# Cloud Native Ecosystem

Published articles for Cloud Native Ecosystem.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Kubernetes v1.37 brings 67 enhancements. Which matter for operators?

DevFeed: [Kubernetes v1.37 brings 67 enhancements. Which matter for operators?](<https://devfeed.tech/articles/kubernetes-v1-37-brings-67-enhancements-which-matter-for-operators-8480.md>)

Original publisher: [Read original article](<https://thenewstack.io/kubecon-kubernetes-updates-security/>)

Author: Bill Doerrfeld

Published: 2026-09-11T17:40:04Z

Content type: news

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>), [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [migration](<https://devfeed.tech/topics/migration.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [hpe](<https://devfeed.tech/tags/hpe.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubecon-cloudnativecon-na-2026](<https://devfeed.tech/tags/kubecon-cloudnativecon-na-2026.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [post](<https://devfeed.tech/tags/post.md>), [road-to-kubecon](<https://devfeed.tech/tags/road-to-kubecon.md>), [sponsor-hpe](<https://devfeed.tech/tags/sponsor-hpe.md>), [sponsored-post](<https://devfeed.tech/tags/sponsored-post.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

A Kubernetes roundup covers v1.37 enhancements, HPE Morpheus and Terraform provider changes, migration tooling, and recent CNCF project graduations including Kubeflow.

### Source excerpt

Welcome to the first edition of Road to KubeCon, where we'll track the world of Kubernetes as we approach KubeCon The post Kubernetes v1.37 brings 67 enhancements. Which matter for operators? appeared first on The New Stack.

## CNCF Welcomes New Silver Members as Enterprises Scale AI From Training to Inference

DevFeed: [CNCF Welcomes New Silver Members as Enterprises Scale AI From Training to Inference](<https://devfeed.tech/articles/cncf-welcomes-new-silver-members-as-enterprises-scale-ai-from-training-to-inference-4597.md>)

Original publisher: [Read original article](<https://www.cncf.io/announcements/2026/09/07/cncf-welcomes-new-silver-members-as-enterprises-scale-ai-from-training-to-inference/>)

Author: Haley White

Published: 2026-09-08T01:58:47Z

Content type: news

Language: en

Sources: [Cloud Native Computing Foundation](<https://devfeed.tech/sources/cloud-native-computing-foundation.md>)

Topics: [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [inference](<https://devfeed.tech/tags/inference.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [production](<https://devfeed.tech/tags/production.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

CNCF announces nine new Silver members as enterprises shift AI workloads from training to production inference. The announcement emphasizes cloud-native infrastructure, operational efficiency, data sovereignty, and resource optimization.

### Source excerpt

New members including SoftBank Corp. and Crusoe join the cloud native community to help build cost-efficient, sovereign infrastructure SHANGHAI, China - KubeCon + CloudNativeCon + OpenInfra Summit + PyTorch Conference China 2026 - September 8, 2026...

## CNCF and SlashData Report Highlights China's Cloud Native Momentum as AI Moves to Inference

DevFeed: [CNCF and SlashData Report Highlights China's Cloud Native Momentum as AI Moves to Inference](<https://devfeed.tech/articles/cncf-and-slashdata-report-highlights-china-s-cloud-native-momentum-as-ai-moves-to-inference-4596.md>)

Original publisher: [Read original article](<https://www.cncf.io/announcements/2026/09/07/cncf-and-slashdata-report-highlights-chinas-cloud-native-momentum-as-ai-moves-to-inference/>)

Author: Haley White

Published: 2026-09-08T01:50:55Z

Content type: news

Language: en

Sources: [Cloud Native Computing Foundation](<https://devfeed.tech/sources/cloud-native-computing-foundation.md>)

Topics: [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [model-deployment](<https://devfeed.tech/topics/model-deployment.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [backend](<https://devfeed.tech/tags/backend.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [developers](<https://devfeed.tech/tags/developers.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [inference](<https://devfeed.tech/tags/inference.md>), [production](<https://devfeed.tech/tags/production.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

CNCF and SlashData report that cloud native adoption in China is growing, including among IIoT and younger backend developers. The research describes cloud native infrastructure as supporting AI teams' transition from experimentation and training to production serving and distributed inference.

### Source excerpt

New research finds China's IIoT developers (48%) outpace the global average (42%) in cloud native adoption as AI infrastructure matures Key Highlights: SHANGHAI - KubeCon + CloudNativeCon + OpenInfra Summit + PyTorch Conference China --Sept. 8,...

## Critical Kyverno Vulnerability -- CVE-2026-54523

DevFeed: [Critical Kyverno Vulnerability -- CVE-2026-54523](<https://devfeed.tech/articles/critical-kyverno-vulnerability-cve-2026-54523-17651.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/07/28/critical-kyverno-vulnerability-cve-2026-54523/>)

Author: Anubhav Sharma

Published: 2026-07-29T01:08:41Z

Content type: news

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [admission-controller](<https://devfeed.tech/tags/admission-controller.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [cve](<https://devfeed.tech/tags/cve.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [nctl-ai](<https://devfeed.tech/tags/nctl-ai.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [policy-management](<https://devfeed.tech/tags/policy-management.md>), [release](<https://devfeed.tech/tags/release.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports CVE-2026-54523, a critical Kyverno vulnerability affecting versions 1.18.0 and 1.18.1. A tenant able to create a NamespacedMutatingPolicy could bypass namespace isolation and generate resources in other namespaces, potentially enabling cluster-wide privilege escalation. Kyverno 1.18.2 patches the vulnerability.

### Source excerpt

Critical Kyverno Vulnerability -- CVE-2026-54523 On July 13, 2026, a critical vulnerability was disclosed in Kyverno, the Kubernetes-native policy engine used broadly across the cloud native ecosystem for policy-as-code enforcement. The vulnerability, tracked as CVE-2026-54523 (GHSA-79gf-7frw-68m9), allows a tenant with permission to create a NamespacedMutatingPolicy... The post Critical Kyverno Vulnerability -- CVE-2026-54523 first appeared on Nirmata.

## Cloud native application challenges: installing the walking skeleton

DevFeed: [Cloud native application challenges: installing the walking skeleton](<https://devfeed.tech/articles/cloud-native-application-challenges-installing-the-walking-skeleton-17634.md>)

Original publisher: [Read original article](<https://thenewstack.io/kubernetes-yaml-management-scale/>)

Author: Manning Book Authors

Published: 2026-05-13T13:00:00Z

Content type: tutorial

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [article](<https://devfeed.tech/tags/article.md>), [chronosphere](<https://devfeed.tech/tags/chronosphere.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container](<https://devfeed.tech/tags/container.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [sponsor-chronosphere](<https://devfeed.tech/tags/sponsor-chronosphere.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This excerpt from Platform Engineering on Kubernetes explains how Kubernetes YAML defines and configures containerized applications. It introduces Deployments, Services, Ingress, and ConfigMaps or secrets, including their roles in replication, traffic routing, service discovery, and configuration management.

### Source excerpt

Editor's note: This article is an excerpt from Chapter 1 of the Manning book, Platform Engineering on Kubernetes. This excerpt The post Cloud native application challenges: installing the walking skeleton appeared first on The New Stack.

## Why Prometheus couldn't see Cilium metrics at 2 a.m.

DevFeed: [Why Prometheus couldn't see Cilium metrics at 2 a.m.](<https://devfeed.tech/articles/why-prometheus-couldn-t-see-cilium-metrics-at-2-a-m-17617.md>)

Original publisher: [Read original article](<https://thenewstack.io/cncf-projects-integration-production/>)

Author: Rishi Mondal

Published: 2026-05-10T14:00:00Z

Content type: article

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [Grafana](<https://devfeed.tech/topics/grafana.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [grafana](<https://devfeed.tech/tags/grafana.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [sponsor-cncf](<https://devfeed.tech/tags/sponsor-cncf.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This article examines the integration tax that platform teams encounter when combining CNCF projects in production. It uses Prometheus and Cilium metrics as an example, and discusses integration failures involving Hubble, Grafana, cert-manager, ingress controllers, and cloud DNS configuration.

### Source excerpt

I still remember the first time we lost sleep over something that wasn't a bug. It was a Tuesday. Grafana The post Why Prometheus couldn't see Cilium metrics at 2 a.m. appeared first on The New Stack.

## How Microsoft is governing thousands of Kubernetes clusters without manual intervention

DevFeed: [How Microsoft is governing thousands of Kubernetes clusters without manual intervention](<https://devfeed.tech/articles/how-microsoft-is-governing-thousands-of-kubernetes-clusters-without-manual-intervention-17630.md>)

Original publisher: [Read original article](<https://thenewstack.io/kubernetes-fleet-management-scale/>)

Author: Adrian Bridgwater

Published: 2026-05-07T22:07:21Z

Content type: article

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [inference](<https://devfeed.tech/tags/inference.md>), [kubecon-cloudnativecon-eu-2026](<https://devfeed.tech/tags/kubecon-cloudnativecon-eu-2026.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [observability](<https://devfeed.tech/tags/observability.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [post](<https://devfeed.tech/tags/post.md>), [sponsor-microsoft](<https://devfeed.tech/tags/sponsor-microsoft.md>), [sponsored-post](<https://devfeed.tech/tags/sponsored-post.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

The article examines how Microsoft addresses the operational challenges of governing thousands of Kubernetes clusters across on-premises, cloud, and edge environments. It describes limitations of single-cluster GitOps assumptions, including multi-cluster routing, secret synchronization, and unified observability, especially as distributed AI inference workloads increase.

### Source excerpt

Kubernetes is complicated; everybody knows it. Logically enough, Kubernetes deployed as a cluster of collected and coalesced instances at "fleet The post How Microsoft is governing thousands of Kubernetes clusters without manual intervention appeared first on The New Stack.

## Kubernetes User Namespaces Improve Pod Isolation but Do Not Isolate the Shared Kernel

DevFeed: [Kubernetes User Namespaces Improve Pod Isolation but Do Not Isolate the Shared Kernel](<https://devfeed.tech/articles/kubernetes-finally-lands-user-namespace-support-but-shared-kernel-problem-remains-17633.md>)

Original publisher: [Read original article](<https://thenewstack.io/kubernetes-user-namespace-security/>)

Author: Kaylin Trychon

Published: 2026-05-06T14:50:05Z

Content type: opinion

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [edera](<https://devfeed.tech/tags/edera.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsor-edera](<https://devfeed.tech/tags/sponsor-edera.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>)

### AI overview

Kubernetes user namespaces can reduce the impact of some container escapes by remapping pod root identities to unprivileged host identities. The article argues that this improves isolation but does not address the security limitations of a shared kernel.

### Source excerpt

Kubernetes shipped a long-awaited security feature last week: user namespace support for pods. It may sound like an obscure feature The post Kubernetes finally lands user namespace support, but shared kernel problem remains appeared first on The New Stack.

## Behind the Scenes: How Maintaining Cloud Native Buildpacks Powers Platforms Like Heroku

DevFeed: [Behind the Scenes: How Maintaining Cloud Native Buildpacks Powers Platforms Like Heroku](<https://devfeed.tech/articles/behind-the-scenes-how-maintaining-cloud-native-buildpacks-powers-platforms-like-heroku-26448.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/how-maintaining-cloud-native-buildpacks-powers-platforms-like-heroku/>)

Author: Juan Bustamante

Published: 2026-03-17T15:00:03Z

Content type: opinion

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Heroku](<https://devfeed.tech/topics/heroku.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub Issues](<https://devfeed.tech/topics/github-issues.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [buildpacks](<https://devfeed.tech/tags/buildpacks.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [docker](<https://devfeed.tech/tags/docker.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-issues](<https://devfeed.tech/tags/github-issues.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [google-cloud-run](<https://devfeed.tech/tags/google-cloud-run.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [patches](<https://devfeed.tech/tags/patches.md>), [platform](<https://devfeed.tech/tags/platform.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article describes how pack CLI maintainers support Cloud Native Buildpacks through releases, security patches, issue triage, pull request reviews, CI changes, and feature development. It explains how Heroku-funded maintenance benefits Heroku, Google Cloud Run, and internal platform teams.

### Source excerpt

Most developers never see the 11 pack releases we shipped in the last 14 months as pack CLI maintainers. That's actually a good sign--it means the infrastructure just works. When a critical vulnerability emerges requiring an immediate upgrade, the fix is shipped within days. Here's what most developers don't see: that same security patch now [...] The post Behind the Scenes: How Maintaining Cloud Native Buildpacks Powers Platforms Like Heroku appeared first on Heroku.

## Keycloak's Bug Bounty Program on YesWeHack

DevFeed: [Keycloak's Bug Bounty Program on YesWeHack](<https://devfeed.tech/articles/keycloak-s-bug-bounty-program-on-yeswehack-31742.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/01/bugbounty-yes-we-hack>)

Author: Alexander Schwartz

Published: 2026-01-16T00:00:00Z

Content type: news

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak announces its public bug bounty program on YesWeHack as part of an EU-sponsored initiative. The program is currently paused while submissions are reviewed after receiving many submissions.

### Source excerpt

As a Cloud Native Computing Foundation (CNCF) project, Keycloak is the open-source IAM backbone for countless applications. This is your chance to secure a core piece of the cloud-native ecosystem in this public bug bounty program!. We are proud to be part of this EU sponsored initiative. Projects like ours fuel a lot of public and private infrastructure in the EU and worldwide. Thank you for choosing our project for this initiative to help us to improve and provide secure services to our users! We received a lot of good submissions to the program. While we sort out the submissions, the program is paused.

## Guest Post: Resiliency by Design and the Importance of Internal Developer Platforms

DevFeed: [Guest Post: Resiliency by Design and the Importance of Internal Developer Platforms](<https://devfeed.tech/articles/guest-post-resiliency-by-design-and-the-importance-of-internal-developer-platforms-13076.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guest-post-resiliency-by-design-and-the-importance-of-internal-developer-platforms>)

Published: 2025-08-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [assemble-2025](<https://devfeed.tech/tags/assemble-2025.md>), [automotive-software-engineering](<https://devfeed.tech/tags/automotive-software-engineering.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [disaster-recovery](<https://devfeed.tech/tags/disaster-recovery.md>), [git](<https://devfeed.tech/tags/git.md>), [idp](<https://devfeed.tech/tags/idp.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [observability](<https://devfeed.tech/tags/observability.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [resiliency-by-design](<https://devfeed.tech/tags/resiliency-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how internal developer platforms support resiliency by design. It argues that a well-designed platform can reduce the effects of cloud-native complexity by providing consistency, CI/CD integration, declarative infrastructure, observability, governance, and an orchestration layer across Git, Kubernetes, and cloud providers. It also describes standardized disaster recovery, failover, deployment, rollback, and security practices as platform capabilities.

### Source excerpt

Gaurav Saxena, a Director of Engineering at an automotive company, talks through how internal developer platforms are an important part of resiliency by design.

## Recap from KubeCon + CloudNativeCon Europe 2024

DevFeed: [Recap from KubeCon + CloudNativeCon Europe 2024](<https://devfeed.tech/articles/recap-from-kubecon-cloudnativecon-europe-2024-31639.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/04/keycloak-at-kubecon-eu-2024-recap>)

Author: Thomas Darimont

Published: 2024-04-15T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>)

Tags: [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [openid](<https://devfeed.tech/tags/openid.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [recap](<https://devfeed.tech/tags/recap.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

A recap of Keycloak's presence at KubeCon + CloudNativeCon Europe 2024, covering talks on OAuth2 Token Exchange for microservice API security, Keycloak's use in CERN's IAM infrastructure, federated IAM for Kubernetes with OpenFGA, and recent support for Passkeys, OAuth 2.1, and OpenID for Verifiable Credentials.

### Source excerpt

After a packed week of fantastic talks at KubeCon + CloudNativeCon Europe 2024 in Paris, we're delighted to share our impressions with the rest of the Keycloak community. Keycloak and OAuth2 Token Exchange for Microservice API Security The presence of Keycloak in many presentations highlighted its importance in the cloud-native ecosystem. Notably, the talk "OAuth2 Token Exchange for Microservice API Security" by Ahmet Soormally & Letz Yaara on OAuth2 Token Exchange (RFC 8693) underscored its application in microservice security and pinpointed areas for Keycloak's enhancement. Efforts to advance the support for Token Exchange are underway, and community feedback is invaluable. Please join the discussion on the current usage of Token Exchange to help us out. Keycloak and the Secrets of the Universe at CERN A standout moment was learning about Keycloak's role at CERN in the talk "The Hard Life of Securing a Particle Accelerator", as shared by Antonio Nappi and Sebastian Lopienski, emphasizing its contribution to securing the particle accelerator's IAM infrastructure. Keycloak supports research on the nature of the universe. How cool is that :) Keycloak, OpenFGA, and Kubernetes Authorizer Jonathan Whitaker's talk "Federated IAM for Kubernetes with OpenFGA" on federated IAM with OpenFGA showcased innovative approaches for managing access to Kubernetes resources through the combination of Keycloak, OpenFGA and a custom Kubernetes Authorizer Web Hook. In particular, the demonstration of temporarily elevated access to Kubernetes resources was very well received. Keycloak: The Leading Edge of AuthN and AuthZ Last but not least, our session, "The Leading Edge of AuthN and AuthZ by Keycloak", presented by Takashi Norimatsu and Thomas Darimont, introduced the latest Keycloak advancements, including support for Passkeys, OAuth 2.1, and OpenID for Verifiable Credentials (OpenID4VC). As part of our talk, we showed the current support for Passkeys and some integration options with

## Spotlight on SIG CLI

DevFeed: [Spotlight on SIG CLI](<https://devfeed.tech/articles/spotlight-on-sig-cli-17562.md>)

Original publisher: [Read original article](<https://www.kubernetes.dev/blog/2023/07/20/sig-cli-spotlight-2023/>)

Author: The Kubernetes Authors

Published: 2023-07-20T00:00:00Z

Content type: article

Language: en

Sources: [Kubernetes Contributors Blog](<https://devfeed.tech/sources/kubernetes-contributors-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [kubectl](<https://devfeed.tech/topics/kubectl.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [cli](<https://devfeed.tech/tags/cli.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [spotlight](<https://devfeed.tech/tags/spotlight.md>), [tech-lead](<https://devfeed.tech/tags/tech-lead.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

An interview with SIG CLI leaders describes the group's role in improving Kubernetes command-line tooling, including kubectl, and supporting contributors. It covers the group's goals, ongoing efforts, CLI libraries, and interoperability specifications for Kubernetes-related tooling.

### Source excerpt

In the world of Kubernetes, managing containerized applications at scale requires powerful and efficient tools. The command-line interface (CLI) is an integral part of any developer or operator's toolkit, offering a convenient and flexible way to interact with a Kubernetes cluster. SIG CLI plays a crucial role in improving the Kubernetes CLI experience by focusing on the development and enhancement of kubectl, the primary command-line tool for Kubernetes. In this SIG CLI Spotlight, Arpit Agrawal, SIG ContribEx-Comms team member, talked with Katrina Verey , Tech Lead & Chair of SIG CLI,and Maciej Szulik , SIG CLI Batch Lead, about SIG CLI, current projects, challenges and how anyone can get involved. So, whether you are a seasoned Kubernetes enthusiast or just getting started, understanding the significance of SIG CLI will undoubtedly enhance your Kubernetes journey. Introductions Arpit: Could you tell us a bit about yourself, your role, and how you got involved in SIG CLI? Maciej: I'm one of the technical leads for SIG-CLI. I was working on Kubernetes in multiple areas since 2014, and in 2018 I got appointed a lead. Katrina: I've been working with Kubernetes as an end-user since 2016, but it was only in late 2019 that I discovered how well SIG CLI aligned with my experience from internal projects. I started regularly attending meetings and made a few small PRs, and by 2021 I was working more deeply with the Kustomize team specifically. Later that year, I was appointed to my current roles as subproject owner for Kustomize and KRM Functions, and as SIG CLI Tech Lead and Chair. About SIG CLI Arpit: Thank you! Could you share with us the purpose and goals of SIG CLI? Maciej: Our charter has the most detailed description, but in few words, we handle all CLI tooling that helps you manage your Kubernetes manifests and interact with your Kubernetes clusters. Arpit: I see. And how does SIG CLI work to promote best-practices for CLI development and usage in the cloud native e