Autonomous Patching for Cloud-Native Workloads

The cloud-native stack didn’t make security go away—it just spread it across more layers, more repos, more images, and more “who owns this?” moments.

Eilon Elhadad, co-founder and CTO of Echo, talks about a problem every platform team runs into once containers become the default unit of delivery: patching, hardening and vulnerability triage turn into a second job. Not the fun kind, either—the kind where you’re burning cycles on CVEs and rebuilds instead of shipping features.

The cloud-native angle here isn’t “yet another tool.” It’s the idea that a big chunk of security work should be handled before your workloads ever hit production. Think of it like this: instead of every team pulling base images and packages from wherever, then scrambling when a supply chain issue or dependency vulnerability lights up the scanner, you standardize on pre-hardened artifacts that are continuously patched and tested upstream.

That’s the thread Eilon keeps pulling: what happens when you treat the OS and container layer as something that can be managed more like an always-up-to-date, security-aware supply chain—without forcing developers to stop and become part-time vulnerability managers?

Eilon frames it as “autonomous infrastructure,” with AI/agent-driven workflows doing the unglamorous work: research a new vulnerability, figure out what’s real vs. noise, apply the fix, run the tests, and publish updated artifacts. The payoff is simple: platform teams get fewer emergency rebuilds, developers stay focused on product work, and security stops being a whack-a-mole exercise across hundreds of images.

The practical detail: adoption doesn’t require a huge rip-and-replace mindset. It’s closer to swapping what you pull into your CI/CD pipeline—using secure, maintained container images and packages as building blocks—so the baseline gets safer by default.

Cloud marketplaces and predictable pricing matter, but the real story is what this signals for cloud-native operations—security as an upstream, automated discipline, not a constant downstream fire drill.

Alan Shimel

Alan Shimel is founder, CEO and editor-in-chief of Techstrong Group, a Futurum company, and a member of Futurum's executive leadership team. A technology entrepreneur, media executive and industry commentator, Shimel has spent more than three decades building businesses, communities and media platforms serving enterprise technology professionals, including co-founding StillSecure, a network security company, and the DevOps Institute, a DevOps certification and training body. At Techstrong, he leads a portfolio of media brands including DevOps.com, Security Boulevard, Cloud Native Now, Techstrong AI, Techstrong IT, Digital CxO, Platform Engineering, Techstrong Semi and Techstrong TV, along with a growing portfolio of events, educational programs and digital communities. With more than 25 years of experience in cybersecurity, Shimel is a familiar voice in the space and was an early advocate of the DevOps movement, helping bring DevOps practices into mainstream enterprise technology. His work today spans cybersecurity, DevOps, cloud-native technologies, artificial intelligence, semiconductors and digital transformation, and he hosts popular programs including Techstrong Gang, Shimmy Says and Still Cyber, After All These Years. He holds a Bachelor of Arts in Government and Politics from St. John's University and a Juris Doctor from New York Law School.

    Alan Shimel has 116 posts and counting. See all posts by Alan Shimel