Newslurp

<< Stories

Argo CD Security πŸ₯·, GKE Autoscaler Performance ⏩, Building Data Culture πŸ‘₯

TLDR DevOps <dan@tldrnewsletter.com>

January 20, 12:06 pm

TLDR DevOps
The Argo CD team resolved 28 vulnerabilities in 2024, including critical issues like Redis cache encryption and XSS in the UI β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ  β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ 

TLDR

Together With Rootly

TLDR DevOps 2025-01-20

πŸ’Έ You're paying how much for PagerDuty? (Sponsor)

πŸ‘‹ Meet Rootly: a modern on-call and incident response platform, trusted by Dropbox, Figma, Replit, and NVIDIA.

Why the fastest-growing companies trust Rootly:

πŸ’° Fair pricing: 50% less than PagerDuty, without hidden upsells or fees.

πŸ’… Stunning UI: Purpose-built with smart defaultsβ€”so intuitive that even non-engineers can use it.

πŸ“Ÿ On-call done right: Page teams (not just services), painless overrides, pay calculator, native shadow rotations, and more.

πŸ’» Native Slack/MS Teams: Request coverage, check who's on-call, and manage the entire incidentβ€”all without leaving your chat.

⏰ Seamless migration: Import everything in under 10 minutes with our automated scripts and ex-PagerDuty team.

Check out the full comparison.

πŸ“±

News & Trends

Securing Argo CD for 2025: Looking Back at Key Achievements and Innovations in 2024 (5 minute read)

This post recaps Argo CD's highlights in 2024. The Argo CD team resolved 28 vulnerabilities, including critical issues like Redis cache encryption and XSS in the UI, demonstrating a strong commitment to security through regular updates and partnerships like the HackerOne Internet Bug Bounty program.
GKE delivers breakthrough Horizontal Pod Autoscaler performance (3 minute read)

Google Cloud has introduced an improved Horizontal Pod Autoscaler (HPA) for Google Kubernetes Engine (GKE) that offers 2x faster scaling, enhanced metrics resolution, and support for up to 1,000 HPA objects for large-scale deployments. This Performance HPA profile minimizes resource waste, boosts application responsiveness, and enhances operational efficiency. It is available now as a preview opt-in feature.
πŸš€

Opinions & Tutorials

How data habits help build a data culture (5 minute read)

Building a data-driven culture requires fostering organizational habits that prioritize accessible, relevant, and actionable data rather than focusing solely on technology. Companies can make data-driven decision-making an instinctive part of their operations by integrating data seamlessly into workflows, promoting organization-wide awareness through curated alerts, and encouraging creative data usage.
Thoughts On A Month With Devin (7 minute read)

Devin, an autonomous AI software engineer, impressed early with its ability to handle straightforward coding tasks and integrate APIs autonomously, showcasing potential in greenfield development. However, extensive testing revealed inconsistent performance, frequent failures, and inefficiencies, with only three out of 20 tasks succeeding, highlighting the need for AI tools to prioritize user-guided workflows over full autonomy for real-world utility.
πŸ§‘β€πŸ’»

Resources & Tools

Geodesic (GitHub Repo)

Geodesic is a streamlined, Debian-based Docker image designed to enhance DevOps workflows by offering a robust Linux toolbox.
Quarkdown (GitHub Repo)

Quarkdown introduces a versatile, Turing-complete extension of Markdown that seamlessly converts documents into print-ready books or interactive presentations. This modern typesetting system expands Markdown's capabilities with an extensive standard library, live previews, and fast compilation speed, all while allowing users to define custom functions and libraries.
🎁

Miscellaneous

Ultimate guide to CI/CD by GitLab: Fundamentals to advanced implementation (14 minute read)

CI/CD transforms software development by automating code integration, testing, and deployment for faster, more reliable releases. AI can enhance these processes, ensuring quality, compliance, and security throughout the pipeline.
Logical replication in Postgres: Basics (7 minute read)

This article introduces logical replication in PostgreSQL, explaining how it enables replication of specific data changes (e.g., inserts, updates) between databases with different PostgreSQL versions. Through a hands-on example, the author sets up logical replication, modifies PostgreSQL source code to log changes, and demonstrates how publishing and subscribing databases exchange messages.
Story of a Pentester Recruitment 2025 (17 minute read)

Silent Signal has retired its Mushroom challenge after successfully hiring 14 penetration testers since 2015. The web application test, which remained largely unchanged, evaluated candidates' skills with reflected XSS and SQL injection vulnerabilities, highlighting weaknesses in MD5 hashing and server-side security filters while offering insights into industry hiring and assessment practices.
⚑

Quick Links

Elevating access management with HashiCorp Boundary & ServiceNow (8 minute read)

Organizations can automate just-in-time access management to critical resources, enhancing security and operational efficiency by integrating ServiceNow with HashiCorp Boundary.
Introducing Customizable Resource Auto-naming in Pulumi (5 minute read)

Pulumi now allows users to customize auto-generated cloud resource names with its new auto-naming configuration feature, addressing community needs for compliance with organizational naming standards while maintaining robust resource management.
Investigate memory leaks and OOMs with Datadog's guided workflow (5 minute read)

Datadog's Memory Leaks workflow centralizes relevant data and provides guided steps to quickly identify, investigate, and resolve memory issues, improving service health and reducing downtime.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


If you don't want to receive future editions of TLDR DevOps, please unsubscribe from TLDR DevOps or manage all of your TLDR newsletter subscriptions.