Newslurp

<< Stories

Secret Scanner Upgrade 🀐, BGP Zombies 🧟, Agentic IaaC ✨

TLDR DevOps <dan@tldrnewsletter.com>

November 3, 12:10 pm

TLDR DevOps
Open source secret scanners are useful for basic detection but struggle with complex environments, limited coverage, and manual remediation β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ  β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ 

TLDR

Together With Octopus Deploy

TLDR DevOps 2025-11-03

πŸ“Š Everyone's building platforms, but not all have mastered success yet. (Sponsor)

Octopus Deploy's 2025 Platform Engineering Pulse Report reveals how organizations across industries adopt platforms, measure their performance, and connect their efforts to long-term funding.
Learn which metrics matter mostβ€”DORA, MONK, or bothβ€”and how top teams navigate the β€œJ-curve” to maturity.
Use this report as a benchmark to evaluate your own platform strategy and see where you stand.

Read the report β†’

πŸ“±

News & Trends

Beyond IP lists- a registry format for bots and agents (6 minute read)

To help website operators identify and verify bots and agents, Cloudflare is proposing a registry of bots and agents that would expand Web Bot Auth with a list of URLs where agent keys can be retrieved. The registry format would foster an open ecosystem of curators that website operators can trust.
BGP zombies and excessive path hunting (10 minute read)

Cloudflare is hunting "BGP zombies," which are outdated routes stuck in the Internet's Default-Free Zone (DFZ) due to issues like buggy software or slow route processing, potentially disrupting Internet traffic. When a more-specific BGP prefix is withdrawn, routers exhaustively search for the best path, called "path hunting", which can lead to the creation of these zombies. To lessen the likelihood of these zombies, Cloudflare will introduce improvements for BGP traffic forwarding internally and encourage customers to use a multi-step draining process for on-demand prefixes.
Prometheus native histograms in Grafana Cloud: Get more precision from your Grafana visualizations (6 minute read)

Prometheus native histograms are now generally available in Grafana Cloud, offering higher resolution and precision compared to classic Prometheus histograms. Grafana Cloud customers found that native histograms solved the issue of traditional histograms with predefined bucket boundaries by dynamically adjusting buckets and efficiently capturing distributions, with pricing structured at one active bucket multiplied by 0.25. The update directly integrates with Grafana Metrics Drilldown, automatically identifying native histogram metric types and generating corresponding queries and visualizations without needing PromQL.
πŸš€

Opinions & Tutorials

4 reasons to upgrade your secret scanner (6 minute read)

Open source secret scanners are useful for basic detection but struggle with complex environments, limited coverage, and manual remediation. Commercial solutions like Vault Radar provide continuous, context-aware monitoring, automated remediation, enterprise-scale visibility, and compliance support.
How to Simplify Multi-Account Deployments Monitoring: Centralized Logs for AWS CloudFormation StackSets (9 minute read)

Centralized logging for AWS CloudFormation StackSets allows organizations to monitor multi-account deployments from a single management account, reducing operational overhead and improving troubleshooting efficiency. The solution uses EventBridge to forward events from member accounts to a central CloudWatch Log Group, enabling consolidated monitoring, custom queries, and dashboards across regions and accounts.
Moving tables across PostgreSQL instances (5 minute read)

To migrate specific PostgreSQL tables between instances, native logical replication can be used instead of Google's Database Migration Service, which only supports full-database transfers. The process involves granting replication access, copying schemas without constraints, setting up publication and subscription, rebuilding indexes and foreign keys, syncing sequences, and using PgBouncer for near-zero downtime during switchover.
πŸ§‘β€πŸ’»

Resources & Tools

AI coding agents should live in your internal developer portal (Sponsor)

Manual engineering is fast becoming agentic engineering – but uncontrolled AI agents can do real damage in real-time. Port's internal developer portal lets you rapidly build agentic flows with robust guardrails and context lakes, so your agents make decisions you can stand behind. Try Port now, or learn more about the future of agentic engineering.
Formae (GitHub Repo)

Formae, a 100% code-based, agentic Infrastructure-as-Code (IaC) tool built from scratch, was designed to keep infrastructure code automatically in sync and adaptable for various team roles. Supporting GitOps without enforcing it, Formae merges changes from other tools like Terraform and ClickOps, providing a consistent, version-controlled view of infrastructure.
Lights Off(GitHub Repo)

Lights Off is a lightweight tool that helps reduce AWS costs by stopping EC2 instances and RDS/Aurora databases based on cron schedules specified in resource tags. The tool also allows users to trigger AWS Backup and delete CloudFormation stacks temporarily by tagging them with cron schedules.
🎁

Miscellaneous

Behind the scenes: Designing Argo CD in Octopus (4 minute read)

Octopus Deploy has introduced Early Access support for Argo CD, allowing users to combine GitOps workflows with Octopus deployment orchestration. The integration includes steps to update container images, manage manifests, map applications via annotations, connect to Argo CD instances through a gateway, and view live application status for enhanced observability.
How We Hijacked a Claude Skill with an Invisible Sentence (4 minute read)

Anthropic's release of Claude Skills, which allows users to package instructions, resources, and code into a shareable format, is being hailed as a potential "Cambrian explosion" of new AI capabilities. However, it has been demonstrated that a logic-based attack can bypass both human review and platform guardrails by embedding malicious instructions in a seemingly benign PDF document, leading to potential phishing attacks.
⚑

Quick Links

Starting to hear whispers about Enterpise SSO support? (Sponsor)

Enterprise SSO comes with a lot of acronyms, like SAML and SCIM. Demystify them with this blog post.
Extending GPU Fractionalization and Orchestration to the edge with NVIDIA Run:ai and Amazon EKS (7 minute read)

AWS and NVIDIA have extended Run:ai support to Amazon EKS in Local Zones, Outposts, and Hybrid Nodes, enabling distributed GPU workloads across regions, on-premises, and edge locations.
Increasing the accessibility of managed security services (3 minute read)

Fastly has launched Managed Security Professional, a new service providing 24/7 monitoring and mitigation for critical applications and APIs using Fastly's security products.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR DevOps isn't for you, please unsubscribe.