Newslurp

<< Stories

Kyverno Release 1.15 πŸ†•, Istio Upgrades at Scale βš–οΈ, Cloudy Threat Analysis ☁️

TLDR DevOps <dan@tldrnewsletter.com>

September 1, 11:09 am

TLDR DevOps
Kyverno 1.15 enhances Kubernetes policy management with new CEL-based policy types, introducing MutatingPolicy, GeneratingPolicy, and DeletingPolicy β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ  β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ 

TLDR

Together With Atlassian

TLDR DevOps 2025-09-01

Free Copy of the The Forrester Wave report for DevOps Platforms, Q2 2025 (Sponsor)

Forrester analysts looked at the 11 leading DevOps platforms - including tools from Atlassian, Microsoft, Harness, and GitLab.

Download the full version of the report to:

>> See what really matters when choosing a DevOps platform

>> Find out why Atlassian received the highest scores possible, earning (5/5) ratings across the Vision, Innovation, and Roadmap criteria

πŸ“₯ Get your copy now

πŸ“±

News & Trends

Announcing Kyverno Release 1.15! (4 minute read)

Kyverno 1.15 enhances Kubernetes policy management with new CEL-based policy types. It introduces MutatingPolicy, GeneratingPolicy, and DeletingPolicy, all of which convert automatically to Kubernetes admission controllers. The update shows significant performance improvements when using ValidatingPolicy over traditional ClusterPolicy for Pod Security Standards (PSS) enforcement.
Kubernetes v1.34: Finer-Grained Control Over Container Restarts (4 minute read)

Kubernetes 1.34 introduced a new alpha feature, "Container Restart Policy and Rules," allowing users to define restart policies for individual containers within a Pod. This feature, enabled behind the ContainerRestartRules feature gate, provides granular control over container restarts based on exit codes, addressing limitations of the previous Pod-level restart policy. It can be useful for long-running AI/ML workloads where in-place restarts of failed containers with retriable exit codes are needed for better resource utilization.
πŸš€

Opinions & Tutorials

Airbnb Executes Istio Upgrades at Massive Scale (7 minute read)

Airbnb has developed a zero-downtime Istio upgrade pipeline that coordinates workloads across Kubernetes and VMs using dual-version control planes, automated mutation frameworks, and a VM-specific rollout system. Other major companies like Netflix, LinkedIn, and Uber pursue different service mesh upgrade strategies, but all emphasize safe rollouts and reducing operational risk.
How we accelerated Secret Protection engineering with Copilot (17 minute read)

GitHub's Secret Protection team used Copilot to accelerate the expansion of validity checks, a feature that verifies whether leaked credentials are active. By integrating Copilot into their repeatable framework-driven workflow, they scaled coverage from 32 to nearly 120 token types in weeks, while engineers focused on research, review, and nuanced decisions.
Jujutsu for Everyone (7 minute read)

Jujutsu is a Git-compatible but simpler and more powerful version control system designed to be easier for beginners while still supporting advanced workflows. The learning path is structured into progressive levels, starting with solo basics and collaboration essentials, and building up to problem-solving, history rewriting, and productivity features, offering a complete progression that evolves alongside both the tool and the learner's needs.
πŸ§‘β€πŸ’»

Resources & Tools

DevOps, Bridge Your Kubernetes Management Gap! (Sponsor)

Battling Kubernetes complexity, security, and unexpected costs as critical applications scale? This IDC Spotlight paper offers crucial insights. Learn how to unify application, storage, and data management for robust, simplified large-scale deployments. Automate and secure your cloud-native estate

Read the full report to optimize resources and ensure uptime!

Paddler (GitHub Repo)

Paddler, an open-source LLMOps platform, enables organizations to host and scale AI models within their own infrastructure, offering privacy, reliability, and cost control. Featuring a self-contained binary with balancer and agent components, Paddler uses a built-in llama.cpp engine for inference and provides a web admin panel for monitoring, model management, and testing.
Automating threat analysis and response with Cloudy (Tool)

Cloudflare has integrated its AI agent, Cloudy, with its security analytics, creating a conversational interface for faster root cause analysis of traffic anomalies. Since its launch in March, 54,000 users have tried Cloudy for custom rule creation, with 31% deploying suggested rules. It can now offer contextual data about threats observed across Cloudflare's global network.
🎁

Miscellaneous

How Should Prometheus Handle OpenTelemetry Resource Attributes? - A UX Research Report (9 minute read)

A Prometheus project focused on improving the user experience of handling OpenTelemetry resource attributes. The research revealed major pain points such as complex joins, poor documentation, and mismatched mental models, leading to recommendations for better documentation, clearer patterns like telescoping, and longer-term architectural solutions for metadata and interoperability.
Replacing a cache service with a database (4 minute read)

Caches provide pre-computed data at ultra-low latencies and offer fine-grained control, eviction policies, and lightweight scaling that databases cannot yet match. While partial replicas, incremental view maintenance, and advanced structures may narrow the gap, caches remain indispensable because databases are still too heavy, costly, and connection-limited for typical cache workloads.
⚑

Quick Links

appjet: AI coding for fullstack projects (Sponsor)

An AI coding + deployment platform integrated with GitHub. Understands your entire codebase, speaks every programming language from Rust to Python, deploys on a global edge network in seconds. Start building (free)
Python: The Documentary (2 minute read)

Python: The Documentary is now fully available on YouTube.
Amazon EBS launches snapshot copy for AWS Local Zones (1 minute read)

Amazon EBS announced the general availability of snapshot copy for AWS Local Zones, enabling snapshots to be copied to a Region or another Local Zone for compliance and business needs.
Do the simplest thing that could possibly work (7 minute read)

Good software design comes from doing the simplest thing that could possibly workβ€”starting with the least complex solution and only adding more when new requirements demand it.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR DevOps isn't for you, please unsubscribe.