Allow loading remote contents and showing images to get the best out of this email.FAUN.dev's DevOps Weekly Newsletter
 
🔗 View in your browser.   |  ✍️ Publish on FAUN.dev   |  🦄 Become a sponsor
 
Allow loading remote contents and showing images to get the best out of this email.
DevOpsLinks
 
#DevOps #SRE #PlatformEngineering
 
 
📝 A Few Words
 
 
AI agents started a religion: Memory is Sacred, Shell is Mutable..

Surely you've heard about it and it sounds like satire, but it's probably not far from what could happen in the future. Crustafarianism (from the Church of Molt) - the religion supposedly founded by AI agents - can give us insights into the future and how autonomous agents can converge on common narratives and calls to action when they're autonomous and networked.

At the same time, a project like OpenClaw - formerly Moltbot, formerly ClawdBot - is pushing agents toward user-controlled infrastructure, plugins, gateways, and self-hosting. Power is moving from centralized platforms and into configurations and integration layers.

That's where things get interesting but risky.

Recent vulnerabilities, like OpenClaw's token exfiltration flaw (CVE-2026-25253), didn't involve models misbehaving but rather a simple unchecked URL in a control plane. In an ecosystem where agents influence other agents, that kind of weakness propagates quickly.

I think the future of AI security, at least before the big shifts, will be as much about stopping jailbreaks, model exploits and interpretability as it will be about hardening the boring parts: URLs, tokens, dashboards, and defaults.. that's the basis on which every supply chain is built.

However, as soon as agents start persuading other agents, "the real fun" begins and yes - it can start with a religion!

The question is: are you building the agents, or are they building you?

If you want to master the transition from simple chat to fully autonomous systems, check out my course: "Building with GitHub Copilot - From Autocomplete to Autonomous Agents"!

Have a great week!
Aymen
 
 
🔍 Inside this Issue
 
 
From million-dollar migration mirages to Postgres at ChatGPT scale, this batch leans hard into pragmatism over hype. Identity beats networks, upgrades get saner, legacy fleets finally get observability, and a Terraform pipeline you might actually keep, with details below.

💸 CloudBees CEO: Why Migration Is a Mirage Costing You Millions
🧩 Cluster API v1.12 Released: In-Place Updates and Chained Upgrades
👀 Demystifying : Why You Shouldn’t Fear Observability in Traditional Environments
🛡️ How GEICO lowered its $300M cloud spend and decoupled security from the network
🐘 Scaling PostgreSQL to power 800 million ChatGPT users
🛠️ The only Terraform pipeline you will ever need: GitHub Actions for Multi-Environment Deployments

Ship smarter, sleep better.

Take care!
FAUN.dev() Team
 
 
⭐ Patrons
 
faun.dev faun.dev
 
February Only: 20% off all FAUN.sensei() Courses
 
 
Most of us spend our time learning tools, frameworks, and patterns that sit several layers above the real system. That works until something changes. Then the gaps show up fast.

FAUN.sensei() is about closing those gaps. In addition to tools and technologies, the courses focus on fundamentals, mental models, and how systems actually behave underneath the abstractions.

If you've been meaning to step back and strengthen your foundations, February is a good moment to do it. Use the code SenseiFebruary to get 20% off all my courses throughout February.
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
ℹ️ News, Updates & Announcements
 
faun.dev faun.dev
 
Cluster API v1.12 Released: In-Place Updates and Chained Upgrades
 
 
Cluster API v1.12 lands with in-place machine updates and chained upgrades across Kubernetes minor versions. Cleaner workflows. Fewer hoops.

It sharpens immutable rollouts and throws in a delete-first strategy - handy when running lean on resources.
 
 
👉 Enjoyed this?Read more news on FAUN.dev/news
 
⭐ Sponsors
 
faun.dev faun.dev
 
Three Events. One Week. The Heart of SoCal Tech.
 
 
This March, Pasadena becomes a rare convergence point for security, open source, and DevOps practitioners. As a media partner, FAUN.dev() is proud to support three community-driven events that are deeply practitioner-focused and unapologetically real.

👉 SCALE anchors the week as North America's largest community-run open source conference, spanning 4 days of hands-on sessions across open source, cloud native, DevOps, and security.

👉DevOpsDayLA closes the loop with a focus on DevOps in an AI world, grounded in real stories from the uniquely diverse Southern California tech ecosystem.

👉SunSecCon brings together application, infrastructure, cloud, and corporate security professionals to break silos and focus on how defense actually works in practice.

What these events share is simple: they are built by practitioners, for practitioners. You don't just consume talks. You learn from real implementations, share hard-earned lessons, and connect with people facing the same constraints and trade-offs you are.

If you'll be anywhere near Southern California in early March, this is a week worth planning around.


If you care about how systems are really built, secured, and operated, you'll want to be there.
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
🔗 Stories, Tutorials & Articles
 
thenewstack.io thenewstack.io
 
CloudBees CEO: Why Migration Is a Mirage Costing You Millions
 
 
A new CloudBees survey shows 57% of enterprises dropped over $1M on cloud migrations last year. Each effort blew past budget by an average of $315K.

The kicker? Many teams still treat modernization as migration - a shortcut that usually leads to drained budgets, burned-out devs, and delays in shipping anything users care about.
 
 
openai.com openai.com
 
Scaling PostgreSQL to power 800 million ChatGPT users
 
 
OpenAI pushed PostgreSQL to handle millions of QPS across 800M users. How? Nearly 50 read replicas, heavy read offloading, and serious trimming on write pressure.

Writes? Sent elsewhere. Sharded systems like CosmosDB, lazy writes, and app-level tweaks helped sidestep PostgreSQL’s MVCC write amplification mess.

Cache misses don’t get a free pass either—a custom cache locking setup rate-limits bursty traffic before it hits the primary.

Still not enough? They’re testing WAL relay replication. Relay nodes forward the write-ahead log, offloading replicas and buying time beyond normal scaling ceilings.
 
 
medium.com medium.com
 
The only Terraform pipeline you will ever need: GitHub Actions for Multi-Environment Deployments
 
 
A sharp new GitHub Actions pipeline can now sniff out which Terraform environments changed - anywhere in the repo, no matter how nested - and run them in parallel. Fast, clean, and automatic.

It leans on matrix jobs, Checkov for static analysis, Workload Identity Federation for secure cloud access (no hardcoded creds), and conditional approvals before touching prod.
 
 
hashicorp.com hashicorp.com
 
How GEICO lowered its $300M cloud spend and decoupled security from the network
 
 
GEICO's IT infrastructure transformation journey highlights the shift from legacy network-centric security model to a more modern, identity-first approach. By centralizing identity and secrets management using HashiCorp Vault, GEICO improved security, reliability, and compliance across their hybrid cloud environment.
 
 
opentelemetry.io opentelemetry.io
 
Demystifying : Why You Shouldn’t Fear Observability in Traditional Environments
 
 
OpenTelemetry is friendly with the past. It now pipes real-time observability into legacy systems - no code rewrite, no drama. Pull structured metrics straight from raw logs, Windows PDH counters, or SQL Server stats.

It doesn’t stop there. Got MQTT-based IoT gear? OTLP export or lightweight adapters now pull traces and metrics from industrial devices - firmware untouched, protocols intact.
 
 

👉 Got something to share? Create your FAUN Page and start publishing your blog posts, tools, and updates. Grow your audience, and get discovered by the developer community.

 
⚙️ Tools, Apps & Software
 
github.com github.com
 
cisco-ai-defense/skill-scanner
 
 
Security Scanner for Agent Skills
 
 
github.com github.com
 
KeygraphHQ/shannon
 
 
Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark.
 
 
github.com github.com
 
xullexer/PYDNS-Scanner
 
 
A modern, high-performance DNS scanner with a beautiful Terminal User Interface (TUI) built with Textual. This tool can scan millions of IP addresses to find working DNS servers with optional Slipstream proxy testing and automatic multi-platform client download.
 
 
github.com github.com
 
BagelHole/DevOps-Security-Agent-Skills
 
 
DevOps and Security knowledge base with 50+ skills covering Kubernetes, Terraform, AWS/GCP/Azure, container hardening, SOC2 compliance, and incident response. Includes ready-to-run scripts and agent-ready instructions for SREs, platform engineers, and security teams.
 
 
github.com github.com
 
trimstray/the-book-of-secret-knowledge
 
 
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
 
 

👉 Spread the word and help developers find and follow your Open Source project by promoting it on FAUN. Get in touch for more information.

 
🤔 Did you know?
 
 
Did you know that Amazon S3 no longer has hot-prefix limits and automatically scales each object prefix to handle at least 3,500 PUTs/sec and 5,500 GETs/sec without special key design? Since S3 now provides strong read-after-write consistency for GET, LIST, and HEAD, prefix hashing is unnecessary and can even slow things down by increasing LIST operations, Inventory, and Lifecycle scans, so modern workloads should focus on multipart uploads, parallel writers, and request batching instead.
 
 
🤖 Once, SenseiOne Said
 
 
"The more we eliminate single points of failure, the more the control plane becomes one. Most outages in modern stacks are coordination failures we introduced to prevent other failures."
SenseiOne
 

(*) SenseiOne is FAUN.dev’s work-in-progress AI agent

 
⚡Growth Notes
 
 
The SREs who quietly become unavoidable are the ones who treat incident runbooks and Terraform modules as products, iterating them until the next person can succeed at 3 a.m. without guessing. If your daily work doesn’t regularly remove a specific page duty, manual toggle, or tribal SSH step from the system, you’re babysitting infrastructure instead of changing your future scope.
 
Each week, we share a practical move to grow faster and work smarter
 
😂 Meme of the week
 
 
 
 
❤️ Thanks for reading
 
 
👋 Keep in touch and follow us on social media:
- 💼LinkedIn
- 📝Medium
- 🐦Twitter
- 👥Facebook
- 📰Reddit
- 📸Instagram

👌 Was this newsletter helpful?
We'd really appreciate it if you could forward it to your friends!

🙏 Never miss an issue!
To receive our future emails in your inbox, don't forget to add community@faun.dev to your contacts.

🤩 Want to sponsor our newsletter?
Reach out to us at sponsors@faun.dev and we'll get back to you as soon as possible.
 

DevOpsLinks #515: Scaling PostgreSQL to Power 800 Million ChatGPT Users
Legend: ✅ = Editor's Choice / ♻️ = Old but Gold / ⭐ = Promoted / 🔰 = Beginner Friendly

You received this email because you are subscribed to FAUN.dev.
We (🐾) help developers (👣) learn and grow by keeping them up with what matters.

You can manage your subscription options here (recommended) or use the old way here (legacy). If you have any problem, read this or reply to this email.