CuraDevOps

Daily DevOps intelligence with actionable verdicts β€” each item judged independently for Platform/SRE engineers, CI/CD engineers, and Engineering Leaders, cross-referenced against EOL dates, deprecation deadlines, and release signals.

πŸ”₯ Act β€” needs attention now

2026-08-26 Β· Docker Blog Β· source β†— #base-images#registry-migration#docker
  • Platform/SRE β€” Act: The Minimus registry goes offline October 22, 2026; audit all Dockerfiles, Helm charts, and Kubernetes manifests for Minimus base image references and complete migration to Docker Hardened Images before that date to prevent broken image pulls in production.
  • CI/CD β€” Act: Any pipeline pulling from the Minimus registry will break after October 22, 2026; inventory all build Dockerfiles and CI base-image references now and migrate to Docker Hardened Images using the provided migration path and Docker’s free migration assistance before the deadline.
  • Leader β€” Skip
2026-08-24 Β· Releases: opentofu Β· source β†— #opentofu#security#iac
  • Platform/SRE β€” Act: OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.
  • CI/CD β€” Act: The credential-leak bug affects tofu init when pulling modules or providers from OCI registries β€” a standard pipeline step β€” and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL.
  • Leader β€” Skip
  • Signals: OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)
2026-08-18 Β· GitLab Blog Β· source β†— #gitlab#security-patch#ci-cd
  • Platform/SRE β€” Plan: If running a self-managed GitLab instance, upgrade to the patched version in your release line; no public PoC or KEV listing is confirmed from the title alone, so this is urgent-but-scheduled rather than emergency.
  • CI/CD β€” Act: GitLab CI users on self-managed instances should upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 promptly β€” a critical patch to the CI/CD platform itself can directly break or compromise pipelines and should be treated as an outage-level priority.
  • Leader β€” Skip
  • Signals: major release (19.0)
2026-08-18 Β· GitLab Blog Β· source β†— #mcp-security#rce#ai-coding-agent
  • Platform/SRE β€” Skip
  • CI/CD β€” Act: Published GHSA-pp25-4cg4-qcr9 details a critical server-side template injection in serena-agent ≀1.6.1 that executes arbitrary code via a malicious .serena/project.yml smuggled in any cloned repo β€” a direct supply-chain threat to developer and CI environments; upgrade to serena-agent 1.7.0 now.
  • Leader β€” Plan: This is an early, documented example of a new risk class: MCP servers embedded in the SDL grant LLMs broad filesystem and shell access, making any compromise severe; evaluate whether your AI coding-agent adoption policies explicitly address this attack surface before broader org rollout.
2026-08-13 Β· Azure Updates Β· source β†— #microsoft-sentinel#deprecation#sap
  • Platform/SRE β€” Act: If you run the containerized SAP data connector agent for Microsoft Sentinel, migrate to the replacement agent before September 14, 2026, when the agent will be permanently disabled and SAP log ingestion will stop.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Signals: deprecation/EOL deadline mentioned: September 14, 2026

πŸ“Œ Plan β€” review this quarter

2026-09-02 Β· Azure Updates Β· source β†— #aks#windows#kubernetes
  • Platform/SRE β€” Plan: Windows Server 2025 is now a supported node OS on AKS, giving teams a clear upgrade target as older Windows Server versions approach end of support. Schedule evaluation of Windows node pool migration this quarter, especially if running 2019 or 2022 nodes β€” no forced-upgrade date is signaled yet, but the deprecation mention warrants adding it to the roadmap.
  • CI/CD β€” Skip
  • Leader β€” Learn: AKS now supports Windows Server 2025, extending the viability of Windows-based workloads on managed Kubernetes β€” useful context if the org is evaluating its Windows modernization strategy, but no strategic or cost decision is required now.
  • Signals: deprecation mentioned (no explicit date found) Β· GA announcement
2026-09-02 Β· GitHub Changelog Β· source β†— #github-copilot#deprecation#ai-models
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Plan: Copilot model deprecations took effect September 1, 2026 β€” verify which models your org relies on in Copilot Chat, completions, or agent mode are still available, and update any tooling or policy that specified a now-removed model.
  • Signals: deprecation/EOL deadline mentioned: September 1, 2026
2026-09-02 Β· HashiCorp Blog Β· source β†— #vault#secrets-management#agentic-ai
  • Platform/SRE β€” Plan: If your org runs Vault Enterprise and is deploying AI agent workloads, this GA feature adds purpose-built IAM controls worth evaluating this quarter; no forced migration or deadline, but assess whether your current Vault version and license tier expose it.
  • CI/CD β€” Skip
  • Leader β€” Learn: This signals Vault Enterprise is extending its security model to cover AI agent identities; worth noting if AI agent adoption is on the roadmap and the org is already standardized on Vault Enterprise, but no strategy or contract decision is required now.
  • Signals: GA announcement
2026-09-02 Β· GitHub Changelog Β· source β†— #github#enterprise#migration
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Plan: If the org runs GHES and is evaluating a move to GitHub Enterprise Cloud with Data Residency, this GA milestone removes the primary operational risk (downtime) from the migration path β€” worth scheduling an evaluation this quarter.
  • Signals: GA announcement
2026-09-02 Β· Azure Updates Β· source β†— #azure#container-security#cloud-security
  • Platform/SRE β€” Plan: If your platform runs Azure Container Apps, this GA feature lets you consolidate posture management under Defender for Cloud rather than operating a separate security toolchain; evaluate enabling it this quarter.
  • CI/CD β€” Skip
  • Leader β€” Learn: Extends unified container security posture to serverless workloads on Azure β€” worth noting if your org is standardizing on Defender for Cloud as the security management plane.
  • Signals: GA announcement
2026-09-02 Β· Azure Updates Β· source β†— #azure#kubernetes#security
  • Platform/SRE β€” Plan: CVM node pools on AKS are now GA, enabling sensitive workload isolation at the hardware level; evaluate whether regulated or high-sensitivity workloads in your clusters warrant migrating to CVM node pools this quarter.
  • CI/CD β€” Skip
  • Leader β€” Learn: GA confidential compute on AKS is a new capability relevant to compliance and data-sovereignty positioning, but no immediate strategic decision is required unless the org has active regulated-workload requirements on Azure.
  • Signals: GA announcement
2026-09-02 Β· AWS What's New Β· source β†— #observability#postgresql#aws
  • Platform/SRE β€” Plan: New GA capability unifies monitoring of self-managed PostgreSQL on EC2 alongside RDS/Aurora in a single console; worth evaluating if you run mixed database fleets to consolidate your observability stack.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Platform/SRE β€” Plan: This GA capability lets platform teams migrate high-volume compliance and audit Azure tables to the lower-cost Auxiliary plan without rebuilding pipelines. Evaluate which existing Log Analytics tables qualify for plan switching this quarter to reduce observability ingestion costs.
  • CI/CD β€” Skip
  • Leader β€” Plan: The plan-switching capability is a concrete FinOps lever for reducing Azure Monitor spend on high-volume, rarely-queried compliance logs. Worth scheduling an audit of Log Analytics table plans to identify cost-reduction opportunities within the current planning cycle.
  • Signals: GA announcement
  • Platform/SRE β€” Plan: If you operate workloads in Azure Government or Azure China, this new GA log tier offers a cheaper ingestion and retention path for high-volume compliance/audit logs β€” evaluate whether shifting verbose log streams to Auxiliary tables reduces your Monitor costs this quarter.
  • CI/CD β€” Skip
  • Leader β€” Learn: Auxiliary Logs adds a cost-effective tier for compliance and audit log retention in sovereign cloud regions; useful context if the org has Azure Government or China footprint and is managing observability spend, but no strategic decision is forced.
  • Signals: GA announcement
2026-09-02 Β· Azure Updates Β· source β†— #aks#container-registry#kubernetes
  • Platform/SRE β€” Plan: Artifact streaming on AKS+ACR is now GA and can reduce pod startup latency during scale-out events; evaluate enabling it for workloads where image pull time is a bottleneck this quarter.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Signals: GA announcement
2026-09-01 Β· Kubernetes Blog Β· source β†— #kubernetes#storage-migration#crd-lifecycle
  • Platform/SRE β€” Plan: StorageVersionMigration API (storagemigration.k8s.io/v1) is now stable and enabled by default in Kubernetes 1.37, removing the need for manual migration scripts when promoting or dropping CRD API versions. Plan to incorporate SVM into your CRD lifecycle runbooks when scheduling the upgrade to 1.37 (EOL 2027-10-28).
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Signals: Kubernetes 1.37 EOL 2027-10-28 Β· GA announcement
2026-09-01 Β· AWS What's New Β· source β†— #aws-security#remediation#automation
  • Platform/SRE β€” Plan: Teams using ASR on AWS should evaluate the AI Toolkit and expanded GuardDuty/Inspector/Macie coverage; the enhanced console replaces manual DynamoDB/SSM config, making this a worthwhile platform security upgrade to schedule this quarter.
  • CI/CD β€” Skip
  • Leader β€” Learn: The shift from manual SSM Automation expertise to AI-guided remediation generation signals a meaningful reduction in barrier-to-entry for automated security response β€” worth tracking as an indicator of where cloud-native security tooling is heading.
2026-09-01 Β· AWS What's New Β· source β†— #aws#ai-agents#governance
  • Platform/SRE β€” Plan: New GA AWS service adds cross-account agent catalog support via CloudFormation, Terraform, CDK, and AWS RAM β€” worth evaluating this quarter if your org is building shared AI agent infrastructure, as it may change how you architect agent discovery and access control across accounts.
  • CI/CD β€” Skip
  • Leader β€” Learn: AWS Agent Registry offers a governed, org-wide catalog for AI agents and tools with audit trails and cross-account sharing; worth tracking as a pattern for AI governance strategy, but no immediate decision or vendor-risk event is present.
  • Signals: GA announcement
2026-09-01 Β· AWS What's New Β· source β†— #aws#redshift#iam
  • Platform/SRE β€” Plan: If Redshift is in your stack and you have data residency or network-isolation requirements, this is worth adopting: SSO via IAM Identity Center with all auth traffic staying inside your VPC via PrivateLink. Evaluate enabling EVR and wiring up Identity Center for your provisioned clusters or serverless workgroups this quarter.
  • CI/CD β€” Skip
  • Leader β€” Learn: Redshift now supports SSO via IAM Identity Center with network traffic fully contained in your VPC β€” relevant context if your org has regulatory or data-residency mandates for analytics infrastructure, but no decision is forced by this launch.
2026-09-01 Β· AWS What's New Β· source β†— #aws#ec2#graviton
  • Platform/SRE β€” Plan: New GA Graviton5 memory-optimized instances offer up to 25% better compute and 30% faster database performance vs R8g; evaluate migrating memory-intensive workloads (Kubernetes nodes, caches, databases) this quarter to capture the price-performance gains.
  • CI/CD β€” Skip
  • Leader β€” Learn: Graviton5 R9g instances establish a new price-performance ceiling for memory-intensive workloads on AWS; useful context for future FinOps and instance-family standardization decisions but no forcing function today.
  • Signals: GA announcement
2026-09-01 Β· AWS What's New Β· source β†— #cloudwatch#observability#alerting
  • Platform/SRE β€” Plan: New GA WarmUpConfiguration parameter lets teams delay alarm evaluation after resource creation, reducing on-call noise from missing-data transitions during startup. Update IaC alarm definitions (Terraform/CloudFormation) to include warm-up periods for resources that take time to begin emitting metrics.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-31 Β· Releases: terraform Β· source β†— #terraform#infrastructure-as-code#release
  • Platform/SRE β€” Plan: New GA minor release of a core IaC tool with meaningful platform capabilities: import blocks inside modules, a store block for ephemeral/sensitive values across plan and apply, and on_failure modes for resource action triggers. No breaking changes or EOL deadline, but worth scheduling evaluation and adoption this quarter.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-31 Β· Releases: pulumi Β· source β†— #pulumi#secrets#iac
  • Platform/SRE β€” Plan: If you use Pulumi with connection-string URLs (e.g. Postgres), upgrade to sdk/v3.260.0 to prevent passwords leaking into state/log output; no hard deadline but a meaningful security hygiene improvement.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-31 Β· Releases: kubernetes Β· source β†— #kubernetes#release#upgrade
  • Platform/SRE β€” Plan: Kubernetes 1.37.0 is a new minor release worth evaluating for adoption this quarter; review the CHANGELOG for API removals or deprecations that may affect running workloads before scheduling an upgrade window.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-31 Β· Releases: istio Β· source β†— #service-mesh#istio#kubernetes
  • Platform/SRE β€” Plan: A new Istio minor release is always a candidate for upgrade planning β€” review the full release notes for breaking changes, API removals, or deprecations before scheduling a mesh upgrade this quarter.
  • CI/CD β€” Skip
  • Leader β€” Skip

πŸ“š Learn β€” worth knowing

2026-09-02 Β· CNCF Blog Β· source β†— #kubernetes#bare-metal#kubevirt
  • Platform/SRE β€” Learn: Interesting integration pattern for teams using KubeVirt and Metal3 together, enabling bare-metal provisioning workflows for VMs. No GA release, deadline, or operational change required; worth evaluating if your platform uses KubeVirt.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-02 Β· Kubernetes Blog Β· source β†— #kubernetes#etcd#memory-optimization
  • Platform/SRE β€” Learn: RangeStream is still beta in v1.37 (requires etcd v3.7), so not yet production-adoptable, but SREs running clusters with many large objects (e.g., Pods at scale) should track this as a near-term mitigation for API server and etcd OOM risk during cache repopulation.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Signals: Kubernetes 1.37 EOL 2027-10-28 Β· etcd 3.7 supported
  • Platform/SRE β€” Learn: Interesting pattern for zero-trust mainframe access using Boundary workers, but no deadline or GA capability change β€” worth evaluating if mainframes are in scope for the platform.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-02 Β· GitHub Changelog Β· source β†— #github#cost-management#developer-platform
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: GitHub now supports expiring individual user spending budgets automatically, useful for managing contractor or temporary-staff access costs without manual cleanup.
  • Signals: GA announcement
2026-09-02 Β· GitHub Changelog Β· source β†— #github-actions#developer-experience#ai
  • Platform/SRE β€” Skip
  • CI/CD β€” Learn: Copilot can now be authorized to formally approve PRs, which could change how teams gate merges; worth evaluating if the org uses GitHub and wants to automate lightweight review sign-off.
  • Leader β€” Learn: AI-assisted PR approval is a governance and standards question β€” assess whether org policy should permit or restrict automated approvals before teams opt in independently.
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: Conceptual framing on trust and governance for AI agents as org adoption grows; useful for shaping early policy on AI tooling in the platform, but no actionable decision required now.
2026-09-02 Β· GitHub Changelog Β· source β†— #github-copilot#ai-coding#anthropic
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: A new Anthropic model tier optimized for autonomous coding tasks is now available in GitHub Copilot; worth tracking if evaluating AI-assisted development tooling for the org’s golden path.
  • Signals: GA announcement
  • Platform/SRE β€” Learn: Teams using Azure Monitor who store high-volume telemetry in Basic or Auxiliary tiers can now query that data through the AI observability agent without changing storage strategy; worth evaluating during next observability stack review.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Signals: GA announcement
  • Platform/SRE β€” Learn: Conceptual framing on platform maturity stages may inform how teams think about IDP evolution, but no operational change or deadline is present.
  • CI/CD β€” Skip
  • Leader β€” Learn: Useful for benchmarking where the org sits on the platform maturity curve and shaping IDP strategy conversation, but no actionable decision follows from this piece alone.
  • Platform/SRE β€” Learn: A conceptual overview of Kubernetes observability patterns β€” useful for shaping how SREs reason about distributed tracing, metrics, and logs across complex workloads, but no new tooling, GA release, or deadline requiring action.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-01 Β· GitHub Changelog Β· source β†— #github-copilot#billing#governance
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: If your org has Copilot Team seats spanning multiple GitHub organizations, review how the new multi-org model-access rules affect your billing and governance setup β€” no deadline, but worth confirming entitlements are as expected.
  • Platform/SRE β€” Learn: Pre-built signed binaries for Amazon Linux 2023 and Windows Server lower the barrier to adopting AWCP for in-memory secret caching on EC2 β€” worth evaluating if workloads still build from source. No action required for existing deployments.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-01 Β· AWS What's New Β· source β†— #aws-lambda#serverless#guardrails
  • Platform/SRE β€” Learn: This default-on guardrail stops runaway Lambda recursion via S3/SQS/SNS and sends Health Dashboard alerts; worth knowing if you operate Lambda at scale, and note that intentional recursive patterns now require explicit opt-out via PutFunctionRecursionConfig.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-01 Β· AWS What's New Β· source β†— #aws-msk#kafka#streaming
  • Platform/SRE β€” Learn: Teams running MSK Connect can now restart connectors and individual failed tasks instead of deleting and recreating them, reducing recovery toil. No migration required β€” worth updating runbooks if you operate Kafka Connect pipelines on MSK.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-09-01 Β· AWS What's New Β· source β†— #aws-cognito#m2m-auth#api
  • Platform/SRE β€” Learn: New GA path for service-to-service auth in Cognito that skips user pool domain setup; worth evaluating if you use Cognito for M2M flows, but no existing configuration breaks and no deadline exists.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-31 Β· CNCF Blog Β· source β†— #opentelemetry#observability#cncf
  • Platform/SRE β€” Learn: Graduation signals long-term project stability, reinforcing OTel as the safe default for new observability pipelines β€” no operational change required today.
  • CI/CD β€” Skip
  • Leader β€” Learn: CNCF graduation confirms OTel as a low-risk, long-term standard alongside Kubernetes and Prometheus β€” useful context when evaluating observability vendor lock-in or standardizing on OTel in the golden path.
2026-08-29 Β· GCP Release Notes Β· source β†— #gcp#cloud-build#application-integration
  • Platform/SRE β€” Skip
  • CI/CD β€” Learn: Cloud Build now offers a UI path to rotate expired access tokens for 2nd-gen Bitbucket and GitLab host connections, useful if those credentials are aging. The Application Integration authorization changeβ€”scheduled/event-triggered runs will require an explicit run-as service accountβ€”could affect event-driven release workflows, but no enforcement deadline is given and the product is outside the standard CI/CD toolchain for most teams.
  • Leader β€” Skip
2026-08-28 Β· CNCF Blog Β· source β†— #kubernetes#autoscaling#gpu
  • Platform/SRE β€” Learn: Covers a real incident pattern β€” GPU pods pending during traffic spikes β€” and predictive scaling approaches; worth reading to inform GPU cluster design, but no GA tool, deadline, or breaking change anchors an action now.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-28 Β· Kubernetes Blog Β· source β†— #kubernetes#metrics-api#api-graduation
  • Platform/SRE β€” Learn: The metrics.k8s.io/v1 API is functionally identical to v1beta1 β€” no field changes, no behavioral differences. Worth noting when planning a v1.37 upgrade so any hardcoded v1beta1 API paths in tooling or manifests get updated, but no v1beta1 deprecation deadline is announced.
  • CI/CD β€” Skip
  • Leader β€” Skip
2026-08-28 Β· HashiCorp Blog Β· source β†— #hashicorp#infrastructure#documentation
  • Platform/SRE β€” Learn: If your stack includes Vault, Consul, or Terraform, the refreshed HVDs are a useful reference for validated production deployment patterns β€” worth a bookmark, but no change to running infrastructure.
  • CI/CD β€” Skip
  • Leader β€” Skip

πŸ—„ Recently archived

2026-08-19 Β· GitLab Blog Β· source β†— #gitops#infrastructure-as-code#gitlab
  • Platform/SRE β€” Learn: A practical walkthrough integrating OpenTofu, GitLab CI/CD, and Argo CD into a unified IaC + GitOps platform pattern β€” useful design reference, but no GA capability change or deadline requiring action.
  • CI/CD β€” Learn: Illustrates how to wire GitLab pipelines to OpenTofu provisioning and Argo CD deployments end-to-end; worth reviewing as a pipeline design reference, but nothing here forces a pipeline change.
  • Leader β€” Skip
2026-08-19 Β· GitHub Changelog Β· source β†— #github-copilot#jetbrains#enterprise
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: Organizations standardizing on JetBrains IDEs with GitHub Copilot can now enforce plugin governance, MCP server access controls, and permission modes centrally β€” worth reviewing if Copilot is part of the AI tooling policy.
  • Platform/SRE β€” Skip
  • CI/CD β€” Learn: Illustrates a prompt-injection attack vector where malicious repo content hijacks an AI agent’s pre-approved command scope; informs how to think about sandboxing agent-assisted pipeline steps, but no deadline or active exploit anchor.
  • Leader β€” Learn: Useful framing for setting policy on where and how AI coding agents are permitted to run in the development workflow, particularly around isolation boundaries β€” but no decision is forced today.
  • Platform/SRE β€” Learn: Conceptual framing of multi-plane sovereignty architecture that could inform future platform design decisions, but no actionable change required today and no concrete deadline or migration target.
  • CI/CD β€” Skip
  • Leader β€” Learn: Useful strategic context on sovereignty architecture patterns for leaders weighing data-residency or regulatory requirements, but no vendor decision or cost implication is triggered by this piece.
  • Platform/SRE β€” Learn: Useful capability for EU Sovereign Cloud workloads needing short-lived JWT auth to external services without long-term credentials, but no deadline or EOL pressure β€” evaluate if operating in the Germany Sovereign Cloud region.
  • CI/CD β€” Skip
  • Leader β€” Learn: Relevant context for organizations with EU data sovereignty requirements: AWS Sovereign Cloud now supports outbound identity federation, potentially reducing compliance friction for regulated workloads in Germany.
2026-08-19 Β· AWS What's New Β· source β†— #aws-bedrock#ai-ml#data-residency
  • Platform/SRE β€” Skip
  • CI/CD β€” Skip
  • Leader β€” Learn: Relevant if the org operates in India with data-residency requirements and uses Bedrock β€” this expands the compliant model options available without leaving AWS, worth noting for AI strategy reviews.
2026-08-19 Β· Docker Blog Β· source β†— #ai-agents#security#governance
  • Platform/SRE β€” Learn: The incident data on 17,600 attacker actions is a useful framing for why platform-level controls (observation, constraint, blast-radius limiting) matter for agentic workloads, but there is no deployment action or deadline here β€” useful for teams beginning to run AI agents on shared infrastructure.
  • CI/CD β€” Skip
  • Leader β€” Learn: Relevant context for leaders setting AI adoption standards: the argument that agent governance requires systemic controls, not per-action review, shapes how to frame agentic AI policy, but no licensing, cost, or vendor decision is forced by this piece.
2026-08-18 Β· AWS What's New Β· source β†— #aws-ec2#compute#regional-availability
  • Platform/SRE β€” Learn: New memory-optimized instance family now available in Calgary; worth evaluating if you run memory-intensive or PostgreSQL workloads in that region, but no deadline or breaking change forces action.
  • CI/CD β€” Skip
  • Leader β€” Skip
  • Platform/SRE β€” Learn: Docker’s extended security coverage and source-built images could reduce CVE surface on base images, but no EOL date or forced migration anchor exists β€” worth evaluating at next image refresh cycle.
  • CI/CD β€” Learn: Policy enforcement moving to developer machines and provenance guarantees through customized images are worth tracking for supply-chain hardening plans, but no deadline or breaking change makes this actionable now.
  • Leader β€” Skip
  • Signals: deprecation mentioned (no explicit date found)
2026-08-18 Β· AWS What's New Β· source β†— #opensearch#aws#search
  • Platform/SRE β€” Learn: Useful capability expansion for teams running OpenSearch in VPC environments β€” semantic search now available without public exposure. No operational changes required; worth noting if search relevance is on the roadmap.
  • CI/CD β€” Skip
  • Leader β€” Skip