× Want to read this newsletter every week?! × 👋  Join FAUN
 
Last week's must-read news and stories from the DevOps communityDevOps Weekly Newsletter, DevOpsLinks, a FAUN Newsletter.
 
🔗 View in your browser.   |  ✍️ Publish on FAUN   |  🦄 Become a sponsor
 
Last week's must-read news and stories from the DevOps community
DevOpsLinks
 
Curated DevOps news, tutorials, tools and more!
 
 
⭐ Patrons
 
info.lumigo.io info.lumigo.io
 
How Jit Reduced Serverless Troubleshooting by 80%
 
 
In the fast-paced world of cloud-native development, efficient troubleshooting, and monitoring is crucial for maintaining application performance and user satisfaction. Join us to learn about the tangible benefits Jit experienced, including higher operational efficiency, improved error resolution times, and a more reliable user experience.
 
 

👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.

 
ℹ️ News, Updates & Announcements
 
techcrunch.com techcrunch.com
 
Google Cloud now has a dedicated cluster of Nvidia GPUs for Y Combinator startups
 
 

Google Cloud offers Y Combinator startups a dedicated subsidized cluster of Nvidia GPUs and Google TPUs, plus $350,000 in cloud credits over two years. This includes $12,000 in Enhanced Support credits, a free year of Google Workspace Business Plus, and access to Google's internal AI experts.

 
 
 
🔗 Stories, Tutorials & Articles
 
samsungads.ca samsungads.ca
 
Live Migrating Production Clusters From Calico to Cilium
 
 

Kubernetes clusters can run on different CNIs, and switching between them is complex. Migrating from Calico to Cilium, for example, involves deploying Cilium alongside Calico, testing connectivity, and gradually switching workloads to use Cilium. This method ensures minimal downtime and service disruption.

 
 
medium.com medium.com
 
Revealing the Inner Structure of AWS Session Tokens   ✅
 
 

Researchers have successfully reverse-engineered AWS Session Tokens, revealing their internal structure and cryptographic methods. They created open-source tools for analyzing and modifying these tokens and tested their resilience against forging attacks, finding them robust. Additionally, they identified five distinct token variants and detailed AWS's key management practices.

 
 
holdmybeersecurity.com holdmybeersecurity.com
 
Making Damn Vulnerable Web Application (DVWA) almost unhackable with Cilium and Tetragon   ✅
 
 

Cilium and Tetragon are two powerful tools combined to defend the Damn Vulnerable Web Application (DVWA) against attacks by harnessing the power of eBPF technology in the Kubernetes universe. By utilizing Cilium for process, file, HTTP, and network-based defenses alongside Tetragon for security observability and runtime enforcement, the DVWA becomes almost impervious to common OWASP vulnerabilities. The integration of Cilium and Tetragon in an enterprise setting bridges the gap between developers and security by providing robust defenses against known threats.

 
 
jpetazzo.github.io jpetazzo.github.io
 
Is Cloudflare overcharging us for their images service?   ✅
 
 
The author investigated unexpectedly high charges from Cloudflare Images for EphemeraSearch , involving complex billing cycles and credits. They discovered that changing image storage capacity triggers immediate charges, with credits applied the following month, leading to temporary overbilling. Despite the good service, the pricing model proved unsuitable for their needs, prompting exploration of alternative storage solutions.
 
 
spectralops.io spectralops.io
 
The DevOps Guide to SaaS Security
 
 

In February 2023, LastPass experienced a security breach involving a targeted attack on a DevOps engineer’s access to the corporate vault. This incident highlights the critical importance of robust access controls and security practices in SaaS environments, where customers must secure applications, data, and configurations. Implementing strong authentication, least privilege access controls, and automated identity governance are essential for maintaining SaaS security.

 
 
jbp.io jbp.io
 
CVE-2024-5535: `SSL_select_next_proto` buffer overread 
 
 

CVE-2024-5535 is a bug in OpenSSL that has been present since 2011, allowing the leakage of up to 255 bytes of the client's heap data to the server when the SSL_select_next_proto function is called with a client buffer that is not a valid list of protocols. This bug affects OpenSSL, BoringSSL, Node.js, and Python versions prior to specific updates that removed NPN support. Despite being low severity, it could have resulted in memory safety issues.

 
 
tracebit.com tracebit.com
 
How I discovered the Organization ID of any AWS Account   ✅
 
 

The author's research led to a new finding, prompting AWS to make significant changes to VPC Endpoint behavior by preventing information discovery using VPC endpoints. The change includes restrictions on the usage of wildcard characters in VPC Endpoint policies, specifically in relation to global context keys like aws:PrincipalAccount. This change was swiftly implemented by AWS in response to the author's findings, with updates to the documentation reflecting the new policy restrictions.

 
 
survey.stackoverflow.co survey.stackoverflow.co
 
2024 Stack Overflow Developer Survey   ✅
 
 
Here are some key findings:
  • 66% of developers have a BA/BS or MA/MS degree
  • PostgreSQL is the most popular database for the second year in a row
  • Docker is used the most by professional developers and npm is used the most by developers learning to code
  • Jira and Confluence are the most used asynchronous tools
  • Rust is the most-admired programming language
  • Erlang developers have the highest reported median salary
  • ChatGPT is the most used AI tool, with many developers wanting to use GitHub Copilot next year
  • 76% of respondents are currently using or planning to use AI tools in their development process
  • Most developers agree that AI tools will be more integrated in documentation, testing, and writing code in the next year
  • 75% of developers are more likely to endorse technologies that provide access to APIs
 
 
semaphoreci.com semaphoreci.com
 
10 Open-Source Tools for Optimizing Cloud Expenses
 
 

Explore 10 open-source tools that can reduce cloud costs and may be chosen as cost optimization tools.

 
 
sysdig.com sysdig.com
 
Kubernetes 1.31 - What’s new?   ✅
 
 

Kubernetes 1.31 introduces several major enhancements, including AppArmor support for defining security profiles at the container or pod level. Another notable change is the removal of all in-tree integrations with cloud providers, pushing Kubernetes towards vendor neutrality. Additionally, improvements include better handling of pod-level resource limits, enhanced connectivity reliability for KubeProxy Ingress, and various user-friendly updates like a randomized algorithm for Pod selection when downscaling ReplicaSets.

 
 
 
⭐ Supporters
 
bytevibe.co bytevibe.co
 
Unleash Your Inner Geek with ByteVibe!
 
 
Discover ByteVibe, where code, science, and style converge! Our unique apparel and accessories are designed for tech enthusiasts and developers. From eye-catching t-shirts and hoodies to must-have mugs and desk mats, each item features clever, tech-inspired designs that make a statement.
Why ByteVibe?
  • Unique Designs: Express your passion for tech and science with our exclusive prints.
  • Quality Products: Durable, comfortable, and made to last.
  • Great Deals: Sign up for our newsletter and receive our future deals!
 
 
👉 Spread the word and help developers find you by promoting your projects on FAUN. Get in touch for more information.
 
💬 Discussions, Q&A & Forums
 
www.reddit.com www.reddit.com
 
AlmaLinux reaches 1 million active systems!
 
 
 
 
 
⚙️ Tools, Apps & Software
 
github.com github.com
 
drawdb-io/drawdb
 
 

Free, simple, and intuitive online database design tool and SQL generator.

 
 
github.com github.com
 
cyclops-ui/cyclops
 
 

Developer Friendly Kubernetes

 
 
github.com github.com
 
GyulyVGC/sniffnet
 
 

Comfortably monitor your Internet traffic

 
 
github.com github.com
 
DiceDB/dice
 
 

A drop-in replacement of Redis with SQL-based realtime reactivity.

 
 
github.com github.com
 
derailed/popeye
 
 

A Kubernetes cluster resource sanitizer

 
 
github.com github.com
 
sickcodes/Docker-OSX
 
 

Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.

 
 

👉 Spread the word and help developers find and follow your Open Source project by promoting it on FAUN. Get in touch for more information.

 
🤔 Did you know?
 
 
AlmaLinux is an open-source Linux distribution that was launched in 2021 as a direct successor to CentOS Linux, which Red Hat decided to shift focus from in favor of CentOS Stream. AlmaLinux was developed by CloudLinux, Inc. with the aim to provide a free and community-supported enterprise-grade operating system that is binary compatible with Red Hat Enterprise Linux (RHEL). This compatibility ensures that software and applications developed for RHEL will work seamlessly on AlmaLinux.
 
 
😂 Meme of the week
 
 
 
 
🗣️ Quote of the week
 
 
"Completly happiness is utopic, but getting paid for doing some lines of "only you know what" it's almost the the same. The problem arises when neither you know what these lines were for!" -- Anonymous
 
 
❤️ Thanks for reading
 
 
👉 Never miss an issue
Join FAUN Developer Community and subscribe to our newsletter here.

👋 Keep in touch and follow us on social media:
- 💼LinkedIn
- 📝Medium
- 🐦Twitter
- 👥Facebook
- 📰Reddit
- 📸Instagram

👌 Was this newsletter helpful?
We'd really appreciate it if you could share it with your friends! You can also donate to help us keep this newsletter going.

ℹ️ Have a question or feedback?
Feel free to reach out to us at community@faun.dev. We'd love to hear from you!

🤩 Want to sponsor our newsletter?
Reach out to us at sponsors@faun.dev and we'll get back to you as soon as possible.