containers
Manifestly Safer, Why Kubernetes Wants Developers to Speak KYAML
KYAML gives Kubernetes developers a stricter, more predictable YAML dialect designed to reduce configuration errors, ambiguity, indentation problems and unexpected type coercion ...
Adrian Bridgwater | | CI/CD, cloud native, cloud native security, cloud-native architecture, configuration management, containers, devops, DevSecOps, Helm, KEP 5295, kubectl, kubernetes, Kubernetes configuration, Kubernetes manifests, Kubernetes security, Kubernetes YAML, KYAML, open source, platform engineering, SIG CLI, YAML, YAML errors
Containers Became the Unit of Speed. AI Agents Are Making VMs the Unit of Trust
The container is not disappearing. But as autonomous agents generate code, install packages and invoke tools, cloud-native infrastructure is placing a VM-grade security boundary around it ...
Alan Shimel | | Agent Sandboxing, agent security, agentic AI, AI agents, AI infrastructure, autonomous agents, cloud native security, container security, containers, Docker Sandboxes, Firecracker, gVisor, Kata Containers, kubernetes, MCP security, MicroVMs, platform engineering, RuntimeClass, secure execution, virtualization, workload isolation, zero-trust
Rust Rewrite Readies Kata Containers for Agent Sandboxing
The OpenInfra Foundation has released version 4 of Kata Containers, which arrives with a new Rust-based default runtime that brings new memory safety and performance gains. With the Rust rewrite, the Foundation ...
BellSoft Rings Change Bringing Zero-CVE Images to Buildpacks Users
BellSoft is bolstering Paketo Buildpacks. As an OpenJDK vendor known for providing tested (and commercially supported) Java distributions, Bellsoft is now offering a new hardened builder image for Paketo Buildpacks ...
Apple Ships Stable 1.0 of its Native Container Tool for macOS
Apple Container hits 1.0, giving macOS developers a native, VM-per-container alternative to Docker Desktop — with real tradeoffs ...
The AI Remediation Bottleneck: Why the Software Supply Chain Demands Radical Openness
For years, the DevSecOps movement has operated on a foundational premise that if you detect a vulnerability, you triage it, patch it, and redeploy. This cycle assumes that our capability to remediate ...
Together, Edera and Minimus Claim They Can Protect Your Software From AI Hackers
Hopefully, they can deliver because AI programs like Anthropic’s Mythos AI are cracking open programs faster than an otter can shuck oysters. MINNEAPOLIS — At Open Source Summit North America, Edera, a ...
Cloud Native Is Becoming AI Native
Open Source Summit North America has always been a good place to see where infrastructure is going before the market fully catches up. This year, the signal is not exactly subtle. The ...
Kubernetes v1.36 Promotes Stability, Compatibility & Reproducibility
Kubernetes v1.36 (Spring 2026) introduces 70 enhancements, including major security hardening for the Kubelet API and the debut of Workload-Aware Scheduling (WAS) for AI/ML. This release focuses on fine-grained resource health, stable ...
Adrian Bridgwater | | AI/ML Infrastructure, CI/CD, cloud native security, cloud-native applications, Cluster Hardening, container security, containers, CSI Token Redaction, developers, Distributed Training, DRA, Dynamic Resource Allocation, External Token Signing, Gang Scheduling, K8s v1.36, Kubelet API Authorization, kubernetes, Kubernetes Enhancements 2026., Kubernetes v1.36, microservices, Node Logs, open source, PodGroup API, Resource Health Status, storage, Volume Group Snapshots, WAS, workload-aware scheduling
Edera Adds Rust Library to Run Container Images on Hardened Runtime Faster
Edera this week revealed at the KubeCon + CloudNativeCon Europe conference that it has developed a Rust library, dubbed ocirender, that assembles container images based on the Open Container Image (OCI) format ...

