< ciso
brief />
Tag Banner

All news with #kubernetes tag

55 articles

Amazon EKS Distro Adds Kubernetes 1.37 Support

🚀 Amazon EKS and EKS Distro now support Kubernetes version 1.37. This release lets you create new clusters or upgrade existing ones via the EKS console, eksctl, or infrastructure-as-code tools. Kubernetes 1.37 promotes the Metrics API to GA, graduates Dynamic Resource Allocation device taints and tolerations to GA, and enables HPA scale-to-zero by default. EKS 1.37 is available in all Regions where EKS operates, with EKS Distro images published to ECR Public Gallery and GitHub.
read more →

GKE CPU Startup Boost for Faster Pod Starts

🚀 GKE introduces CPU startup boost in preview, integrated into the Vertical Pod Autoscaler (VPA), to temporarily elevate CPU allocation during container initialization and then in-place scale it back to steady-state levels without restarting containers. The feature leverages Kubernetes In-place Pod Resize (IPPR) and operates across admission, startup, and unboosting phases. It targets CPU-intensive startup workloads—such as Java JVMs, Node.js, and Python/AI microservices—so teams can avoid overprovisioning while reducing cold starts and costs. Available on GKE 1.36.0-gke.4447000+ for Standard and Autopilot clusters.
read more →

EKS Auto Mode adds advanced node tuning options

🚀 Amazon EKS Auto Mode now supports advanced node tuning via the NodeClass resource, enabling kubelet, Linux kernel sysctl, and hugepage configuration directly through the Kubernetes API. advancedCompute lets you set user namespaces for rootless builds, adjust eviction thresholds and log rotation, raise network and ARP cache limits, and pre-allocate 2Mi or 1Gi hugepages for HPC and low-latency workloads. EKS Auto Mode validates and applies settings at node boot and preserves them across scaling and upgrades, with no custom AMIs, EC2 launch templates, or privileged DaemonSets to manage.
read more →

Compromised Identity Leads to Broad DevOps and Cloud Access

🔒 Microsoft DART investigated an incident where the Storm-3068 actor turned a self-service password reset into persistent access across Azure DevOps, development pipelines, and Kubernetes. The actor used legitimate identity and cloud services to enumerate repositories, create malicious pipelines to harvest kubeconfig files, and deploy remote access tools like Atera and Chisel. DART worked with the customer to contain the intrusion, reconstruct activity from audit logs and Git history, and provide remediation guidance to reduce future identity-driven risks.
read more →

GKE Adds Native Prometheus Metrics for Autoscaling

🔔 Google Cloud announced built-in Prometheus metrics processing for GKE, enabling HPA to use PromQL queries directly via Google Managed Service for Prometheus. This removes the need for third-party adapters, reduces latency, and simplifies autoscaling configuration. The controller runs in the control plane and only deploys pods on nodes when PromQL metrics are actively requested, minimizing resource use. The feature is in preview with plans to add self-hosted Prometheus support before GA.
read more →

GKE Adds Native Scale-to-Zero Capabilities

🚀 GKE 1.37 introduces native scale-to-zero so workloads can fully scale down to zero replicas and stop consuming compute while idle. The feature uses HPA with the new AutoscalingMetric CRD and KEP-2021 support for minReplicas: 0 to wake workloads based on external signals such as Pub/Sub or Cloud Monitoring. Capacity buffers provide pooled warm capacity to eliminate cold-start latency and balance cost with instant responsiveness.
read more →

Amazon EMR on EKS adds IPv6 support

🚀 Amazon announces that Amazon EMR on EKS now supports running Spark and Flink workloads on IPv6 Amazon EKS clusters. This enables teams to use the larger IPv6 address space to scale high-executor analytics jobs without IPv4 workarounds. Support starts with EMR releases emr-7.14.0 and emr-spark-8.0.0 and is available in regions where IPv6 EKS clusters are offered.
read more →

AWS PCS adds GRES, hardware topology, and MIG support

🔧 AWS Parallel Computing Service (AWS PCS) now supports custom Generic Resource (GRES) settings, hardware topology configuration, and NVIDIA Multi-Instance GPU (MIG), and upgrades to Slurm 26.05. These additions let Slurm autodetect NUMA domains as sockets, configure GPU core affinity and GPU interconnects, and enable finer control over task placement for HPC and ML workloads. Custom GRES and topology settings let administrators declare accelerators, partition GPUs with MIG, or override defaults for specialized scheduling.
read more →

AWS Private CA connectors arrive in GovCloud

🔒 AWS Private Certificate Authority (AWS Private CA) now offers the AWS Private CA Connector for Kubernetes as a managed Amazon EKS add-on and the AWS Private CA Connector for Active Directory in AWS GovCloud (US-East) and (US-West). These additions simplify certificate automation for government workloads, integrating with cert-manager to provision and renew TLS certificates in Kubernetes and enabling AD-based automatic issuance for domain-joined objects. The service secures private keys using FIPS 140-3 Level 3 HSMs.
read more →

Amazon EKS Argo CD now supports custom configuration

🔧 The Amazon EKS Capability for Argo CD now accepts a standard argocd-cm ConfigMap in your cluster to enable custom configuration. This managed GitOps continuous delivery experience can be tuned to your team’s workflows, including custom health checks for Custom Resources, UI banner content, and resource watch/compare behavior. AWS applies settings configured the same way as upstream Argo CD, and built-in health checks for AWS Controllers for Kubernetes (ACK) and kro resources are included.
read more →

Microsoft named a Leader in Gartner MQ 2026

🔷 Microsoft was named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms, marking its third consecutive year in that quadrant. The post highlights how Azure’s platform consolidates application modernization, AI toolchains, operations, and security into a single foundation. It describes services like Azure App Service, Container Apps, Azure Functions, and API Management as core components enabling production AI workloads and agentic applications. Customer examples illustrate real-world production usage and operational impact.
read more →

Amazon EKS adds control plane configuration options

🔧 Amazon Elastic Kubernetes Service (Amazon EKS) now lets administrators configure control plane parameters for the scheduler, controller manager, and API server. This capability enables tuning of pod placement strategies, horizontal pod autoscaler responsiveness, and resource lifecycle settings such as event retention. Cluster operators can choose different scheduler fit strategies (for example, MostAllocated or LeastAllocated) to prioritize density or headroom. These control plane configuration options are available in any AWS Region where Amazon EKS is offered.
read more →

Amazon Managed Service for Prometheus scales massively

📈 Amazon Managed Service for Prometheus now supports up to 1.5 billion active metric time series and up to 200,000 recording and alerting rules per workspace, with customers able to create many workspaces per account. Amazon Managed Service for Prometheus is a fully managed, Prometheus-compatible monitoring service that automatically scales ingestion and storage for high-cardinality workloads across containerized, serverless, and hybrid environments. It integrates with AWS security services to provide secure access to monitoring data and lets customers request higher workspace limits via AWS Support Center or AWS Service Quotas.
read more →

Open-source k8s‑aibom for automated AI BOMs

🔍 k8s-aibom is an unprivileged Kubernetes controller that continuously monitors cluster workloads to detect AI runtimes and generate standard CycloneDX 1.6 Machine Learning Bill of Materials (ML-BOMs). It runs as a single Deployment with zero developer friction—no sidecars, no privileged DaemonSets—and exports deterministic BOMs to in-cluster CRs and optional external sinks like Google Cloud Storage. Designed for audit-grade evidence, it supports compliance frameworks and GitOps workflows.
read more →

16-year KVM bug allows guest-to-host escape

🛡️ A critical KVM vulnerability, tracked as CVE-2026-53359 and nicknamed Januscape, lets an attacker with root in a guest VM execute code on the Linux host by exploiting a use-after-free in KVM's shadow MMU emulation on x86. Discovered by Hyunwoo Kim and present for 16 years, it affects both Intel and AMD servers and can enable host kernel panic, denial-of-service, or full RCE; some distros also allow local escalation via world-writable /dev/kvm. The Linux kernel was patched on June 16, but distribution rollouts may lag.
read more →

Amazon EKS adds Kubernetes version rollback support

🔧 Amazon Elastic Kubernetes Service (Amazon EKS) now supports Kubernetes minor version rollback, letting you revert to the prior minor version within 7 days if an upgrade causes issues. You can start a rollback via the Amazon EKS console, AWS CLI, or AWS SDKs, and EKS evaluates cluster rollback readiness with automated checks for API compatibility, version skew, add-on compatibility, and cluster health. For clusters using EKS Auto Mode, worker nodes are automatically managed during rollback to respect configured disruption controls, and the feature is available at no additional cost in all AWS Regions where EKS is offered.
read more →

CloudWatch OTel Container Insights for Amazon EKS

🚀 Amazon CloudWatch now offers OTel Container Insights for Amazon EKS, collecting infrastructure metrics at 30-second granularity using open-source receivers like cAdvisor, Kube State Metrics, and NVIDIA DCGM. Each metric includes OpenTelemetry semantic conventions and Kubernetes labels to simplify correlation across nodes, pods, and workloads with a single PromQL query. Pre-built dashboards provide immediate visibility into cluster health, node performance, and pod-level resource usage, and the CloudWatch PromQL endpoint enables direct connection of existing Prometheus and Grafana dashboards. Enable the feature from the EKS console, the CloudWatch Observability add-on (v6.2.0+), Helm, or CloudFormation; it is available in all commercial AWS Regions except UAE, Bahrain, and Israel (Tel Aviv).
read more →

EKS local clusters now support EC2 instance store on Outposts

🆕 AWS now supports Amazon EKS local clusters on first- and second-generation AWS Outposts racks that boot Amazon EC2 instances from EC2 instance store. This extends Outposts’ static stability benefits to EKS local clusters, keeping the entire Kubernetes control plane on the Outpost to meet data residency needs and reduce impact from temporary network disconnects. The updated architecture brings greater operational parity with cloud EKS, includes managed control plane responsibilities, and adds support for EKS add-ons and modern auth mechanisms.
read more →

Deploy ADK agents on GKE Autopilot securely

🚀 This tutorial shows how to build an AI agent with Google’s Agent Development Kit (ADK), containerize it, and deploy it to GKE Autopilot using Vertex AI (Gemini) as the model backend. It walks through local testing, creating a multi-stage Docker image, pushing to Artifact Registry, and configuring a Kubernetes Deployment and Service. The guide emphasizes secure authentication with Workload Identity and exposes the agent via the Kubernetes Gateway API with a Google-managed TLS certificate.
read more →

Amazon EKS and EKS Distro add Kubernetes 1.36 support

🔔 AWS now supports Kubernetes version 1.36 in Amazon EKS and Amazon EKS Distro. You can create new clusters or upgrade existing ones using the EKS console, eksctl, or infrastructure-as-code tools across all AWS Regions, including GovCloud. Key features in 1.36 include GA User Namespaces, Mutating Admission Policies for CEL, In-Place Pod-Level Vertical Scaling, and Resource Health Status reporting. EKS Distro images are available in ECR Public Gallery and GitHub, with documentation covering upgrade guidance and lifecycle policies.
read more →