『Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News』のカバーアート

Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

著者: Teller's Tech - DevOps SRE and Cloud Podcast
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Ship It Weekly is a short, practical recap of what actually matters in DevOps, SRE, cloud infrastructure, and platform engineering.

Each episode, your host Brian Teller walks through the latest outages, releases, tools, and incident writeups, then translates them into “here’s what this means for your systems” instead of just reading headlines. Expect a couple of main stories with context, a quick hit of tools or releases worth bookmarking, and the occasional segment on on-call, burnout, or team culture.

This isn’t a certification prep show or a lab walkthrough. It’s aimed at people who are already working in the space and want to stay sharp without scrolling status pages, cloud updates, and blogs all week. You’ll hear about things like cloud provider incidents, Kubernetes and platform trends, Terraform and infrastructure changes, and real postmortems that are actually worth your time.

Most episodes are 15–30 minutes, so you can catch up on the way to work or between meetings. Every now and then there will be a “special” focused on a big outage or a specific theme, but the default format is simple: what happened, why it matters, and what you might want to do about it in your own environment.

If you’re the person people DM when something is broken in prod, or you’re building the cloud and platform everyone else ships on top of, Ship It Weekly is meant to be in your rotation.

Brian Teller - Teller's Tech - DevOps, SRE and Cloud
政治・政府
エピソード
  • AWS Retires DevOps Guru: What the End of Support Means, Kubernetes Cross-Namespace CVE-2026-2270, Node.js Undici WebSocket DoS & Cloudflare’s New CLI for AI Agents
    2026/10/01

    This week on Ship It Weekly: AWS is retiring Amazon DevOps Guru and pointing customers toward CloudWatch and the newer Amazon DevOps Agent. Kubernetes disclosed a vulnerability where StatefulSet and ControllerRevision permissions can allow cross-namespace pod creation under specific conditions. A vulnerability in Undici can let a malicious WebSocket server crash a Node.js process through compressed data. And Cloudflare launched a new CLI as AI agents grow from 25 percent to 48 percent of Wrangler usage.

    The bigger theme this week is how the systems around our infrastructure are changing. Managed cloud services still have lifecycles that eventually become migration work. Kubernetes authorization can depend on what controllers do with the resources users are allowed to manipulate. Applications acting as clients still process untrusted data. And infrastructure tooling is starting to treat AI agents as first-class users rather than humans who happen to automate commands.

    In the lightning round: another Kubernetes vulnerability affecting Windows nodes can expose NetNTLMv2 credentials through NTLM coercion. GitHub now supports custom runners for Dependabot version and security updates. And external systems like a CMDB or internal developer portal can push repository properties into GitHub while remaining the source of truth.

    And the human closer comes from Lorin Hochstein and SRE Weekly. Some availability risks are probably never going away. Resources are finite, networks fail, security controls can affect availability, and production systems have to change. Preventing individual failures still matters, but incident response is part of reliability engineering too. Sometimes improving reliability means getting better at handling the failures you cannot eliminate.

    Links

    Amazon DevOps Guru End of Support - https://tsn.io/GQHN8

    Kubernetes CVE-2026-2270: Cross-Namespace Pod Creation - https://tsn.io/BsNs8

    Undici CVE-2026-85024: WebSocket Denial of Service - https://tsn.io/LncLd

    Cloudflare: Introducing the cf CLI - https://tsn.io/Wk3ma

    Cloudflare Forge - https://tsn.io/bAPJu

    Lightning Round

    Kubernetes CVE-2026-76654: Windows NTLM Coercion - https://tsn.io/36Kc3

    GitHub: Custom Runners for Dependabot - https://tsn.io/tYl9K

    GitHub: External Custom Properties - https://www.tellerstech.com/go/s-1fd1396d/

    Human Closer

    Omnipresent Availability Risks in Cloud Software - https://www.tellerstech.com/go/s-076db9dd/

    Our Links

    This Week’s On Call Brief - https://tsn.io/fKB9V

    Ship It Weekly - https://tsn.io/NqkdP

    On Call Brief - https://tsn.io/Gpz2d

    続きを読む 一部表示
    17 分
  • AWS Puts Elastic Beanstalk on EKS, CrowdSec Supply-Chain Breach, Critical Next.js RCE, Microsoft Disrupts EvilTokens & Why Fixing the Initial Compromise Isn’t Enough
    2026/09/25

    This week on Ship It Weekly: AWS introduced Elastic Beanstalk Cluster Mode, allowing multiple applications to run on shared EKS infrastructure while AWS handles much of the Kubernetes complexity. CrowdSec published how a software supply-chain compromise led to attackers copying roughly 170 private repositories using a stolen OAuth token. A critical Next.js vulnerability in ImageResponse can lead to remote code execution through attacker-controlled SVG data. And Microsoft disrupted EvilTokens, a cybercrime platform linked to more than 12,000 compromised inboxes across 10,000 organizations.

    The bigger theme this week is what happens after trust has been established. Elastic Beanstalk Cluster Mode puts more infrastructure behind a managed abstraction, but shared infrastructure still means understanding isolation and blast radius. CrowdSec shows how an initial compromise can become a credential problem long after the malicious code is gone. Next.js shows how something as ordinary as generating a social preview image can expose a server-side execution path. And EvilTokens shows how attackers can use valid access to move faster once inside an account.

    In the lightning round: F5 has a critical BIG-IP APM vulnerability under active exploitation. GitHub Enterprise Cloud can now export an inventory of credentials with enterprise access, including PATs, SSH keys, OAuth tokens, and GitHub App credentials. Zyxel patched a vulnerability affecting GS1900 switches. And Veeam Agent for Microsoft Windows has a privilege-escalation vulnerability that can lead to SYSTEM access.

    And the human closer comes back to CrowdSec. Removing the malicious package, patching the server, or reimaging the workstation does not necessarily end the incident. If an attacker already stole an OAuth token, cloud credential, SSH key, session, or registry credential, that access can survive long after the original compromise is gone. Containment means understanding not only how the attacker got in, but what they took with them

    Links

    AWS Elastic Beanstalk Cluster Mode

    https://tsn.io/1xaV7

    CrowdSec Supply-Chain Attack Analysis

    https://tsn.io/7yq2f

    Next.js ImageResponse Security Advisory

    https://tsn.io/8JvHp

    Microsoft: Disrupting EvilTokens

    https://tsn.io/DtbC9

    Microsoft: EvilTokens and Device-Code Phishing

    https://tsn.io/ZzwtD

    F5 BIG-IP APM CVE-2026-94127

    https://tsn.io/sFuKW

    GitHub Enterprise Credential Inventory

    https://tsn.io/7bpMn

    Zyxel GS1900 Security Advisory

    https://www.tellerstech.com/go/s-b2595852/

    Veeam Agent for Microsoft Windows Vulnerability

    https://www.tellerstech.com/go/s-166d3119/

    This Week’s On Call Brief

    https://tsn.io/Nnd8g

    Ship It Weekly

    https://tsn.io/NqkdP

    On Call Brief

    https://tsn.io/Gpz2d

    続きを読む 一部表示
    17 分
  • GitHub Actions Security, Cisco Email Gateway RCE, Helm 3 End-of-Life, Ubuntu 26.04 Runners & Why “Nothing Changed” Is Never the Whole Story
    2026/09/19

    This week on Ship It Weekly: GitHub Actions workflow execution protections are now generally available, giving organizations more control over who and what can trigger individual workflows. Cisco is patching critical vulnerabilities in Secure Email Gateway, including an actively exploited issue that can lead to remote command execution as root. Helm 3 has reached its final minor release and is heading toward end-of-life in February 2027. And GitHub’s ubuntu-latest Actions runner is preparing to move from Ubuntu 24.04 to 26.04.

    The bigger theme this week is infrastructure that changes even when your code does not. GitHub is making CI execution permissions more explicit, Helm teams now have a defined migration deadline, and the ubuntu-latest transition is a good example of how a completely unchanged workflow can suddenly be running in a different environment. Pinning everything forever is not necessarily the answer. The important part is knowing which dependencies are allowed to move and testing those changes deliberately.

    In the lightning round: GitHub Actions checks, workflow runs, and statuses will begin following your configured retention period on October 1. GitHub Advanced Security can now enforce configurations from the enterprise level. GitHub added API support for tracking when self-hosted Actions runner versions lose support. And AI Scan for pull requests can now be used without requiring CodeQL default setup.

    And the human closer starts with a sentence almost every infrastructure engineer has heard during an incident: “But nothing changed.” Maybe nothing changed in the application, but the runner image changed, a dependency moved, a certificate expired, DNS changed, or an external service behaved differently. Latest tags, loose version constraints, external APIs, and even support windows are dependencies. The goal is not to freeze everything forever. It is to avoid accidental mutability, where something can change without the team realizing it was ever allowed to change.

    Links

    GitHub Actions Workflow Execution Protections

    https://tsn.io/fbqif

    Cisco Secure Email Gateway Security Advisory

    https://tsn.io/jX2wk

    Helm 3 End of Life

    https://tsn.io/Ii7jb

    Ubuntu 26.04 GitHub Actions Runners and ubuntu-latest Migration

    https://tsn.io/7IJ9k

    GitHub Actions Retention Changes

    https://tsn.io/idFxy

    GitHub Advanced Security Configuration Enforcement

    https://tsn.io/8vRMx

    GitHub Actions Self-Hosted Runner Lifecycle API

    https://tsn.io/9UhY1

    GitHub Code Scanning AI Scan

    https://tsn.io/ULAVW

    This Week’s On Call Brief

    https://www.tellerstech.com/go/26w38/

    Ship It Weekly

    https://tsn.io/NqkdP

    On Call Brief

    https://tsn.io/Gpz2d

    続きを読む 一部表示
    16 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません