, Markdown, PDF or JSON!</p><p><strong><a href="https://github.com/hashicorp/terraform-cdk?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - hashicorp/terraform-cdk: Define infrastructure resources using programming constructs and provision them using HashiCorp Terraform</a> &#8212; <a href="https://github.com/hashicorp/terraform-cdk">github.com</a></strong> Define infrastructure resources using programming constructs and provision them using HashiCorp Terraform - GitHub - hashicorp/terraform-cdk: Define infrastructure resources using programming constructs and provision them using HashiCorp Terraform</p><p><strong><a href="https://github.com/tsenart/vegeta?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - tsenart/vegeta: HTTP load testing tool and library. It's over 9000!</a> &#8212; <a href="https://github.com/tsenart/vegeta">github.com</a></strong> HTTP load testing tool and library. It's over 9000! - GitHub - tsenart/vegeta: HTTP load testing tool and library. It's over 9000!</p><h2>Skills</h2><p><strong><a href="https://devopslearners.com/what-is-a-kubernetes-ephemeral-container-aa8ab658755d?gi=d2daa8cc3967&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What is a Kubernetes Ephemeral Container? | DevOps Learners</a> &#8212; <a href="https://devopslearners.com/what-is-a-kubernetes-ephemeral-container-aa8ab658755d?gi=d2daa8cc3967">devopslearners.com</a></strong> An ephemeral container is a concept of adding a container in an exiting pod for debugging purposes. You can also debug a pod in CrashLoopBackOff state.</p><div id="youtube2-6ES4JzMlKgc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;6ES4JzMlKgc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/6ES4JzMlKgc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://liveandletlearn.net/post/carvel-imgbld-with-helm-post-render/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Carvel kbld With Helm Post Render - Live and let Learn</a> &#8212; <a href="https://liveandletlearn.net/post/carvel-imgbld-with-helm-post-render/">liveandletlearn.net</a></strong></p><p>For the past couple of years I&#8217;ve been working on the Kubeapps project, which until recently has been a UI dashboard for the Helm project - providing a simple, web-based UI to deploy applications on Kubernetes.</p><p><strong><a href="https://itsfoss.com/display-linux-logo-in-ascii?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Display Linux Distribution Logo in ASCII Art in Terminal - It's FOSS</a> &#8212; <a href="https://itsfoss.com/display-linux-logo-in-ascii">itsfoss.com</a></strong> Wondering how they display Linux logo in terminal? With these tools, you can display logo of your Linux distribution in ASCII art in the Linux terminal.</p><p><strong><a href="https://dev.to/aws-builders/saving-on-aws-lambda-amazon-cloudwatch-logs-costs-51od?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Saving on Amazon CloudWatch Logs costs - DEV Community</a> &#8212; <a href="https://dev.to/aws-builders/saving-on-aws-lambda-amazon-cloudwatch-logs-costs-51od">dev.to</a></strong> Amazon CloudWatch Logs costs can get out of hand quickly. Here is the remedy. Tagged with aws, serverless, typescript, observability.</p><p><strong><a href="https://www.redhat.com/sysadmin/migrate-database-container?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">6 steps for migrating a PostgreSQL database between containers | Enable Sysadmin</a> &#8212; <a href="https://www.redhat.com/sysadmin/migrate-database-container">www.redhat.com</a></strong> Upgrading your container-based database? Keep the process straightforward using these steps.</p><p><strong><a href="https://blog.rishabkumar.com/linux-commands-i-use-as-a-cloud-and-devops-engineer?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Linux commands I use as a Cloud and DevOps Engineer</a> &#8212; <a href="https://blog.rishabkumar.com/linux-commands-i-use-as-a-cloud-and-devops-engineer">blog.rishabkumar.com</a></strong> Top 7 Linux commands I use as a Cloud and DevOps Engineer</p><p><strong><a href="https://aws.amazon.com/blogs/containers/how-to-route-udp-traffic-into-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to route UDP traffic into Kubernetes | Amazon Web Services</a> &#8212; <a href="https://aws.amazon.com/blogs/containers/how-to-route-udp-traffic-into-kubernetes/">aws.amazon.com</a></strong> Since its release, Amazon Elastic Kubernetes Service (Amazon EKS) has been helping customers to run their applications reliably and at scale. UDP, or User Datagram Protocol, is a low-latency protocol that is ideal for workloads such as real-time streaming, online gaming, and IoT. The Network Load Balancer (NLB) is designed to handle tens of millions [&#8230;]</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #28]]></title><description><![CDATA[Hello, friends; this week, I have been polishing my Terraform skills and using a new free course by my friend Sid.This weekend there was a debate when I went downstairs to the Kitchen, which was choosing which cheese is better Spanish Goat Cheese or Spanish Manchego Cheese, so I did what any nerd would do and created a Twitter Poll. There was a good conversation on why Kubernetes doesn't have more batteries included like using digest for images, and an interesting one since Knative does this by default.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-28-1038010</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-28-1038010</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 21 Feb 2022 03:52:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/7xngnjfIlK4" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello, friends; this week, I have been polishing my Terraform skills and using a new<a href="https://www.youtube.com/watch?v=7xngnjfIlK4"> free course</a> by my friend Sid.</p><p>This weekend there was a debate when I went downstairs to the Kitchen, which was choosing which cheese is better Spanish Goat Cheese or Spanish Manchego Cheese, so I did what any nerd would do and created a <a href="https://twitter.com/csantanapr/status/1495424284864430082?s=20&amp;t=dJ2JaLKvjnPCJ44DMAFucw">Twitter Poll</a>.</p><p>There was a good conversation on why Kubernetes doesn't have more batteries included like <a href="https://twitter.com/ahmetb/status/1494746034177810441?s=20&amp;t=dJ2JaLKvjnPCJ44DMAFucw">using digest for images</a>, and an interesting one since Knative does this by default.</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.argoproj.io/best-practices-for-multi-tenancy-in-argo-cd-273e25a047b0?gi=c4401d3f9436&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Best Practices for Multi-tenancy in Argo CD | by Dan Garfield | Feb, 2022 | Argo Project</a> &#8212; <a href="https://blog.argoproj.io/best-practices-for-multi-tenancy-in-argo-cd-273e25a047b0?gi=c4401d3f9436">blog.argoproj.io</a></strong> This blogpost is co-authored by Dan Garfield and Jesse Suen. Special thanks to Alexander Matyushentsev, Jann Fischer, Henrik Blixt, and the amazing community for all their hard work in making Argo CD&#8230;</p><div id="youtube2-7xngnjfIlK4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;7xngnjfIlK4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/7xngnjfIlK4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://www.youtube.com/watch?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter&amp;v=1lhARQKdmNw">[Technical Product Update] What's New: OpenShift 4.10 [Feb-2022]</a> &#8212; <a href="https://www.youtube.com/watch?v=1lhARQKdmNw">www.youtube.com</a></strong> Hear directly from Red Hat OpenShift Product Managers on the key updates expected with Red Hat OpenShift 4.10.</p><p><strong><a href="https://www.armosec.io/blog/kubernetes-security-best-practices/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Security Best Practices: The Definitive Guide | ARMO</a> &#8212; <a href="https://www.armosec.io/blog/kubernetes-security-best-practices/">www.armosec.io</a></strong> All you need to know about kubernetes security best practices, from implementing best practices to the importance of kubernetes security and much more</p><p><strong><a href="https://developer.1password.com/docs/ssh/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">1Password for SSH &amp; Git (Beta) | 1Password Developer Documentation</a> &#8212; <a href="https://developer.1password.com/docs/ssh/">developer.1password.com</a></strong> Introducing 1Password for SSH &amp; Git (Beta), the single source of truth for all your SSH keys. With 1Password, you can:</p><p><strong><a href="https://www.youtube.com/watch?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter&amp;v=a8fIyUd9438">Kubernetes Virtual clusters with Loft Labs</a> &#8212; <a href="https://www.youtube.com/watch?v=a8fIyUd9438">www.youtube.com</a></strong> We'll look at benefits and use cases for Kubernetes virtual clusters using Loft.loft.sh</p><p><strong><a href="https://optimismpbc.medium.com/disclosure-fixing-a-critical-bug-in-optimisms-geth-fork-a836ebdf7c94?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Disclosure: Fixing a critical bug in Optimism&#8217;s Geth fork | by Optimism PBC | Feb, 2022 | Medium</a> &#8212; <a href="https://optimismpbc.medium.com/disclosure-fixing-a-critical-bug-in-optimisms-geth-fork-a836ebdf7c94">optimismpbc.medium.com</a></strong> On February 2nd, the Optimism team was alerted by Jay Freeman (saurik of Cydia and Orchid fame) to the existence of a critical bug in Optimism&#8217;s Geth fork. The bug made it possible to create ETH on&#8230;</p><p><strong><a href="https://mrd0x.com/bypass-2fa-using-novnc/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Steal Credentials &amp; Bypass 2FA Using noVNC | mr.d0x</a></strong> Security Research | C:\Users\mr.d0x&gt;</p><p><strong><a href="https://medium.com/sellerapp/golang-project-structuring-ben-johnson-way-2a11035f94bc?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Golang project structuring &#8212; Ben Johnson way | by vignesh dharuman | SellerApp | Feb, 2022 | Medium</a> &#8212; <a href="https://medium.com/sellerapp/golang-project-structuring-ben-johnson-way-2a11035f94bc">medium.com</a></strong> Project code organisation is an ever evolving problem. As all wise developers put it, &#8220;it always depends on the requirement&#8221;. But following a standard structure will help in keeping the code base&#8230;</p><p><strong><a href="https://cloud.redhat.com/blog/global-load-balancer-approaches?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Global Load Balancer Approaches</a> &#8212; <a href="https://cloud.redhat.com/blog/global-load-balancer-approaches">cloud.redhat.com</a></strong> When working with Kubernetes or OpenShift in a multicluster (possibly hybrid cloud) deployment, one of the considerations that comes up is how to direct traffic to the applications deployed across these clusters. To solve this problem, we need a global load balancer.</p><p><strong><a href="https://www.wix.engineering/post/auto-scaling-ci-agents-at-wix?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Auto Scaling CI Agents At Wix</a> &#8212; <a href="https://www.wix.engineering/post/auto-scaling-ci-agents-at-wix">www.wix.engineering</a></strong></p><p>This article is part II of "6 Challenges We Faced While Building a Super CI Pipeline"</p><p><strong><a href="https://picluster.ricsanfre.com/docs/backup/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Backup &amp; Restore | Raspberry Pi Kubernetes Cluster</a> &#8212; <a href="https://picluster.ricsanfre.com/docs/backup/">picluster.ricsanfre.com</a></strong> Backup Architecture and Design</p><p><strong><a href="https://medium.com/@andrew.kaczynski/gitops-in-kubernetes-argo-cd-and-gitlab-ci-cd-5828c8eb34d6?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitOps in Kubernetes: How to do it with GitLab CI and Argo CD | by Andrzej Kaczynski | Medium</a> &#8212; <a href="https://medium.com/@andrew.kaczynski/gitops-in-kubernetes-argo-cd-and-gitlab-ci-cd-5828c8eb34d6">medium.com</a></strong> The world of Cloud Native in recent days is continuously speaking about GitOps. Indeed this model of Continuous Delivery is a kind of revolution in modern IT world. I&#8217;m not going to describe what&#8230;</p><h2>Assets</h2><p><strong><a href="https://github.com/rebuy-de/aws-nuke?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - rebuy-de/aws-nuke: Nuke a whole AWS account and delete all its resources.</a> &#8212; <a href="https://github.com/rebuy-de/aws-nuke">github.com</a></strong> Nuke a whole AWS account and delete all its resources. - GitHub - rebuy-de/aws-nuke: Nuke a whole AWS account and delete all its resources.</p><p><strong><a href="https://github.com/developer-guy/rekor-falco?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - developer-guy/rekor-falco: A Falco Plugin for Rekor Transparency Log Server</a> &#8212; <a href="https://github.com/developer-guy/rekor-falco">github.com</a></strong> A Falco Plugin for Rekor Transparency Log Server. Contribute to developer-guy/rekor-falco development by creating an account on GitHub.</p><p><strong><a href="https://github.com/google/k8s-digester?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - google/k8s-digester: Add digests to container and init container images in Kubernetes pod and pod template specs. </a>&#8212; <a href="https://github.com/google/k8s-digester">github.com</a></strong></p><p>Add digests to container and init container images in Kubernetes pod and pod template specs.</p><p><strong><a href="https://kyverno.io/policies/other/resolve_image_to_digest/resolve-image-to-digest/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Resolve Image to Digest | Kyverno</a></strong> Image tags are mutable and the change of an image can result in the same tag. This policy resolves the image digest of each image in a container and replaces the image with the fully resolved reference which includes the digest rather than tag.</p><p><strong><a href="https://github.com/estesp/mquery?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - estesp/mquery: Multi-platform (manifest list/OCI index) registry image query utility</a> &#8212; <a href="https://github.com/estesp/mquery">github.com</a></strong> Multi-platform (manifest list/OCI index) registry image query utility - GitHub - estesp/mquery: Multi-platform (manifest list/OCI index) registry image query utility</p><p><strong><a href="https://github.com/mylesagray/tanzu-cluster-gitops?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - mylesagray/tanzu-cluster-gitops</a> &#8212; <a href="https://github.com/mylesagray/tanzu-cluster-gitops">github.com</a></strong> Contribute to mylesagray/tanzu-cluster-gitops development by creating an account on GitHub.</p><p><strong><a href="https://medium.com/@charled.breteche/kind-keycloak-securing-kubernetes-api-server-with-oidc-371c5faef902?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kind, Keycloak &#8212; Securing Kubernetes api server with OIDC | by Charles-Edouard Br&#233;t&#233;ch&#233; | Feb, 2022 | Medium</a> &#8212; <a href="https://medium.com/@charled.breteche/kind-keycloak-securing-kubernetes-api-server-with-oidc-371c5faef902">medium.com</a></strong> Securing Kubernetes control plane can be a challenging task, especially when a company grows and more people come and go to work in a shared Kubernetes cluster. One important tool to setup as early&#8230;</p><h2>Skills</h2><p><strong><a href="https://hashnode.com/post/tekton-ci-simplified-ckzleauyw0n6beks1diq6ejvv?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Real world Tekton pipeline - Hashnode</a> &#8212; <a href="https://hashnode.com/post/tekton-ci-simplified-ckzleauyw0n6beks1diq6ejvv">hashnode.com</a></strong> Complete guide to getting started with Tekton</p><p><strong><a href="https://services.acm.org/public/qj/proflevel/countryListing.cfm?form_type=Professional&amp;promo=PWEBTOP&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Special Rates for Individuals in Economically Developing Countries</a></strong></p><p>Low cost ACM subscription includes OReilly book subscription</p><p><strong><a href="https://jayconrod.com/posts/123/internals-of-go-s-new-fuzzing-system?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Internals of Go's new fuzzing system &#8212; jayconrod.com</a> &#8212; <a href="https://jayconrod.com/posts/123/internals-of-go-s-new-fuzzing-system">jayconrod.com</a></strong> Go 1.18 is coming out soon. It's a huge release, but native fuzzing has a special place in my heart. Not much has been written yet on how Go's fuzzing system actually works, so I'll talk a bit about that here.</p><p><strong><a href="https://azurecharts.com/learning/map/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Azure Study Map</a> &#8212; <a href="https://azurecharts.com/learning/map/">azurecharts.com</a></strong></p><p>Most studied Azure learning subjects by complexity levels and student roles based on aggregated user vote count</p><p><strong><a href="https://aws.amazon.com/blogs/containers/introducing-amazon-cloudwatch-container-insights-for-amazon-eks-fargate-using-aws-distro-for-opentelemetry/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing Amazon CloudWatch Container Insights for Amazon EKS Fargate using AWS Distro for OpenTelemetry | Amazon Web Services</a> &#8212; <a href="https://aws.amazon.com/blogs/containers/introducing-amazon-cloudwatch-container-insights-for-amazon-eks-fargate-using-aws-distro-for-opentelemetry/">aws.amazon.com</a></strong> Your description for this link...</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #27]]></title><description><![CDATA[News How to Make Package Signing Useful &#8212; blog.chainguard.dev The Case for Farm-to-Table Package SigningThe benefits and limitations of signing an open source package&#8211;using a private key to create a unique digital signature&#8211;are a surprisingly contentious topic.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-27-1026667</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-27-1026667</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Sun, 13 Feb 2022 22:40:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/upload/w_1028,c_limit,q_auto:best/awdrfwcusvw5x3nkuccj" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>News</h2><p><strong><a href="https://blog.chainguard.dev/making-package-signing-useful/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Make Package Signing Useful</a> &#8212; <a href="https://blog.chainguard.dev/making-package-signing-useful/">blog.chainguard.dev</a></strong> The Case for Farm-to-Table Package SigningThe benefits and limitations of signing an open source package&#8211;using a private key to create a unique digital signature&#8211;are a surprisingly contentious topic. One of the maintainers associated with the Python Package Index maintainer has a cogent blog post called &#8220;Why Package Signing</p><p><strong><a href="https://www.jedi.be/blog/2022/02/11/shades-of-devops-roles/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Shades of DevOps - Related Job titles</a> &#8212; <a href="https://www.jedi.be/blog/2022/02/11/shades-of-devops-roles/">www.jedi.be</a></strong> A quick overview of the titles/roles use to related to devops related subject matter experts. I will stick with my definition of devops regardless of job title: Dev(sec)Ops: everything you do to overcome the friction created by silos &#8230; All the rest is plain engineering</p><p><strong><a href="https://medium.com/paypal-tech/scaling-kubernetes-to-over-4k-nodes-and-200k-pods-29988fad6ed?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Scaling Kubernetes to Over 4k Nodes and 200k Pods | by Abdul Qadeer | The PayPal Technology Blog | Jan, 2022 | Medium</a> &#8212; <a href="https://medium.com/paypal-tech/scaling-kubernetes-to-over-4k-nodes-and-200k-pods-29988fad6ed">medium.com</a></strong> At PayPal, we recently started testing the waters with Kubernetes. A majority of our workloads run on Apache Mesos, and as part of this migration, we needed to understand several performance aspects&#8230;</p><p><strong><a href="https://www.geekwire.com/2022/amazon-more-than-doubles-max-base-pay-to-350k-for-corporate-and-tech-workers-citing-labor-market/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Amazon more than doubles max base pay to $350k for corporate and tech workers, citing labor market - GeekWire</a> &#8212; <a href="https://www.geekwire.com/2022/amazon-more-than-doubles-max-base-pay-to-350k-for-corporate-and-tech-workers-citing-labor-market/">www.geekwire.com</a></strong> Amazon will boost its maximum base pay to $350,000 for corporate and tech employees, from $160,000 previously, as part of an overall increase in total&#8230;</p><p><strong><a href="https://medium.com/trendyol-tech/a-modern-toolkit-to-start-working-with-container-images-on-macos-that-meets-your-needs-without-caa0f38529de?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A modern toolkit to start working with container images on macOS that meets your needs without requiring Docker Desktop </a>&#8212; <a href="https://medium.com/trendyol-tech/a-modern-toolkit-to-start-working-with-container-images-on-macos-that-meets-your-needs-without-caa0f38529de">medium.com</a></strong> Most of us stepped into the containerization world with Docker. So, we&#8217;ll always be grateful to Docker for that. But, to be honest, even we&#8217;re working with Docker, we know that it is not the only&#8230;</p><p><strong><a href="https://www.cncf.io/reports/cncf-annual-survey-2021/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CNCF Annual Survey 2021 | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/reports/cncf-annual-survey-2021/">www.cncf.io</a></strong> Featuring production data and insights from Datadog, New Relic, and SlashData download report View the complete raw data on GitHub Are you a CNCF member with in&#8230;</p><p><strong><a href="https://danluu.com/cache-incidents">A decade of major cache incidents at Twitter</a></strong></p><p><strong><a href="https://www.appvia.io/blog/podsecuritypolicy-is-dead-long-live?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">PodSecurityPolicy is dead. Long live...? | Appvia.io</a> &#8212; <a href="https://www.appvia.io/blog/podsecuritypolicy-is-dead-long-live">www.appvia.io</a></strong> PodSecurityPolicy is being deprecated. Find out what replaces it and how to migrate with our online free tool</p><p><strong><a href="https://blog.dshr.org/2022/02/ee380-talk.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">DSHR's Blog: EE380 Talk</a> &#8212; <a href="https://blog.dshr.org/2022/02/ee380-talk.html">blog.dshr.org</a></strong> I was asked at short notice to fill in for a speaker in Stanford's EE380 course who had to cancel. Below the fold is a hastily updated vers...</p><p><strong><a href="https://mattermost.com/blog/the-top-7-open-source-tools-for-securing-your-kubernetes-cluster/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The Top 7 Open Source Tools for Securing Your Kubernetes Cluster</a> &#8212; <a href="https://mattermost.com/blog/the-top-7-open-source-tools-for-securing-your-kubernetes-cluster/">mattermost.com</a></strong> This article from the Mattermost community explores how to secure production Kubernetes clusters with the help of open source tools.</p><p><strong><a href="https://dlorenc.medium.com/oci-artifacts-explained-8f4a77945c13?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">OCI Artifacts Explained. Are they real? Kind of! | by Dan Lorenc | Medium</a> &#8212; <a href="https://dlorenc.medium.com/oci-artifacts-explained-8f4a77945c13">dlorenc.medium.com</a></strong> The OCI (Open Containers Initiative) manages a few specifications and projects related to the storage, distribution, and execution of container images. If you&#8217;ve ever run a docker container, you&#8217;ve&#8230;</p><p><strong><a href="https://www.cncf.io/announcements/2022/02/10/cncf-sees-record-kubernetes-and-container-adoption-in-2021-cloud-native-survey/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CNCF Sees Record Kubernetes and Container Adoption in 2021 Cloud Native Survey | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/announcements/2022/02/10/cncf-sees-record-kubernetes-and-container-adoption-in-2021-cloud-native-survey/">www.cncf.io</a></strong> Record number of organizations are using or evaluating Kubernetes as the technology goes mainstream and users start to move up the stack SAN FRANCISCO, Calif.</p><p><strong><a href="https://falco.org/blog/falco-0-31-0/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Falco 0.31.0 a.k.a. "the Gyrfalcon" | Falco</a></strong></p><p><strong>Falco 0.31.0</strong>&nbsp;finally ships with the brand&nbsp;<strong>new plugin system</strong>&nbsp;&#127881;</p><p><strong><a href="https://mayakaczorowski.com/blogs/beyondcorp-is-dead?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">BeyondCorp is dead, long live BeyondCorp</a></strong> No organization has successfully implemented a fully zero trust architecture. Many proponents of zero trust, including the US government, have ignored device...</p><p><strong><a href="https://felixge.de/2022/02/11/connecting-go-profiling-with-tracing/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Connecting Go Profiling With Tracing &#183; Felix Geisend&#246;rfer</a></strong></p><h2>Profiling Improvements in Go 1.18</h2><p><strong><a href="https://www.sloconf.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">SLOConf - Service Level Objective Conference</a></strong> The first Service Level Objective Conference for Site Reliability Engineers</p><p><strong><a href="https://isovalent.com/blog/post/2021-11-container-escape?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Detecting a Container Escape with Cilium and eBPF</a> &#8212; <a href="https://isovalent.com/blog/post/2021-11-container-escape">isovalent.com</a></strong> Learn how to use Isovalent Cilium Enterprise observability to detect container escapes</p><p><strong><a href="https://www.usenix.org/publications/loginonline/prodspec-and-annealing-intent-based-actuation-google-production?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Prodspec and Annealing | USENIX</a> &#8212; <a href="https://www.usenix.org/publications/loginonline/prodspec-and-annealing-intent-based-actuation-google-production">www.usenix.org</a></strong></p><p>focus on the state you want to reach. Instead of maintaining step-by-step workflows</p><p><strong><a href="https://kubernetes.io/blog/2018/07/09/ipvs-based-in-cluster-load-balancing-deep-dive/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">IPVS-Based In-Cluster Load Balancing Deep Dive | Kubernetes</a></strong> Author: Jun Du(Huawei), Haibin Xie(Huawei), Wei Liang(Huawei) Editor&#8217;s note: this post is part of a series of in-depth articles on what&#8217;s new in Kubernetes 1.11 Introduction Per the Kubernetes 1.11 release blog post , we announced that IPVS-Based In-Cluster Service Load Balancing graduates to General Availability. In this blog, we will take you through a deep dive of the feature. What Is IPVS? IPVS (IP Virtual Server) is built on top of the Netfilter and implements transport-layer load balancing as part of the Linux kernel.</p><p><strong><a href="https://authzed.com/blog/zanzibar-implementations?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Zanzibar Implementations</a></strong> Reviewing the current landscape of Zanzibar implementations.</p><p><strong><a href="https://www.vox.com/the-goods/22922511/crypto-nfts-sports-betting-money-hobby?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Crypto, NFTs, and sports betting: Money is now a hobby - Vox</a> &#8212; <a href="https://www.vox.com/the-goods/22922511/crypto-nfts-sports-betting-money-hobby">www.vox.com</a></strong> Why (mostly) 20- and 30-something dudes made crypto and sports betting their personality.</p><h2>Assets</h2><p><strong><a href="https://github.com/sbstp/kubie?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - sbstp/kubie: A more powerful alternative to kubectx and kubens</a> &#8212; <a href="https://github.com/sbstp/kubie">github.com</a></strong> A more powerful alternative to kubectx and kubens. Contribute to sbstp/kubie development by creating an account on GitHub.</p><p><strong><a href="https://github.com/apiaryio/curl-trace-parser?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - apiaryio/curl-trace-parser: Parser for output from Curl --trace option</a> &#8212; <a href="https://github.com/apiaryio/curl-trace-parser">github.com</a></strong> Parser for output from Curl --trace option. Contribute to apiaryio/curl-trace-parser development by creating an account on GitHub.</p><p><strong><a href="https://github.com/ruoshan/autoportforward?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - ruoshan/autoportforward: Bidirectional port-forwarding for docker, podman and kubernetes</a> &#8212; <a href="https://github.com/ruoshan/autoportforward">github.com</a></strong> Bidirectional port-forwarding for docker, podman and kubernetes - GitHub - ruoshan/autoportforward: Bidirectional port-forwarding for docker, podman and kubernetes</p><p><strong><a href="https://github.com/kameshsampath/kluster?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kameshsampath/kluster: Tool to run local k3s clusters backed by multipass vms</a> &#8212; <a href="https://github.com/kameshsampath/kluster">github.com</a></strong> Tool to run local k3s clusters backed by multipass vms - GitHub - kameshsampath/kluster: Tool to run local k3s clusters backed by multipass vms</p><p><strong><a href="https://github.com/anchore/grype?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - anchore/grype: A vulnerability scanner for container images and filesystems</a> &#8212; <a href="https://github.com/anchore/grype">github.com</a></strong> A vulnerability scanner for container images and filesystems - GitHub - anchore/grype: A vulnerability scanner for container images and filesystems</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/belbaoverhill/status/1485980493183164425&quot;,&quot;full_text&quot;:&quot;<span class=\&quot;tweet-fake-link\&quot;>#gopls</span> and <span class=\&quot;tweet-fake-link\&quot;>#VSCode</span> playing together to handle Go template file. (gopls v0.7.5, <span class=\&quot;tweet-fake-link\&quot;>#VSCodeGo</span> extension v0.31.0-rc.1)\n\n  \&quot;gopls\&quot;: {\n    \&quot;ui.semanticTokens\&quot;: true\n  }\n\nMany thanks to the gopls team! &#128591; &quot;,&quot;username&quot;:&quot;belbaoverhill&quot;,&quot;name&quot;:&quot;Hana&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Tue Jan 25 14:18:52 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://substackcdn.com/image/upload/w_1028,c_limit,q_auto:best/l_twitter_play_button_rvaygk,w_88/awdrfwcusvw5x3nkuccj&quot;,&quot;link_url&quot;:&quot;https://t.co/Js7plrBjMZ&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:27,&quot;like_count&quot;:131,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:&quot;https://video.twimg.com/ext_tw_video/1485979297793859591/pu/vid/576x270/hUBZ8FqVpLK0pvMJ.mp4?tag=12&quot;,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><h2>Skills</h2><div id="youtube2-OD527yvej34" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;OD527yvej34&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/OD527yvej34?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://www.tigera.io/blog/comparing-kube-proxy-modes-iptables-or-ipvs/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Comparing kube-proxy modes: iptables or IPVS?</a></strong></p><h2>Performance Comparison</h2><p><strong><a href="https://www.youtube.com/watch?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter&amp;v=GsS38peaM64">What is MicroK8s?</a></strong> K3s, Kind, Minikube, VM's with Kubespray... why MicroK8s? What makes it interesting and unique to me? In this video, I'll show off three killer features that...</p><p><strong><a href="https://nikofischer.com/cors-does-not-secure-api-endpoints?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CORS is not meant to secure an API endpoint</a></strong> A few days ago I came across this article.&nbsp;The author shows how to access a Drupal system in the backend with a Vue.js app. For authentication he uses an API key - and I find that dangerous. Here's why.</p><p><strong><a href="https://portswigger.net/daily-swig/http-3-everything-you-need-to-know-about-the-next-generation-web-protocol?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">HTTP/3: Everything you need to know about the next-generation web protocol | The Daily Swig</a> &#8212; <a href="https://portswigger.net/daily-swig/http-3-everything-you-need-to-know-about-the-next-generation-web-protocol">portswigger.net</a></strong> QUIC march</p><p><strong><a href="https://www.youtube.com/watch?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter&amp;v=0RUDoTi-Lw4">Kubernetes and Checkpoint Restore - Adrian Reber, Red Hat</a> &#8212; <a href="https://www.youtube.com/watch?v=0RUDoTi-Lw4">www.youtube.com</a></strong> https://youtu.be/0RUDoTi-Lw4</p><p><strong><a href="https://www.pmbanugo.me/blog/2022-02-13-from-aws-lambda-api-gateway-to-knative-kong-api-gateway/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=pocket_mylist">From AWS Lambda &amp; API Gateway To Knative &amp; Kong API Gateway | Blog</a> &#8212; <a href="https://www.pmbanugo.me/blog/2022-02-13-from-aws-lambda-api-gateway-to-knative-kong-api-gateway/?utm_source=pocket_mylist">www.pmbanugo.me</a></strong> How to build a serverless function API using Knative, Kong, and kazi</p><p><strong><a href="https://blog.argoproj.io/introducing-the-applicationset-controller-for-argo-cd-982e28b62dc5?gi=642bdfa8d874&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing the ApplicationSet Controller for Argo CD | by Jonathan West | Argo Project</a> &#8212; <a href="https://blog.argoproj.io/introducing-the-applicationset-controller-for-argo-cd-982e28b62dc5?gi=642bdfa8d874">blog.argoproj.io</a></strong> I am excited to announce the first release of the Argo CD ApplicationSet controller, v0.1.0, releasing now alongside Argo CD v2.0! Unlike with an Argo CD Application resource, which deploys resources&#8230;</p><p><strong><a href="http://kernel.community/en/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kernel Community | Kernel</a> &#8212; <a href="http://kernel.community/en/">kernel.community</a></strong> A peer-to-peer, lifelong learning community of the most talented individuals in web3</p><p><strong><a href="https://www.edwardtufte.com/tufte/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The Work of Edward Tufte and Graphics Press</a> &#8212; <a href="https://www.edwardtufte.com/tufte/">www.edwardtufte.com</a></strong> Edward Tufte home page for books, posters, sculpture, fine art and one-day course: Presenting Data and Information</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #26]]></title><description><![CDATA[Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and SkillsThis week I started streaming videos on TwitchTV, YouTube, and Twitter about Kubernetes and Knative. The goal is to help others learn about Cloud Native and Open Source. Please let me know if you like the videos.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-26-1014265</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-26-1014265</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 07 Feb 2022 00:07:19 GMT</pubDate><enclosure url="https://substackcdn.com/video/upload/e_loop,vs_40/v1ixllmwn3frsbplpdjq.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories <strong>News</strong>, <strong>Assets</strong>, and <strong>Skills</strong></p><p>This week I started streaming videos on <a href="https://www.twitch.tv/csantanapr">TwitchTV</a>, <a href="https://www.youtube.com/c/CarlosSantanaDev">YouTube</a>, and <a href="https://twitter.com/csantanapr/status/1490395354813984769">Twitter</a> about Kubernetes and Knative. The goal is to help others learn about Cloud Native and Open Source. Please let me know if you like the videos.</p><div><hr></div><h2>News</h2><p><strong><a href="https://blog.argoproj.io/argo-cd-v2-3-release-candidate-a5b8cf11b0d3?gi=187d129eb22a&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Argo CD v2.3 release candidate. The next Argo CD release is around the&#8230; | by Alexander Matyushentsev | Feb, 2022 | Argo Project</a> &#8212; <a href="https://blog.argoproj.io/argo-cd-v2-3-release-candidate-a5b8cf11b0d3?gi=187d129eb22a">blog.argoproj.io</a></strong> The next Argo CD release is around the corner. During the last three months, Argo CD got 200+ commits from the 71 contributors. We worked hard to improve the usability of core Argo CD features&#8230;</p><p><strong><a href="https://github.blog/2021-12-06-safeguard-container-signing-capability-actions/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Safeguard your containers with new container signing capability in GitHub Actions | The GitHub Blog</a> &#8212; <a href="https://github.blog/2021-12-06-safeguard-container-signing-capability-actions/">github.blog</a></strong> GitHub has partnered with the OpenSSF and Project Sigstore to add container image signing to our default &#8220;Publish Docker Container&#8221; workflow, giving your users confidence that the container images they got from their container registry was the trusted code that you built and published.</p><p><strong><a href="https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Malicious Kubernetes Helm Charts can be used to steal sensitive information from Argo CD deployments</a> &#8212; <a href="https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/">apiiro.com</a></strong> Apiiro's Security Research team has discovered a major vulnerability in Argo CD platform (CVE-2022-24348).</p><p><strong><a href="https://github.blog/changelog/2022-02-03-more-ways-to-keep-your-pull-request-branch-up-to-date/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">More ways to keep your pull request branch up-to-date | GitHub Changelog</a> &#8212; <a href="https://github.blog/changelog/2022-02-03-more-ways-to-keep-your-pull-request-branch-up-to-date/">github.blog</a></strong> More ways to keep your pull request branch up-to-date</p><p><strong><a href="https://dev.to/quirrel/quirrel-is-acquired-and-i-am-joining-netlify-dha?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Quirrel is acquired! And I am joining Netlify - DEV Community</a> &#8212; <a href="https://dev.to/quirrel/quirrel-is-acquired-and-i-am-joining-netlify-dha">dev.to</a></strong> I am very happy to announce that Quirrel was acquired by Netlify, and I am joining as a software... Tagged with quirrel, netlify, jamstack.</p><p><strong><a href="https://venturebeat.com/2022/02/01/google-and-microsoft-back-the-alpha-omega-project-to-bolster-software-supply-chain/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google and Microsoft back the Alpha-Omega Project to bolster software supply chain | VentureBeat</a> &#8212; <a href="https://venturebeat.com/2022/02/01/google-and-microsoft-back-the-alpha-omega-project-to-bolster-software-supply-chain/">venturebeat.com</a></strong> The Open Source Security Foundation has launched the Alpha-Omega Project to help secure the software supply chain.</p><p><strong><a href="https://elastisys.com/designing-and-deploying-scalable-applications-on-kubernetes/?_hsenc=p2ANqtz--iNbqCikZhhzErvkvDOFCyNNEl8cofQ-2vUJzF343x2dA8QXYaS_whLounJFKGe7mbOmRQxNB1P84l88aN8eBpTidiVw&amp;_hsmi=202939033&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_content=202939033&amp;utm_medium=email&amp;utm_source=hs_email">Principles for Designing and Deploying Scalable Applications on Kubernetes</a> &#8212; <a href="https://elastisys.com/designing-and-deploying-scalable-applications-on-kubernetes/?_hsenc=p2ANqtz--iNbqCikZhhzErvkvDOFCyNNEl8cofQ-2vUJzF343x2dA8QXYaS_whLounJFKGe7mbOmRQxNB1P84l88aN8eBpTidiVw&amp;_hsmi=202939033&amp;utm_content=202939033&amp;utm_medium=email&amp;utm_source=hs_email">elastisys.com</a></strong> 15 principles for how to design and deploy cloud native applications on Kubernetes - for scalability, observability, automation &amp; security.</p><p><strong><a href="https://cloud.google.com/blog/topics/financial-services/google-cloud-launches-dedicated-digital-asset-team?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google Cloud launches dedicated Digital Asset Team | Google Cloud Blog</a></strong> Google Cloud launches a new, dedicated Digital Assets Team to help underpin the blockchain ecosystems of the future. Whether you're implementing blockchain strategies or blockchain-native, you can rely on Google Cloud&#8217;s scalable, secure, and sustainable infrastructure.</p><p><strong><a href="https://octoverse.github.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The State of the Octoverse | The State of the Octoverse explores a year of change with new deep dives into writing code faster, creating documentation and how we build sustainable communities on GitHub.</a> &#8212; <a href="https://octoverse.github.com/">octoverse.github.com</a></strong> Octoverse Report</p><p><strong><a href="https://blog.chainguard.dev/how-citi-are-building-the-secure-software-factory-with-sigstore-and-tekton/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How Citi is building the secure software factory with Sigstore and Tekton</a> &#8212; <a href="https://blog.chainguard.dev/how-citi-are-building-the-secure-software-factory-with-sigstore-and-tekton/">blog.chainguard.dev</a></strong></p><p>Securing the software supply chain is of paramount importance to the tech industry today.</p><p><strong><a href="https://threatpost.com/supply-chain-security-predicament/178166/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Supply Chain Security Is Not a Problem&#8230;It&#8217;s a Predicament | Threatpost</a> &#8212; <a href="https://threatpost.com/supply-chain-security-predicament/178166/">threatpost.com</a></strong> Despite what security vendors might say, there is no way to comprehensively solve our supply-chain security challenges, posits JupiterOne CISO Sounil Yu. We can only manage them.</p><p><strong><a href="https://www.cncf.io/blog/2022/01/31/cncf-archives-the-opentracing-project/?_hsenc=p2ANqtz-8tCP8_FWXG77LAyGl3p4l1BWzemSuesewWk4OwJZyrRrpQEAXVGSRmpEaFRpO2eW-MUJtrHJI5Z-hz4ArXp3b_IyzCLA&amp;_hsmi=202939033&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_content=202939033&amp;utm_medium=email&amp;utm_source=hs_email">CNCF Archives the OpenTracing Project | Cloud Native Computing Foundation</a> &#8212; <a href="https://www.cncf.io/blog/2022/01/31/cncf-archives-the-opentracing-project/?_hsenc=p2ANqtz-8tCP8_FWXG77LAyGl3p4l1BWzemSuesewWk4OwJZyrRrpQEAXVGSRmpEaFRpO2eW-MUJtrHJI5Z-hz4ArXp3b_IyzCLA&amp;_hsmi=202939033&amp;utm_content=202939033&amp;utm_medium=email&amp;utm_source=hs_email">www.cncf.io</a></strong> CNCF announced today that the Technical Oversight Committee (TOC) has approved the archiving of the OpenTracing project. Archived projects are fairly rare but a&#8230;</p><p><strong><a href="https://venturebeat.com/2022/02/03/major-vulnerability-found-in-open-source-dev-tool-for-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Major vulnerability found in open source dev tool for Kubernetes | VentureBeat</a> &#8212; <a href="https://venturebeat.com/2022/02/03/major-vulnerability-found-in-open-source-dev-tool-for-kubernetes/">venturebeat.com</a></strong> A zero day vulnerability with a "high" severity rating affects Argo CD, an open source developer tool for Kubernetes, Apiiro researchers said.</p><p><strong><a href="https://fluxcd.io/blog/2022/01/january-update/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">January 2022 Update | Flux</a></strong> New Flux and Flagger releases bring more security, terraform-controller team wants feedback, Flux articles and docs, upcoming Flux events helping you get started and more.</p><p><strong><a href="https://dev.to/nheidloff/new-open-source-multi-cloud-asset-to-build-saas-1b08?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">New Open-Source Multi-Cloud Asset to build SaaS - DEV Community</a></strong> Development and automated deployment of SaaS for multiple tenants, using Red Hat OpenShift/Kubernetes and DevSecOps. Tagged with saas, development, devops, cloudnative.</p><p><strong><a href="https://blog.chmarny.com/posts/twitter-follower-activity-monitoring-using-tweethingz/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Mark Chmarny | Twitter follower status monitoring made easy using TweeThingz</a></strong> few longer thoughts, <br>because every once in a while <br>140 characters is just not enough</p><h2>Assets</h2><p><strong><a href="https://github.com/AdminTurnedDevOps/Terraform-The-Hard-Way?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - AdminTurnedDevOps/Terraform-The-Hard-Way</a> &#8212; <a href="https://github.com/AdminTurnedDevOps/Terraform-The-Hard-Way">github.com</a></strong></p><p>The most efficient way to learn Terraform for beginners and intermediate practitioners</p><p><strong><a href="https://github.com/firecracker-microvm/firecracker?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - firecracker-microvm/firecracker: Secure and fast microVMs for serverless computing.</a> &#8212; <a href="https://github.com/firecracker-microvm/firecracker">github.com</a></strong> Secure and fast microVMs for serverless computing. - GitHub - firecracker-microvm/firecracker: Secure and fast microVMs for serverless computing.</p><p><strong><a href="https://github.com/kotalco/kotal?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kotalco/kotal: Kubernetes Blockchain Operator</a> &#8212; <a href="https://github.com/kotalco/kotal">github.com</a></strong> Kubernetes Blockchain Operator. Contribute to kotalco/kotal development by creating an account on GitHub.</p><p><strong><a href="https://houdini.secsi.io/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=eks.news">HOUDINI: Hundreds of Offensive and Useful Docker Images for Network Intrusion</a></strong> HOUDINI (Hundreds of Offensive and Useful Docker Images for Network Intrusion) is a curated list of Network Security related Docker Images for Network Intrusion purposes.</p><p><strong><a href="https://github.com/kubeshop/monokle?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kubeshop/monokle: &#129488; Monokle is your K8s best friend for creating, validating, debugging and managing manifests! &#128640;</a> &#8212; <a href="https://github.com/kubeshop/monokle">github.com</a></strong></p><p>&#129488; Monokle is your K8s best friend for creating, validating, debugging and managing manifests! &#128640; -</p><p><strong><a href="https://github.com/direktiv/vorteil?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - direktiv/vorteil: turn your applications and containers into micro virtual machines</a> &#8212; <a href="https://github.com/direktiv/vorteil">github.com</a></strong> turn your applications and containers into micro virtual machines - GitHub - direktiv/vorteil: turn your applications and containers into micro virtual machines</p><p><strong><a href="https://www.redhat.com/sysadmin/create-containers-podman-quickly?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Create fast, easy, and repeatable containers with Podman and shell scripts | Enable Sysadmin</a> &#8212; <a href="https://www.redhat.com/sysadmin/create-containers-podman-quickly">www.redhat.com</a></strong> Get started with containers in a fast, repeatable way through the familiar shell scripting interface.</p><p><strong><a href="https://github.com/weaveworks/flintlock?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - weaveworks/flintlock: Lock, Stock, and Two Smoking MicroVMs. Create and manage the lifecycle of MicroVMs backed by containerd.</a> &#8212; <a href="https://github.com/weaveworks/flintlock">github.com</a></strong></p><p>Lock, Stock, and Two Smoking MicroVMs. Create and manage the lifecycle of MicroVMs backed by containerd.</p><p><strong><a href="https://github.com/hamidgholami/k8s-lab?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - hamidgholami/k8s-lab: Kubernetes Labratory</a> &#8212; <a href="https://github.com/hamidgholami/k8s-lab">github.com</a></strong> Kubernetes Labratory. Contribute to hamidgholami/k8s-lab development by creating an account on GitHub.</p><h2>Skills</h2><p><strong><a href="https://blog.pragmaticengineer.com/performance-reviews-for-software-engineers/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Performance Reviews for Software Developers &#8211; How I Do Them In a (Hopefully) Fair Way - The Pragmatic Engineer</a> &#8212; <a href="https://blog.pragmaticengineer.com/performance-reviews-for-software-engineers/">blog.pragmaticengineer.com</a></strong> Note: if you're just looking for performance review templates and examples, head to the templates page to download them. I've had about a dozen performance reviews during my decade-long software engineering career. Some of them were unmemorable, some okay, but a good chunk of them were just... plain bad. Often,</p><p><strong><a href="https://hopin.com/events/openshift-commons-gathering-on-gitops?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">OpenShift Commons Gathering on GitOps - Feb 09 | Hopin</a></strong> Get tickets to OpenShift Commons Gathering on GitOps, taking place 02/09/2022. Hopin is your source for engaging events and experiences.</p><p><strong><a href="https://medium.com/@drashti.ved_84172/level-up-your-go-presentations-b4d06fc495e5?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Level up your Go Presentations. What is present? Present is used to&#8230; | by Drashti Ved | Medium</a> &#8212; <a href="https://medium.com/@drashti.ved_84172/level-up-your-go-presentations-b4d06fc495e5">medium.com</a></strong> A mini guide to use Present tools for your next Golang presentation</p><p><strong><a href="https://github.com/tebeka/talks/tree/master/fosdem22?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">FOSDEM 2022: Golang JSON Serialization - The Fine Print</a> &#8212; <a href="https://github.com/tebeka/talks/tree/master/fosdem22">github.com</a></strong></p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/csantanapr/status/1490304499407368202&quot;,&quot;full_text&quot;:&quot;Join <span class=\&quot;tweet-fake-link\&quot;>#FOSDEM</span> virtual conference today; Containers track topics are hot &#128293; \n<a class=\&quot;tweet-url\&quot; href=\&quot;https://fosdem.org/2022/schedule/track/containers/\&quot;>fosdem.org/2022/schedule/&#8230;</a> &quot;,&quot;username&quot;:&quot;csantanapr&quot;,&quot;name&quot;:&quot;Carlos Santana&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Sun Feb 06 12:40:55 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://res.cloudinary.com/hhsslviub/video/upload/e_loop,vs_40/v1ixllmwn3frsbplpdjq.gif&quot;,&quot;link_url&quot;:&quot;https://t.co/3JQvj4nbpj&quot;,&quot;alt_text&quot;:&quot;Sizzling Hot Sizzle GIF&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:0,&quot;like_count&quot;:10,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/csantanapr/status/1489999961651560458&quot;,&quot;full_text&quot;:&quot;The State of Go <span class=\&quot;tweet-fake-link\&quot;>@fosdem</span> 2022 \n<a class=\&quot;tweet-url\&quot; href=\&quot;https://youtu.be/3UHeCyw2MjQ\&quot;>youtu.be/3UHeCyw2MjQ</a>\nGo 1.18 is planned to be released in February 2022 and this talk covers what's coming up with it.\n\nWe'll talk about new features and fixes in Go, new proposals for Go 2. All of the new things you might have missed&quot;,&quot;username&quot;:&quot;csantanapr&quot;,&quot;name&quot;:&quot;Carlos Santana&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Sat Feb 05 16:30:48 +0000 2022&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:2,&quot;like_count&quot;:7,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{&quot;url&quot;:&quot;https://youtu.be/3UHeCyw2MjQ&quot;,&quot;image&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3ffd83c8-63f0-4b5e-86c3-4c46aed41f57_1280x720.jpeg&quot;,&quot;title&quot;:&quot;The State of Go @ FOSDEM 2022&quot;,&quot;description&quot;:&quot;Speaker: Maartje EyskensGo 1.18 is planned to be released in February 2022 and this talk covers what&#8217;s coming up with it.We&#8217;ll talk about new features and fi...&quot;,&quot;domain&quot;:&quot;youtu.be&quot;},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p><strong><a href="https://www.pulumi.com/blog/executing-remote-commands/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Executing Remote Commands with Pulumi | Pulumi Blog</a> &#8212; <a href="https://www.pulumi.com/blog/executing-remote-commands/">www.pulumi.com</a></strong> In this article, we deploy k3s and use the Command package to retrieve our kubeconfig from the virtual-machine and create a Kubernetes provider</p><p><strong><a href="https://www.devseccon.com/the-secure-developer-podcast/ep-110-supply-chain-security?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Ep. #110 Supply Chain Security | DevSecCon</a></strong> Supply chain security is a multifaceted, complex, and currently unsolved problem, and Jonathan Meadows is determined to change that!</p><p><strong><a href="https://openshifttipsandtricks.blogspot.com/2022/01/what-is-openshift-cpu-throttling.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What is OpenShift CPU throttling? Turbonomic to the Rescue!</a> &#8212; <a href="https://openshifttipsandtricks.blogspot.com/2022/01/what-is-openshift-cpu-throttling.html">openshifttipsandtricks.blogspot.com</a></strong> Your description for this link...</p><p><strong><a href="https://twitter.com/devops_tech/status/1488101541395394561?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Rakesh Jain on Twitter: "Linux Diagnostics and Troubleshooting Series - Managing Kernel Modules! "</a> &#8212; <a href="https://twitter.com/devops_tech/status/1488101541395394561">twitter.com</a></strong> Your description for this link...</p><p><strong><a href="https://michael-tissen.medium.com/setting-up-an-raspberrypi4-k3s-cluster-with-nfs-persistent-storage-a931ebb85737?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Setting up an raspberrypi4 k3s-cluster with nfs persistent-storage | by Michael Tissen | Medium</a> &#8212; <a href="https://michael-tissen.medium.com/setting-up-an-raspberrypi4-k3s-cluster-with-nfs-persistent-storage-a931ebb85737">michael-tissen.medium.com</a></strong> There are not many options to add persistent-storage to a k3s raspberry cluster. I will present you a relative simple and powerfull method with the nfs-client-provisioner. I&#8217;ve created a folder named&#8230;</p><p><strong><a href="https://blog.kubecost.com/blog/kubernetes-kops/?_hsenc=p2ANqtz--eCMoabTz7BBxiEoNua_kQ270ZO2usAEZ7ESd87eu16ef-0soXiDZVHzkpC7ibVBwRX4MM_E064v9bSDCAhUuEbTmI0A&amp;_hsmi=202939033&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_content=202939033&amp;utm_medium=email&amp;utm_source=hs_email">Kubernetes kOps: Step-By-Step Example &amp; Alternatives - Kubecost Blog</a></strong> Learn the features and functionality of Kubernetes kOps, explore its alternatives, and follow step-by-step instructions to implement it.</p><p><strong><a href="https://smallstep.com/blog/everything-pki/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Everything Public Key Infrastructure (PKI) - The Missing Manual | Smallstep Blog</a> &#8212; <a href="https://smallstep.com/blog/everything-pki/">smallstep.com</a></strong> Everything you should know about certificates and public key infrastructure (PKI) but are too afraid to ask.</p><p><strong><a href="https://blog.flant.com/kubernetes-security-with-kube-bench-and-kube-hunter/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=eks.news">Kubernetes cluster security assessment with kube-bench and kube-hunter &#8211; Flant blog</a> &#8212; <a href="https://blog.flant.com/kubernetes-security-with-kube-bench-and-kube-hunter/?utm_medium=email&amp;utm_source=eks.news">blog.flant.com</a></strong> Your description for this link...</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #25]]></title><description><![CDATA[Welcome to another issue where I'll update you on Cloud Native topics in 3 categories: News, Assets, and Skills.This weekend I finally ran some ethernet cable to by new office upstairs to get a 10x internet performance boost. My wife said if I go up and down the stairs to get snacks I have a better chance to lose some belly fat :-)This weekend I saw the terrible news that a person admired by the developer community was in a terrible car accident. Kent C. Dodds is alive to tell us what happened. Hug your loved ones.PS: Follow me on Twitter &#128591;]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-25-1003174</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-25-1003174</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 31 Jan 2022 01:27:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/5g3dK2DgW-k" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to another issue where I'll update you on Cloud Native topics in 3 categories: <strong>News</strong>, <strong>Assets</strong>, and <strong>Skills</strong>.</p><p>This weekend I finally ran some ethernet cable to by new office upstairs to get a <a href="https://twitter.com/csantanapr/status/1487615959586250752">10x internet performance boost</a>. My wife said if I go up and down the stairs to get snacks I have a better chance to lose some belly fat :-)</p><p>This weekend I saw the terrible news that a person admired by the developer community was in a terrible car accident. <a href="https://twitter.com/kentcdodds/status/1487314342366171139">Kent C. Dodds is alive to tell us what happened</a>. Hug your loved ones.</p><p>PS: <a href="https://twitter.com/csantanapr">Follow me on Twitter</a> &#128591;</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.opensourcerers.org/2022/01/17/openshift-on-raspberry-pi-4/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">OpenShift on Raspberry Pi 4? &#8211; Open Sourcerers</a> &#8212; <a href="https://www.opensourcerers.org/2022/01/17/openshift-on-raspberry-pi-4/">www.opensourcerers.org</a></strong></p><p>Almost! We run MicroShift on a Raspberry Pi4. MicroShift is an experimental flavour of OpenShift/Kubernetes optimized for the device edge.</p><p><strong><a href="https://knative.dev/blog/releases/announcing-knative-v1-2-release/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">v1.2 release - Knative</a> &#8212; <a href="https://knative.dev/blog/releases/announcing-knative-v1-2-release/">knative.dev</a></strong> Knative v1.2 release announcement</p><p><strong><a href="https://blog.aquasec.com/cve-2022-0185-linux-kernel-container-escape-in-kubernetes?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CVE-2022-0185 in Linux Kernel Can Allow Container Escape in Kubernetes</a></strong> A high-severity CVE was released that affects the Linux kernel, allowing unprivileged users to escalate those rights to root and escape from the container</p><p><strong><a href="https://blog.upbound.io/cloud-service-coverage/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcing 100% Cloud Service Coverage for Crossplane</a></strong> Crossplane now has 100% coverage for major cloud services with the new providers: provider-jet-aws, provider-jet-azure, and provider-jet-gcp. To create new providers like these, we are introducing Terrajet, a code generation pipeline for creating Crossplane providers.</p><p><strong><a href="https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Linux system service bug gives root on all major distros, exploit released</a> &#8212; <a href="https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/">www.bleepingcomputer.com</a></strong> A vulnerability in Polkit's pkexec component identified as CVE-2021-4034 (PwnKit) is present in the default configuration of all major Linux distributions and can be exploited to gain full root privileges on the system, researchers warn today.</p><p><strong><a href="https://isovalent.com/blog/post/2021-12-08-ebpf-servicemesh?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How eBPF will solve Service Mesh - Goodbye Sidecars</a> &#8212; <a href="https://isovalent.com/blog/post/2021-12-08-ebpf-servicemesh">isovalent.com</a></strong> eBPF Service Mesh - How we can build an eBPF-based service mesh in the kernel to replace the complex sidecar model</p><p><strong><a href="https://www.leebriggs.co.uk/blog/2022/01/23/gha-cloud-credentials.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Stop using static cloud credentials in GitHub Actions | lbr.</a></strong> Engineering, DevOps &amp; Cloud Computing</p><p><strong><a href="https://salaboy.com/2022/01/29/event-driven-applications-with-cloudevents-on-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Event-Driven applications with CloudEvents on Kubernetes &#8211; Salaboy (Open Source Knowledge)</a> &#8212; <a href="https://salaboy.com/2022/01/29/event-driven-applications-with-cloudevents-on-kubernetes/">salaboy.com</a></strong></p><p>This week I've spent time writing this tutorial and examples that contain the building blocks that I will use to build a larger example.</p><p><strong><a href="https://blog.argoproj.io/new-sync-and-diff-strategies-in-argocd-44195d3f8b8c?gi=82851912fdb&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">New sync and diff strategies in ArgoCD | by Leonardo Luz | Jan, 2022 | Argo Project</a> &#8212; <a href="https://blog.argoproj.io/new-sync-and-diff-strategies-in-argocd-44195d3f8b8c?gi=82851912fdb">blog.argoproj.io</a></strong> ArgoCD 2.3 will be shipping with a new experimental sync option that will verify diffing customizations while preparing the patch to be applied in the cluster. It also includes a new diff strategy&#8230;</p><p><strong><a href="https://github.com/devtron-labs/devtron?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - devtron-labs/devtron: Web based CI/CD Platform for Kubernetes</a> &#8212; <a href="https://github.com/devtron-labs/devtron">github.com</a></strong> Web based CI/CD Platform for Kubernetes. Contribute to devtron-labs/devtron development by creating an account on GitHub.</p><p><strong><a href="https://fosdem.org/2022/schedule/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">FOSDEM 2022 - Schedule</a> &#8212; <a href="https://fosdem.org/2022/schedule/">fosdem.org</a></strong> Every year, FOSDEM hosts a wide variety of activities. This page gives an overview with links to further information about scheduled events. All times CET (UTC+1).</p><p><strong><a href="https://www.suse.com/c/rancher_blog/rancher-desktop-1-0-0-has-arrived/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Rancher Desktop 1.0.0 Has Arrived | SUSE Communities</a> &#8212; <a href="https://www.suse.com/c/rancher_blog/rancher-desktop-1-0-0-has-arrived/">www.suse.com</a></strong></p><p>We are happy to announce the 1.0.0 release of Rancher Desktop. This release has been months in the making since development on Rancher Desktop began.</p><p><strong><a href="https://www.redhat.com/architect/kubernetes-hierarchical-namespaces?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes architecture: How to use hierarchical namespaces for multiple tenants | Enable Architect</a> &#8212; <a href="https://www.redhat.com/architect/kubernetes-hierarchical-namespaces">www.redhat.com</a></strong> Hierarchical namespaces make it easier to manage individual tenants' permissions and capabilities in a multi-tenant Kuberentes architecture.</p><p><strong><a href="https://www.parca.dev/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Parca - Open Source infrastructure-wide continuous profiling | Parca</a></strong> Open Source infrastructure-wide continuous profiling</p><p><strong><a href="https://blog.chainguard.dev/wtf-is-chainguard/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">WTF is Chainguard ?</a></strong> Chainguard is a 3-month start up in the software supply chain security industry. The mission of Chainguard is to make the software lifecycle secure by default. Sounds kinda vague. Do you have a product?No. Not yet. We have some exciting ideas though, and are working on them right now!</p><p><strong><a href="https://www.bleepingcomputer.com/news/security/researchers-use-gpu-fingerprinting-to-track-users-online/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Researchers use GPU fingerprinting to track users online</a> &#8212; <a href="https://www.bleepingcomputer.com/news/security/researchers-use-gpu-fingerprinting-to-track-users-online/">www.bleepingcomputer.com</a></strong> A team of researchers from French, Israeli, and Australian universities has explored the possibility of using people's GPUs to create unique fingerprints and use them for persistent web tracking.</p><p><strong><a href="https://jvns.ca/blog/2022/01/29/reasons-for-servers-to-support-ipv6/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Reasons for servers to support IPv6</a></strong> Reasons for servers to support IPv6</p><p><strong><a href="https://medium.com/@bruce_25864/the-road-to-sre-ad4c73df78b8?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The ROAD to SRE. There are many ways to introduce Site&#8230; | by Bruce Dominguez | Dec, 2021 | Medium</a> &#8212; <a href="https://medium.com/@bruce_25864/the-road-to-sre-ad4c73df78b8">medium.com</a></strong> There are many ways to introduce Site Reliability Engineering practices to your organisation, but it can be confusing where you should start. Do you start with introducing Service Level Objectives&#8230;</p><p><strong><a href="https://buttondown.email/nelhage/archive/two-reasons-kubernetes-is-so-complex?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Two reasons Kubernetes is so complex &#8226; Buttondown</a> &#8212; <a href="https://buttondown.email/nelhage/archive/two-reasons-kubernetes-is-so-complex">buttondown.email</a></strong> Preface Hello friends! It&#8217;s been a while. I&#8217;ve been finding it very hard to write while holding up a full-time job, and I&#8217;ve also been dealing with some very...</p><p><strong><a href="https://learnk8s.io/kubernetes-network-packets?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Tracing the path of network traffic in Kubernetes</a> &#8212; <a href="https://learnk8s.io/kubernetes-network-packets">learnk8s.io</a></strong> Learn how packets flow inside and outside a Kubernetes cluster. Starting from the initial web request and down to the container hosting the application</p><p><strong><a href="https://medium.com/pareture/kubernetes-scaling-capacity-and-resource-planning-in-complex-clusters-97a6105b43a4?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Scaling, Capacity and Resource Planning in Complex Clusters | by Nick Gibbon | Pareture | Medium</a> &#8212; <a href="https://medium.com/pareture/kubernetes-scaling-capacity-and-resource-planning-in-complex-clusters-97a6105b43a4">medium.com</a></strong> An intermediate take on Kubernetes various elements of scaling, capacity and resource planning after some pain and confusion over a few years. My experience is that of a Kubernetes Cluster and&#8230;</p><p><strong><a href="https://research.ibm.com/blog/codenet-ai-for-code?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kickstarting AI for Code: Introducing IBM&#8217;s Project CodeNet | IBM Research Blog</a> &#8212; <a href="https://research.ibm.com/blog/codenet-ai-for-code">research.ibm.com</a></strong> Project CodeNet is a large dataset aimed at teaching AI to code.</p><p><strong><a href="https://theankurtyagi.com/everything-about-super-tokens-an-open-source-alternative-to-auth0-firebase-auth-and-aws-cognito/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Everything about super tokens - an open source alternative to Auth0, Firebase Auth, and AWS Cognito. - Ankur Tyagi</a> &#8212; <a href="https://theankurtyagi.com/everything-about-super-tokens-an-open-source-alternative-to-auth0-firebase-auth-and-aws-cognito/">theankurtyagi.com</a></strong> Super Tokens An Open Source User Auth Quick to implement and easy to customize</p><p><strong><a href="https://blog.sigstore.dev/sigstore-ruby-ce3591838fe8?gi=fab445a2d1f5&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Sigstore &#10084; Ruby! - sigstore</a> &#8212; <a href="https://blog.sigstore.dev/sigstore-ruby-ce3591838fe8?gi=fab445a2d1f5">blog.sigstore.dev</a></strong> We started the Sigstore project with a goal of making key management, certificates, and digital signatures accessible and easy to use for&#8230;</p><p><strong><a href="https://about.gitlab.com/handbook/engineering/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter#code-quality-and-standards">Engineering | GitLab</a> &#8212; <a href="https://about.gitlab.com/handbook/engineering/#code-quality-and-standards">about.gitlab.com</a></strong></p><p>GitLab is an open-source company that everything is public. Here is their engineering handbook</p><p><strong><a href="https://practicalkubernetes.blogspot.com/2022/01/making-case-for-kubernetes-operators.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Making the case for Kubernetes operators</a> &#8212; <a href="https://practicalkubernetes.blogspot.com/2022/01/making-case-for-kubernetes-operators.html">practicalkubernetes.blogspot.com</a></strong> Your description for this link...</p><p><strong><a href="https://www.businesswire.com/news/home/20220125005277/en/Open-Source-Kubernetes-Virtual-Cluster-Project-vcluster-Now-Runs-on-k0s?utm_campaign=shareaholic&amp;utm_medium=twitter&amp;utm_source=socialnetwork">Open Source Kubernetes Virtual Cluster Project vcluster Now Runs on k0s | Business Wire</a> &#8212; <a href="https://www.businesswire.com/news/home/20220125005277/en/Open-Source-Kubernetes-Virtual-Cluster-Project-vcluster-Now-Runs-on-k0s?utm_campaign=shareaholic&amp;utm_medium=twitter&amp;utm_source=socialnetwork">www.businesswire.com</a></strong> vcluster is now available to spin up virtual clusters with k0s.</p><p><strong><a href="https://charity.wtf/2022/01/29/how-can-you-tell-if-the-company-youre-interviewing-with-is-rotten-on-the-inside/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How can you tell if the company you&#8217;re interviewing with is rotten on the inside? &#8211; charity.wtf</a> &#8212; <a href="https://charity.wtf/2022/01/29/how-can-you-tell-if-the-company-youre-interviewing-with-is-rotten-on-the-inside/">charity.wtf</a></strong></p><p>How can you tell the companies who are earnestly trying to improve apart from the ones who sound all polished and healthy from the outside, whilst rotting on the inside?</p><p><strong><a href="https://tailscale.com/blog/2021-12-newsletter/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">December Tailscale newsletter &#183; Tailscale</a> &#8212; <a href="https://tailscale.com/blog/2021-12-newsletter/">tailscale.com</a></strong> December brought fascinating community contributions, including How To Get Tailscale Working With a Fire TV Stick and how to use Tailscale for SSH access to &#8216;LAN&#8217; locked machines.</p><p><strong><a href="https://dev.to/aws/aws-open-source-news-and-updates-97-55gf?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AWS open source news and updates, #97 - DEV Community</a></strong> Jan 22nd, 2022 - Instalment #97 Newsletter #97. Welcome to another edition of the AWS... Tagged with opensource, aws.</p><p><strong><a href="https://danielcompton.net/2021/07/28/apple-m1-displaylink-multiple-display?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Understanding DisplayLink, multiple displays, and M1 Macs &#8211; Daniel Compton</a></strong></p><p>Geek out about connecting Monitors to your new Mac</p><p><strong><a href="https://niklasmtj.de/blog/alternative-docker-installation-macos-with-multipass/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">An alternative Docker installation with Multipass on macOS without using Docker for Mac | Niklas Metje</a></strong> Last week I received an email from the Docker Team which said that Docker for Mac (the software which also comes with a GUI) will be forbidden for commercial&#8230;</p><p><strong><a href="https://mirror.xyz/dhaiwat.eth/O5CK6Tjfv8uhl6FPbjT0yZ8LUwViDPWGYHdu9khRWpM?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A guide to Web3 for Web2 frontend devs &#8212; Dhaiwat Pandya</a> &#8212; <a href="https://mirror.xyz/dhaiwat.eth/O5CK6Tjfv8uhl6FPbjT0yZ8LUwViDPWGYHdu9khRWpM">mirror.xyz</a></strong> With all the hype around, web3 can be overwhelming if you&#8217;re looking to get started. Luckily if you are a frontend dev coming from web2, you already have most of the skills you need to get started in web3. I can say this because I come from a web2 frontend background myself and I made the move to web3 last year. I now work full-time in web3.</p><h2>Assets</h2><p><strong><a href="https://github.com/lukehinds/sigstore-the-hard-way?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - lukehinds/sigstore-the-hard-way: sigstore the hard way!</a> &#8212; <a href="https://github.com/lukehinds/sigstore-the-hard-way">github.com</a></strong> sigstore the hard way! Contribute to lukehinds/sigstore-the-hard-way development by creating an account on GitHub.</p><p><strong><a href="https://tunnelbroker.net/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Hurricane Electric Free IPv6 Tunnel Broker</a></strong></p><p>Get a free tunnel to your internal IPv6 addresses</p><p><strong><a href="https://github.com/amplication/amplication?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - amplication/amplication: </a>&#8212; <a href="https://github.com/amplication/amplication">github.com</a></strong></p><p>Amplication is an open&#8209;source development tool. It helps you develop quality Node.js applications without spending time on repetitive coding tasks. - GitHub -</p><p><strong><a href="https://github.com/fleetbase/storefront-app?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - fleetbase/storefront-app: </a>&#8212; <a href="https://github.com/fleetbase/storefront-app">github.com</a></strong></p><p>Storefront by Fleetbase is an open source hyperlocal shopping or services app. Enables users to quickly launch their own shop or service booking app or setup a multi-vendor marketplace. -</p><p><strong><a href="https://github.com/opencontainers/artwork?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - opencontainers/artwork: OCI artwork and logos</a> &#8212; <a href="https://github.com/opencontainers/artwork">github.com</a></strong> OCI artwork and logos. Contribute to opencontainers/artwork development by creating an account on GitHub.</p><p><strong><a href="https://monorepo.tools/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Everything you need to know about monorepos, and the tools to build them.</a> &#8212; <a href="https://monorepo.tools/">monorepo.tools</a></strong> Everything you need to know about monorepos, and the tools to build them.</p><p><strong><a href="https://github.com/collections/pixel-art-tools?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Collection: Pixel Art Tools &#183; GitHub</a> &#8212; <a href="https://github.com/collections/pixel-art-tools">github.com</a></strong> GitHub is where people build software. More than 73 million people use GitHub to discover, fork, and contribute to over 200 million projects.</p><p><strong><a href="https://weekly.tf/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">weekly.tf | Revue</a> &#8212; <a href="https://weekly.tf/">weekly.tf</a></strong> weekly.tf - Terraform Weekly...</p><p><strong><a href="https://devopscube.com/build-docker-image-kubernetes-pod?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How To Build Docker Image In Kubernetes Pod Using Kaniko</a> &#8212; <a href="https://devopscube.com/build-docker-image-kubernetes-pod">devopscube.com</a></strong> This beginner's guide focuses on step by step process of setting up Docker image build in Kubernetes pod using Kaniko image builder.</p><p><strong><a href="https://github.com/marcosnils/bin/releases/tag/v0.13.0?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Release v0.13.0 &#183; marcosnils/bin &#183; GitHub</a> &#8212; <a href="https://github.com/marcosnils/bin/releases/tag/v0.13.0">github.com</a></strong> Effortless binary manager. Contribute to marcosnils/bin development by creating an account on GitHub.</p><p><strong><a href="https://lit.dev/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Lit</a></strong> Simple. Fast. Web Components.</p><h2>Skills</h2><p><strong><a href="https://www.docker.com/blog/how-docker-desktop-networking-works-under-the-hood/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How Docker Desktop Networking Works Under the Hood - Docker Blog</a> &#8212; <a href="https://www.docker.com/blog/how-docker-desktop-networking-works-under-the-hood/">www.docker.com</a></strong> Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version announcements!</p><p><strong><a href="https://www.solo.io/events-webinars/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Solo Events and Webinars</a> &#8212; <a href="https://www.solo.io/events-webinars/">www.solo.io</a></strong></p><p><strong><a href="https://docs.google.com/document/d/11qMVVdn95tyGvYiVA5HwjlIV750-gYiT-dJCNS0ZPE0/edit?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">[PUBLIC] The Art of SLOs &#8211; Participant Handbook - Google Docs</a> &#8212; <a href="https://docs.google.com/document/d/11qMVVdn95tyGvYiVA5HwjlIV750-gYiT-dJCNS0ZPE0/edit">docs.google.com</a></strong></p><p>Practical Guide to calculate SLOs</p><div id="youtube2-5g3dK2DgW-k" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5g3dK2DgW-k&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5g3dK2DgW-k?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://open.spotify.com/episode/24AselKayur58sQVsKKraB?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">#437: A Day in the Life of an SA - AWS Podcast | Podcast on Spotify</a> &#8212; <a href="https://open.spotify.com/episode/24AselKayur58sQVsKKraB">open.spotify.com</a></strong></p><p>Listen to this episode from AWS Podcast on Spotify. What does a day in the life of a Solution Architect look like at AWS? Simon speaks with four SA&#8217;s from around the globe to discuss</p><p><strong><a href="https://anchor.fm/alanmbarr/episodes/Junior-Developers-e1cnpoo?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Junior Developers by The Alan Barr Show</a></strong></p><p>"The average tenure of software engineers in small companies is only 1.5 years, where it&#8217;s 2.3 years for large companies." - Why Programmers Shouldn't Stay in One Company for a long time.</p><p><strong><a href="https://sysdig.com/blog/kubernetes-1-23-whats-new/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes 1.23 - What's new? - New features and deprecations</a> &#8212; <a href="https://sysdig.com/blog/kubernetes-1-23-whats-new/">sysdig.com</a></strong> Kubernetes 1.23 brings 50 enhancement, including improved support for OpenAPI v3, a new kubectl events command. Discover more!</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #24]]></title><description><![CDATA[Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and Skills.I did minor updates to my site; I added a page for all my Cloud Native learning resources https://www.santana.dev/learn.I also updated the Kubernetes Book Club roadmap https://www.santana.dev/book-club. My two highlights are the Kubernetes Documentary on youtube and microshift from Red Hat to get openshift running on Raspberry Pi.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-24-990563</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-24-990563</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Mon, 24 Jan 2022 02:46:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/BE77h7dmoQU" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and Skills.</p><p>I did minor updates to my site; I added a page for all my Cloud Native learning resources <a href="https://www.santana.dev/learn.">https://www.santana.dev/learn.</a></p><p>I also updated the Kubernetes Book Club roadmap <a href="https://www.santana.dev/book-club.">https://www.santana.dev/book-club.</a></p><p>My two highlights are the Kubernetes Documentary on youtube and microshift from Red Hat to get openshift running on Raspberry Pi.</p><div><hr></div><h2>News</h2><div id="youtube2-BE77h7dmoQU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;BE77h7dmoQU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/BE77h7dmoQU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://next.redhat.com/2022/01/19/introducing-microshift/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing MicroShift - Red Hat Emerging Technologies</a> &#8212; <a href="https://next.redhat.com/2022/01/19/introducing-microshift/">next.redhat.com</a></strong> MicroShift has been specifically designed for edge computing use cases, with a goal of fitting in the limited storage capacity of field-deployed devices that can be embedded into a variety of appliances such as cars, factory lines, airplanes or even satellites.</p><p><strong><a href="https://www.bleepingcomputer.com/news/security/over-90-wordpress-themes-plugins-backdoored-in-supply-chain-attack/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Over 90 WordPress themes, plugins backdoored in supply chain attack</a> &#8212; <a href="https://www.bleepingcomputer.com/news/security/over-90-wordpress-themes-plugins-backdoored-in-supply-chain-attack/">www.bleepingcomputer.com</a></strong> A massive supply chain attack compromised 93 WordPress themes and plugins to contain a backdoor, giving threat-actors full access to websites.</p><p><strong><a href="https://www.santana.dev/blog/homelab-1?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Home Lab</a></strong> Home lab using Intel NUC and Raspberry Pi running Kubernetes, K3S, Knative</p><p><strong><a href="https://medium.com/paypal-tech/scaling-kubernetes-to-over-4k-nodes-and-200k-pods-29988fad6ed?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Scaling Kubernetes to Over 4k Nodes and 200k Pods | by Abdul Qadeer | The PayPal Technology Blog | Jan, 2022 | Medium</a> &#8212; <a href="https://medium.com/paypal-tech/scaling-kubernetes-to-over-4k-nodes-and-200k-pods-29988fad6ed">medium.com</a></strong> At PayPal, we recently started testing the waters with Kubernetes. A majority of our workloads run on Apache Mesos, and as part of this migration, we needed to understand several performance aspects&#8230;</p><p><strong><a href="https://www.nextplatform.com/2022/01/04/inside-amazons-graviton3-arm-server-processor/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Inside Amazon&#8217;s Graviton3 Arm Server Processor</a> &#8212; <a href="https://www.nextplatform.com/2022/01/04/inside-amazons-graviton3-arm-server-processor/">www.nextplatform.com</a></strong> The Graviton family of Arm server chips designed by the Annapurna Labs division of Amazon Web Services is arguably the highest volume Arm server chips the</p><p><strong><a href="https://www.suse.com/c/neuvector-open-source/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">SUSE releases NeuVector, the industry&#8217;s first open source container security platform | SUSE Communities</a> &#8212; <a href="https://www.suse.com/c/neuvector-open-source/">www.suse.com</a></strong> Today, we are pleased to announce that the NeuVector codebase is now available to the open source community on GitHub. The work to fully open source a formerly proprietary technology is a testament to SUSE&#8217;s open-source culture and our commitment to deliver open, interoperable and innovative solutions to our partners and customers. With this release, &#8230;</p><p><strong><a href="https://www.bloomberg.com/news/articles/2022-01-12/teen-hacker-claims-to-have-taken-control-of-25-teslas-worldwide?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Third-Party Software for Teslas Can Be Hacked, German Teen Says - Bloomberg</a> &#8212; <a href="https://www.bloomberg.com/news/articles/2022-01-12/teen-hacker-claims-to-have-taken-control-of-25-teslas-worldwide">www.bloomberg.com</a></strong> A 19-year-old said he&#8217;s found flaws in a piece of third-party software that appears to be used by a relatively small number of owners of Tesla Inc. cars that could allow hackers to remotely control some of the vehicles&#8217; functions.</p><p><strong><a href="https://medium.com/ibm-cloud/our-cloud-native-journey-to-red-hat-openshift-using-quarkus-7384847dfd99?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Our Cloud Native Journey to Red Hat OpenShift Using Quarkus</a> &#8212; <a href="https://medium.com/ibm-cloud/our-cloud-native-journey-to-red-hat-openshift-using-quarkus-7384847dfd99">medium.com</a></strong> Once you have a hypothesis and some spare time, what do you do? You perform an experiment! That is exactly what our Go To Markets &#8212; Assets and Architecture team did. Throughout this blog series&#8230;</p><p><strong><a href="https://dustinspecker.com/posts/ubuntu-vm-pulumi-libvirt/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Spin up a Ubuntu VM using Pulumi and libvirt | Dustin Specker</a> &#8212; <a href="https://dustinspecker.com/posts/ubuntu-vm-pulumi-libvirt/">dustinspecker.com</a></strong> Pulumi is an Infrastructure as Code (IaC) tool that supports using Go, .Net, Python, and TypeScript/JavaScript. Libvirt is a tool for managing virtual machines (VM). Typically, teams use Pulumi with different cloud providers, but we can leverage libvirt to manage virtual machines on bare-metal servers, perfect for a homelab.</p><p><strong><a href="https://komodor.com/learn/kubernetes-nodes-complete-guide/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Nodes - The Complete Guide | Komodor</a> &#8212; <a href="https://komodor.com/learn/kubernetes-nodes-complete-guide/">komodor.com</a></strong> Learn about Kubernetes node components, status, best practices for running nodes in a cluster, and common errors.</p><p><strong><a href="https://iximiuz.com/en/posts/kubernetes-api-structure-and-terminology/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes API Basics - Resources, Kinds, and Objects</a> &#8212; <a href="https://iximiuz.com/en/posts/kubernetes-api-structure-and-terminology/">iximiuz.com</a></strong> The article explains the most fundamental concepts of the Kubernetes API - Resources, API Groups, Kinds, and Objects - preparing the reader to the first access of the API from code.</p><p><strong><a href="https://kubernetes.io/blog/2022/01/19/secure-your-admission-controllers-and-webhooks/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Securing Admission Controllers | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2022/01/19/secure-your-admission-controllers-and-webhooks/">kubernetes.io</a></strong></p><p>Author: Rory McCune (Aqua Security) Admission control is a key part of Kubernetes security, alongside authentication and authorization. Webhook admission controllers</p><p><strong><a href="https://orca.security/resources/blog/aws-glue-vulnerability/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Orca Security Discovers AWS Glue Vulnerability - Orca Security</a> &#8212; <a href="https://orca.security/resources/blog/aws-glue-vulnerability/">orca.security</a></strong> Orca's Research Team discovered a critical vulnerability that could allow an actor to create resources and access data of AWS Glue customers.</p><p><strong><a href="https://www.pmbanugo.me/blog/2022-01-20-goodbye-dockerfiles-build-secure-optimised-node-js-container-images-with-cloud-native-buildpacks/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Goodbye Dockerfiles: Build Secure &amp; Optimised Node.js Container Images with Cloud Native Buildpacks | Blog</a> &#8212; <a href="https://www.pmbanugo.me/blog/2022-01-20-goodbye-dockerfiles-build-secure-optimised-node-js-container-images-with-cloud-native-buildpacks/">www.pmbanugo.me</a></strong> Learn how to secure container images using Cloud Native Buildpacks</p><p><strong><a href="https://falco.org/blog/falco-monitoring-new-syscalls/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Monitoring new syscalls with Falco | Falco</a></strong> Falco is currently the de facto standard for runtime threat detection in Kubernetes environments. The project is growing at a very fast pace, and so is its open source community. The role of Falco is to collect all the system events of a cluster and send some kind of alert whenever suspicious behavior is detected. Among the other data sources supported, system calls are the core kind of events monitored by Falco.</p><p><strong><a href="https://remix.run/blog/remix-vs-next?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Remix vs Next.js | Remix</a> &#8212; <a href="https://remix.run/blog/remix-vs-next">remix.run</a></strong> An objective comparison between Remix and Next.js</p><h2>Assets</h2><p><strong><a href="https://github.com/up9inc/mizu?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - up9inc/mizu: API traffic viewer for Kubernetes enabling you to view all API communication between microservices. </a>&#8212; <a href="https://github.com/up9inc/mizu">github.com</a></strong> API traffic viewer for Kubernetes enabling you to view all API communication between microservices. Think TCPDump and Wireshark re-invented for Kubernetes - GitHub - up9inc/mizu: API traffic viewer for Kubernetes enabling you to view all API communication between microservices. Think TCPDump and Wireshark re-invented for Kubernetes</p><p><strong><a href="https://github.com/tohjustin/kube-lineage?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - tohjustin/kube-lineage: A CLI tool to display all dependencies or dependents of an object in a Kubernetes cluster.</a> &#8212; <a href="https://github.com/tohjustin/kube-lineage">github.com</a></strong> A CLI tool to display all dependencies or dependents of an object in a Kubernetes cluster. - GitHub - tohjustin/kube-lineage: A CLI tool to display all dependencies or dependents of an object in a Kubernetes cluster.</p><p><strong><a href="https://marketplace.visualstudio.com/items?itemName=CodeZero.codezero&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CodeZero - Visual Studio Marketplace</a> &#8212; <a href="https://marketplace.visualstudio.com/items?itemName=CodeZero.codezero">marketplace.visualstudio.com</a></strong></p><p>Extension for Visual Studio Code - CodeZero extension for VS Code</p><p>CodeZero is a modern development platform for Kubernetes</p><p><strong><a href="https://github.com/asobti/kube-monkey?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - asobti/kube-monkey: An implementation of Netflix's Chaos Monkey for Kubernetes clusters</a> &#8212; <a href="https://github.com/asobti/kube-monkey">github.com</a></strong> An implementation of Netflix's Chaos Monkey for Kubernetes clusters - GitHub - asobti/kube-monkey: An implementation of Netflix's Chaos Monkey for Kubernetes clusters</p><p><strong><a href="https://github.com/sagittaros/terraform-k3s-private-cloud?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - sagittaros/terraform-k3s-private-cloud: Private cluster with k3s. Why have 1 huge complicated cluster (pet) when you can have many simple, cheap clusters (cattle)?</a> &#8212; <a href="https://github.com/sagittaros/terraform-k3s-private-cloud">github.com</a></strong> Private cluster with k3s. Why have 1 huge complicated cluster (pet) when you can have many simple, cheap clusters (cattle)? - GitHub - sagittaros/terraform-k3s-private-cloud: Private cluster with k3s. Why have 1 huge complicated cluster (pet) when you can have many simple, cheap clusters (cattle)?</p><p><strong><a href="https://github.com/vercel/micro?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - vercel/micro: Asynchronous HTTP microservices</a> &#8212; <a href="https://github.com/vercel/micro">github.com</a></strong> Asynchronous HTTP microservices. Contribute to vercel/micro development by creating an account on GitHub.</p><p><strong><a href="https://github.com/jedi4ever/bashpack?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - jedi4ever/bashpack: turns nodejs projects into a single executable bash file</a> &#8212; <a href="https://github.com/jedi4ever/bashpack">github.com</a></strong> turns nodejs projects into a single executable bash file - GitHub - jedi4ever/bashpack: turns nodejs projects into a single executable bash file</p><p><strong><a href="https://www.glideapps.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Create powerful apps and websites, without code.</a> &#8212; <a href="https://www.glideapps.com/">www.glideapps.com</a></strong> Turn spreadsheets into powerful apps &amp; websites, without writing any code. Pick a spreadsheet or start with a template, customize your app, then share it instantly with anyone. Start today for free!</p><p><strong><a href="https://www.runatlantis.io/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Terraform Pull Request Automation | Atlantis</a></strong> Atlantis: Terraform Pull Request Automation</p><p><strong><a href="https://asdf-vm.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Home | asdf</a></strong> Manage multiple runtime versions with a single CLI tool</p><h2>Skills</h2><div id="youtube2-PqghsyBF7ug" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PqghsyBF7ug&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PqghsyBF7ug?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://www.asykim.com/blog/deep-dive-into-kubernetes-external-traffic-policies?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A Deep Dive into Kubernetes External Traffic Policies &#8212; Andrew Sy Kim</a> &#8212; <a href="https://www.asykim.com/blog/deep-dive-into-kubernetes-external-traffic-policies">www.asykim.com</a></strong> Based on recent discussions, I&#8217;ve noticed some confusion around external traffic policies for Kubernetes Services. This is not surprising given there&#8217;s a lot of context around this feature that can only be found by digging through many Github issues and pull requests. In this post I'll try to do a deep dive into this feature to clarify some of the important assumptions that may not be clear in the API or the documentation.</p><p><strong><a href="https://aws.fm/episodes/episode-17-brian-leroux?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Episode 17 w/ Brian LeRoux: The Case for a Local Dev Experience in Serverless, Architect and Begin.com, and Making Sense of the Web Today &#8211; AWS FM</a> &#8212; <a href="https://aws.fm/episodes/episode-17-brian-leroux">aws.fm</a></strong> Brian joins Adam to discuss his belief that we shouldn't forego a local dev experience when building cloud-native apps, his experiences building frameworks and products like arc.codes and Begin.com, and an honest evaluation of where we're at with the web in 2021.</p><p><strong><a href="https://roadmap.sh/devops?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">DevOps Roadmap: Learn to become a DevOps Engineer or SRE</a> &#8212; <a href="https://roadmap.sh/devops">roadmap.sh</a></strong> Community driven, articles, resources, guides, interview questions, quizzes for DevOps. Learn to become a modern DevOps engineer by following the steps, skills, resources and guides listed in this roadmap.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #23]]></title><description><![CDATA[Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and Skills.Follow me on Twitter https://twitter.com/csantanaprI restarted the Kubernetes Book Club for 2022"We may have all come on different ships, but we're in the same boat now."A quote from Dr. Martin Luther King Jr.]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-23-978382</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-23-978382</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Sun, 16 Jan 2022 23:20:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DXis!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fmedia%2FFJCOspSXMAY478K.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to my newsletter. Every week, I'll update you on Cloud Native topics in 3 categories News, Assets, and Skills.</p><p>Follow me on Twitter <a href="https://twitter.com/csantanapr">https://twitter.com/csantanapr</a></p><p>I restarted the <a href="https://www.santana.dev/book-club">Kubernetes Book Club</a> for 2022</p><p>"We may have all come on different ships, but we're in the same boat now."</p><p>A quote from Dr. Martin Luther King Jr.</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/01/13/readout-of-white-house-meeting-on-software-security/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Readout of White House Meeting on Software Security | The White House</a> &#8212; <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/01/13/readout-of-white-house-meeting-on-software-security/">www.whitehouse.gov</a></strong> Today, the White House convened government and private sector stakeholders to discuss initiatives to improve the security of open source software and ways</p><p><strong><a href="https://parade.com/252644/viannguyen/15-of-martin-luther-king-jr-s-most-inspiring-motivational-quotes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">55 of Dr. Martin Luther King Jr.'s Most Inspiring Motivational Quotes&nbsp;</a> &#8212; <a href="https://parade.com/252644/viannguyen/15-of-martin-luther-king-jr-s-most-inspiring-motivational-quotes/">parade.com</a></strong> Be inspired by 55 of Martin Luther King Jr.'s quotes, ranging from his famous MLK sayings about equality, faith and love, to MLK quotes about peaceful protests.</p><p><strong><a href="https://blog.chainguard.dev/what-an-sbom-can-do-for-you/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What an SBOM Can Do for You</a> &#8212; <a href="https://blog.chainguard.dev/what-an-sbom-can-do-for-you/">blog.chainguard.dev</a></strong> By now, it is common knowledge that a Software Bill of Materials is becoming an increasingly expected requirement from software releases, yet here still seems that some confusion persists about what an SBOM can/could do for your project.</p><p><strong><a href="https://iximiuz.com/en/posts/prometheus-learning-promql/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to learn PromQL with Prometheus Playground</a> &#8212; <a href="https://iximiuz.com/en/posts/prometheus-learning-promql/">iximiuz.com</a></strong> How to setup Prometheus playground. How to learn PromQL running example queries? How to prefill Prometheus with metric data?</p><p><strong><a href="https://www.redhat.com/sysadmin/top-security-articles-2021?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Top 10 Linux security tutorials for sysadmins from 2021 | Enable Sysadmin</a> &#8212; <a href="https://www.redhat.com/sysadmin/top-security-articles-2021">www.redhat.com</a></strong> Even as the world changes around us, the importance of IT security is one of the things that stands firm.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/csantanapr/status/1481841621398347776&quot;,&quot;full_text&quot;:&quot;Every Friday is Kubernetes Book Club &#128218;\nNew Book: 97 Things Every SRE Should Know\nThis week: Part I and II (1-73)\n10AMEDT/5PMCEST/15UTC/8:30PMIST\n\nGet a Calendar invite, Join our Discord, and get a free copy of the book at \n<a class=\&quot;tweet-url\&quot; href=\&quot;https://santana.dev/book-club\&quot;>santana.dev/book-club</a> &quot;,&quot;username&quot;:&quot;csantanapr&quot;,&quot;name&quot;:&quot;Carlos Santana&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Jan 14 04:12:28 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FJCOspSXMAY478K.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/KtVZW6jPGT&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:11,&quot;like_count&quot;:56,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p><strong><a href="https://research.nccgroup.com/2022/01/13/10-real-world-stories-of-how-weve-compromised-ci-cd-pipelines/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">10 real-world stories of how we&#8217;ve compromised CI/CD pipelines &#8211; NCC Group Research</a> &#8212; <a href="https://research.nccgroup.com/2022/01/13/10-real-world-stories-of-how-weve-compromised-ci-cd-pipelines/">research.nccgroup.com</a></strong> Mainstream appreciation for cyberattacks targeting continuous integration and continuous delivery/continuous deployment (CI/CD) pipelines has been gaining momentum. Attackers and defenders increasingly understand that build pipelines are highly-privileged targets with a substantial attack surface. But what are the potential weak points in a CI/CD pipeline? What does this type of attack look like in practice? NCC&#8230;</p><p><strong><a href="https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Google Online Security Blog: Introducing SLSA, an End-to-End Framework for Supply Chain Integrity</a> &#8212; <a href="https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html">security.googleblog.com</a></strong> Posted Kim Lewandowski, Google Open Source Security Team &amp; Mark Lodato, Binary Authorization for Borg Team&nbsp; Supply chain integrity attacks&#8212;u...</p><p><strong><a href="https://blog.flant.com/running-mongodb-in-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Running MongoDB in Kubernetes: An overview of existing solutions &#8211; Flant blog</a> &#8212; <a href="https://blog.flant.com/running-mongodb-in-kubernetes/">blog.flant.com</a></strong> Here are the challenges of using MongoDB in Kubernetes and the options we have to overcome them including ready-to-use Helm charts and Kubernetes operators.</p><p><strong><a href="https://blog.sequin.io/events-not-webhooks?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Give me /events, not webhooks - Sequin</a></strong> Webhooks come with some challenges. We prefer polling an /events endpoint instead when possible.</p><p><strong><a href="https://www.sethvargo.com/what-id-like-to-see-in-go-2?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What I'd like to see in Go 2.0 | Seth Vargo</a> &#8212; <a href="https://www.sethvargo.com/what-id-like-to-see-in-go-2">www.sethvargo.com</a></strong> Audit logs are very useful for retroactive analysis following a security incident, but what if they could also be used to proactively alert before a security incident occurs?</p><p><strong><a href="https://iximiuz.com/en/posts/kubernetes-api-call-simple-http-client/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How To Call Kubernetes API using Simple HTTP Client</a> &#8212; <a href="https://iximiuz.com/en/posts/kubernetes-api-call-simple-http-client/">iximiuz.com</a></strong> There are plenty of reasons to call the Kubernetes API using a CLI or GUI HTTP client. This article will show you how to get the API server address, authenticate requests using certificates and Service Account tokens, and call the API using kubectl in the raw mode.</p><p><strong><a href="https://devops.com/using-event-driven-architecture-with-microservices/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Using Event-Driven Architecture With Microservices - DevOps.com</a> &#8212; <a href="https://devops.com/using-event-driven-architecture-with-microservices/">devops.com</a></strong> To optimize business applications, DevOps teams must understand the full potential of microservices and event-driven architecture.</p><p><strong><a href="https://terrytangyuan.github.io/2022/01/11/unveil-the-secret-ingredients-of-continuous-delivery-at-enterprise-scale-with-argocd-kubecon-china-2021/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Unveil the Secret Ingredients of Continuous Delivery at Enterprise Scale with Argo CD - Yuan's Blog</a></strong> This is a recap from our KubeCon China 2021 talk. If you are interested in learning more about Argo or Akuity&#8217;s products and services, you can find all our past and upcoming conference talks on our website.</p><p><strong><a href="https://learnk8s.io/kubernetes-network-packets?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Tracing the path of network traffic in Kubernetes</a> &#8212; <a href="https://learnk8s.io/kubernetes-network-packets">learnk8s.io</a></strong> Learn how packets flow inside and outside a Kubernetes cluster. Starting from the initial web request and down to the container hosting the application</p><div id="youtube2-7l_n97Mt0ko" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;7l_n97Mt0ko&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/7l_n97Mt0ko?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://blog.rewanthtammana.com/cosign-with-kubernetes-ensure-integrity-of-images-before-deployment?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">CoSign with Kubernetes: Ensure integrity of images before deployment</a> &#8212; <a href="https://blog.rewanthtammana.com/cosign-with-kubernetes-ensure-integrity-of-images-before-deployment">blog.rewanthtammana.com</a></strong> Notary vs CoSign? Is CoSign a good alternative? Can we automate keys &amp; signature rotation?</p><p><strong><a href="https://www.jetstack.io/blog/k8s-1.24-intro/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Looking Ahead to Kubernetes 1.24 | Jetstack Blog</a> &#8212; <a href="https://www.jetstack.io/blog/k8s-1.24-intro/">www.jetstack.io</a></strong> Kubernetes 1.24 is scheduled for release on Tuesday 19th April 2022, but some of us are already deep in the planning and work for it.</p><p><strong><a href="https://blog.bradmccoy.io/how-to-pass-your-kcna-exam-cf98cfa7d70f?gi=1f6bbd80d94f&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How to Pass your KCNA Exam. The CNCF has just launched the new&#8230; | by Brad McCoy | Nov, 2021 | Medium</a> &#8212; <a href="https://blog.bradmccoy.io/how-to-pass-your-kcna-exam-cf98cfa7d70f?gi=1f6bbd80d94f">blog.bradmccoy.io</a></strong> The CNCF has just launched the new Kubernetes and Cloud Native Associate Exam also known as the KCNA. I was one of the first 400 people to go through the Beta exam which contained the full suite of&#8230;</p><p><strong><a href="https://dev.to/aws/aws-open-source-news-and-updates-95-m42?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AWS open source news and updates, #95 - DEV Community</a></strong> Jan 10th, 2022 - Instalment #95 Newsletter #95. Feliz Ano and a very happy new year to... Tagged with opensource, aws.</p><p><strong><a href="https://thenewstack.io/run-a-google-kubernetes-engine-cluster-for-under-25-month/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Run a Google Kubernetes Engine Cluster for Under $25/Month &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/run-a-google-kubernetes-engine-cluster-for-under-25-month/">thenewstack.io</a></strong> This article will demonstrate a solution (available on GitHub) for running a full-blown GKE cluster on Google Cloud with a goal to keep the costs under $1 per day.</p><p><strong><a href="https://blog.google/technology/safety-security/making-open-source-software-safer-and-more-secure/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Making Open Source software safer and more secure</a> &#8212; <a href="https://blog.google/technology/safety-security/making-open-source-software-safer-and-more-secure/">blog.google</a></strong> We welcomed the opportunity to participate in the White House Open Source Software Security Summit today.</p><p><strong><a href="https://medium.com/@nyrahul/kubernetes-threat-modeling-bf044745cf85?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Threat Modeling. Every security team has to deal with&#8230; | by Rahul Jadhav | Medium</a> &#8212; <a href="https://medium.com/@nyrahul/kubernetes-threat-modeling-bf044745cf85">medium.com</a></strong> Answering this is non-trivial, and involves understanding the threat vectors faced by the services. To understand threat vectors one needs an understanding of how the services works, what&#8230;</p><p><strong><a href="https://cal.com/blog/open-startup?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Open Startup | cal.com</a> &#8212; <a href="https://cal.com/blog/open-startup">cal.com</a></strong> The term "Open Startup" is not new, but still fairly niche. There are Open Startups with millions in revenue, yet only a tiny percentage of Startups today fall into the category.</p><h2>Assets</h2><p><strong><a href="https://github.com/kube-rs?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">kube-rs &#183; GitHub</a> &#8212; <a href="https://github.com/kube-rs">github.com</a></strong> rust kubernetes client and controller runtime. kube-rs has 6 repositories available. Follow their code on GitHub.</p><p><strong><a href="https://distrobox.privatedns.org/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Distrobox | Use any linux distribution inside your terminal</a></strong> Use any linux distribution inside your terminal</p><p><strong><a href="https://github.com/developer-guy/buildkit-machine?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - developer-guy/buildkit-machine: A proof-of-concept project that makes accessible buildkitd daemon from macOS</a> &#8212; <a href="https://github.com/developer-guy/buildkit-machine">github.com</a></strong> A proof-of-concept project that makes accessible buildkitd daemon from macOS - GitHub - developer-guy/buildkit-machine: A proof-of-concept project that makes accessible buildkitd daemon from macOS</p><p><strong><a href="https://github.com/coder?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Coder &#183; GitHub</a> &#8212; <a href="https://github.com/coder">github.com</a></strong> Developer workspaces on your infrastructure. Coder has 51 repositories available. Follow their code on GitHub.</p><p><strong><a href="https://www.nfsmith.ca/articles/step-cli/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Taking the bite out of x509 certificates with the step CLI</a></strong> Parsing, generating and troubleshooting certificates is critical skill in developing web services. Certificates establish trust on the web (e.g that indeed the company Google is serving you content when you go to www.google.com) and to encrypt traffic once trust is established using TLS.</p><p><strong><a href="https://github.com/ory/hydra?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - ory/hydra: OpenID Certified&#8482; OpenID Connect and OAuth Provider written in Go</a> &#8212; <a href="https://github.com/ory/hydra">github.com</a></strong> OpenID Certified&#8482; OpenID Connect and OAuth Provider written in Go - cloud native, security-first, open source API security for your infrastructure. SDKs for any language. Works with Hardware Security Modules. Compatible with MITREid. - GitHub - ory/hydra: OpenID Certified&#8482; OpenID Connect and OAuth Provider written in Go - cloud native, security-first, open source API security for your infrastructure. SDKs for any language. Works with Hardware Security Modules. Compatible with MITREid.</p><p><strong><a href="https://github.com/vladimirvivien/ktop?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - vladimirvivien/ktop: A top-like tool for your Kubernetes clusters</a> &#8212; <a href="https://github.com/vladimirvivien/ktop">github.com</a></strong> A top-like tool for your Kubernetes clusters. Contribute to vladimirvivien/ktop development by creating an account on GitHub.</p><p><strong><a href="https://learnk8s.io/kubernetes-instance-calculator?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes instance calculator</a> &#8212; <a href="https://learnk8s.io/kubernetes-instance-calculator">learnk8s.io</a></strong> Explore the best instance types for your Kubernetes cluster interactively.</p><p><strong><a href="https://3musketeers.io/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">3 Musketeers</a> &#8212; <a href="https://3musketeers.io/">3musketeers.io</a></strong> Test, build, and deploy your apps from anywhere, the same way!</p><p><strong><a href="https://github.com/nsmith5/rekor-sidekick?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - nsmith5/rekor-sidekick: &#128269; Rekor transparency log monitoring and alerting</a> &#8212; <a href="https://github.com/nsmith5/rekor-sidekick">github.com</a></strong> &#128269; Rekor transparency log monitoring and alerting. Contribute to nsmith5/rekor-sidekick development by creating an account on GitHub.</p><p><strong><a href="https://github.com/kubeshop/kusk?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - kubeshop/kusk: Kusk makes your OpenAPI definition the source of truth for API resources in your cluster</a> &#8212; <a href="https://github.com/kubeshop/kusk">github.com</a></strong> Kusk makes your OpenAPI definition the source of truth for API resources in your cluster - GitHub - kubeshop/kusk: Kusk makes your OpenAPI definition the source of truth for API resources in your cluster</p><p><strong><a href="https://github.com/jucardi/go-streams?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - jucardi/go-streams: Stream Collections for Go. Inspired in Java 8 Streams and .NET Linq</a> &#8212; <a href="https://github.com/jucardi/go-streams">github.com</a></strong> Stream Collections for Go. Inspired in Java 8 Streams and .NET Linq - GitHub - jucardi/go-streams: Stream Collections for Go. Inspired in Java 8 Streams and .NET Linq</p><p><strong><a href="https://snappify.io/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">snappify</a> &#8212; <a href="https://snappify.io/">snappify.io</a></strong> Snappify helps you to create beautiful code snippets with ease.</p><p><strong><a href="https://github.com/developer-guy/setup-krew?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - developer-guy/setup-krew: &#128230;&#128640; A GitHub Action to install &#128071; https://github.com/kubernetes-sigs/krew</a> &#8212; <a href="https://github.com/developer-guy/setup-krew">github.com</a></strong> &#128230;&#128640; A GitHub Action to install &#128071; https://github.com/kubernetes-sigs/krew - GitHub - developer-guy/setup-krew: &#128230;&#128640; A GitHub Action to install &#128071; https://github.com/kubernetes-sigs/krew</p><h2>Skills</h2><p><strong><a href="https://blog.chainguard.dev/cosign-image-signing-in-aws-codepipeline/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cosign Image Signing In AWS CodePipeline</a></strong> In this post we are going to show you how to integrate sigstore&#8217;s Cosign with AWS CodePipeline.</p><p><strong><a href="https://graystum.com/aws-ssm-do-you-really-need-ssh/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AWS SSM: Do you really need SSH? How to connect to EC2 using Session Manager</a> &#8212; <a href="https://graystum.com/aws-ssm-do-you-really-need-ssh/">graystum.com</a></strong> Do you really need SSH? Maybe not!</p><p><strong><a href="https://github.com/ossu/computer-science?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - ossu/computer-science: Path to a free self-taught education in Computer Science!</a> &#8212; <a href="https://github.com/ossu/computer-science">github.com</a></strong> :mortar_board: Path to a free self-taught education in Computer Science! - GitHub - ossu/computer-science: Path to a free self-taught education in Computer Science!</p><p><strong><a href="https://www.atomiccommits.io/everything-useful-i-know-about-kubectl?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Everything Useful I Know About kubectl</a></strong></p><p>I am a blogv</p><p><strong><a href="https://www.linkedin.com/pulse/i-took-20-linkedin-skill-assessments-so-you-dont-have-garrison?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">I Took 20 LinkedIn Skill Assessments So You Don't Have To</a> &#8212; <a href="https://www.linkedin.com/pulse/i-took-20-linkedin-skill-assessments-so-you-dont-have-garrison">www.linkedin.com</a></strong> I was updating my LinkedIn profile and saw a notification to take a skills assessment for Python. Sure, I know python, or so I thought.</p><p><strong><a href="https://fly.io/blog/api-tokens-a-tedious-survey/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">API Tokens: A Tedious Survey &#183; Fly</a> &#8212; <a href="https://fly.io/blog/api-tokens-a-tedious-survey/">fly.io</a></strong> News, tips, and tricks from the team at Fly</p><p><strong><a href="https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Configure Liveness, Readiness and Startup Probes | Kubernetes</a> &#8212; <a href="https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/">kubernetes.io</a></strong> This page shows how to configure liveness, readiness and startup probes for containers. The kubelet uses liveness probes to know when to restart a container. For example, liveness probes could catch a deadlock, where an application is running, but unable to make progress. Restarting a container in such a state can help to make the application more available despite bugs. The kubelet uses readiness probes to know when a container is ready to start accepting traffic.</p>]]></content:encoded></item><item><title><![CDATA[Newsletter of Carlos Santana - Issue #22]]></title><description><![CDATA[Happy New Year &#127870;&#127882;!!!    This newsletter issue comes packed with all resources from the last three weeks. I took a break and I hope you too.    I wish you an excellent start on all your 2022 goals.I have been more active on Twitter lately; if you are not already, please&#160; follow me on Twitter PS: I want to share the news that &#160;I got accepted as a shadow for the Kubernetes v1.24 Release Team &#127881;]]></description><link>https://news.santana.dev/p/newsletter-of-carlos-santana-issue-22-943420</link><guid isPermaLink="false">https://news.santana.dev/p/newsletter-of-carlos-santana-issue-22-943420</guid><dc:creator><![CDATA[Carlos Santana]]></dc:creator><pubDate>Sun, 09 Jan 2022 13:00:02 GMT</pubDate><enclosure url="https://s3.amazonaws.com/revue/profiles/images/000/192/965/thumb/31661FED-509E-4054-996C-381C578A9D33.jpeg?1670077659" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Happy New Year &#127870;&#127882;!!!</p><p>This newsletter issue comes packed with all resources from the last three weeks. I took a break and I hope you too.</p><p>I wish you an excellent start on all your 2022 goals.</p><p>I have been more active on Twitter lately; if you are not already, please&nbsp; <a href="https://twitter.com/csantanapr">follow me on Twitter</a></p><p>PS: I want to share the news that <a href="https://github.com/kubernetes/sig-release/blob/master/releases/release-1.24/release-team.md">&nbsp;I got accepted as a shadow for the Kubernetes v1.24 Release Team</a> &#127881;</p><div><hr></div><h2>News</h2><p><strong><a href="https://www.infoworld.com/article/3646231/2022-the-year-of-software-supply-chain-security.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">2022: The year of software supply chain security | InfoWorld</a> &#8212; <a href="https://www.infoworld.com/article/3646231/2022-the-year-of-software-supply-chain-security.html">www.infoworld.com</a></strong> Strengthening the software supply chain must be priority No. 1 in the new year. Here are three areas to focus on.</p><p><strong><a href="https://developers.redhat.com/articles/2021/12/16/secure-your-kubernetes-deployments-ebpf?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Secure your Kubernetes deployments with eBPF | Red Hat Developer</a> &#8212; <a href="https://developers.redhat.com/articles/2021/12/16/secure-your-kubernetes-deployments-ebpf">developers.redhat.com</a></strong> Learn how to use eBPF and the Security Profiles Operator to automatically generate seccomp profiles, a Linux kernel security feature for Kubernetes.</p><p><strong><a href="https://www.santana.dev/blog/skaffold-book?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Skaffold book review</a> &#8212; <a href="https://www.santana.dev/blog/skaffold-book">www.santana.dev</a></strong> Skaffold book review, Effortless Cloud-Native App Development Using Skaffold.</p><p><strong><a href="https://www.solo.io/blog/solo-announces-bumblebee/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">&#8203;&#8203;BumbleBee: Build, Ship, Run eBPF tools - Solo.io</a> &#8212; <a href="https://www.solo.io/blog/solo-announces-bumblebee/">www.solo.io</a></strong> Today we are thrilled to announce BumbleBee, an open-source project focused on simplifying the user experience around building eBPF tools. BumbleBee helps</p><p><strong><a href="https://medium.com/trendyol-tech/manage-kubernetes-admission-webhooks-certificates-with-cert-manager-ca-injector-and-vault-pki-281b065e1044?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Manage Kubernetes Admission Webhook's certificates with cert-manager CA Injector and Vault PKI</a> &#8212; <a href="https://medium.com/trendyol-tech/manage-kubernetes-admission-webhooks-certificates-with-cert-manager-ca-injector-and-vault-pki-281b065e1044">medium.com</a></strong> &#183; &#9973;&#65039; Kubernetes Admission Controllers &#183; &#128221; cert-manager and CA Injector &#183; &#128272; Vault PKI (Public Key Infrastructure) &#183; &#128187; Installation &#183; &#128064; How to monitor certificates? &#183; &#10024; How to accomplish&#8230;</p><p><a href="https://docs.google.com/spreadsheets/d/17nKMpi_Dh5slCqzLSFBoWMxNvWiwt2R-t4e_l7LPLhU/htmlview">COSSI: $100M+ Revenue Commercial Open-Source Software (COSS) Company Index</a></p><p><strong><a href="https://grafana.com/blog/2022/01/03/introducing-grafana-university-our-virtual-hands-on-education-platform-thats-free-and-easy-to-use/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introducing Grafana University: our virtual hands-on education platform that's free and easy to use | Grafana Labs</a> &#8212; <a href="https://grafana.com/blog/2022/01/03/introducing-grafana-university-our-virtual-hands-on-education-platform-thats-free-and-easy-to-use/">grafana.com</a></strong> Get realistic, hands-on experience with Grafana technologies and products with free online classes that can be consumed anytime and anywhere.</p><p><strong><a href="https://venturebeat.com/2021/12/27/kubernetes-security-will-have-a-breakout-year-in-2022/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes security will have a breakout year in 2022 | VentureBeat</a> &#8212; <a href="https://venturebeat.com/2021/12/27/kubernetes-security-will-have-a-breakout-year-in-2022/">venturebeat.com</a></strong> Kubernetes security will take another big leap in 2022, as companies focus on cloud-native, container-based approaches to app development.</p><p><strong><a href="https://thenewstack.io/gitops-on-kubernetes-deciding-between-argo-cd-and-flux?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitOps on Kubernetes: Deciding Between Argo CD and Flux &#8211; The New Stack</a> &#8212; <a href="https://thenewstack.io/gitops-on-kubernetes-deciding-between-argo-cd-and-flux">thenewstack.io</a></strong> There are many ways to build out application CI/CD pipelines in Kubernetes, but in this article we are going to focus on Flux and Argo CD.</p><p><strong><a href="https://edgeandnode.com/blog/defining-the-web3-stack?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Defining the web3 stack</a> &#8212; <a href="https://edgeandnode.com/blog/defining-the-web3-stack">edgeandnode.com</a></strong> Want to build on web3? Nader Dabit identifies the building blocks of the web3 technology stack in an introductory guide.</p><p><strong><a href="https://isovalent.com/blog/post/2021-12-08-ebpf-servicemesh?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How eBPF will solve Service Mesh - Goodbye Sidecars</a> &#8212; <a href="https://isovalent.com/blog/post/2021-12-08-ebpf-servicemesh">isovalent.com</a></strong> eBPF Service Mesh - How we can build an eBPF-based service mesh in the kernel to replace the complex sidecar model</p><p><strong><a href="https://www.armosec.io/blog/kubernetes-security-frameworks-and-guidance/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Comparing Kubernetes Security Frameworks and Guidance | ARMO</a> &#8212; <a href="https://www.armosec.io/blog/kubernetes-security-frameworks-and-guidance/">www.armosec.io</a></strong> Comparing popular Kubernetes security and compliance frameworks, how they differ, when to use, common goals, and suggested tools</p><p><strong><a href="https://www.cloudnative.quest/posts/security/2022/01/01/improve-supply-chain-security-with-github-actions-and-open-source-tools/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Improve supply chain security with GitHub actions, Cosign, Kyverno and other open source tools</a></strong> This article discusses about improving supply chain security of containers and kuberentes using GitHub actions, Cosign, Kyverno and other open source tools</p><p><strong><a href="https://o11y.engineering/the-state-of-continuous-profiling-b89cdbdd47f6?gi=e8c04aa47121&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">On The State Of Continuous Profiling | by Michael Hausenblas | Dec, 2021 | Medium</a> &#8212; <a href="https://o11y.engineering/the-state-of-continuous-profiling-b89cdbdd47f6?gi=e8c04aa47121">o11y.engineering</a></strong> Continuous profiling background and open source offerings: Parca, Pixie, and Pyroscope.</p><p><strong><a href="https://www.philvenables.com/post/cybersecurity-and-the-curse-of-binary-thinking?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cybersecurity and the Curse of Binary Thinking</a></strong></p><p>Working in information/cybersecurity and technology risk is a fascinating and challenging career, as I&#8217;ve covered here. There is, mostly, a great spirit of sharing and collaboration among security professionals. However, I&#8217;ve observed one disturbing and growing trend in the past few years that might be characterized as a curse of binary thinking. By this I mean the assertion that if something isn&#8217;t perfect then it must be terrible&#8230;</p><p><strong><a href="https://www.pulumi.com/blog/kubernetes-sdks-pulumiverse/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes SDKs from the Pulumiverse | Pulumi Blog</a> &#8212; <a href="https://www.pulumi.com/blog/kubernetes-sdks-pulumiverse/">www.pulumi.com</a></strong> In this article, we look at a new repository published on the Pulumiverse that delivers rich Kubernetes SDKs for popular CRDs.</p><p><strong><a href="https://shopify.engineering/voucher-docker-images?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Vouching for Docker Images &#8212; Security</a> &#8212; <a href="https://shopify.engineering/voucher-docker-images">shopify.engineering</a></strong> If you were using computers in the &#8216;90s and the early 2000s, you probably had the experience of installing a piece of software you downloaded from the internet, only to discover that someone put some nasty into it, and now you&#8217;re dragging your computer to IT to beg them to save your data. To remedy this, software...</p><p><strong><a href="https://iximiuz.com/en/posts/container-networking-is-simple/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Container Networking Is Simple!</a> &#8212; <a href="https://iximiuz.com/en/posts/container-networking-is-simple/">iximiuz.com</a></strong> How container networking works under the hood? Setting up docker-like container networking from scratch. Bonus: podman rootless container networking explained.</p><p><strong><a href="https://www.slim.ai/blog/why-dockerslim-users-should-try-slim-saas.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">What DockerSlim Users Get Out of Slim's SaaS Platform | Slim.AI</a> &#8212; <a href="https://www.slim.ai/blog/why-dockerslim-users-should-try-slim-saas.html">www.slim.ai</a></strong> Anyone using DockerSlim understands the value of container minificaiton. What they might not appreciate is the additional value of using DockerSlim within the broader feature set and support functions of the Slim.AI SaaS offering.</p><p><strong><a href="https://danielmangum.com/posts/controller-runtime-client-go-rate-limiting/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Rate Limiting in controller-runtime and client-go &#183; Daniel Mangum</a> &#8212; <a href="https://danielmangum.com/posts/controller-runtime-client-go-rate-limiting/">danielmangum.com</a></strong> Daniel Mangum's personal website</p><p><strong><a href="https://www.jetstack.io/blog/cert-manager-gateway-api-traefik-guide/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Getting started using cert-manager with the sig-network Gateway API | Jetstack Blog</a></strong> The Gateway API, introduced by the sig-network community, is a new API that aims at replacing the Ingress API. In this guide, we will walk through the installation of cert-manager, ExternalDNS and Traefik to deploy a simple service using the Gateway API.</p><p><strong><a href="https://www.miketheman.net/2021/12/28/container-to-container-communication/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Container-to-Container Communication &#8211; Mike's House</a> &#8212; <a href="https://www.miketheman.net/2021/12/28/container-to-container-communication/">www.miketheman.net</a></strong> In a containerized world, is there a material difference between communicating over local network TCP vs local Unix domain sockets?</p><p><strong><a href="https://appleinsider.com/articles/21/12/28/apple-offering-180000-bonuses-to-engineers-to-prevent-poaching?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Apple offering engineers $180,000 bonuses to prevent poaching | AppleInsider</a> &#8212; <a href="https://appleinsider.com/articles/21/12/28/apple-offering-180000-bonuses-to-engineers-to-prevent-poaching">appleinsider.com</a></strong> Apple's top engineering talents are being offered significant stock bonuses worth up to $180,000 to prevent defection to Meta and others.</p><p><strong><a href="https://dlorenc.medium.com/a-bit-of-ambiance-comes-to-sigstore-f80d1d6b1c30?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">A Bit of Ambiance comes to Sigstore | by Dan Lorenc | Medium</a> &#8212; <a href="https://dlorenc.medium.com/a-bit-of-ambiance-comes-to-sigstore-f80d1d6b1c30">dlorenc.medium.com</a></strong> Zero-trust security starts with trusting actual entities based on strong identity, not whoever happens to control a secret, or whoever gets behind a firewall. No secrets sounds great in theory! It&#8230;</p><p><strong><a href="https://opensource.googleblog.com/2020/08/new-case-studies-about-googles-use-of-go.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">New Case Studies About Google&#8217;s Use of Go | Google Open Source Blog</a> &#8212; <a href="https://opensource.googleblog.com/2020/08/new-case-studies-about-googles-use-of-go.html">opensource.googleblog.com</a></strong> Go turned out to have a much broader reach than expected. Its growth in the industry has been phenomenal, and it has powered many Google projects.</p><p><strong><a href="https://blog.wiz.io/82-of-companies-unknowingly-give-3rd-parties-access-to-all-their-cloud-data/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">82% of companies unknowingly give 3rd parties access to all their cloud data</a> &#8212; <a href="https://blog.wiz.io/82-of-companies-unknowingly-give-3rd-parties-access-to-all-their-cloud-data/">blog.wiz.io</a></strong> Cloud identity permissions are complex. So complex that innocent looking permissions provided to 3rd party vendors can lead to unintended exposure of all of your data.</p><p><strong><a href="https://zaccharles.medium.com/looking-at-lambdashell-com-after-3-years-f86b87ba2e47?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Looking at LambdaShell.com after 3+ years | by Zac Charles | Dec, 2021 | Medium</a> &#8212; <a href="https://zaccharles.medium.com/looking-at-lambdashell-com-after-3-years-f86b87ba2e47">zaccharles.medium.com</a></strong> Since 2018, lambdashell.com has challenged visitors to do their worst. In this post, I take a look at what is possible 3+ years on (a lot).</p><p><strong><a href="https://www.kloia.com/blog/karpenter-cluster-autoscaler?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Karpenter Cluster Autoscaler</a></strong> There are 3 main options for autoscaling in Kubernetes clusters. HPA (Horizontal Pod Autoscaling), VPA (Vertical Pod Autoscaling) and Cluster Autoscaling.</p><p><strong><a href="https://www.qovery.com/blog/announcement-of-pleco-the-open-source-kubernetes-and-cloud-services-garbage-collector/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Announcement: Pleco - the open-source Kubernetes and Cloud Services garbage collector</a> &#8212; <a href="https://www.qovery.com/blog/announcement-of-pleco-the-open-source-kubernetes-and-cloud-services-garbage-collector/">www.qovery.com</a></strong> Pleco is a service that automatically removes Cloud managed services and Kubernetes resources based on tags with TTL. We are proud to offer this tool that save tons of time and money to our R&amp;D team.</p><p><strong><a href="https://db.cs.cmu.edu/seminar2021-dose2/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Vaccination Database Talks (Second Dose) &#8211; Fall 2021</a> &#8212; <a href="https://db.cs.cmu.edu/seminar2021-dose2/">db.cs.cmu.edu</a></strong> Vaccination Database Tech Talks - 2021Second Dose - Fall 2021There are some things in life that are just better when you have more of it. Fresh orange</p><p><strong><a href="https://www.siderolabs.com/blog/talos-v0-14-is-live/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Talos v0.14 is live! - Sidero Labs</a> &#8212; <a href="https://www.siderolabs.com/blog/talos-v0-14-is-live/">www.siderolabs.com</a></strong> This release of Talos accumulates a lot of changes resulting in an improved user experience. It brings more knobs and switches to play with so that you can dial in exactly what you need. Getting Ready for Something Awesome If you run Kubernetes on bare metal you need Sidero Metal. It is the simplest, yet [&#8230;]</p><p><strong><a href="https://www.suse.com/c/harvester-ga-announcement/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Harvester is&nbsp;now production-ready and&nbsp;generally available&nbsp;&nbsp; | SUSE Communities</a> &#8212; <a href="https://www.suse.com/c/harvester-ga-announcement/">www.suse.com</a></strong> Harvester is now production-ready and generally available. Learn more about SUSE's newest product Harvester, the open, interoperable hyper-converged infrastructure (HCI) solution built on modern, cloud-native solutions.</p><p><strong><a href="https://containerjournal.com/editorial-calendar/best-of-2021/kubernetes-enables-devops-as-a-service-daas/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Best of 2021 - Kubernetes Enables DevOps-as-a-Service (DaaS) - Container Journal</a> &#8212; <a href="https://containerjournal.com/editorial-calendar/best-of-2021/kubernetes-enables-devops-as-a-service-daas/">containerjournal.com</a></strong> DevOps-as-a-Service (DaaS) and Kubernetes alone provide many valuable capabilities, and greater benefits when deployed together.</p><p><strong><a href="https://devops.com/measuring-the-value-of-devops-as-a-service-daas/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Measuring the Value of DevOps-as-a-Service (DaaS) - DevOps.com</a> &#8212; <a href="https://devops.com/measuring-the-value-of-devops-as-a-service-daas/">devops.com</a></strong> DaaS delivers benefits for business, app-dev users and DaaS teams. Here's how to accurately gather data, set SLOs/SLIs and measure value.</p><p><strong><a href="https://kubernetes.io/blog/2021/12/21/admission-controllers-for-container-drift/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Using Admission Controllers to Detect Container Drift at Runtime | Kubernetes</a> &#8212; <a href="https://kubernetes.io/blog/2021/12/21/admission-controllers-for-container-drift/">kubernetes.io</a></strong> Author: Saifuding Diliyaer (Box) Illustration by Munire Aireti At Box, we use Kubernetes (K8s) to manage hundreds of micro-services that enable Box to stream data at a petabyte scale. When it comes to the deployment process, we run kube-applier as part of the GitOps workflows with declarative configuration and automated deployment. Developers declare their K8s apps manifest into a Git repository that requires code reviews and automatic checks to pass, before any changes can get merged and applied inside our K8s clusters.</p><p><strong><a href="https://falco.org/blog/sysflow-falco-sidekick/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Cloud-Native Observability and Security Analytics with SysFlow and Falco | Falco</a></strong> Hello, fellow Falcoers! This blog introduces you to a new open system telemetry format and project called SysFlow. The project has deep ties to Falco, the de facto CNCF cloud-native runtime security project. Falco is exceptional at detecting unexpected application behavior and alerting on threats at runtime. Furthermore, its components and architecture open itself to creative uses. For example, SysFlow embeds Falco's rich observability libraries into its cloud-native security telemetry stack and Falco's rules language to achieve data abstraction, behavioral analytics, and noise reduction.</p><p><strong><a href="https://blog.twitter.com/engineering/en_us/topics/infrastructure/2021/how-we-built-twitter-s-highly-reliable-ads-pacing-service?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How we built Twitter&#8217;s highly reliable ads pacing service</a> &#8212; <a href="https://blog.twitter.com/engineering/en_us/topics/infrastructure/2021/how-we-built-twitter-s-highly-reliable-ads-pacing-service">blog.twitter.com</a></strong> In this blog, we describe how we separate Twitter&#8217;s pacing system from the serving stack to an independent service.</p><p><strong><a href="https://iximiuz.com/en/posts/containers-101-attach-vs-exec/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Containers 101: attach vs. exec - what's the difference?</a> &#8212; <a href="https://iximiuz.com/en/posts/containers-101-attach-vs-exec/">iximiuz.com</a></strong> Understanding the difference between attach, logs, run, and exec commands through learning the container management internals.</p><p><strong><a href="https://www.infracloud.io/blogs/multi-tenancy-kubernetes/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Introduction to Multi-Tenancy in Kubernetes</a> &#8212; <a href="https://www.infracloud.io/blogs/multi-tenancy-kubernetes/">www.infracloud.io</a></strong> This blog post discusses the various type of solutions to implement multi-tenancy in Kubernetes. Multi-tenancy helps to share the same infrastructure with different set of users.</p><p><strong><a href="https://www.technologyreview.com/2021/12/17/1042692/log4j-internet-open-source-hacking?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The internet runs on free open-source software. Who pays to fix it? | MIT Technology Review</a> &#8212; <a href="https://www.technologyreview.com/2021/12/17/1042692/log4j-internet-open-source-hacking">www.technologyreview.com</a></strong> Volunteer-run projects like Log4J keep the internet running. The result is unsustainable burnout, and a national security risk when they go wrong.</p><p><strong><a href="https://openssf.org/blog/2021/12/16/open-source-foundations-must-work-together-to-prevent-the-next-log4shell-scramble/?hss_channel=fbp-41911143546&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Open Source Foundations Must Work Together to Prevent the Next Log4Shell Scramble - Open Source Security Foundation</a></strong> As someone who has spent their entire career in open source software (OSS), the Log4Shell scramble (an industry-wide four-alarm-fire to address a serious vulnerability in the Apache Log4j package) is...</p><p><a href="https://www.linkedin.com/posts/rddill_architecture-devops-activity-6876971839998971904-1d3D">Is technology&nbsp;architecture still relevant with CI/CD devops?</a></p><p><strong><a href="https://sourcepatch.blogspot.com/2021/12/the-art-and-science-of-probing.html?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Source Patch: The art and science of probing a Kubernetes container</a> &#8212; <a href="https://sourcepatch.blogspot.com/2021/12/the-art-and-science-of-probing.html">sourcepatch.blogspot.com</a></strong> Keeping containers alive in a Kubernetes cluster can feel more like art than science. In this article, I dive into the sea of madness awaiti...</p><p><strong><a href="https://www.ibm.com/blogs/blockchain/2020/08/how-blockchain-adds-trust-to-ai-and-iot/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">How blockchain adds trust to AI and IoT IBM Supply Chain and Blockchain Blog</a> &#8212; <a href="https://www.ibm.com/blogs/blockchain/2020/08/how-blockchain-adds-trust-to-ai-and-iot/">www.ibm.com</a></strong> Find out how blockchain stands to accelerate the adoption of emerging technologies including AI, Cloud, and IoT by bringing in the missing element of trust.</p><p><strong><a href="https://anchore.com/sbom/sbom-management-and-six-ways-it-prevents-sbom-sprawl?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Understanding SBOM Management and The Six Ways It Prevents SBOM Sprawl</a> &#8212; <a href="https://anchore.com/sbom/sbom-management-and-six-ways-it-prevents-sbom-sprawl">anchore.com</a></strong> Learn why SBOM management is critical to secure the software supply and the six ways it prevents SBOM sprawl.</p><p><strong><a href="https://dev.to/aws/aws-open-source-news-and-updates-94-3o90?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AWS open source news and updates #94 - DEV Community</a></strong> December 20th, 2021 - Instalment #94 Newsletter #94. This will be the last newsletter ... Tagged with opensource, aws.</p><p><strong><a href="https://github.com/alicebob/miniredis?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - alicebob/miniredis: Pure Go Redis server for Go unittests</a> &#8212; <a href="https://github.com/alicebob/miniredis">github.com</a></strong> Pure Go Redis server for Go unittests. Contribute to alicebob/miniredis development by creating an account on GitHub.</p><p><strong><a href="https://blog.aspect.dev/bzlmod?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">.css-1b9oi20{display:block;width:8rem;}@media (min-width: 768px){.css-1b9oi20{width:16rem;}}.css-1082qq3{display:block;width:100%;}</a> &#8212; <a href="https://blog.aspect.dev/bzlmod">blog.aspect.dev</a></strong> Bazel packages (called "modules") have historically been distributed with a long "WORKSPACE snippet", which required users to install and configure the module and also its dependencies. This caused a lot of headache for users, since the first declara...</p><p><strong><a href="http://danluu.com/cgroup-throttling/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The container throttling problem</a> &#8212; <a href="http://danluu.com/cgroup-throttling/">danluu.com</a></strong> This is an excerpt from an internal document David Mackey and I co-authored in April 2019. The document is excerpted since much of the original doc was about comparing possible approaches to increasing efficency at Twitter, which is mostly information that's meaningless outside of Twitter without a large amount of additional explanation/context.</p><p><strong><a href="https://www.ibm.com/cloud/blog/multizone-kubernetes-and-vpc-load-balancer-setup?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Multizone Kubernetes and VPC Load Balancer Setup | IBM</a> &#8212; <a href="https://www.ibm.com/cloud/blog/multizone-kubernetes-and-vpc-load-balancer-setup">www.ibm.com</a></strong> Securely expose your Kubernetes app by setting up a Load Balancer for VPC in a different zone.</p><p><strong><a href="https://blog.gitguardian.com/kubernetes-tutorial-part-1-pods/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Kubernetes Security Tutorial: Pods (Part 1)</a> &#8212; <a href="https://blog.gitguardian.com/kubernetes-tutorial-part-1-pods/">blog.gitguardian.com</a></strong> Get a deeper understanding of Kubernetes Pods security with this hands-on tutorial.</p><h2>Assets</h2><p><strong><a href="https://github.com/armosec/kubescape?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - armosec/kubescape:</a> &#8212; <a href="https://github.com/armosec/kubescape">github.com</a></strong></p><p>Kubescape is the first open-source tool for testing if Kubernetes is deployed securely according to multiple frameworks: regulatory, customized company policies and DevSecOps best practices, such as the NSA-CISA and the MITRE ATT&amp;CK&#174;.</p><p><strong><a href="https://github.com/suborbital?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Suborbital &#183; GitHub</a> &#8212; <a href="https://github.com/suborbital">github.com</a></strong> Rocket-fueled open source platform tools. Suborbital has 20 repositories available. Follow their code on GitHub.</p><p><strong><a href="https://github.com/iximiuz/client-go-examples?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - iximiuz/client-go-examples: Collection of mini-programs demonstrating Kubernetes client-go usage.</a> &#8212; <a href="https://github.com/iximiuz/client-go-examples">github.com</a></strong></p><p>Collection of mini-programs demonstrating Kubernetes client-go usage.</p><p><strong><a href="https://github.com/drakkan/sftpgo?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - drakkan/sftpgo</a> &#8212; <a href="https://github.com/drakkan/sftpgo">github.com</a></strong> Fully featured and highly configurable SFTP server with optional HTTP, FTP/S and WebDAV support - S3, Google Cloud Storage, Azure Blob - GitHub - drakkan/sftpgo: Fully featured and highly configurable SFTP server with optional HTTP, FTP/S and WebDAV support - S3, Google Cloud Storage, Azure Blob</p><p><strong><a href="https://github.com/up9inc/mizu?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - up9inc/mizu</a> &#8212; <a href="https://github.com/up9inc/mizu">github.com</a></strong> API traffic viewer for Kubernetes enabling you to view all API communication between microservices. Think TCPDump and Wireshark re-invented for Kubernetes - GitHub - up9inc/mizu: API traffic viewer for Kubernetes enabling you to view all API communication between microservices. Think TCPDump and Wireshark re-invented for Kubernetes</p><p><strong><a href="https://github.com/plausible/analytics?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - plausible/analytics</a> &#8212; <a href="https://github.com/plausible/analytics">github.com</a></strong> Simple, open-source, lightweight (&lt; 1 KB) and privacy-friendly web analytics alternative to Google Analytics. - GitHub - plausible/analytics: Simple, open-source, lightweight (&lt; 1 KB) and privacy-friendly web analytics alternative to Google Analytics.</p><p><strong><a href="https://github.com/castrojo/awesome-immutable?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - castrojo/awesome-immutable</a> &#8212; <a href="https://github.com/castrojo/awesome-immutable">github.com</a></strong> A list of resources for people who want to investigate image-based Linux desktops - GitHub - castrojo/awesome-immutable: A list of resources for people who want to investigate image-based Linux desktops</p><p><strong><a href="https://github.com/vitejs/vite?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - vitejs/vite</a> &#8212; <a href="https://github.com/vitejs/vite">github.com</a></strong> Next generation frontend tooling. It's fast! Contribute to vitejs/vite development by creating an account on GitHub.</p><p><strong><a href="https://github.com/coinbase/salus?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - coinbase/salus</a> &#8212; <a href="https://github.com/coinbase/salus">github.com</a></strong> Security scanner coordinator. Contribute to coinbase/salus development by creating an account on GitHub.</p><p><strong><a href="https://github.com/dirien/infrastructure-as-code-workshop?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - dirien/infrastructure-as-code-workshop: Infrastructure as Code Workshop</a> &#8212; <a href="https://github.com/dirien/infrastructure-as-code-workshop">github.com</a></strong> Infrastructure as Code Workshop. Contribute to dirien/infrastructure-as-code-workshop development by creating an account on GitHub.</p><p><strong><a href="https://github.com/GoogleCloudPlatform/terraformer?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - GoogleCloudPlatform/terraformer</a> &#8212; <a href="https://github.com/GoogleCloudPlatform/terraformer">github.com</a></strong> CLI tool to generate terraform files from existing infrastructure (reverse Terraform). Infrastructure to Code - GitHub - GoogleCloudPlatform/terraformer: CLI tool to generate terraform files from existing infrastructure (reverse Terraform). Infrastructure to Code</p><p><strong><a href="https://www.baeldung.com/jbang-guide?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Guide to JBang | Baeldung</a> &#8212; <a href="https://www.baeldung.com/jbang-guide">www.baeldung.com</a></strong> Learn how to create, edit and run self-contained source-only or binary Java programs with ease using JBang.</p><p><strong><a href="https://github.com/google/log4jscanner?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - google/log4jscanner</a> &#8212; <a href="https://github.com/google/log4jscanner">github.com</a></strong> A log4j vulnerability filesystem scanner and Go package for analyzing JAR files. - GitHub - google/log4jscanner: A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.</p><p><strong><a href="https://github.com/FrancescoXX/100-days-of-Web3?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - FrancescoXX/100-days-of-Web3</a> &#8212; <a href="https://github.com/FrancescoXX/100-days-of-Web3">github.com</a></strong> This is a list of the content I shared about Web3 for the upcoming 100 days - GitHub - FrancescoXX/100-days-of-Web3: This is a list of the content I shared about Web3 for the upcoming 100 days</p><p><strong><a href="https://kustomizer.dev/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">kustomizer</a> &#8212; <a href="https://kustomizer.dev/">kustomizer.dev</a></strong> An experimental package manager for distributing Kubernetes configuration as OCI artifacts.</p><p><strong><a href="https://github.com/ogham/dog?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - ogham/dog: A command-line DNS client.</a> &#8212; <a href="https://github.com/ogham/dog">github.com</a></strong> A command-line DNS client. Contribute to ogham/dog development by creating an account on GitHub.</p><p><strong><a href="https://github.com/boldandbusted/vagrant-kind?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - boldandbusted/vagrant-kind</a> &#8212; <a href="https://github.com/boldandbusted/vagrant-kind">github.com</a></strong> Use Vagrant's 'ansible_local' provisioner to set up KinD (https://kind.sigs.k8s.io/) - GitHub - boldandbusted/vagrant-kind: Use Vagrant's 'ansible_local' provisioner to set up KinD (https://kind.sigs.k8s.io/)</p><p><strong><a href="https://rapidapi.com/hub?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">API Hub - Free Public &amp; Open Rest APIs | RapidAPI</a> &#8212; <a href="https://rapidapi.com/hub">rapidapi.com</a></strong> Browse, Test &amp; Connect to 1000s of Public Rest APIs on RapidAPI's API Hub - the world's largest API directory. Sign up today for Free!</p><p><strong><a href="https://github.com/thanos-io/kube-thanos?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - thanos-io/kube-thanos</a> &#8212; <a href="https://github.com/thanos-io/kube-thanos">github.com</a></strong> Kubernetes specific configuration for deploying Thanos. - GitHub - thanos-io/kube-thanos: Kubernetes specific configuration for deploying Thanos.</p><p><strong><a href="https://github.com/duiker101/twitter-interaction-circles?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - duiker101/twitter-interaction-circles</a> &#8212; <a href="https://github.com/duiker101/twitter-interaction-circles">github.com</a></strong> A guide project on how to make interaction circles for Twitter - GitHub - duiker101/twitter-interaction-circles: A guide project on how to make interaction circles for Twitter</p><p><strong><a href="https://github.com/faressoft/terminalizer?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - faressoft/terminalizer</a> &#8212; <a href="https://github.com/faressoft/terminalizer">github.com</a></strong> &#129412; Record your terminal and generate animated gif images or share a web player - GitHub - faressoft/terminalizer: &#129412; Record your terminal and generate animated gif images or share a web player</p><p><strong><a href="https://github.com/goreleaser/supply-chain-example?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - goreleaser/supply-chain-example</a> &#8212; <a href="https://github.com/goreleaser/supply-chain-example">github.com</a></strong> Example goreleaser + github actions config with keyless signing and SBOM generation - GitHub - goreleaser/supply-chain-example: Example goreleaser + github actions config with keyless signing and SBOM generation</p><p><strong><a href="https://github.com/anchore/syft?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - anchore/syft</a> &#8212; <a href="https://github.com/anchore/syft">github.com</a></strong> CLI tool and library for generating a Software Bill of Materials from container images and filesystems - GitHub - anchore/syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems</p><p><strong><a href="https://github.com/codeboten/practical-otel?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - codeboten/practical-otel: Practical OpenTelemetry</a> &#8212; <a href="https://github.com/codeboten/practical-otel">github.com</a></strong> Practical OpenTelemetry. Contribute to codeboten/practical-otel development by creating an account on GitHub.</p><p><strong><a href="https://github.com/svenstaro/genact?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - svenstaro/genact: &#127744; A nonsense activity generator</a> &#8212; <a href="https://github.com/svenstaro/genact">github.com</a></strong> &#127744; A nonsense activity generator. Contribute to svenstaro/genact development by creating an account on GitHub.</p><p><strong><a href="https://github.com/cue-lang/cue?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - cue-lang/cue: The new home of the CUE language! Validate and define text-based and dynamic configuration</a> &#8212; <a href="https://github.com/cue-lang/cue">github.com</a></strong> The new home of the CUE language! Validate and define text-based and dynamic configuration - GitHub - cue-lang/cue: The new home of the CUE language! Validate and define text-based and dynamic configuration</p><p><strong><a href="https://github.com/bloomrpc/bloomrpc?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - bloomrpc/bloomrpc: GUI Client for GRPC Services</a> &#8212; <a href="https://github.com/bloomrpc/bloomrpc">github.com</a></strong> GUI Client for GRPC Services. Contribute to bloomrpc/bloomrpc development by creating an account on GitHub.</p><p><strong><a href="https://gist.github.com/developer-guy/4a732a1fe4f7f32a7eb70e63fbc3d026?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Experimental Keyless Cosign verify-blob command to verify signature that is exported by the skopeo tool to the directory &#183; GitHub</a> &#8212; <a href="https://gist.github.com/developer-guy/4a732a1fe4f7f32a7eb70e63fbc3d026">gist.github.com</a></strong> Experimental Keyless Cosign verify-blob command to verify signature that is exported by the skopeo tool to the directory - demo.md</p><p><strong><a href="https://github.com/sogos/cdk-eks-full-featured?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - sogos/cdk-eks-full-featured</a> &#8212; <a href="https://github.com/sogos/cdk-eks-full-featured">github.com</a></strong> Contribute to sogos/cdk-eks-full-featured development by creating an account on GitHub.</p><p><strong><a href="https://github.com/wagoodman/dive?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - wagoodman/dive: A tool for exploring each layer in a docker image</a> &#8212; <a href="https://github.com/wagoodman/dive">github.com</a></strong> A tool for exploring each layer in a docker image. Contribute to wagoodman/dive development by creating an account on GitHub.</p><p><strong><a href="https://github.com/crossplane/crossplane/blob/master/design/design-doc-external-secret-stores.md?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">crossplane/design-doc-external-secret-stores.md at master &#183; crossplane/crossplane &#183; GitHub</a> &#8212; <a href="https://github.com/crossplane/crossplane/blob/master/design/design-doc-external-secret-stores.md">github.com</a></strong> Your Universal Control Plane. Contribute to crossplane/crossplane development by creating an account on GitHub.</p><p><strong><a href="https://github.com/cpuguy83/containerd-shim-systemd-v1?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - cpuguy83/containerd-shim-systemd-v1</a> &#8212; <a href="https://github.com/cpuguy83/containerd-shim-systemd-v1">github.com</a></strong></p><p>This project aims to provide a containerd shim implementation which uses systemd to manage containers.</p><h2>Skills</h2><p><strong><a href="https://github.com/moabukar/KCNA-Kubernetes-and-Cloud-Native-Associate?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">GitHub - moabukar/KCNA-Kubernetes-and-Cloud-Native-Associate</a> &#8212; <a href="https://github.com/moabukar/KCNA-Kubernetes-and-Cloud-Native-Associate">github.com</a></strong> Useful notes for the KCNA - Kubernetes and Cloud Native Associate - GitHub - moabukar/KCNA-Kubernetes-and-Cloud-Native-Associate: Useful notes for the KCNA - Kubernetes and Cloud Native Associate</p><p><strong><a href="https://www.reddit.com/r/kubernetes/comments/rnfq81/took_my_ckad_failed_the_first_time_passed_using/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Took my CKAD, failed the first time, passed using retake with 98% : kubernetes</a> &#8212; <a href="https://www.reddit.com/r/kubernetes/comments/rnfq81/took_my_ckad_failed_the_first_time_passed_using/">www.reddit.com</a></strong> Background: Junior software engineer with 1+ year of experience. So as you guessed, not much prior knowledge to docker, kubernetes and linux :) ...</p><p><strong><a href="https://medium.com/@marino.wijay/the-kcna-exam-a-quick-guide-to-kicking-off-your-k8s-and-cloud-native-journey-56a3a5be345?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The KCNA Exam &#8212; A quick guide to kicking off your K8S and Cloud Native Journey | by Marino Wijay | Dec, 2021 | Medium</a> &#8212; <a href="https://medium.com/@marino.wijay/the-kcna-exam-a-quick-guide-to-kicking-off-your-k8s-and-cloud-native-journey-56a3a5be345">medium.com</a></strong> Just a few months ago, the Kubernetes and Cloud Native Associate Exam (KCNA) was launched. After some thought, I figured I&#8217;d give it a shot. I took the exam and passed! This exam was released after&#8230;</p><p><strong><a href="https://lab.redhat.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Red Hat Enterprise Linux Interactive Lab Portal</a></strong> Work with Red Hat Enterprise Linux hands-on labs to learn new skills and technologies</p><p><strong><a href="https://www.eddiejaoude.io/course-github-profile-landing?r_done=1&amp;utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Free course landing page</a></strong> It started with fixing a typo, then on to&nbsp;fixing a bug;&nbsp;contributing to Open Source and collaborating to improve technology for everyone.</p><p><strong><a href="https://algocademy.com/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">AlgoCademy - Become the Software Engineer companies are fighting for</a> &#8212; <a href="https://algocademy.com/">algocademy.com</a></strong> Master the coding interview and get your dream job. Learn how to write clean quality code that passes the technical interview. Develop your problem solving skills using our step by step interactive lessons, video content and code quality tests</p><p><strong><a href="https://blog.pragmaticengineer.com/books/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Books - The Pragmatic Engineer</a></strong></p><p>Here are books I recommend for software engineers or managers.</p><p><strong><a href="https://changelog.com/shipit?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">The Ship It! Podcast |&gt; Changelog</a> &#8212; <a href="https://changelog.com/shipit">changelog.com</a></strong> A show about getting your best ideas into the world and seeing what happens. We talk about code, ops, infrastructure, and the people that make it happen.</p><p><strong><a href="https://layoffs.fyi/tracker/?utm_campaign=Newsletter%20of%20Carlos%20Santana&amp;utm_medium=email&amp;utm_source=Revue%20newsletter">Layoffs Tracker - Layoffs.fyi</a> &#8212; <a href="https://layoffs.fyi/tracker/">layoffs.fyi</a></strong> [LIVE] Tracking all tech startup layoffs &#8212; and lists of employees laid off &#8212; since COVID-19 was declared a pandemic. This page is constantly being updated.</p>]]></content:encoded></item></channel></rss>