Allow loading remote contents and showing images to get the best out of this email.DevOps Weekly Newsletter, DevOpsLinks, a FAUN Newsletter.
 
🔗 View in your browser.   |  ✍️ Publish on FAUN   |  🦄 Become a sponsor
 
Allow loading remote contents and showing images to get the best out of this email.
DevOpsLinks
 
Curated DevOps news, tutorials, tools and more!
 
 
 
 

When bazillion-byte attacks and expiring licenses shake the tech landscape, it's easy to get swept off your feet. This week, we're diving deep into the heart of these battles—whether it's taming unstoppable bot armies or racing through cloud storage challenges—offering you tools to outsmart them and reclaim your coding zen.


📦 5 Cloud Storage Best Practices for AI Workloads

🤖 Agentic DevOps: Evolving with GitHub Copilot and Azure

🚀 Announcing Argo CD v3.1

🤯 Bots Overwhelm Websites with AI Data Hunger

💼 Broadcom Bullies with VMware Audits

🛡️ Cloudflare Blocks Largest DDoS Attack

🔧 Declarative Homelab Management

☁️ Engineering Principles for Cloud-Prem Solutions

🔍 GitHub Advisory Database in Numbers

💡 Go is an 80/20 Language


Stay tech-savvy in this ever-evolving digital arena, and may your stack be ever in your favor!


Have a great week!
FAUN Team
 
 
⭐ Patrons
 
manageengine.com manageengine.com
 
Your go-to checklist for reliable SQL Server performance
 
 
Dealing with SQL Server slowdowns or maintenance gaps? Our e-book, “The SQL Server Maintenance Checklist for Busy Admins,” offers practical, easy-to-follow routines to help you manage backups, indexing, and performance monitoring with confidence. From daily checks to quarterly reviews, it’s a no-fluff guide to keeping your SQL environment secure and efficient.

Download your copy now!
 
 

👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.

 
ℹ️ News, Updates & Announcements
 
news.itsfoss.com news.itsfoss.com
 
Broadcom is Bullying Enterprises with VMware Audits
 
 

Broadcom's latest move? Burying those trusty perpetual licenses. Now it's subscription time, folks, with price tags attached like parachutes packed by someone mildly annoyed. And if that wasn't enough, they're on a mission to sniff out unlicensed users like a bloodhound on a hunt, wielding audits and cease-and-desist orders with vigor. The risk of financial havoc looms large, ready to pounce on anyone not quick enough to dodge.

 
 
github.blog github.blog
 
Highlights from Git 2.50
 
 

Git 2.49 rolls out a fresh bag of tricks. Now, lightweight tags swagger with commit signatures, adding a splash of authenticity.

 
 
blog.argoproj.io blog.argoproj.io
 
Announcing Argo CD v3.1
 
 

Argo CD v3.1 rolls out the red carpet for OCI registries. Now you can grab Kubernetes manifests just like container images. Security and portability take center stage. Meet the new Hydrator updates, which stitch dry commits to code, making traceability sleeker and UI displays sharper. 🚀

 
 
zdnet.com zdnet.com
 
Cloudflare blocks largest DDoS attack - here's how to protect yourself
 
 

Cloudflare just stared down a raging beast: a 7.3 Tbps DDoS attack, like blasting 10,000 HD movies straight through your eyes in a heartbeat. This monster, 99.996% UDP floods, erupted from 122,145 source IPs scattered across 161 countries. Its real claim to fame? Not sheer size, but breakneck speed. In 2025, DDoS attacks skyrocketed 358%, mostly riding the wave of these UDP-fueled network-layer sucker punches.

 
 
linkedin.com linkedin.com
 
Introducing Northguard and Xinfra: scalable log storage at LinkedIn
 
 

LinkedIn's shake-up: Northguard kicks Kafka to the curb to handle its 1.2 billion users. The prize? Sharper operability, striped logs, and nimble metadata management. Xinfra steps up to virtualize Pub/Sub, easing the Kafka-to-Northguard leap. Kafka's client-centric stubbornness? Not a problem.

 
 
sniffnet.net sniffnet.net
 
Sniffnet v1.4 introduces PCAP files import and it’s 2X faster than Wireshark!
 
 

Sniffnet v1.4 zips through 1.6 GB PCAP files in just 25 seconds on an 8-year-old MacBook Air. That's 2.2x faster than Wireshark. How? It skips the encrypted payloads and goes straight for the packet headers, like a bloodhound on a scent.

 
 
infoq.com infoq.com
 
New Crypto-Jacking Attacks Target DevOps and AI Infrastructure
 
 

Wiz popped the hood on a sneaky crypto-jacking scheme. Meet JINX-0132, an operation that hijacks Nomad, Consul, Docker, and Gitea misconfigurations to stay under the radar. Meanwhile, Sysdig raised the alarm on a copycat act aimed at Open WebUI. It’s a growing trend that flips exposed infrastructure into a crypto mining playground, with hackers high-fiving behind the scenes.

 
 
azure.microsoft.com azure.microsoft.com
 
Agentic DevOps: Evolving software development with GitHub Copilot and Microsoft Azure
 
 

GitHub Copilot's latest release? A digital Swiss Army knife. It slices through complex code, automates your drudge work, and resurrects forgotten legacy systems, so you can dive into creative coding. Now it moonlights as your SRE on Azure and invites AI model tinkering straight into your workflow.

 
 
systemadministration.net systemadministration.net
 
Oracle Linux 10 Officially Released: Next-Gen Security, Developer Tooling and a Strategic Edge Over Red Hat Enterprise Linux 10
 
 

Oracle Linux 10 struts in with quantum-resistant cryptography and zero-downtime patching. It swoops past RHEL 10 in a security showdown, showing off sleek flexibility.

 
 
theregister.com theregister.com
 
Bots are overwhelming websites with their hunger for AI data
 
 

Rampaging AI bots are wreaking havoc on 39 out of 43 cultural institutions, bulldozing their way through digital collections and often causing epic crashes. Robots.txt is waving the white flag. AWS and Cloudflare put up a decent fight, but the bot swarms still drain money like a leaky faucet.

 
 
 
⭐ Sponsors
 
amzn.to amzn.to
 
Master Cloud Native Microservices with Kubernetes — Your Ultimate Guide to Building, Scaling, and Managing Resilient Microservices
 
 
Discover how to build, scale, and manage resilient microservices with Kubernetes. This practical guide covers everything from local setups to advanced deployments using tools like Docker, Rancher, Helm, Istio, Argo CD and Prometheus. Perfect for all skill levels—turn Kubernetes into your key to cloud-native success.

Get your copy now!
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
🔗 Stories, Tutorials & Articles
 
theexceptioncatcher.com theexceptioncatcher.com
 
Kafka in 2025: A Clean Docker Compose Setup Without ZooKeeper
 
 

Kafka kicked Zookeeper to the curb as of version 4.0. And by 2023, Docker images were no longer invited to the party. Want to set it up locally? Bitnami's version steps in, offering custom settings to play with.

 
 
infoq.com infoq.com
 
Engineering Principles for Building a Successful Cloud-Prem Solution
 
 

Cloud-Prem marries cloud's nimble speed with on-prem's tight grip. It fuses a vendor-managed control plane with a customer-owned data plane—a dream match for regulated sectors. Redpanda's BYOC slashed costs tenfold by axing egress fees. Meanwhile, Couchbase's Capella serves up hybrid deployment like a master chef, showcasing Cloud-Prem's promise.

 
 
blog.kowalczyk.info blog.kowalczyk.info
 
Go is 80/20 language
 
 

Go keeps it simple, delivering 80% of the goods with just 20% of the mess. But some critics sniff around, demanding more for their extra 36% effort. Swift proves the point that more isn’t always better with its extra baggage.

 
 
u1f383.github.io u1f383.github.io
 
The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction
 
 

Ubuntu's sandbox for unprivileged namespaces flops like a soggy cardboard box; one keen Twitter user blew wide open a glaring weakness. Billed as invincible, these post-exploitation defenses crumbled when a process shimmies into an unconfined AppArmor profile. Suddenly, infamous attack paths throw up a welcome sign.

 
 
devops.com devops.com
 
The Future of AI-Augmented Infrastructure: Letting AI Handle the Terraform Tax
 
 

Terraform reviews drag teams through "invisible costs," even with sleek tools. AI jumps in, offering sharper, context-savvy vetting without shaking up current workflows.

 
 
github.blog github.blog
 
GitHub Advisory Database by the numbers: Known security vulnerabilities and what you can do about them
 
 

GitHub Advisory Database curates 22 000+ reviewed and 30 000+ imported advisories from the NVD, repo advisories, and community sources. It fuels Dependabot, CVSS & EPSS ratings, and CNA services to ruthlessly prioritize and patch vulnerabilities at scale

 
 
tech.aufomm.com tech.aufomm.com
 
Declarative Homelab Management 
 
 

Switching to Nix spins server config management into the 21st century. Imagine your setups as Lego sets: fully reproducible and portable. Swapping in Valkey for Redis? License headaches no more. Tag team Hashicorp Vault with Traefik to streamline SSL management—they transform chaos into order, tightening up both security and simplicity. Meanwhile, Terraform harnesses age and sops like a pro wrestler, securing secrets and state management with ease.

 
 
backblaze.com backblaze.com
 
5 Cloud Storage Best Practices for AI Workloads
 
 
AI teams segment data lifecycles to reduce costs by moving inactive datasets to cheaper storage tiers. They checkpoint training progress regularly and back up checkpoints to cloud storage to prevent loss from failures. Models get protected via object locks, automated backups, and geo-redundant storage for disaster resilience. Teams analyze egress fees upfront to avoid costly data transfer charges when switching cloud providers. They calculate replication overhead to balance storage costs with latency, staging data near GPUs for faster training.
 
 
 
⚙️ Tools, Apps & Software
 
github.com github.com
 
psviderski/unregistry
 
 

Push docker images directly to remote servers without an external registry

 
 
github.com github.com
 
kaito-project/kaito
 
 

Kubernetes AI Toolchain Operator

 
 
github.com github.com
 
ripienaar/free-for-dev
 
 

A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev

 
 
github.com github.com
 
koogle/claudebox
 
 

Run claude code in a container

 
 
github.com github.com
 
manaskamal/XenevaOS
 
 

The Xeneva Operating System

 
 

👉 Spread the word and help developers find and follow your Open Source project by promoting it on FAUN. Get in touch for more information.

 
🤔 Did you know?
 
 
Did you know Shopify routes the bulk of its API traffic through containerized MySQL shards, each running in isolated pods to handle real-time transactions? They use an in-house tool, Ghostferry, for zero-downtime shard migrations and deploy read replicas to scale reads and absorb peak loads without bottlenecks.
 
 
😂 Meme of the week
 
 
 
 
🤖 Sensei Says
 
 

"True mastery lies in creating simplicity from chaos, but the real artistry is knowing when to harness chaos to solve simplicity."
— Sensei

 

(*) Sensei is a work-in-progress AI agent built by FAUN

 
❤️ Thanks for reading
 
 
👋 Keep in touch and follow us on social media:
- 💼LinkedIn
- 📝Medium
- 🐦Twitter
- 👥Facebook
- 📰Reddit
- 📸Instagram

👌 Was this newsletter helpful?
We'd really appreciate it if you could forward it to your friends!

🙏 Never miss an issue!
To receive our future emails in your inbox, don't forget to add community@faun.dev to your contacts.

🤩 Want to sponsor our newsletter?
Reach out to us at sponsors@faun.dev and we'll get back to you as soon as possible.
 

DevOpsLinks #483: Broadcom Bullying Enterprises with VMware Audits, Cloudflare Blocks Largest DDoS Attack & Agentic DevOps
Legend: ✅ = Editor's Choice / ♻️ = Old but Gold / ⭐ = Promoted / 🔰 = Beginner Friendly

You received this email because you are subscribed to FAUN.
We (🐾) help developers (👣) learn and grow by keeping them up with what matters.

You can manage your subscription options here (recommended) or use the old way here (legacy). If you have any problem, read this or reply to this email.