





















































🔐 Cloud Security
How Red Canary Detects Cloud Threats at Scale
Red Canary processes over 6 billion telemetry records a day to find threats in cloud control planes like unauthorized access, API abuse, and data exfiltration. They break detection into six key steps: Ingest, Standardize, Combine, Detect, Suppress, Respond.
WAF Just Got Smarter: Now It Sees the “#” in Your URLs
AWS WAF can now match against URI fragments (the part after # in a URL), allowing more granular security rules to block unauthorized access or detect bots.
Scanning S3 for Malware? Now Available in GovCloud Too
GuardDuty Malware Protection is now live in AWS GovCloud regions, letting teams scan S3 uploads for threats and automatically isolate suspicious files.
IAM Access Analyzer Now Speaks IPv6
AWS IAM Access Analyzer now supports IPv6 through new dual-stack endpoints—helping teams monitor and secure resource access in IPv6-enabled environments.
Amazon Inspector Expands to Lightweight Containers and More
Amazon Inspector now supports scanning scratch, distroless, and Chainguard containers, plus detects vulnerabilities in widely used ecosystems like Go, JDK, WordPress, and more.
It also flags discontinued OSes to help prioritize security fixes.
⚙️ Infrastructure & DevOps
From Serverless to CDK: One Dev’s Full Migration Playbook
David Behroozi shares his complete journey migrating a live API from the Serverless Framework to AWS CDK, including how to safely import existing resources like DynamoDB and CloudWatch LogGroups.
9+ Terraform Tools That Make Your Code Cleaner, Safer, and Production-Ready
Essential tools for managing Terraform code: from linters like TFLint and documentation generators like terraform-docs to security scanners like Checkov and cost estimators like Infracost.
A Terraform Toolbox for Real-World IaC Teams
This post breaks down the best tools to supercharge your Terraform pipeline—static analysis, automated docs, pre-commit hooks, and more.
Terraform Just Made Importing Resources Easier: Here's How
With Terraform 1.5+, the new import block lets you declaratively bring existing resources (like S3, EC2, or Azure RGs) into your config, no CLI hackery required.
10 Terraform Config Structures That Scale With Your Team and Infra
Ryan Cartwright breaks down 10 Terraform setup patterns—from single env to multi-tenant SaaS, microservices, and multi-cloud. Clear examples, pros/cons, and use cases make this a go-to resource for scaling Terraform cleanly.
Sponsored: M365 Protection: Guided Lab Experience. See how Rubrik's M365 backup functionality saves time
📦 Kubernetes & Cloud Native
Zero-Downtime Kubernetes deployments on AWS with EKS
Glasskube’s engineers dissect the nuances of AWS Load Balancer Controller behavior and explain why rolling updates often trigger 502/504 errors. Their fix? A trio of battle-tested solutions: inject Pod Readiness Gates to sync with ALB health checks, implement graceful shutdown in Go, and bake in termination delays to handle load balancer lag.
Amazon EKS auto mode with Terraform
Marcin Cuber walks through provisioning a fully-managed EKS Auto Mode cluster using Terraform—no node groups, minimal networking hassle, and serverless-like scaling. Includes full Terraform config for VPC, IAM, and EKS, plus a clean demo deploying a 2048 game app with ALB via Ingress.
Kubernetes CPU limits: Best practices for Kubernetes CPU management
Devtron’s Rupin Solanki lays out why CPU limits can sabotage performance: unnecessary throttling, wasted resources, and misleading stability. TL;DR: stop setting CPU limits unless you absolutely need them. Use requests instead.
Provisioning Kubernetes on Bare Metal using AWS EKS-Anywhere
You’ll learn how PXE booting, DHCP/TFTP, and YAML-driven workflows come together to spin up nodes with Bottlerocket OS. Includes multi-yaml config samples, hardware CSV explanations, and notes on local testing with VirtualBox.
My Kubernetes pods keep crashing with “CrashLoopBackOff” but I can’t find any log
10-step guide to diagnosing CrashLoopBackOff issues—when logs are missing and clues are scarce. Covers probes, exit codes, resource limits, and debugging techniques like kubectl exec with sleep overrides. Also includes lesser-known tricks like using ephemeral debug containers.
🔍 Observability, Monitoring & SRE
OpenTelemetry collector deployment modes in Kubernetes
The ultimate guide to OpenTelemetry visualization
Observing Lambdas using the OpenTelemetry Collector Extension Layer | OpenTelemetry
Grafana Loki 3.4: Standardized storage config, sizing guidance, and Promtail merging into Alloy
Scaling Prometheus from single node to enterprise-grade observability
🌐 Industry, Tools, AI & Other
How GitLab lost 300GB of production data
SQLite or PostgreSQL? It isn't very easy!
Admineris a full-featured database management tool written in PHP. It consists of a single file ready to deploy to the target server.
xlskubectlis a spreadsheet to control your Kubernetes cluster.
Beginner’s guide to software architecture with design patterns
Cheers,
Editor-in-Chief
📢 If your company is interested in reaching an audience of developers and, technical professionals, and decision makers, you may want toadvertise with us.
If you have any comments or feedback, just reply back to this email.
Thanks for reading and have a great day!