Newslurp

<< Stories

Coding Agent Safety 🥷, Oncall Rotations 📱, CSS 2025 🎨

TLDR DevOps <dan@tldrnewsletter.com>

December 10, 12:10 pm

TLDR DevOps
The Linux Foundation has launched the Agentic AI Foundation to standardize infrastructure protocols for AI agents, bringing together major companies ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Luma

TLDR DevOps 2025-12-10

How Coinbase delivers 10x engineering output using AI for Prod (Sponsor)

The market's done a great job with AI agents for coding. It's time engineers have tools to fight the other half of the battle: managing prod.

Great AI for production systems does 3 things: resolves incidents, optimizes cost+performance, and streamlines development. Customers like Coinbase, DoorDash, and Zscaler choose Resolve AI as their daily debugging and decision-making partner because it -

  • plays nicely with existing tools
  • plugs directly into incident workflows, and
  • closes the loop on reliability on the daily

....all while getting smarter with every interaction.

Sign up for early access, or check out their prompt library to see real DevOps examples.

📱

News & Trends

Replit is delivering enterprise-grade vibe coding with Google Cloud (3 minute read)

Google Cloud and Replit expanded their partnership with a multi-year agreement that deepens Replit's use of Google infrastructure and integrates Google's latest Gemini and Imagen models. Together, they will promote enterprise adoption of vibe coding through joint go-to-market efforts and enhanced AI-powered developer tools.
Docker Joins the Agentic AI Foundation (3 minute read)

The Linux Foundation has launched the Agentic AI Foundation to standardize infrastructure protocols for AI agents, bringing together major tech companies like Amazon, Google, Microsoft, and OpenAI. This initiative unifies projects like Anthropic's Model Context Protocol (MCP), Block's goose agent framework, and OpenAI's AGENTS.md standard to ensure transparent evolution and interoperability, with Docker joining as a Gold member.
🚀

Opinions & Tutorials

How we deploy the largest GitLab instance 12 times daily (12 minute read)

GitLab deploys code to GitLab.com up to 12 times daily using its own CI/CD platform, leveraging Canary deployments, progressive rollouts, and multiversion compatibility to ensure zero downtime. The deployment pipeline manages both containerized and traditional services, runs backward-compatible database migrations in Canary before post-deploy changes, and validates every stage through automated tests to maintain stability at scale.
Building microservices the easy way with Dapr (4 minute read)

The Dapr project, an open-source Distributed Application Runtime under the Cloud Native Computing Foundation (CNCF), recently graduated in October 2024, simplifying microservices development. Co-created by Yaron Schneider, Dapr leverages an intelligent sidecar to handle complexities like messaging, observability, and AI/LLM integration, drastically cutting development time.
Join the on-call roster, it'll change your life (5 minute read)

On-call can accelerate your growth as an engineer by building stress tolerance, leadership, and deep systems expertise through real incidents. However, it also imposes lifestyle limits and serious sleep- and health-related risks, so it's only worthwhile if those impacts are kept under control.
🧑‍💻

Resources & Tools

Stop hunting for needles in Terraform haystacks (Sponsor)

There's a vulnerability in line 4,000 of your IaC. Good luck finding it manually. Tenable scans Terraform and CloudFormation to pinpoint the exact line causing risk before deployment. Analysts praise this code-to-cloud approach for reducing developer friction. 

Read the analyst report

OpenSpec (GitHub Repo)

OpenSpec is a spec-driven development workflow for AI coding assistants that aims to make their outputs more predictable and reviewable by locking intent before any code is written. This lightweight specification process enables deterministic code generation from agreed-upon requirements, addressing the common issue of vague prompts.
Agent Lightning (GitHub Repo)

Agent Lightning is a new trainer designed to streamline the development and improvement of AI agents. It allows developers to focus on their ideas by minimizing implementation complexities. The trainer integrates with any existing agent framework, collecting prompt, tool call, and reward events into a central "LightningStore" which then feeds an algorithm to continuously refine agent performance.
🎁

Miscellaneous

Cloud security, the right way: What the industry should demand (and why "good enough" isn't) (4 minute read)

Cloud security teams face pressure that drives compromises. CNAPP must evolve to unify shift left controls with real-time runtime visibility, open innovation, and truly agentic AI that reasons and acts autonomously. Raising the industry standard toward transparent, community-driven, runtime-aware security eliminates blind spots and avoids the speed versus safety tradeoff.
A New Approach for Coding Agent Safety (4 minute read)

Coding agents are gaining autonomy and need controlled access, prompting Docker to introduce experimental container-based sandboxes that isolate agent workflows while mirroring local workspaces. The preview supports Claude Code and Gemini CLI and will evolve toward microVM isolation, stronger controls, and broader agent compatibility.

Quick Links

Codacy's new AI Reviewer helps devs regain control of Pull Requests (Sponsor)

GenAI is rewriting your codebase faster than your devs can review it. Codacy's new AI Reviewer pairs deterministic static analysis with context-aware code reviews that catch issues missed by legacy scanners. See how it works
Kubernetes 1.35 - New security features (8 minute read)

Kubernetes 1.35 introduces breaking security changes, including the removal of cgroup v1, stricter image pull credential checks, a transition from SPDY to WebSockets with new RBAC requirements, and hardened kubelet certificate validation.
New Era: Transforming New Relic's Lambda Extensions with Rust (5 minute read)

New Relic's Lambda Extension was fundamentally re-architected with a migration from Go to Rust, significantly reducing billed duration by approximately 40% across both cold and warm starts and decreasing memory usage by about 13%.
CSS Wrapped 2025 (18 minute read)

Chrome's CSS Wrapped 2025 introduces powerful new native styling and interaction features.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR DevOps isn't for you, please unsubscribe.