Newslurp

<< Stories

Docker Hardened Images πŸ†•, Go Misdirection ▢️, Kubernetes Surgeon Handbook πŸ“š

TLDR DevOps <dan@tldrnewsletter.com>

May 21, 11:23 am

TLDR DevOps
Docker Hardened Images (DHI) were introduced by Docker as secure-by-default container images for modern production environments β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ  β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ 

TLDR

Together With Neurox

TLDR DevOps 2025-05-21

Think your GPUs are working? Silent failures are costing you - Neurox (Sponsor)

Companies are spending millions on AI infra, yet engineers can't track usage, manage costs, or spot idle compute.

🧠  Surface GPU hardware failures 

πŸ“Š  Automate monthly GPU cost reports

πŸ‰  Neurox = GPU metrics + workload state + cost 

Neurox is the first purpose-built GPU monitoring platform for AI workloads. Helping DevOps, FinOps, and security teams.

Try the live demo 🐐

πŸ“±

News & Trends

Your IPs, your rules: enabling more efficient address space usage (7 minute read)

Cloudflare has enhanced its BYOIP (Bring Your Own IP) capabilities, allowing customers to dynamically reassign portions of their IP prefixes between services like CDN, Spectrum, and Magic Transit to optimize IP address usage and control costs, as IPv4 addresses now exceed $30-$50 per address due to scarcity.
Amazon Inspector enhances container security by mapping Amazon ECR images to running containers (6 minute read)

Amazon Inspector now maps ECR images to running containers and extends vulnerability scanning to minimal base images, allowing security teams to prioritize vulnerabilities based on images actively running in their environment.
Introducing Docker Hardened Images: Secure, Minimal, and Ready for Production (4 minute read)

Docker Hardened Images (DHI) were introduced by Docker as secure-by-default container images for modern production environments. These images reduce the attack surface by up to 95% and are continuously updated to ensure near-zero known CVEs, with critical and high-severity CVEs patched within 7 days. DHI supports distros like Alpine and Debian and integrates with platforms like Microsoft, NGINX, and Sonatype.
πŸš€

Opinions & Tutorials

How to install and run Minikube with Rootless Podman on ARM-based MacBooks (6 minute read)

Minikube can be installed and run on ARM-based MacBooks using rootless Podman by setting up a Podman machine with Homebrew, configuring it appropriately, and starting it in rootless mode for improved security. Once Podman is running, Minikube can be installed via Homebrew, configured for rootless operation, and started using the Podman driver to provide a local Kubernetes environment, with deployment and port-forwarding managed through kubectl or minikube kubectl.
Too Much Go Misdirection (3 minute read)

Go's interface design and standard library conventions often hinder zero-copy optimizations, especially when working with io.Reader and trying to reuse existing []byte buffers. Due to missing implementations like Peek on bytes.Reader and hidden wrappers like bufio.Reader, developers must resort to custom types and undocumented interface patternsβ€”what amounts to a β€œshadow API”—to achieve efficient behavior without relying on unsafe hacks.
πŸ§‘β€πŸ’»

Resources & Tools

GitDiagram (GitHub Repo)

GitDiagram transforms GitHub repositories into interactive diagrams using Mermaid.js and OpenAI's o4-mini.
A2A (GitHub Repo)

Google's Agent2Agent (A2A) protocol was released as an open-source project to establish a common language for gen AI agents across diverse frameworks. A2A aims to enable seamless communication and collaboration between these agents, fostering a more interconnected and innovative AI ecosystem.
🎁

Miscellaneous

The Kubernetes Surgeon's Handbook: Precision Recovery from etcd Snapshots (4 minute read)

Precision recovery from etcd snapshots enables Kubernetes administrators to restore specific resources like ConfigMaps without initiating a full cluster rollback. By using tools such as etcdctl, auger, and kubectl, admins can isolate, decode, and reapply deleted objects with minimal disruption.
OpenVox InfraTales - macOS Signing and Notarization (5 minute read)

This post describes the process of making the OpenVox macOS agent fully signed and notarized to meet Apple's stricter Gatekeeper requirements in macOS 15, ensuring binaries, dylibs, and bundles are properly secured. The new build system centralizes signing and notarization within Vanagon, with future plans to streamline builds via GitHub Actions and increase accessibility beyond the current VM setup.
Revenue Attribution Report: how we used homomorphic encryption to enhance privacy and cut network congestion by 99% (3 minute read)

LinkedIn's Revenue Attribution Report (RAR) now features a new system that computes queries over encrypted records without decrypting each row, boosting performance and security. By leveraging privacy-enhancing technologies like additive symmetric homomorphic encryption (ASHE), the new approach has reduced network congestion by over 99% and enabled a wider range of reporting capabilities.
⚑

Quick Links

JetBrains Guide: 9 Ways to Prevent Supply Chain Attacks Against Your CI/CD Server (Sponsor)

CI/CD servers are a juicy target. This guide covers credential storage, version control, build agent configurations, and 6 other things you can do today to stop attackers. Read the guide
SSL/TLS Certificate Lifespans to Shrink to 47 Days by 2029 (2 minute read)

The CA/Browser Forum, aiming to improve security and promote automation, has approved a phased reduction in SSL/TLS certificate lifespans from 398 days to 47 days by 2029.
Keeping Up With AI: The Painful New Mandate for Software Engineers (6 minute read)

AI-native software engineering is rapidly emerging, with AI tools expected to become integral across the software development lifecycle, shifting developers from traditional coding roles to orchestrating intelligent agents that automate and enhance workflows.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR DevOps isn't for you, please unsubscribe.