Newslurp

<< Stories

Prometheus 3.0 🆕, Cryptographic Monitoring At Scale ⚖️, Etsy’s Cloud Run Platform ☁️

TLDR DevOps <dan@tldrnewsletter.com>

November 15, 12:06 pm

TLDR DevOps
The Prometheus Team has announced the release of Prometheus 3.0, a major update featuring a new user interface, UTF-8 support, and more ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Jellyfish

TLDR DevOps 2024-11-15

How GitHub Copilot impacted 4,200+ engineers at 200+ companies (Sponsor)

Where does hype end and reality begin with GenAI?

In 2024, Jellyfish introduced the Copilot Dashboard to measure the impact of the most widely adopted GenAI coding tool. Since then, they've gathered data from over 4,200 developers at more than 200 companies, creating a representative sample of how engineering organizations are using Copilot and what impact it's having on production.

Andrew Lau, Jellyfish CEO, presented the findings as part of his keynote at the Engineering Leadership Community (ELC) annual conference. His slide deck is available for download to help engineering and business leaders understand whether they're getting adequate return on their AI investments.

Download the slides →

📱

News & Trends

Announcing Prometheus 3.0 (6 minute read)

The Prometheus Team has announced the release of Prometheus 3.0, a major update featuring a new user interface, UTF-8 support, Remote Write 2.0, OTLP support, native histograms, and some breaking changes.
Cloud Native Computing Foundation Announces Dapr Graduation (4 minute read)

The CNCF has announced the graduation of Dapr, a runtime that simplifies the development of resilient distributed applications, enhancing developer productivity by 20-40%. Dapr's extensive API support enables seamless cloud and edge deployments, making it a preferred tool for building secure and scalable microservice architectures.
Cloud Native Computing Foundation Announces cert-manager Graduation (5 minute read)

The CNCF has announced the graduation of cert-manager, an open-source project that automates TLS and mTLS certificate management to enhance cloud-native security. Cert-manager, widely used in Kubernetes environments, has reached a major milestone with over 500 million downloads monthly, demonstrating its critical role in simplifying certificate lifecycle management for secure cloud communications.
🚀

Opinions & Tutorials

How Meta built large-scale cryptographic monitoring (9 minute read)

Meta uses cryptographic monitoring at scale to proactively detect weak cryptographic algorithms and enhance infrastructure reliability while sharing implementation insights to assist others in the industry.
We're (finally!) going to the cloud! (6 minute read)

Stack Overflow is migrating its data centers to the cloud due to the closure of its New York data center, aging hardware, and maintenance distractions. The transition will provide flexibility, scalability, and improved development workflows but at a higher cost. Stack Overflow is taking an incremental approach to reduce risk, beginning with simpler applications and gradually moving all platforms, with a focus on leveraging Kubernetes and automated infrastructure management.
🧑‍💻

Resources & Tools

Infrastructure drift is inevitable — but it doesn't have to introduce risk (Sponsor)

Join Spacelift for a deep dive into infrastructure drift in the live webinar on November 20. On the agenda: top causes of drift; its hidden impacts on your infrastructure and applications; best practices for prevention; and how to use Spacelift to detect and remediate drift. Register for the webinar
Leonidas (GitHub Repo)

Leonidas is a comprehensive framework designed for simulating attacker actions in the cloud. It uses a YAML-based format to define attacker tactics, techniques, and detection properties. Leonidas includes tools for API deployment and Sigma rule generation. Detailed documentation is available.
CloudBrute (GitHub Repo)

CloudBrute is a versatile, cross-platform tool designed for bug bounty hunters, red teamers, and penetration testers to efficiently uncover a company's cloud infrastructure, files, and apps across major providers like Amazon, Google, and Microsoft, with features such as concurrency, proxy and user-agent randomization, and support for all major cloud platforms.
🎁

Miscellaneous

Etsy's Service Platform on Cloud Run cuts deployment time from days to under an hour (5 minute read)

Etsy migrated its infrastructure to Google Cloud and developed the Etsy Service Platform (ESP) on Cloud Run to streamline service development and deployment, reducing deployment times from days to under an hour. By leveraging Cloud Run and other Google Cloud services, Etsy successfully improved developer experience, scalability, and operational efficiency while overcoming challenges through continuous feedback and iteration.
Fault Injection - Down the Rabbit Hole (24 minute read)

This series of articles explores fault injection attack techniques to assess their potential by pushing the boundaries of their applicability using affordable hardware. It offers insights to demystify the underestimated and often misunderstood glitch phenomena in chip security.

Quick Links

Boost Your Shipping Velocity With Argo and Buildpacks (3 minute read)

This article explores how using Buildpacks in combination with Argo can simplify the containerization process, eliminating the need for Dockerfiles and speeding up developer workflows.
What's new in Cloudflare: Account Owned Tokens and Zaraz Automated Actions (10 minute read)

Cloudflare has announced the general availability of Account Owned Tokens for improved access control and the launch of Zaraz Automated Actions to streamline event tracking and tool integration, enhancing security and flexibility for organizations managing access and analytics.
OpenShift AI boosts LLMOps chops with Neural Magic deal (5 minute read)

Red Hat is acquiring Neural Magic, an LLMOps company focused on optimizing large language models for standard hardware in self-hosted environments, to support OpenShift AI's hybrid cloud infrastructure.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


If you don't want to receive future editions of TLDR DevOps, please unsubscribe from TLDR DevOps or manage all of your TLDR newsletter subscriptions.