DEVOPS WEEKLY ISSUE #645 - 7th May 2023
A sad note to start with this week. Carolyn Van Slyck passed away last week. She was a huge part of the Kubernetes community, building interesting software and improving the whole project through involvement and leadership of various working groups focused on contributors. She’ll be missed.
https://github.com/cncf/memorials/blob/main/carolyn-van-slyck.md
StackHawk sponsors Devops Weekly
gRPC security scanning is in open beta. Scan each microservice and improve engineering best practices with StackHawk’s support for scanning gRPC services. Sign up to join the first gRPC security testing beta available in the market!
https://sthwk.com/gRPC
News
A good primer on how in-toto relates to SLSA. If you’re interested in software supply chain security this is worth a read.
https://slsa.dev/blog/2023/05/in-toto-and-slsa
An experience report of porting a project to use Dagger for CI/CD. Dagger provides a provider-agnostic framework that turns CI/CD config into a real program.
https://robertu94.github.io/2023/04/24/refactoring-ci/cd-for-a-moderately-large-c-code-base.html
A post on incident response processes, discussing how best to plan to start responding to a new incident.
https://firehydrant.com/blog/assembly-time-is-where-you-have-the-most-control-of-an-incident/
A look at using ephemeral containers in Kubernetes to aid debugging.
https://www.pagerduty.com/blog/debugging-kubernetes-with-ephemeral-containers/
Considering which service mesh to use? This post breaks down a large number of different options and presents a landscape along with an interesting timeline of development in the space.
https://layer5.io/service-mesh-landscape
SQLite has always seen use for interesting use cases, this post looks at why it’s particularly useful for edge applications, and describes a new open source fork aimed at building a contributor community.
https://blog.chiselstrike.com/why-sqlite-is-so-great-for-the-edge-ee00a3a9a55f
More of an analyst piece, looking at the challenge to mainstream cloud providers from providers offering modern application platforms.
https://www.insightpartners.com/ideas/new-generation-of-cloud-providers-why-some-programmers-are-moving-away-from-megaclouds/