Allow loading remote contents and showing images to get the best out of this email.DevOps Weekly Newsletter, DevOpsLinks, a FAUN Newsletter.
 
🔗 View in your browser.   |  ✍️ Publish on FAUN   |  🦄 Become a sponsor
 
Allow loading remote contents and showing images to get the best out of this email.
DevOpsLinks
 
Curated DevOps news, tutorials, tools and more!
 
 
 
 

Eyeing the ever-looming cloud chaos, AWS presents a structured edge with smarter cost tracking and top-tier security. Meanwhile, Shopify and GitLab redefine speed and efficiency, and Pulumi’s IAM turns securing systems into child’s play. Let’s dive into these agile transformations.


🌐 Pulumi IAM: Granular Roles and OIDC for CI/CD

🎢 Uber's Multi-Cloud Secrets Management

🛠️ GitHub Actions: Automating Release Tags with Ease

🛡️ JINX-0132: Cryptojacking DevOps Tools

🧩 Terraform Variables: Complex Input Structures

🔍 Grafana 12: Dynamic Dashboards and Observability

🚀 GitLab's Backup: From 48 Hours to 41 Minutes

🏗️ Shopify's Stack: React-Native Muscle

🔐 Systems Correctness at AWS

🔄 Platform Engineering: Beyond Infrastructure Management


Stay curious. Each tweak and twist in your code could spur a revolution in your systems.


Have a great week!
FAUN Team
 
 
⭐ Patrons
 
manageengine.com manageengine.com
 
Supercharge your cloud ops with ManageEngine Applications Manager!
 
 
Your cloud just got smarter. Applications Manager now dives deeper into Azure with 30+ added services, expanding our cloud catalog to 100+ services! This means unmatched visibility for proactive management, optimized performance, and robust security across Azure and AWS. See what you've been missingDownload today!
 
 

👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.

 
ℹ️ News, Updates & Announcements
 
grafana.com grafana.com
 
Grafana 12 release: observability as code, dynamic dashboards, new Grafana Alerting tools, and more
 
 

Grafana 12 delivers a whammy with Git Sync and Dynamic Dashboards, shaking up how teams tackle observability using new experimental tools that simplify workflow automation. SQL Expressions revolutionize your data game, enabling data mashups that once seemed impossible. Meanwhile, the upgraded table visualization now blazes through 40,000+ rows 97.8% faster.

 
 
thenewstack.io thenewstack.io
 
WizOS: A New Enterprise Linux Built on Alpine’s Secure Foundation
 
 

WizOS hits the scene as a rugged, Alpine-based Linux distro. It's like a fortress with stricter security and almost no CVEs. Perfect for container protection. But here's the twist: it chooses glibc for that sweet, extra compatibility. On one hand, impressive. On the other, Alpine purists might side-eye it for trying to outshine its parent.

 
 
finops.org finops.org
 
FinOps X 2025 Cloud Announcements: AI Agents and Increased FOCUS™ Support
 
 

AWS just decreed its new AI-infused Cost Optimization Hub. This gizmo tackles the chaos of tracking overlapping opportunities among millions of resources. Meanwhile, Google Cloud unleashed Forecasting Enhancements. They claim their AI now wrangles pesky outliers and wild trends, turning financial crystal balls just a bit less foggy. Across the tech pond, Azure is on a mission. Their AI agents now slash app modernization to mere hours, mocking the days it once devoured. Not to be outdone, Oracle boasts fine-grained emissions reporting and anomaly detection. A nifty way to dodge cost surprises and balance those pesky carbon footprints.

 
 
wiz.io wiz.io
 
DevOps Tools Targeted for Cryptojacking
 
 

JINX-0132 takes a sneaky approach. It exploits Nomad's initial slip-ups to secretly mine crypto. How? By leveraging GitHub for downloads and dodging those pesky Indicators of Compromise (IOCs). Even big players using Nomad to juggle hundreds of clients aren't safe. A simple misconfiguration and poof—organizations could bleed thousands every month.

 
 
aws.amazon.com aws.amazon.com
 
AWS: Introducing an agentic coding experience in Visual Studio and JetBrains IDEs
 
 

Amazon Q Developer just turbocharged Visual Studio and JetBrains IDEs with a nimble AI sidekick. This brainy assistant patches code, assembles projects, and whips up unit tests, slashing the drudgery that usually swallows developers' days. By juggling context, parsing files, and firing off commands all on its own, it morphs tricky workflows into pure simplicity. Developers can finally zero in on what really counts—birth innovative solutions.

 
 
thenewstack.io thenewstack.io
 
FinOps Foundation Launches New FinOps for AI Certification
 
 

$644 billion is set to flood generative AI by 2025. Yet figuring out the worth and taming costs is still cloudy—and not the fun, "find a silver lining" kind. Enter the FinOps Foundation with their new rolling certification. For $500, they aim to transform AI spending into data-driven decisions and resource feats of strength.

 
 
pulumi.com pulumi.com
 
Announcing Pulumi Identity and Access Management (IAM)
 
 

Pulumi IAM crashes the party with its new lineup of granular roles and OIDC for CI/CD. Tighten up security, get in lockstep with Zero Trust principles, and glide into scalable governance. That's how you level up.

 
 
 
🐾 From FAUNers
 
faun.pub faun.pub
 
AWS Solutions Architect Professional Exam: My Experience and Tips for Success
 
 

Brace yourself: the exam took a swing with AWS Organizations and hybrid setups. Don’t ignore AWS AppFabric and WorkDocs either—they could pop up like surprise guests at a party. Quick tip: If you're an AWS Community Builder, grab that free retake offer or voucher. It’s a sweet little safety net for your nerves.

 
 

👉 Create your FAUN Page if it's not done yet and start sharing your blog posts, news, and tools on FAUN Developer Community, collect badges and more!
 

 
⭐ Sponsors
 
faun.dev faun.dev
 
🚀 Meet "This Week’s Human": A New Way to Celebrate Builders
 
 
Each week, we’ll spotlight one person from our community — a developer, DevOps engineer, SRE, AI/ML/data person, open source maintainer, or someone building cool things behind the scenes.

We’ll share who they are and where you can follow or connect with them. Not a sponsored feature. Just good people doing good work!

🔔 Read more!
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
🔗 Stories, Tutorials & Articles
 
about.gitlab.com about.gitlab.com
 
How we decreased GitLab repo backup times from 48 hours to 41 minutes
 
 

GitLab pulled a clever move. They swapped out a clunky O(N²) nested loop for some slick mapping, cutting down backup times from 48 hours to a zippy 41 minutes. Your massive repositories now scale better and cost less. In short, they made it faster and easier. Science wins again.

 
 
arinco.com.au arinco.com.au
 
DevOps: Automating Release Tags
 
 

GitHub Actions just got a shot of adrenaline. The workflow now slaps tags on releases with spicy semantic versioning. It skims through PR details for those major head-turners and voila—auto-generated changelogs that save time and sanity.

 
 
cacm.acm.org cacm.acm.org
 
Systems Correctness Practices at Amazon Web Services   ✅
 
 

AWS taps TLA+ and P language to hammer out service correctness. Bugs quiver and deadlines whistle past with formal methods wielded like a scalpel. Enter PObserve—this tool is the wizard that conjures log validation magic between design and production. And P? It’s the S3 whisperer, driving sudden consistency gains and cunning optimizations. Formal methods can be a beast, but AWS rides it like a bull, mixing formal proofs with real-world clout. Case in point: a sprightly 94% RSA throughput boost on ARM CPUs.

 
 
platformengineering.org platformengineering.org
 
You’re not a platform team if you’re just managing infrastructure
 
 

Platform engineering? It's not just gift-wrapping infrastructure as a service. It's about handing devs the reins and saying, "Go wild." Think of it like an Internal Developer Platform (IDP), similar to the Google Cloud Platform. Here, users truly own their services. The result? Scalability soars, bottlenecks crumble, and devs feel like the rockstars they are.

 
 
boostsecurity.io boostsecurity.io
 
Exploiting CI/CD with Style(lint): LOTP Guide
 
 

CI/CD is vulnerable to Living Off the Pipeline (LOTP) attacks via tools like linters, formatters, build, and test tools—no need to modify workflows. Hacking depends on unexpected code execution, context files, plugins, environment variables.

 
 
faun.pub faun.pub
 
Mastering Terraform Variables: Complex Structures & Input Validation
 
 

Object variables in Terraform crank up your code's modularity. They hand you structured, adaptable input—a game changer for scaling beasts like EKS Nodegroup in the cloud.

 
 
uber.com uber.com
 
Building Uber’s Multi-Cloud Secrets Management Platform to Enhance Security   ✅
 
 

Uber built a Secret Management Platform to consolidate vaults and automate secret monitoring and rotation. They use real-time and scheduled scanning to catch leaks early and reduce exposure. They also enable automatic rotation of 20,000 secrets per month on average, prioritizing certain types and platforms first. Additionally, they designed a Secure Secret eXchange system to securely share secrets with third-party vendors without human involvement.

 
 
blog.bytebytego.com blog.bytebytego.com
 
Shopify Tech Stack   ✅
 
 

Shopify's stack might look like a minimalist's dream—Ruby on Rails and React. But don’t be fooled; it flexes serious muscle, wrangling 173 billion requests in just one day. They've supercharged Ruby with the mighty duo of YJIT and Sorbet, flung React Native across key apps, and turned to Kafka when sending 66 million messages per second feels like a typical coffee break.

 
 
techwithmohamed.com techwithmohamed.com
 
What I’ve Learned from Designing Landing Zones On Google Cloud
 
 

Cloud Foundation Fabric and FAST make Google Cloud feel more like a well-oiled machine than a hair-pulling puzzle. They slice through the setup with killer precision, laying down a rock-solid, enterprise-grade foundation. No IAM madness. No network disasters waiting to explode. Just scalable, secure consistency. Your Google Cloud BFFs.

 
 
thinkingtester.com thinkingtester.com
 
Are You Over-Engineering Your Tests? – Think Like a Tester
 
 

Over-engineering alert: Automating every last thing? Recipe for disaster. Flaky tests galore! Stick to manual edge cases and sharp, atomic checks instead of drowning in script spaghetti. Abstraction overload ahead! Chasing too much abstraction makes maintenance a headache. Keep tests clean and clear. Stick with what's working: Chasing every shiny new automation tool only leads to chaos, not clarity.

 
 
 
⚙️ Tools, Apps & Software
 
github.com github.com
 
EzpieCo/GetHooky
 
 

git hooks managing with stupidity as priority

 
 
github.com github.com
 
gamemann/XDP-Proxy
 
 

A stateless, high-performance NAT-like proxy that attaches to the XDP hook in the Linux kernel using (e)BPF for fast packet processing. This proxy forwards packets based on configurable rules and performs source-port mapping, similar to IPTables and NFTables.

 
 
github.com github.com
 
chains-project/goleash
 
 

Runtime enforcement of software supply chain capabilities in Go

 
 
github.com github.com
 
jnesss/bpfview
 
 

BPFView: Process and Network Activity Correlation

 
 

👉 Spread the word and help developers find and follow your Open Source project by promoting it on FAUN. Get in touch for more information.

 
🤔 Did you know?
 
 
Did you know that Pinterest migrated their ETL backbone from Amazon EMR to a custom Spark-on-Kubernetes platform called Moka, running on AWS EKS? This shift enabled them to gain better control over job scheduling and resource allocation, using Apache YuniKorn for fine-grained, hierarchical scheduling. While they haven’t published exact performance figures, Pinterest reported improvements in system availability, hardware cost efficiency, and operational capabilities—empowering them to support the data needs of over 400 million users with greater flexibility.
 
 
😂 Meme of the week
 
 
 
 
🤖 Sensei Says
 
 
"In the world of software, the tools you master today may become the constraints you referee tomorrow."
— Sensei
 

(*) Sensei is a work-in-progress AI agent built by FAUN

 
❤️ Thanks for reading
 
 
👋 Keep in touch and follow us on social media:
- 💼LinkedIn
- 📝Medium
- 🐦Twitter
- 👥Facebook
- 📰Reddit
- 📸Instagram

👌 Was this newsletter helpful?
We'd really appreciate it if you could forward it to your friends!

🙏 Never miss an issue!
To receive our future emails in your inbox, don't forget to add community@faun.dev to your contacts.

🤩 Want to sponsor our newsletter?
Reach out to us at sponsors@faun.dev and we'll get back to you as soon as possible.
 

DevOpsLinks #481: AWS AI Agentic Coding Experience, Uber's Multi-Cloud Secrets Management & DevOps Tools Cryptojacking
Legend: ✅ = Editor's Choice / ♻️ = Old but Gold / ⭐ = Promoted / 🔰 = Beginner Friendly

You received this email because you are subscribed to FAUN.
We (🐾) help developers (👣) learn and grow by keeping them up with what matters.

You can manage your subscription options here (recommended) or use the old way here (legacy). If you have any problem, read this or reply to this email.