I hope you find this π§΅ helpful, writing, enabling, & executing policy as code, not only a prerequisite, but it's a demand for battle-tested and resilient infra. Share your thoughts on CEDAR's new approach to writing policies & defending clusters βοΈ π
bsky.app/profile/clou...
05.02.2026 17:53 β π 0 π 0 π¬ 0 π 0
Cedar Language Playground
(7/7) An exciting aspect to me is the ability to enforce label-based access control decisions in a cluster. This enables you to partition a K8s cluster not by namespaces, but by k/v label presence. See the launch blog for an example of how this can work. cedarpolicy.com/blog/cedar-f...
05.02.2026 17:53 β π 0 π 0 π¬ 1 π 0
(6/6) Cedar for Kubernetes supports features not available in Kubernetes RBAC today like denials, conditions, and attribute and label-based access controls.
05.02.2026 17:52 β π 0 π 0 π¬ 1 π 0
(5/5) For a walkthrough of Cedar, you can get a crash course in the projectβs GitHub documentation or the language docs. Cedar is powered by formally verified automated reasoning, enabling you to verify that policies are valid and cannot error on enforcement.
05.02.2026 17:51 β π 0 π 0 π¬ 1 π 0
4/4) Cedar access control for K8 aims to help solve this set of problems. By using the same language for both authorization and admission policies, administrators can quickly reason about what permissions are granted and what restrictions are applied in the same policy file.
05.02.2026 17:51 β π 0 π 0 π¬ 1 π 0
(3/3) This introduces high cognitive overhead when authoring policy, and the risk of an unintended effect increases when making and reviewing code changes to existing policies, as a reviewer might not be aware of all permissions or restrictions if only one is being modified.
05.02.2026 17:51 β π 0 π 0 π¬ 1 π 0
(2/2) One of the main motivations for this work is that defenders who secure K8s clusters have to learn and use multiple policy languages to get their job done, often defining permitted actions in one file and restrictions in separate policy files, languages, & frameworks
05.02.2026 17:51 β π 0 π 0 π¬ 1 π 0
Season 4 opener β Episode 144: Agentic DevOps: Automation, Autonomy, & the Risk of Vendor Lock-In
π§ I talk with MahirVora from @CDFoundation Ambassador about safe agent workflows, trust budgets, RBAC for remediation, and pricing & lock-in risks.
Watch the full episode: youtu.be/bQdRpfmSXnI
22.01.2026 17:26 β π 0 π 0 π¬ 0 π 0
GitHub - kubernetes-sigs/ingress2gateway: Convert Ingress resources to Gateway API resources
Convert Ingress resources to Gateway API resources - kubernetes-sigs/ingress2gateway
In case you didn't notice:
ingress2gateway is a CLI that reads Kubernetes Ingress resources and outputs equivalent Gateway API manifests
It maps hosts, paths, and routing rules directly, allowing you to adopt Gateway API resources instead of legacy Ingress
github.com/kubernetes-s...
16.01.2026 18:17 β π 2 π 1 π¬ 0 π 0
If youβre designing an IDP in 2026: start with CRD-driven services (Crossplane), enforce policies (Kyverno), sync cluster state via GitOps (Argo CD), and surface developer UX in Backstage.
If you have built one and have a story to share
Comment below, I will feature it in #cloudnativefm (12/12)
16.01.2026 18:11 β π 1 π 0 π¬ 0 π 0
Real benefits: full control, no vendor lock-in, consistent patterns (like public clouds), easier extension via CRDs, and the ability to enforce policies at the platform level (Kyverno) while exposing a clean developer UX (Backstage). (11/11)
16.01.2026 18:10 β π 0 π 0 π¬ 1 π 0
Whatβs missing? CI/workflows, but thatβs fine.
GitHub Actions, GitLab CI, Tekton, Jenkins, choose your CI. Foundation matters more than which CI runner you pick. (10/10)
16.01.2026 18:10 β π 0 π 0 π¬ 1 π 0
Why BACK Stack?
Open source, CNCF-aligned, mature adopters:
- Argo & Crossplane are graduated;
- Backstage & Kyverno are rapidly maturing.
Strong ecosystem + Crossplane providers for cloud, DBs, SaaS. (9/9)
16.01.2026 18:09 β π 1 π 0 π¬ 1 π 0
Meet the BACK Stack β my pick for 2026 IDPs:
Backstage (portal) + Argo CD (GitOps/CD) + Crossplane (platform controllers/CRDs) + Kyverno (policy).
Each leads its domain, and they work together harmoniously. (8/8)
16.01.2026 18:08 β π 0 π 0 π¬ 1 π 0
Build on CNCF + Kubernetes-native components. Services as controllers, APIs as CRDs, policy via Kubernetes policy engines, thatβs modern platform design, not a shortcut. (7/7)
16.01.2026 18:08 β π 1 π 0 π¬ 1 π 0
Beware partial/proprietary solutions: portals-only (Roadie, Port, Cortex) or closed all-in-one vendors (Harness, Qovery) can lock you into outdated patterns or vendor lock-in. (6/6)
16.01.2026 18:07 β π 0 π 0 π¬ 1 π 0
Interact with those APIs however you want: kubectl, Helm, GitOps (Argo CD/Flux), Backstage, custom UIs. The portal becomes a client, not the center of the universe. (5/5)
16.01.2026 18:07 β π 0 π 0 π¬ 1 π 0
Where do you run platform services? Kubernetes controllers. Why? They reconcile the desired state β actual state, exactly what platform services must do. CRDs give you declarative APIs for free.(4/4)
16.01.2026 18:06 β π 0 π 0 π¬ 1 π 0
Starting with a portal = building a house from the roof. Backwards. Start with services and APIs first, then add UIs (portal, CLI, GitOps) as clients. (3/3)
16.01.2026 18:06 β π 0 π 0 π¬ 1 π 0
Real platforms follow the public-cloud pattern: services that do things, APIs that expose those services, and UIs/CLIs/SDKs that consume the APIs.
Design like a public cloud: services β APIs β UIs. (2/2)
16.01.2026 18:06 β π 0 π 0 π¬ 1 π 0
Internal Developer Platform (IDP) is widely misunderstood. a fancy web UI where developers click buttons. Thatβs not a platform.
Design like a public cloud: services/APIs/UIs
My choice for building IDP in 2026 -> Backstack (Backstage, Argo CD, Crossplane, Kyverno) π§΅ / (1/1)
16.01.2026 18:05 β π 1 π 0 π¬ 1 π 0
Richard walks through what reskilling looks like in 2026 for people in cloud, DevOps, and infrastructure roles: from prompt/context engineering to MLOps, agentic AI roadmaps, and vendor learning paths that you can actually start today.
Watch -> youtu.be/lI5m5ILq8yY #CloudNativeFM
Add your π€ βοΈπ
14.01.2026 14:25 β π 0 π 0 π¬ 0 π 0
Will 2026 be a year of new protocols? Will you care about it?
Google just opensourced Universal Commerce Protocol.
AI Agents can now discover products, fill carts, and complete purchases autonomously.
Works with Agent2Agent (A2A), Agents Payment Protocol (AP2) and MCP.
100% Opensource.
14.01.2026 13:57 β π 0 π 0 π¬ 0 π 0
MIT says ~95% of GenAI pilots show no measurable P&L impact. Wharton finds ~75% of firms report positive ROI. Different questions = different headlines.
Short clip w/ RichardSimon unpacks why
#CloudNativeWisdom18: youtu.be/fTE_tSW1NzA
07.01.2026 16:03 β π 0 π 0 π¬ 0 π 0
YouTube video by Cloud Native Podcast
#CloudNativeWisdom17 Resilience β HA: What the US-East-1 Outage Taught Us
Resilience vs High Availability, following the AWS US-East-1 outage,
Richard Simon and I explain why AZ-level resilience wasnβt enough and how true HA needs cross-region failover and practice
Watch our quick explainer π
youtu.be/WMx3kV-qwXE
06.01.2026 13:24 β π 0 π 0 π¬ 0 π 0
@hrexed.bsky.social Happy birthday and best wishes for 2026.
06.01.2026 09:23 β π 0 π 0 π¬ 0 π 0
#CloudNativeWisdom16 How AI and generative agents are reshaping cloud migration from automated discovery & dependency mapping to vendor tools, including those from AWS, Microsoft Azure, Google, and newcomers like Fluid Cloud.
Watch on #CloudNativeFM -> youtu.be/13eEAOCA6SQ
06.01.2026 03:23 β π 0 π 0 π¬ 0 π 0
Chief Email Outputter at Buoyant. Linkerd spokesnerd. Twitter refugee and former engineer
πAustin, TX
CTO @ Grafana Labs (@grafana.bsky.social)
London-based
The database platform built for scale. Postgres and Vitess/MySQL.
https://planetscale.com
Discord: http://discord.gg/pDUGAAFEJx
Status: http://planetscalestatus.com
Prime Minister of Canada and Leader of the Liberal Party | Premier ministre du Canada et chef du Parti libΓ©ral
markcarney.ca
Cosmonic, CNCF wasmCloud, WebAssembly, Security, Chair CNCF Cloud Native WebAssembly Day, wasmCon, CNCF Ambassador
The Universal Application Platform powered by wasmCloud - an open source, incubating CNCF project.
CTO @Cosmonic, TSC director @bytecodeallies, WASI co-chair, playing cozy games, π³οΈβπ
Emergency Physician in Toronto. Co-Chair of the Canadian Covid Society.
Fighter of illness and misfortune, interested in history, politics, tech and AI. #fella,π¨π¦/acc
Cloud Developer Advocate @Google | Co-Host of @kubernetespodcast.com | Devoxx Morocco PC | CNCF Ambassador | Opinions are my own.
#k8s #cloud #servicemesh #security
VP of DevRel at GitHub (he/him)
https://github.com/martinwoodward
Austin Powered. OpenStack co-founder, OpenInfra Foundation COO, ex Rackspace & Yahoo! open source for fun & profit.
Open Source AI early and often
@sparkycollier on twitter and elsewhere
Links: markcollier.me
AWS Community Hero, cloud architect, keynote speaker, and content creator. I explain cloud technology clearly and simply, to help make rewarding tech careers accessible to all.
Serial dabbler.
π₯ Developer Advocate @ https://WeAreDevelopers.com
π§ Building indiebuilds.co & supabooking.com
π₯ Corp. video production https://wearespotlight.co.uk
colorhub.app - profileme.dev - svghub.vercel.app
WebAssembly advocate and compiler enthusiast π¨π½βπ» Co-author of the Grain programming language, server-side wasm at Suborbital π€
Microsoft MVP in #AI | #CloudSecurity Architect (specialising in #DevSecOps, #GenAI and #LLM Security)
API Machinery @ ex-Upbound, ex-Redhat, Kubernetes, OpenSource, logician, restless, hungry & foolish, ΓΎetta reddast, http://github.com/sttts β Opinions&tweets are my own, http://mastodon.social/@sttts
The Captain Corsair of Cloud Native sails free under the blue sky
Building a better world through open collaboration: https://aniszczyk.org | CTO, CNCF and Linux Foundation