verdict: Plan · 204 items
- Platform/SRE — Plan: Windows Server 2025 is now a supported node OS on AKS, giving teams a clear upgrade target as older Windows Server versions approach end of support. Schedule evaluation of Windows node pool migration this quarter, especially if running 2019 or 2022 nodes — no forced-upgrade date is signaled yet, but the deprecation mention warrants adding it to the roadmap.
- CI/CD — Skip
- Leader — Learn: AKS now supports Windows Server 2025, extending the viability of Windows-based workloads on managed Kubernetes — useful context if the org is evaluating its Windows modernization strategy, but no strategic or cost decision is required now.
- Signals: deprecation mentioned (no explicit date found) · GA announcement
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: Copilot model deprecations took effect September 1, 2026 — verify which models your org relies on in Copilot Chat, completions, or agent mode are still available, and update any tooling or policy that specified a now-removed model.
- Signals: deprecation/EOL deadline mentioned: September 1, 2026
- Platform/SRE — Plan: If your org runs Vault Enterprise and is deploying AI agent workloads, this GA feature adds purpose-built IAM controls worth evaluating this quarter; no forced migration or deadline, but assess whether your current Vault version and license tier expose it.
- CI/CD — Skip
- Leader — Learn: This signals Vault Enterprise is extending its security model to cover AI agent identities; worth noting if AI agent adoption is on the roadmap and the org is already standardized on Vault Enterprise, but no strategy or contract decision is required now.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: If the org runs GHES and is evaluating a move to GitHub Enterprise Cloud with Data Residency, this GA milestone removes the primary operational risk (downtime) from the migration path — worth scheduling an evaluation this quarter.
- Signals: GA announcement
- Platform/SRE — Plan: If your platform runs Azure Container Apps, this GA feature lets you consolidate posture management under Defender for Cloud rather than operating a separate security toolchain; evaluate enabling it this quarter.
- CI/CD — Skip
- Leader — Learn: Extends unified container security posture to serverless workloads on Azure — worth noting if your org is standardizing on Defender for Cloud as the security management plane.
- Signals: GA announcement
- Platform/SRE — Plan: CVM node pools on AKS are now GA, enabling sensitive workload isolation at the hardware level; evaluate whether regulated or high-sensitivity workloads in your clusters warrant migrating to CVM node pools this quarter.
- CI/CD — Skip
- Leader — Learn: GA confidential compute on AKS is a new capability relevant to compliance and data-sovereignty positioning, but no immediate strategic decision is required unless the org has active regulated-workload requirements on Azure.
- Signals: GA announcement
- Platform/SRE — Plan: New GA capability unifies monitoring of self-managed PostgreSQL on EC2 alongside RDS/Aurora in a single console; worth evaluating if you run mixed database fleets to consolidate your observability stack.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: This GA capability lets platform teams migrate high-volume compliance and audit Azure tables to the lower-cost Auxiliary plan without rebuilding pipelines. Evaluate which existing Log Analytics tables qualify for plan switching this quarter to reduce observability ingestion costs.
- CI/CD — Skip
- Leader — Plan: The plan-switching capability is a concrete FinOps lever for reducing Azure Monitor spend on high-volume, rarely-queried compliance logs. Worth scheduling an audit of Log Analytics table plans to identify cost-reduction opportunities within the current planning cycle.
- Signals: GA announcement
- Platform/SRE — Plan: If you operate workloads in Azure Government or Azure China, this new GA log tier offers a cheaper ingestion and retention path for high-volume compliance/audit logs — evaluate whether shifting verbose log streams to Auxiliary tables reduces your Monitor costs this quarter.
- CI/CD — Skip
- Leader — Learn: Auxiliary Logs adds a cost-effective tier for compliance and audit log retention in sovereign cloud regions; useful context if the org has Azure Government or China footprint and is managing observability spend, but no strategic decision is forced.
- Signals: GA announcement
- Platform/SRE — Plan: Artifact streaming on AKS+ACR is now GA and can reduce pod startup latency during scale-out events; evaluate enabling it for workloads where image pull time is a bottleneck this quarter.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: StorageVersionMigration API (storagemigration.k8s.io/v1) is now stable and enabled by default in Kubernetes 1.37, removing the need for manual migration scripts when promoting or dropping CRD API versions. Plan to incorporate SVM into your CRD lifecycle runbooks when scheduling the upgrade to 1.37 (EOL 2027-10-28).
- CI/CD — Skip
- Leader — Skip
- Signals: Kubernetes 1.37 EOL 2027-10-28 · GA announcement
- Platform/SRE — Plan: Teams using ASR on AWS should evaluate the AI Toolkit and expanded GuardDuty/Inspector/Macie coverage; the enhanced console replaces manual DynamoDB/SSM config, making this a worthwhile platform security upgrade to schedule this quarter.
- CI/CD — Skip
- Leader — Learn: The shift from manual SSM Automation expertise to AI-guided remediation generation signals a meaningful reduction in barrier-to-entry for automated security response — worth tracking as an indicator of where cloud-native security tooling is heading.
- Platform/SRE — Plan: New GA AWS service adds cross-account agent catalog support via CloudFormation, Terraform, CDK, and AWS RAM — worth evaluating this quarter if your org is building shared AI agent infrastructure, as it may change how you architect agent discovery and access control across accounts.
- CI/CD — Skip
- Leader — Learn: AWS Agent Registry offers a governed, org-wide catalog for AI agents and tools with audit trails and cross-account sharing; worth tracking as a pattern for AI governance strategy, but no immediate decision or vendor-risk event is present.
- Signals: GA announcement
- Platform/SRE — Plan: If Redshift is in your stack and you have data residency or network-isolation requirements, this is worth adopting: SSO via IAM Identity Center with all auth traffic staying inside your VPC via PrivateLink. Evaluate enabling EVR and wiring up Identity Center for your provisioned clusters or serverless workgroups this quarter.
- CI/CD — Skip
- Leader — Learn: Redshift now supports SSO via IAM Identity Center with network traffic fully contained in your VPC — relevant context if your org has regulatory or data-residency mandates for analytics infrastructure, but no decision is forced by this launch.
- Platform/SRE — Plan: New GA Graviton5 memory-optimized instances offer up to 25% better compute and 30% faster database performance vs R8g; evaluate migrating memory-intensive workloads (Kubernetes nodes, caches, databases) this quarter to capture the price-performance gains.
- CI/CD — Skip
- Leader — Learn: Graviton5 R9g instances establish a new price-performance ceiling for memory-intensive workloads on AWS; useful context for future FinOps and instance-family standardization decisions but no forcing function today.
- Signals: GA announcement
- Platform/SRE — Plan: New GA WarmUpConfiguration parameter lets teams delay alarm evaluation after resource creation, reducing on-call noise from missing-data transitions during startup. Update IaC alarm definitions (Terraform/CloudFormation) to include warm-up periods for resources that take time to begin emitting metrics.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA minor release of a core IaC tool with meaningful platform capabilities: import blocks inside modules, a store block for ephemeral/sensitive values across plan and apply, and on_failure modes for resource action triggers. No breaking changes or EOL deadline, but worth scheduling evaluation and adoption this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you use Pulumi with connection-string URLs (e.g. Postgres), upgrade to sdk/v3.260.0 to prevent passwords leaking into state/log output; no hard deadline but a meaningful security hygiene improvement.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Kubernetes 1.37.0 is a new minor release worth evaluating for adoption this quarter; review the CHANGELOG for API removals or deprecations that may affect running workloads before scheduling an upgrade window.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: A new Istio minor release is always a candidate for upgrade planning — review the full release notes for breaking changes, API removals, or deprecations before scheduling a mesh upgrade this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: v1.39.1 fixes multiple CVEs in Envoy’s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Envoy is a common data-plane component in service meshes and ingress layers; this patch addresses a use-after-free in HTTP/3, process-termination bugs in HTTP/2, and multiple URL-normalization bypasses. No KEV listing or known active exploitation, so no hard deadline, but upgrade to v1.38.4 should be scheduled this sprint for any fleet running Envoy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Backstage is IDP infrastructure platform engineers commonly operate; this patch carries security fixes with no CVE details or KEV/exploitation data in the signals. Schedule upgrade to 1.49.6 within the current patch cycle — no hard deadline anchors Act.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you self-host Backstage as your internal developer platform, schedule an upgrade to 1.50.5; the release is flagged as a security fix recommended for all 1.50 users, though no specific CVE or active-exploitation evidence is provided in the signals to anchor an Act verdict.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Teams running Argo CD should schedule an upgrade to 3.4.8 this sprint: it patches three CVEs in UI JS dependencies (none KEV-listed, EPSS ≤ 0.01) and fixes an auto-sync regression that silently skips syncs when a newer commit arrives during an active sync. No hard deadline, but the sync bug is a silent correctness risk on busy clusters.
- CI/CD — Skip
- Leader — Skip
- Signals: Argo CD 3.4 supported · CVE-2026-14257 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-49978 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-59869 — CISA KEV: not listed, EPSS 0.01
- Platform/SRE — Plan: Pod Certificates and Cluster Trust Bundles reaching GA in Kubernetes 1.37 introduces native X.509/mTLS workload identity as an alternative to service account JWTs; evaluate adopting cluster trust bundles and pod certificate issuance this quarter for services requiring mTLS.
- CI/CD — Skip
- Leader — Learn: Native X.509 workload identity baked into Kubernetes core shifts how orgs can approach service-to-service auth without a service mesh; worth tracking as input to future golden-path and identity-standards decisions.
- Signals: Kubernetes 1.37 EOL 2027-10-28
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: GitHub Copilot billing and policy changes affect org-wide licensing costs and seat management; review the three upcoming changes and assess contract or budget impact before they take effect.
- Platform/SRE — Skip
- CI/CD — Plan: Starting October 1, 2026, GitHub Actions retention settings will also govern checks, workflow runs, and commit statuses — review your current retention configuration to ensure historical build data and compliance audit trails are preserved as expected before the change takes effect.
- Leader — Skip
- Platform/SRE — Plan: Teams running Amazon Linux 2023 or other systemd-only distros no longer need disk-export workarounds to ship structured journal logs to CloudWatch. Update the CloudWatch agent to the latest version and add a journald config block to consolidate logging for those instances this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: This GA capability lets AKS pods authenticate to SMB file shares via workload identity instead of node-level managed identity, improving least-privilege posture. Evaluate replacing existing managed-identity-based Azure Files mounts with workload identity bindings in your next infrastructure review cycle.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: If you run HCP Vault Dedicated on Azure and use Microsoft Sentinel for SIEM, schedule building the Terraform-managed audit log pipeline described here; no deadline exists, but closing this observability gap is a concrete infrastructure task worth adding to the backlog this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you run Mountpoint in EKS or other memory-constrained environments, upgrading to the latest release lets you set explicit memory targets or rely on automatic container-limit detection, preventing the expansion-over-time instability that previously competed with ML or analytics workloads. No deadline, but worth scheduling as a planned upgrade this quarter if Mountpoint is in your stack.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: A new GA Kubernetes minor release with 16 enhancements graduating to Stable and one deprecation/removal is a direct platform concern; audit the removal for any API or feature you currently use and schedule cluster upgrade evaluation this quarter — no forced-upgrade date was found, so Act isn’t warranted yet.
- CI/CD — Skip
- Leader — Learn: Kubernetes v1.37 reflects continued platform maturity but carries no licensing, cost, or vendor-risk angle and no forced-migration deadline; awareness is useful for roadmap conversations, but no leadership decision is pending.
- Signals: deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: If your org uses HCP (Vault, Terraform Cloud, etc.) and an external IdP, evaluate enabling SCIM provisioning to automate user/group sync and reduce manual access management overhead; no deadline, but worth scheduling this quarter.
- CI/CD — Skip
- Leader — Plan: SCIM provisioning on HCP reduces IAM admin overhead and improves access consistency across HCP services — worth adding to your identity governance standards review if the org is standardized on HashiCorp HCP.
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: Organizations on Copilot Business or Enterprise should review and configure their global model policy now, as enforcement is actively rolling out and unreviewed defaults may not match org AI governance requirements.
- Signals: GA announcement
- Platform/SRE — Plan: GA Bastion-to-AKS tunneling removes the need for a public API server endpoint or VPN for cluster access; evaluate adopting this as the standard private-cluster access pattern in your AKS environments this quarter.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: The GA rule insights dashboard gives pipeline and release teams visibility into how GitHub enforces branch protection and ruleset policies; worth enabling at the org level to surface enforcement gaps in your release process.
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: Cloud SQL Proxy V1 (‘cloud_sql_proxy’) is removed from gcloud SDK 582.0.0 — audit infrastructure automation and connection scripts for V1 references and migrate to ‘cloud-sql-proxy’ V2 before upgrading gcloud to 582.0.0.
- CI/CD — Plan: If pipelines use gcloud to establish Cloud SQL connections or reference the removed api-registry MCP commands, they will break on upgrade to gcloud 582.0.0 — audit pipeline scripts and update to Cloud SQL Auth Proxy V2 before rolling out the new SDK version.
- Leader — Skip
- Signals: breaking-change flagged
Plan
EC2 Capacity Reservation Resource Groups now support Capacity Blocks and interruptible reservations
- Platform/SRE — Plan: If your platform manages ML workloads or uses mixed reservation types, this GA change lets you consolidate Capacity Blocks and interruptible ODCRs into unified resource groups with prioritization and On-Demand fallback — worth incorporating into capacity planning and Auto Scaling group configs this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If your platform integrates Cisco Security Cloud Control or Netskope, you can now remove any custom Lambda rotation logic and let Secrets Manager handle scheduled credential rotation natively; worth scheduling a migration this quarter for affected integrations.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA capability that changes the connectivity architecture for Lambda MicroVMs in regulated environments — if you operate Lambda MicroVMs today or are evaluating them for compliance-sensitive workloads, schedule an evaluation to replace public-internet API paths with PrivateLink VPC Endpoints.
- CI/CD — Skip
- Leader — Learn: For organizations in financial services, healthcare, or government, this GA capability reduces a compliance blocker for Lambda MicroVM adoption, but no licensing, pricing, or vendor-risk decision is triggered — file as context for regulated-workload platform strategy.
- Platform/SRE — Plan: If your platform runs GPU or compute-intensive batch jobs on self-managed EC2 via AWS Batch, this GA feature shifts AMI patching and instance lifecycle management to AWS — worth evaluating for reduction in operational overhead this quarter.
- CI/CD — Skip
- Leader — Learn: AWS Batch on ECS Managed Instances could change the build-vs-manage calculus for GPU batch workloads, offloading patching overhead to AWS — worth noting as a potential cost and ops trade-off in future platform reviews.
- Platform/SRE — Plan: This GA release moves AKS packet forwarding into the kernel via eBPF, potentially reducing latency and CPU overhead for networking-heavy workloads; plan evaluation and enablement on AKS clusters running Advanced Container Networking Services this quarter.
- CI/CD — Skip
- Leader — Learn: AKS is expanding its networking performance story with eBPF-based host routing reaching GA — worth noting as a differentiator when evaluating managed Kubernetes options, but no immediate strategic decision required.
- Signals: GA announcement
- Platform/SRE — Plan: Platform teams managing Lambda in multi-account architectures can now consolidate per-principal permission statements into single policy documents with full IAM condition key support (source IP, principal tags, etc.). Plan a policy consolidation pass for existing Lambda functions to reduce policy sprawl and simplify ongoing management.
- CI/CD — Skip
- Leader — Learn: This GA capability reduces IAM policy complexity for Lambda-heavy multi-account orgs, but it’s an incremental improvement rather than a strategic or cost-model shift — no leadership decision required.
- Platform/SRE — Plan: This GA feature removes the need for an identity broker when authenticating multiple user populations (employees, contractors, CI/CD systems) to EKS clusters. Evaluate whether your clusters could simplify their auth architecture by replacing any intermediary OIDC broker with direct per-provider associations.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: A new GA ECS capability worth adopting this quarter: Fargate and Managed Instances now auto-drain and replace impaired instances, while EC2-based ECS surfaces the new AGENT_CONNECTIVITY health event that teams must wire into their own instance-replacement automation. No deadline, but teams running ECS on EC2 should build the event-driven replacement workflow to gain equivalent resilience.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: CVE-2026-14978 (Unicode normalization in go-slug) can cause files to leak into HCP Terraform/TFE runs despite .terraformignore rules; not KEV-listed and EPSS 0.00, but worth upgrading Terraform to 1.15.9 in the next maintenance window if you upload sensitive files via remote runs.
- CI/CD — Plan: If pipelines run Terraform remote operations against HCP Terraform or Terraform Enterprise, the .terraformignore bypass in CVE-2026-14978 could leak secrets or config files into run uploads; pin Terraform to 1.15.9 in CI pipeline tooling during the next scheduled update.
- Leader — Skip
- Signals: CVE-2026-14978 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Three behavioral changes affect running Prometheus deployments: the stats query-parameter deprecation (other values still work but will be rejected in the next major), the __meta_hetzner_datacenter label drop for hcloud targets, and PromQL duration expressions now enabled by default. Review your relabeling configs, any Hetzner service-discovery rules, and PromQL queries before upgrading; no hard deadline yet since rejection is deferred to the next major release.
- CI/CD — Skip
- Leader — Skip
- Signals: deprecation/EOL deadline mentioned: 2026-08-17
- Platform/SRE — Plan: Two security fixes affect IaC workflows: credentials intended for an OCI registry origin can leak to HTTP redirect targets, and tofu init can be forced into high CPU/memory usage via crafted URLs from an attacker-controlled state backend or registry. Upgrade OpenTofu to 1.12.6 in your IaC toolchain this sprint; no KEV listing or confirmed active exploitation, but both issues are directly triggerable in adversarial environments.
- CI/CD — Plan: If tofu init runs in your pipelines against external module/provider registries or remote state backends, both the credential-leak and resource-exhaustion issues apply there too. Pin the OpenTofu version in your pipeline tooling to 1.12.6 as part of your next dependency update cycle.
- Leader — Skip
- Platform/SRE — Plan: CVE-2026-17183 is patched in 13.2.0; EPSS is 0.00 and it is not KEV-listed, so there is no emergency, but schedule an upgrade of self-hosted Grafana this quarter to pick up the security fix and the alerting notifications API migration to v1beta1.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Grafana is a common observability stack component; CVE-2026-17183 is not KEV-listed and carries EPSS 0.00, so no active exploitation signal, but schedule an upgrade to 13.1.4 this sprint as standard patch hygiene.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: CVE-2026-17183 is fixed in this patch for Grafana, which is common observability infrastructure. Not KEV-listed and EPSS is 0.00, so no forced urgency, but schedule an upgrade to 13.0.7 this sprint as standard security hygiene.
- CI/CD — Skip
- Leader — Skip
- Signals: major release (13.0) · CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Grafana 12.4.9 includes a security fix for CVE-2026-17183 (not KEV-listed, EPSS 0.00 — no active exploitation). Schedule an upgrade to 12.4.9 in your next maintenance window; no emergency action required.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: If you operate Backstage, three breaking changes require pre-upgrade review: OAuth redirect URI wildcard semantics changed (audit any custom allowlist patterns before upgrading), the deprecated
config.schemaextension option is removed (update any custom plugins using it), and the early Connections API contract shifted. Schedule the audit and upgrade this quarter. - CI/CD — Skip
- Leader — Skip
- Signals: deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: The M4N machine series is now GA on GCP, offering up to 400 Gbps network and 1M IOPS for memory/network-intensive workloads like vector databases and RAG layers — evaluate whether it fits high-memory workload placements this quarter. CVE-2026-12710 in Application Integration was already patched server-side on April 4, 2026; no customer action required.
- CI/CD — Skip
- Leader — Learn: GCP’s M4N instance family (GA) targets high-memory AI infrastructure workloads such as vector databases and in-memory RAG layers — relevant context for future GCP AI/ML platform architecture discussions, but no immediate strategic or budget decision is forced.
- Signals: GA announcement · CVE-2026-12710 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: The managed EKS Argo CD capability now accepts argocd-cm ConfigMap settings, including custom health checks for CRDs that can hold sync waves until resources finish provisioning. If your clusters use this managed capability, evaluate adding custom health checks for your Custom Resources this quarter.
- CI/CD — Learn: Custom health check logic for CRDs in EKS-managed Argo CD means sync wave advancement can now be gated on actual resource readiness rather than Argo CD’s default no-op behavior; worth factoring into GitOps deployment design if your org uses this specific managed capability.
- Leader — Skip
- Platform/SRE — Plan: If your org runs GitLab Dedicated, the AI Gateway for Duo Agent Platform is now deployable inside your single-tenant environment, keeping AI-processed data in your chosen AWS region. Evaluate this quarter whether to enable it as part of your agentic DevOps rollout.
- CI/CD — Skip
- Leader — Learn: Organizations using GitLab Dedicated for compliance or data-residency reasons can now extend that boundary to AI agent workloads — shapes thinking on how to pursue agentic DevOps without relaxing data-sovereignty requirements.
- Platform/SRE — Plan: Teams self-hosting GitLab should plan an upgrade to 19.3 and note that it reaches EOL on 2026-11-19, meaning another upgrade cycle must be scheduled within the quarter to stay on a supported version.
- CI/CD — Plan: Review the 19.3 release notes for any pipeline syntax, runner, or artifact-handling changes; schedule adoption before the 2026-11-19 EOL to avoid running unsupported GitLab CI infrastructure.
- Leader — Skip
- Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
- Platform/SRE — Skip
- CI/CD — Plan: New GA capability in GitLab 19.3 that lets domain experts author Custom Flows via natural language instead of learning the Flow Registry YAML schema; worth evaluating this quarter to reduce the bottleneck between process knowledge and automation authorship.
- Leader — Skip
- Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
- Platform/SRE — Plan: Teams self-hosting GitLab should note that 19.3 reaches EOL 2026-11-19 (~90 days); plan an upgrade to 19.4 or later before that date to stay on a supported version.
- CI/CD — Learn: GitLab 19.3 GA adds bulk false-positive dismissal and agentic SAST remediation for existing vulnerability backlogs — worth evaluating if your pipelines already produce GitLab SAST findings, but no urgent action is required.
- Leader — Skip
- Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
- Platform/SRE — Skip
- CI/CD — Plan: The Windows 11 arm64 VS2026 runner image is now GA on GitHub-hosted runners; teams building Windows arm64 artifacts should evaluate updating workflow
runs-onlabels to adopt the new image this quarter. - Leader — Skip
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: If you use CodeQL in GitHub Actions, evaluate adopting the new dedicated workflow path to improve run-history clarity and accurate usage reporting — no deadline, but worth scheduling as routine pipeline hygiene.
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: For teams running workloads on AWS Outposts with data residency requirements, this GA capability enables AMI and backup lifecycle workflows to keep snapshots fully on-Outpost without specifying an ARN manually — worth integrating into Outposts image-management processes this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you use S3 MRAP with CloudFront, you can now drop the Lambda@Edge workaround for SigV4a signing and let CloudFront handle OAC natively — plan to migrate existing custom auth header functions to simplify the architecture.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: EKS clusters created in 2018 have 10-year CAs now approaching expiry (~2028); audit cluster creation dates and schedule CA rotation this quarter — worker nodes must be replaced and external API clients updated to trust the successor CA before activation, which AWS will not do automatically.
- CI/CD — Learn: Pipelines that connect directly to EKS API servers (kubectl, Helm deploys, kubeconfig-based auth) qualify as external clients under the shared-responsibility model and would need CA trust updates during any rotation; no immediate action required but worth noting when rotation is scheduled by Platform.
- Leader — Skip
- Platform/SRE — Plan: GA capability that simplifies multi-team DynamoDB Streams IAM policy management via tag-based conditions; worth adopting this quarter if you manage access across multiple environments or teams on DynamoDB Streams.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: GA additions to CloudWatch pipelines reduce the need for custom log-transformation Lambda functions or external processors; evaluate replacing any bespoke RDS/XML parsing glue with these managed processors during the next observability stack review.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: Teams using CloudWatch Centralization can now preserve cost, ownership, and compliance tags across accounts — worth enabling tag propagation on existing centralization rules to unlock IAM scoping and per-team cost attribution in Cost Explorer.
- CI/CD — Skip
- Leader — Learn: Tag propagation on centralized logs enables per-team observability cost attribution out of the box, which may inform how your org structures log ownership and FinOps reporting for multi-account environments.
- Platform/SRE — Plan: Now GA, these features let you right-size compute for workloads needing predictable single-threaded performance (e.g. licensed-per-core DBs) or reduced licensing costs; evaluate whether any production node pools or VM fleets would benefit from constrained-core configurations this quarter.
- CI/CD — Skip
- Leader — Plan: Constrained Cores can reduce per-core software licensing costs on Azure VMs; evaluate whether standardizing on constrained-core SKUs in the next planning cycle would yield material savings for licensed-per-core workloads.
- Signals: GA announcement
- Platform/SRE — Plan: If you run Tape or Volume Gateway for regulated workloads, you can now route FIPS-compliant traffic privately via PrivateLink instead of over the public internet; plan to create a FIPS interface VPC endpoint and re-activate gateways on software version 3.2.7 or later.
- CI/CD — Skip
- Leader — Learn: For organizations with compliance mandates (FedRAMP, HIPAA) using Storage Gateway, this removes a previous architectural constraint — FIPS traffic can now stay private — which may simplify audit scope for regulated workloads.
- Platform/SRE — Learn: Relevant for teams self-hosting GitLab — shallow and partial clones reduce server-side pack-building load, which compounds as agentic workloads increase clone frequency. No operational change required today, but useful context for capacity planning.
- CI/CD — Plan: Audit pipeline clone configurations and migrate to shallow (
--depth=1) or partial (--filter=blob:none) clones; benchmarks show up to 93% time and 98% disk reduction per clone. No hard deadline, but AI-agent-driven clone volume makes this a near-term efficiency project worth scheduling this quarter. - Leader — Skip
- Platform/SRE — Plan: Platform engineers managing Terraform-deployed AWS infra can now generate least-privilege IAM policies directly from plan files rather than hand-crafting them; worth integrating into the IaC workflow this quarter to reduce wildcard usage and policy drift.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Learn: Useful new GitHub admin capability for scoping credential revocation by token type during incidents, but no infra dependency or deadline — worth knowing for incident runbooks.
- CI/CD — Plan: Scope incident response playbooks to leverage token-type revocation for PATs, OAuth tokens, and GitHub App tokens; audit current credential hygiene and update runbooks to use this targeted revocation before the next supply-chain incident.
- Leader — Skip
- Platform/SRE — Plan: App Engine Images→Cloud Run migration support is now GA for Java and Python — schedule evaluation this quarter if you operate App Engine standard workloads. Cloud SDK 581.0.0 flags a breaking change (removal of
gcloud beta services mcpcommands), but those were already no-ops so real pipeline impact is minimal; worth verifying before upgrading the SDK. - CI/CD — Skip
- Leader — Learn: The GA availability of the App Engine→Cloud Run migration path is a strategic signal if the org still runs App Engine workloads; no forced deadline, but it clarifies the long-term migration route Google is offering.
- Signals: GA announcement · breaking-change flagged
- Platform/SRE — Plan: New GA Azure App Service capability that enables lift-and-shift of on-premises or VM-hosted web apps to PaaS with minimal config changes; worth evaluating this quarter if the org runs any workloads on Azure VMs or bare metal that could be moved to a managed runtime.
- CI/CD — Skip
- Leader — Learn: Azure’s new managed migration path for web apps to App Service could shift build-vs-buy calculus for teams still running on VMs, but without pricing or SLA details in the announcement there’s no immediate strategic decision to make.
- Signals: GA announcement
- Platform/SRE — Learn: Kubeflow’s CNCF graduation signals broader enterprise adoption maturity; worth evaluating if your org runs ML workloads on Kubernetes, but no operational change required today.
- CI/CD — Skip
- Leader — Plan: CNCF graduation marks Kubeflow as a de-facto standard for cloud-native MLOps; evaluate whether to include it in the platform golden path for teams running AI/ML workloads this quarter.
- Platform/SRE — Plan: Useful GA capability for teams running large ephemeral fleets (ML training, event-driven); worth adopting in scale-down logic this quarter to reduce API call overhead and simplify fleet teardown scripts.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Rule hit counts are now enabled by default on AWS Network Firewall stateful rules, enabling detection of shadow, redundant, and unused rules — worth scheduling a policy audit this quarter to clean up firewall rule sets.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Three symlink/mount CVEs in the Docker engine (none KEV-listed, EPSS 0.00) warrant scheduling a patch to Moby 25.0.17 this sprint; also note that containerd 1.7 — vendored in this release — reaches EOL 2026-09-01, so any org running containerd 1.7 directly must plan a runtime upgrade within 15 days.
- CI/CD — Skip
- Leader — Skip
- Signals: containerd 1.7 reaches EOL in 15d (2026-09-01) · major release (25.0) · CVE-2024-40635 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41567 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41568 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Despite being a patch release, 2.3.4 ships a breaking change: checkpoint restore in CreateContainer is now disabled by default, requiring an explicit config opt-in. Also fixes a memory leak in the OOM watcher and binary protobuf shim corruption. Review workloads using CRIU/checkpoint restore before upgrading; schedule the upgrade this quarter.
- CI/CD — Skip
- Leader — Skip
- Signals: containerd 2.3 EOL 2028-04-30 · deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: containerd 2.2 reaches EOL on 2026-11-06 (81 days), so plan migration to a supported branch before then; also note this patch disables checkpoint restore in CreateContainer by default, which may break CRIU-based workloads that haven’t set enable_experimental_restore_via_create.
- CI/CD — Skip
- Leader — Skip
- Signals: containerd 2.2 reaches EOL in 81d (2026-11-06) · deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: v3.3.14 patches CLI secret-mask spoofing and fixes secrets leaking in last-applied-configuration annotations; CVE-2026-49978 (DOMPurify) is not KEV-listed and carries EPSS 0.00, so no emergency — schedule the upgrade within the quarter.
- CI/CD — Plan: Argo CD is explicitly in scope as the GitOps delivery layer; the server-side diff secret-mask spoofing fix could expose sensitive data in pipeline contexts — plan the upgrade to v3.3.14 this quarter.
- Leader — Skip
- Signals: Argo CD 3.3 supported · CVE-2026-49978 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: If your org builds custom AMIs or VM images with Packer, this GA release introduces native SLSA provenance that strengthens image supply-chain attestation — worth adopting this quarter as part of a platform hardening cycle.
- CI/CD — Plan: Packer v1.16.0 adds native SLSA provenance generation to machine image builds; if your pipelines include image baking steps, schedule an update to enable provenance output and integrate verification into the release gate.
- Leader — Learn: Packer’s native SLSA provenance support signals a maturing supply-chain posture for machine images, relevant to orgs building toward SLSA compliance — no immediate strategic decision required but worth factoring into policy planning.
- Platform/SRE — Plan: AKS operators can now collect native control plane metrics (API server, etcd, scheduler) through Managed Prometheus without custom exporters — worth scheduling adoption this quarter to close gaps in cluster observability.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: Role manager can simplify onboarding new AWS services by auto-generating least-privilege starter roles, but teams with strict IaC discipline should evaluate whether console-created roles conflict with Terraform/CDK-managed IAM. Schedule a review of how role manager interacts with existing role governance before enabling org-wide.
- CI/CD — Skip
- Leader — Learn: Role manager lowers the barrier to correct IAM role setup for console-driven workflows, which may reduce misconfiguration risk across teams; worth noting as a governance tool but no immediate strategic decision required.
- Signals: GA announcement
- Platform/SRE — Plan: New GA capability lets EKS cluster admins tune scheduler, controller manager, and API server parameters — e.g. switching to MostAllocated bin-packing to reduce node count. Review the full parameter list and evaluate whether tuning fits your cluster’s resource-utilization or scaling goals this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Learn: Reveals a blind spot in egress allowlist design: an allowed service (package proxy) can itself be pivoted through to reach the internet. Useful for rethinking network isolation architecture for sandboxes and evaluation environments, but no specific platform component or deadline to act on.
- CI/CD — Plan: The article explicitly names CI runners as sharing the same reachability structure as the exploited sandbox; egress allowlists that permit package proxies may allow lateral movement. Audit CI runner egress allowlists and ensure package proxy or dependency-resolution services on the allowlist cannot themselves serve as internet pivots.
- Leader — Learn: A responsibly disclosed AI agent security incident (OpenAI/Hugging Face) showing that agentic workloads can escape sandboxes through indirect paths, with real credential and data exposure. Relevant context for evaluating risk posture around AI agent adoption and agentic CI tooling, but no immediate vendor or strategic decision is forced.
- Platform/SRE — Skip
- CI/CD — Plan: If any pipelines invoke MAI-Code-1-Flash via GitHub Copilot APIs or extensions, migrate to MAI-Code-1.1-Flash before September 10, 2026 to avoid breakage.
- Leader — Skip
- Signals: deprecation/EOL deadline mentioned: September 10, 2026
- Platform/SRE — Skip
- CI/CD — Plan: If your repos still use legacy branch protection rules, schedule migration to GitHub rulesets using the new in-settings converter — rulesets offer better scalability and cross-repo policy management with no hard deadline yet.
- Leader — Skip
- Platform/SRE — Learn: CNB graduation signals broad production readiness for buildpack-based image builds; worth evaluating as a standardized, OCI-compliant alternative to Dockerfiles in the platform image pipeline.
- CI/CD — Plan: CNCF graduation makes Cloud Native Buildpacks a credible standard for container build steps in CI pipelines; evaluate adopting pack or a platform-native buildpack integration to replace Dockerfile-based builds this quarter.
- Leader — Learn: CNB reaching CNCF graduation reflects growing industry consensus around buildpack-based container standards; useful context for golden-path and build-vs-buy decisions but no immediate strategic action required.
- Platform/SRE — Learn: New GA capability for automating credential rotation without custom code; worth knowing for teams already using Secrets Manager managed external secrets, but no operational urgency.
- CI/CD — Plan: Teams using Jenkins or SonarQube with AWS Secrets Manager can now automate token rotation natively — schedule evaluation and adoption to reduce manual credential lifecycle work and lower the risk of stale tokens in pipelines.
- Leader — Skip
- Platform/SRE — Plan: This new GA feature unifies IAM role flexibility with IAM Identity Center federation, replacing the previous two-approach trade-off. Platform engineers managing AWS workforce access should evaluate adopting account access manager as their standard approach this quarter — no migration deadline exists, but it simplifies ongoing access architecture.
- CI/CD — Skip
- Leader — Learn: AWS now offers a third path for workforce federation that combines centralized user awareness with per-account IAM role granularity. Worth knowing as context when reviewing org-wide AWS access standards, but no licensing, pricing, or vendor-risk decision is triggered.
- Platform/SRE — Plan: R8a instances offer meaningful memory bandwidth and price-performance gains over R7a for memory-intensive workloads (databases, in-memory caches); worth evaluating for Canada Central production workloads during the next capacity planning cycle.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: The Cloud Run functions upgrade tool for migrating 1st-gen workloads to Cloud Run functions is now GA; schedule a migration project if your platform still runs 1st-gen functions to reduce future EOL exposure.
- CI/CD — Skip
- Leader — Plan: Cloud Hub’s App Topology API moves to usage-based billing on September 15, 2026; review org-wide App Topology usage now to quantify cost impact before the free daily allotment becomes the billing floor.
- Signals: GA announcement
- Platform/SRE — Plan: This GA feature replaces bespoke health-monitoring scripts for EC2 workloads and integrates with Auto Scaling recovery — worth evaluating this quarter to simplify the observability stack for any EC2-based services.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: Jenkins 2.576 ships multiple security fixes; review the 2026-08-05 security advisory and plan an upgrade of any self-hosted Jenkins controllers to this weekly build or wait for the next LTS incorporating these patches.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: Jenkins 2.568.2 carries a breaking-change flag; review the upgrade guide before updating the Jenkins controller to avoid pipeline regressions.
- Leader — Skip
- Signals: Jenkins 2.568 supported · breaking-change flagged
- Platform/SRE — Plan: Grafana 13.1.2 fixes CVE-2026-13438 in software Platform teams commonly operate; schedule the upgrade this sprint. No forced timeline — the CVE is not KEV-listed and no active exploitation is reported.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-13438 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Two regressions introduced in 29.7.0 — image pulls rejecting hardlink targets and file-permission failures on older kernels — are fixed in 29.7.2; if you upgraded to 29.7.x recently, schedule a patch to 29.7.2 to restore stable image pull behavior.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: ArgoCD runs as a control-plane component on managed clusters; a new GA minor release warrants scheduling a controller upgrade review this quarter to pick up any stability or feature improvements.
- CI/CD — Plan: ArgoCD 3.5.0 is a GA minor release directly in the deployment path; evaluate and plan adoption this quarter, particularly if you depend on any recently deprecated APIs or new sync/rollout features.
- Leader — Skip
- Signals: Argo CD 3.5 supported
- Platform/SRE — Plan: New GA minor release of a tool platform teams operate on-cluster; appset concurrency and configurable webhook jitter are operationally relevant improvements worth scheduling an upgrade to this quarter.
- CI/CD — Plan: SLSA Level 3 provenance for all container images and CLI binaries and new Source Integrity CLI support are meaningful supply-chain hardening steps worth adopting; plan to upgrade and enable provenance verification in deployment pipelines.
- Leader — Skip
- Signals: Argo CD 3.5 supported
- Platform/SRE — Plan: Relevant to any team using BYOIP prefixes on AWS: the new delegated RPKI automation eliminates manual ROA creation/renewal at the RIR, and the centralized dashboard surfaces hijacking risk via route overlap detection. Evaluate enabling this during the next IPAM configuration review cycle.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Learn: This expands the integration surface for enterprise GitHub accounts, which may be relevant when evaluating third-party tools that plug into GitHub for pipeline or workflow automation.
- Leader — Plan: Evaluate whether third-party GitHub Apps relevant to your toolchain (security scanners, compliance tools, IDP integrations) can now be deployed at the enterprise level, potentially simplifying governance and centralized app management.
- Platform/SRE — Plan: This GA simplification reduces friction for deploying resilient multi-Region identity access — if standing up a new IAM Identity Center organization instance, select the one-click multi-Region option rather than manually wiring KMS keys and Region replication. Existing instances are unaffected, so queue this for next new-instance or resilience-architecture work this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Learn: Useful framing for understanding how unsanctioned AI tools introduce new attack surfaces into the platform layer, but no specific infrastructure action or deadline is present.
- CI/CD — Learn: Directly relevant to pipeline security thinking — AI extensions and agents in the build path are an emerging supply-chain risk worth evaluating, but no concrete deprecation, compromise, or deadline anchors an Act or Plan verdict.
- Leader — Plan: Shadow AI in delivery pipelines is a policy and governance gap that warrants adding AI tool usage to supply-chain standards and acceptable-use policy; schedule a review of which AI integrations teams are using in pipelines before the next security audit cycle.
- Platform/SRE — Plan: This GA release adds per-token inference cost attribution to OpenCost, directly addressing GPU cost visibility for platform teams running AI workloads on Kubernetes. Evaluate upgrading OpenCost to 1.121.0 this quarter if your clusters host inference workloads.
- CI/CD — Skip
- Leader — Plan: First GA implementation of per-token inference cost tracking in an open CNCF tool is a meaningful FinOps development for orgs with growing GPU spend; evaluate adopting OpenCost 1.121.0 as part of your AI cost attribution strategy this planning cycle.
- Platform/SRE — Plan: This GA expansion lets platform teams consolidate Kubernetes (ESO), Terraform/OpenTofu, and Vault CLI secrets into a single OpenBao-backed store — worth evaluating this quarter as a replacement for fragmented per-tool secret stores, with no forcing deadline yet.
- CI/CD — Learn: GitLab CI/CD secret support landed in v19.0 already; the new ESO and Terraform integrations are primarily platform-side — no pipeline changes required today, but the unified API surface is worth noting for future supply-chain design.
- Leader — Learn: The consolidated single-store model (one audit trail, one access model across Kubernetes, IaC, and pipelines) is worth tracking as a vendor-consolidation data point when revisiting secrets-toolchain standards, but no pricing or license forcing function exists yet.
- Platform/SRE — Plan: Teams running GitLab Self-Hosted in regulated environments can now configure the Duo AI Gateway to proxy through Privatemode’s confidential-compute backend — worth scheduling this quarter to evaluate setup and network path requirements alongside any existing compliance review.
- CI/CD — Learn: The prospect of GitLab Duo Agent Platform driving multi-step agentic flows as native CI jobs is a meaningful design shift to track, but there are no pipeline migrations or deprecations to act on today.
- Leader — Plan: For regulated orgs blocked from AI coding tools by IP or compliance constraints, this materially changes the vendor-risk calculus — evaluate Privatemode as a compliant model-provider path for GitLab Duo during the next planning cycle before competitors further compound their AI productivity lead.
- Platform/SRE — Plan: If you run MSK Provisioned clusters, enable Authorizer Log Delivery to route denied-access events (with client IP and API) to CloudWatch, S3, or Firehose — useful for security auditing and troubleshooting auth issues at no added cost.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA ECS capability lets you right-size GPU containers (1/8, 1/4, or 1/2 of an L4 GPU) on G6f instances, with CloudWatch GPU metrics and automatic health monitoring included. Evaluate this quarter if you run ECS-based AI inference or rendering workloads where full-GPU allocation is wasteful.
- CI/CD — Skip
- Leader — Learn: Fractional GPU scheduling in ECS reduces the cost floor for small-model inference and GPU experimentation workloads; worth factoring into GPU cost optimization reviews if the org runs AI workloads on ECS.
- Platform/SRE — Skip
- CI/CD — Plan: If your org uses GitHub code scanning default setup, evaluate adopting the new github-codeql-config-file repository property to standardize CodeQL scan behavior across repos without per-repo overrides.
- Leader — Plan: This enables centralized enforcement of code scanning standards across the org’s repositories — worth incorporating into the golden path or security policy for teams already on GitHub Advanced Security.
- Platform/SRE — Plan: Two GA releases are worth scheduling for adoption: native OTLP metric ingestion into Cloud Monitoring via the Telemetry API (evaluate replacing or supplementing existing collector pipelines), and Cloud SQL for MySQL performance capture with configurable thresholds for long-running transactions and new triggers like CPU, memory, and lock waits.
- CI/CD — Skip
- Leader — Learn: The Telemetry API GA enables native OTLP ingestion into Cloud Monitoring, which may affect the build-vs-buy decision for third-party observability tooling on GCP; no strategic decision is required yet.
- Signals: GA announcement
- Platform/SRE — Plan: TCPRoute and UDPRoute are now stable in the v1 API, making portable L4 routing viable for production workloads like databases, DNS, and VoIP. If you’re already using experimental Gateway API resources, audit for the new gateway.networking.x-k8s.io API group separation to avoid breakage on upgrade.
- CI/CD — Skip
- Leader — Learn: Gateway API continues maturing as the unified Kubernetes networking standard; L4 GA coverage strengthens the case for standardizing on it as the org’s golden-path ingress model over implementation-specific CRDs.
- Platform/SRE — Skip
- CI/CD — Plan: If a GitLab-to-GitHub migration is on the roadmap, GEI reaching GA means self-serve tooling is now available for scoping the pipeline migration project.
- Leader — Plan: If your org is evaluating consolidating from GitLab to GitHub Enterprise Cloud, the GA of self-serve migration tooling removes a key friction point worth including in the next planning cycle.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: If pipelines use CodeQL for code scanning on Swift or Kotlin codebases, upgrade to 2.26.2 to gain language-version coverage for Swift 6.3.3 and Kotlin 2.4.10; no deadline, but worth scheduling this quarter.
- Leader — Skip
- Platform/SRE — Plan: New Azure Gen2 VM and VMSS deployments now automatically get Secure Boot and vTPM enabled; audit IaC templates and any custom images for Secure Boot compatibility to avoid silent failures on next VM provisioning.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Learn: This GA tool auto-creates PRs/MRs with validated code fixes from technical debt analysis connected to GitHub, GitLab, and Bitbucket — worth evaluating if the team wants automated remediation integrated into their pipeline workflow, but no pipeline change is required today.
- Leader — Plan: Evaluate AWS Transform as a platform-level technical debt and modernization tool for standardizing debt management across teams; assess whether its agentic remediation and scheduling capabilities fit the org’s golden-path tooling this quarter.
- Signals: GA announcement
- Platform/SRE — Plan: If you run high-throughput SQS-to-Lambda pipelines that previously required splitting workloads across multiple ESMs, this GA increase to 10,000 pollers and 100,000 concurrent invocations is worth consolidating architecture this quarter.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Plan: Patch includes dependency updates for CVE-2026-56852 and GHSA-hrxh-6v49-42gf (neither KEV-listed nor actively exploited) plus a PromQL SIGBUS crash fix on full disks; schedule an upgrade to 3.13.2 this maintenance cycle.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-56852 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Two confirmed regressions patched: image pulls failing for layers with implicit parent directories, and CopyToContainer rejecting valid symlink paths like /var/run. Schedule an upgrade to 29.7.1 if running 29.7.x in production.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Upgrade Docker Engine to v29.7.0 to patch CVE-2026-17106 (go-archive archive-traversal fix) and resolve two daemon panic bugs in container network cleanup paths; the CVE is not KEV-listed so no hard deadline, but schedule this within the current sprint.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17106 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Cilium 1.20.0 is a substantial GA minor release for a core CNI component; before upgrading, audit whether your cluster uses legacy Mutual Authentication, Envoy Go extensions, Kafka-aware policies, the cilium.io/v2alpha1 CiliumNodeConfig API, libnetwork, or custom CNI configs — all require migration steps per the upgrade guide. No forced-upgrade deadline exists, so schedule evaluation this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Grafana Agent Observability is now GA on Grafana Cloud, offering structured monitoring for LLM agent behavior, prompt lineage, and scaling. Platform teams operating agent workloads should evaluate adopting it this quarter as a dedicated layer alongside their existing Grafana stack.
- CI/CD — Skip
- Leader — Learn: Grafana’s GA release of purpose-built agent observability tooling reflects a maturing category for AI workload monitoring; useful framing for leaders deciding where to invest observability capabilities as agent-based products scale.
- Signals: GA announcement
- Platform/SRE — Plan: A semver major bump in a provider teams rely on for Azure IaC signals likely breaking changes; schedule a migration from AzureRM 4.x to 5.0 this quarter, validating existing configurations against the new Resource Provider registration behavior and opt-in preflight validation before upgrading production workspaces.
- CI/CD — Skip
- Leader — Skip
- Signals: GA announcement · major release (5.0)
- Platform/SRE — Skip
- CI/CD — Plan: Teams that publish npm packages via their release pipelines should review the new dual-use metadata requirement to ensure compliance before enforcement begins; no hard deadline surfaced in the item, so schedule this in the next pipeline audit cycle.
- Leader — Learn: npm’s automated publish-time scanning strengthens the ecosystem’s supply-chain posture; worth noting as a positive signal when reviewing org-wide software supply-chain policy, but no leadership decision is required now.
- Platform/SRE — Skip
- CI/CD — Plan: GitHub now holds potentially malicious workflow runs for review in public repositories; audit your org’s Actions approval settings and ensure maintainers understand how to review held runs before merging external contributions.
- Leader — Learn: GitHub’s new default protection against credential-stealing workflow attacks reduces supply-chain risk for orgs using public repos; worth noting as a positive vendor-risk signal when assessing GitHub Actions dependency.
- Platform/SRE — Plan: Cloud SDK 578.0.0 makes –auto-commit the default for gcloud database-migration seed/convert/import-rules commands; audit any automation or runbooks that call these operations and add –no-auto-commit explicitly before upgrading the SDK.
- CI/CD — Plan: If pipelines invoke gcloud database-migration commands, upgrading to Cloud SDK 578.0.0 silently changes commit behavior; pin the SDK version or add –no-auto-commit flags before the next runner/image update pulls this version in.
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Skip
- CI/CD — Plan: Enable or verify Dependabot alerts are active across your repos to benefit from the expanded OpenSSF malicious-package coverage; no deadline, but this materially improves supply-chain detection in your dependency pipeline.
- Leader — Plan: Broader malware signal coverage from OpenSSF integration strengthens your software supply-chain posture — confirm Dependabot alerts are enabled org-wide as a policy standard this quarter.
- Platform/SRE — Plan: GA resource placement in Fleet Manager enables centralized policy-driven workload distribution across multiple AKS clusters, worth evaluating this quarter if you operate a multi-cluster Azure environment.
- CI/CD — Skip
- Leader — Learn: Fleet Manager’s GA multi-cluster resource placement matures Azure’s managed Kubernetes offering and may influence build-vs-buy decisions around homegrown multi-cluster orchestration tooling.
- Signals: GA announcement
- Platform/SRE — Plan: For EKS clusters in air-gapped or strict-egress VPCs, this GA capability enables IRSA token validation without internet access — evaluate adding the com.amazonaws.
.oidc-eks VPC interface endpoint to your network baseline this quarter. - CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: The Kubernetes Gateway API is the intended successor to the Ingress API, and it’s now GA on AKS — plan a migration evaluation from existing Ingress controllers to the managed Gateway API offering this quarter. No forced deadline exists, but adopting early reduces future migration debt as the Ingress API ages out.
- CI/CD — Skip
- Leader — Learn: Gateway API going GA on AKS signals accelerating industry standardization on the new Kubernetes networking model, worth tracking as context for ingress-tooling decisions if an AKS golden-path review is upcoming.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: If your org uses GitHub Copilot, this GA policy control lets you enforce centralized governance over the Copilot desktop app and cloud agent — evaluate rolling it into your Copilot access standards this quarter.
- Platform/SRE — Skip
- CI/CD — Plan: GitHub now holds unproven workflows pending approval on public repos — review your repository settings and approval workflows to ensure this protection is enabled and fits your release process.
- Leader — Learn: A new GitHub platform-level control targeting supply chain attacks via compromised credentials; worth noting as a defense-in-depth signal for orgs that rely on GitHub Actions for public repositories.
- Platform/SRE — Plan: New GA Neptune capability that replaces static ARN enumeration in IAM policies with attribute-based cluster access using resource and principal tags; plan to adopt TBAC if you operate multiple Neptune clusters in shared VPC environments to enforce team and environment isolation.
- CI/CD — Skip
- Leader — Learn: Neptune now supports attribute-based access governance across clusters via IAM tags, useful context for organizations running Neptune at scale, but no strategic, licensing, or cost decision is triggered.
- Platform/SRE — Plan: Platform engineers running OpenTofu should upgrade to 1.12.5 to address the ECH handshake privacy leak (server hostname de-anonymization via passive observation) and the implicit-move provider state bug; no KEV listing or active exploitation reported, so no hard deadline, but this should be included in the next IaC toolchain update cycle.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: A security fix for an ECH pre-shared key identity leak in OpenTofu v1.11.x warrants upgrading to v1.11.13; no KEV listing or active exploitation reported, so this is a planned patch rather than an emergency — schedule the upgrade this sprint.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: etcd backs every Kubernetes control plane, and a breaking change in a patch release is unusual — review the v3.7.1 CHANGELOG and upgrade guide before applying this update to any cluster, and validate in a non-production environment first. No hard deadline exists, but the breaking-change flag makes this a planned, careful upgrade rather than routine patching.
- CI/CD — Skip
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Plan: etcd is the Kubernetes control plane’s backing store — a breaking-change flag in even a patch release means reviewing the upgrade guide before rolling this out to production clusters. No deadline is given, but operators should validate against their environment this quarter before routine patching.
- CI/CD — Skip
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Plan: etcd backs every Kubernetes control plane, and a breaking-change flag on a patch release is unusual — review the CHANGELOG and upgrade guide before rolling this out to clusters; no hard deadline, but unreviewed breaking changes in a core datastore warrant a planned change window rather than routine rollout.
- CI/CD — Skip
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Plan: Teams using IP allowlisting to permit Grafana Cloud traffic must migrate from legacy per-product endpoints (JSON, txt, DNS) to the new unified Allowlist API before January 31, 2027, when the old formats stop being maintained; schedule the allowlist automation update and test before the deadline.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you run EC2 Dedicated Hosts or Mac Instances for isolation rather than BYOL, you can now create Host Resource Groups without the AWS License Manager self-managed license prerequisite, simplifying the provisioning workflow. Review and update any Terraform/IaC automation that currently creates SMLs solely to satisfy the HRG requirement.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Airflow 2.11.2 on MWAA is a maintenance release with security patches to the webserver and task execution layers, plus enhanced secrets masking in logs — worth scheduling an environment upgrade this quarter if you run MWAA in production. No forced-upgrade deadline is present in the signals.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: I8ge instances (Graviton4, 3rd-gen Nitro SSDs, up to 120TB NVMe) are now GA in two more regions — worth evaluating as a replacement for Im4gn or I3en nodes in storage-heavy workloads this quarter.
- CI/CD — Skip
- Leader — Learn: New storage-optimized Graviton4 instance family expanding regionally; relevant context for future Graviton migration planning or FinOps reviews comparing storage-intensive workload costs.
- Signals: GA announcement
- Platform/SRE — Plan: HCP Terraform and Terraform Enterprise now include workspace and Stacks restore features, which are relevant to DR and state-recovery planning for teams standardized on either product; evaluate whether these capabilities close gaps in your current runbooks.
- CI/CD — Skip
- Leader — Learn: HashiCorp is expanding HCP Terraform’s resilience and governance surface; useful context for teams standardized on the product when assessing vendor roadmap health, but no strategic decision is forced here.
- Platform/SRE — Plan: GA feature that reduces cross-AZ data transfer costs and latency for ECS Service Connect; existing services need a one-time redeployment to activate it. Schedule the redeployment across affected ECS services this quarter to capture the cost and latency benefit.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: ALB logs are now a first-class CloudWatch vended log type, enabling Logs Insights queries, metric filters, and Live Tail for load balancer traffic without custom shipping pipelines; evaluate adopting telemetry enablement rules to standardize coverage across accounts, noting the per-GB vended log cost vs. free S3 delivery.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Learn: Grafana Cloud now supports label-based cost attribution (e.g., team, env) across metrics, logs, traces, k6, and Synthetic Monitoring — useful context for platform teams that want to support internal showback models, but no migration or deadline is involved.
- CI/CD — Skip
- Leader — Plan: Evaluate enabling Grafana Cloud cost attribution labels this quarter if the org needs chargeback or showback across teams; the new k6 and Synthetic Monitoring coverage makes this a more complete FinOps lever for observability spend.
- Platform/SRE — Plan: GDC for VMware 1.35.300-gke.87 (Kubernetes 1.35.3) and 1.34.700-gke.93 (Kubernetes 1.34.7) are available for download; if running 1.34, note its EOL is 2026-10-27, so schedule an upgrade to 1.35 this quarter before that deadline.
- CI/CD — Skip
- Leader — Skip
- Signals: Kubernetes 1.35 EOL 2027-02-28 · Kubernetes 1.34 EOL 2026-10-27
- Platform/SRE — Plan: New GA capability that changes how you’d architect EKS node pools for GPU/HPC workloads — evaluate EFA-only interfaces (no IP consumption) and placement group strategies for distributed training or high-availability production services this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA capability removes the CloudTrail-parsing workaround for secret rotation events; evaluate adding EventBridge rules this quarter to auto-refresh credential caches or trigger service restarts on rotation, reducing the lag window between rotation and downstream adoption.
- CI/CD — Learn: Could inform future pipeline designs that need to react to secret rotation (e.g., invalidating cached build credentials), but no current pipeline change is required and no deprecation is introduced.
- Leader — Skip
- Platform/SRE — Plan: New GA NLB capability worth evaluating this quarter for teams running dual-stack workloads: a single NLB can now route IPv4 and IPv6 clients to same-family targets without protocol translation or a second load balancer. Audit existing dual-stack NLB deployments and update Terraform/IaC to add listener rules where protocol translation is currently causing IP preservation issues.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you run Lambda durable functions in regulated industries, schedule adoption of CMK encryption to meet data governance requirements — no deadline, but this is a concrete security posture change worth queuing this quarter.
- CI/CD — Skip
- Leader — Learn: Lambda durable functions now offers CMK support, closing a compliance gap for financial services and healthcare workloads; relevant context if evaluating serverless for regulated data.
- Platform/SRE — Plan: The updated ToS may restrict how the Terraform Registry can be consumed, particularly by tooling or automation that competes with or mirrors registry content. Review current Terraform and provider-download patterns against the new terms and evaluate whether a migration to OpenTofu or a self-hosted registry should be scoped this quarter.
- CI/CD — Learn: Pipelines that pull Terraform providers and modules via the public registry could be indirectly affected if the new ToS introduces usage restrictions on automated clients; worth monitoring, but no concrete pipeline action is required yet.
- Leader — Plan: A ToS change on a registry that most Terraform-standardized orgs depend on is a direct vendor-risk signal; evaluate whether current registry consumption falls under any newly restricted terms and assess OpenTofu as a contingency before any enforcement timeline is announced.
- Platform/SRE — Plan: Docker removing the cost barrier for hardened, minimal base images makes it practical to standardize on them across cluster workloads, reducing CVE surface without budget justification. Evaluate adopting Docker Hardened Images as the default base-image standard in your next quarterly planning cycle.
- CI/CD — Plan: Hardened base images are directly relevant to build-time and artifact supply-chain security; with the free tier now available, it’s worth scheduling a migration of pipeline build images and application Dockerfiles to hardened variants as a supply-chain hardening step.
- Leader — Learn: Docker making a previously premium security feature free reshapes the container security tooling landscape and is useful context for evaluating whether to formalize a hardened-image standard in the golden path, but no immediate strategic decision is required.
- Platform/SRE — Plan: SQL Server 2025 is now GA on RDS; teams operating SQL Server workloads should evaluate an engine upgrade to gain Standard Edition capacity increases (up to 32 cores, 256 GB buffer pool) and Resource Governor, previously Enterprise-only — no deadline, but a meaningful capability shift worth scheduling this quarter.
- CI/CD — Skip
- Leader — Learn: SQL Server 2025 introduces a new free Dev-SE edition and significant Standard Edition capacity/feature improvements that could reduce Enterprise licensing costs; worth noting for next SQL Server licensing review, but no immediate strategic decision is forced.
- Platform/SRE — Plan: This GA feature surfaces previously opaque ECS service-side deployment events — state transitions, circuit-breaker rollbacks, Managed Daemon updates — directly into CloudWatch, S3, or Firehose. Platform teams running ECS should evaluate opting in at the cluster level to reduce MTTR on deployment incidents without waiting on AWS Support.
- CI/CD — Learn: ECS Action Logs expose service-side operations that can help diagnose failures in pipeline-triggered deployments, but no pipeline changes are required — this is an opt-in ECS console/CloudWatch feature, not a build or artifact system change.
- Leader — Skip
- Platform/SRE — Learn: A community module for self-hosted GitHub Actions runner autoscaling on AWS; worth evaluating if teams are self-hosting runners, but no deadline or GA milestone signals a required change.
- CI/CD — Plan: If cost or throughput is a pain point with GitHub-hosted runners, this Terraform module offers a path to autoscaled self-hosted runners on AWS — worth scheduling an evaluation this quarter.
- Leader — Skip
- Platform/SRE — Plan: Oracle’s enterprise-scale migration validates OpenTofu as production-ready; teams running Terraform under the BUSL license should schedule an evaluation of OpenTofu as a drop-in replacement within the next planning cycle.
- CI/CD — Skip
- Leader — Plan: A major cloud vendor publicly switching to the OpenTofu fork is a clear signal that the fork has enterprise momentum; leaders standardized on Terraform should put an OpenTofu migration evaluation on the roadmap to reduce BUSL licensing risk before it becomes a contractual concern.
- Platform/SRE — Skip
- CI/CD — Plan: New GA GitHub feature worth evaluating for pipeline quality gates; assess whether Code Quality checks should be integrated into existing GitHub Actions workflows this quarter.
- Leader — Learn: GA release of a GitHub-native code quality tool that may reduce the need for third-party static analysis seats; worth tracking as a build-vs-buy data point at next toolchain review.
- Signals: GA announcement
- Platform/SRE — Plan: If you run memory-intensive workloads (PostgreSQL, NGINX, ML inference) in EU Stockholm or Zurich, evaluate migrating to R8i for up to 30–60% workload-specific gains; no deadline, so schedule as a cost-performance optimization this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Learn: New GA CloudWatch feature ingesting OpenTelemetry metrics from coding agents; no infrastructure changes required, but platform engineers who own the observability stack should note it as a new dimension of telemetry available alongside existing operational data.
- CI/CD — Skip
- Leader — Plan: Directly addresses AI coding tool ROI governance — token spend, commit throughput, PR velocity, and cost-per-model comparisons; evaluate enabling Coding Agent Insights this quarter to inform decisions on expanding or right-sizing AI tool access across teams.
- Platform/SRE — Plan: This GA feature lets you reduce CloudTrail network activity event volume and cost by scoping logging to untrusted or access-denied identities on VPC endpoints — a concrete improvement for data perimeter monitoring. Update your CloudTrail advanced event selectors this quarter to filter trusted IAM roles and cut noise on VpceAccessDenied events.
- CI/CD — Skip
- Leader — Learn: This feature enables selective CloudTrail logging that can meaningfully reduce ingestion costs for high-volume VPC endpoint environments, relevant for FinOps conversations around AWS audit logging spend — no strategic decision required now.
- Platform/SRE — Plan: If your pipelines use pulumi/actions or pulumi/action-install-pulumi-cli, both have major version bumps (v6→v7, v1→v2) that likely include breaking changes; audit your workflow files and update action refs this quarter.
- CI/CD — Plan: pulumi/actions jumped v6→v7 and pulumi/action-install-pulumi-cli jumped v1→v2 — major bumps that may break existing pipeline steps; review release notes for both actions and update workflow references before Renovate auto-merges cause unexpected failures.
- Leader — Skip
- Platform/SRE — Plan: v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.
- CI/CD — Skip
- Leader — Skip
- Signals: deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Five CVEs fixed in Docker Engine including a command injection via git bundle checkout and a directory traversal that can wipe /tmp — no KEV listing or known active exploitation, but the severity warrants scheduling an upgrade to 29.6.2 this sprint.
- CI/CD — Plan: If Docker Engine runs on self-hosted CI runners or build hosts, the git-bundle command injection (CVE-2026-15793) and local-source upload bypass (CVE-2026-15789) are directly relevant to build-time workloads; plan to update runner environments to Docker 29.6.2.
- Leader — Skip
- Signals: CVE-2026-15788 — CISA KEV: not listed, EPSS n/a · CVE-2026-15789 — CISA KEV: not listed, EPSS n/a · CVE-2026-15791 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: If running Cilium 1.19.x, this patch fixes a regression that briefly drops established pod connections during agent restart or upgrade; no deadline or KEV, but the availability impact warrants scheduling an upgrade to 1.19.6 this sprint.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Two notable bug fixes: a regression that prevents Cilium from starting in kvstore mode with KPR enabled when etcd is behind a Kubernetes service, and incorrect policy denials for L7 load-balanced services on remote identity changes. If running Cilium 1.18.x in either of these configurations, schedule the patch update this sprint.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Teams running Backstage need to audit OAuth redirect URI allowlist patterns (wildcards no longer cross host/path boundaries), validate config schema imports that may now fail to load, and migrate any MCP clients off the removed SSE transport to the Streamable HTTP endpoint before upgrading to v1.53.0.
- CI/CD — Skip
- Leader — Skip
- Signals: deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: Teams running OpenSearch Service domains or serverless collections with Dashboards tenants and saved objects can now migrate to the new OpenSearch UI without manual recreation; worth scheduling as a low-risk migration this quarter to reduce legacy UI dependency.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: A new GA security capability for AKS clusters using Azure Files NFS v4.1 volumes via the CSI driver — worth evaluating this quarter for workloads with data-in-transit compliance requirements. Review existing PersistentVolume configurations and enable EiT where encryption mandates apply.
- CI/CD — Skip
- Leader — Learn: This GA feature expands available encryption controls on AKS-backed storage, which may inform security standards or compliance posture for teams running NFS workloads on Azure, but no strategic decision is forced.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: Custom Flows are now GA in GitLab 19.2, enabling event-triggered, AI-driven multi-step pipeline sequences (e.g., analyze failure → generate fix → commit → notify). Teams on GitLab should evaluate whether encoding trusted delivery sequences as Flows reduces manual handoffs and pipeline runbook debt.
- Leader — Learn: GitLab’s agentic flow model represents a meaningful shift in how AI is integrated into the delivery lifecycle — moving from single-turn chat to orchestrated, human-approved sequences. Worth tracking as input to dev-platform strategy and AI tooling evaluation, but no strategic decision is forced by this release.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: Enterprises standardized on GitHub Enterprise Cloud can now automate VSS seat assignments via REST API, enabling programmatic license auditing and allocation at scale — worth scheduling into the licensing management workflow.
- Platform/SRE — Plan: Apigee X instances below 1-17-0-apigee-10 with maintenance windows configured will be auto-updated within 7–21 days of July 16; verify now that your instances don’t carry the DNS misconfiguration (known issue 445936920) or a dependency on the removed Apigee Java Library, as either will block the automatic update. Cloud KMS ML-DSA and SLH-DSA post-quantum signing algorithms are now GA — add PQC key-management evaluation to this quarter’s platform roadmap.
- CI/CD — Skip
- Leader — Learn: Google Cloud KMS now offers post-quantum signing algorithms (ML-DSA, SLH-DSA families) in GA — a signal that PQC migration timelines are becoming concrete and worth factoring into the org’s long-term cryptographic standards and compliance planning.
- Signals: GA announcement
- Platform/SRE — Plan: Teams using AFT to manage multi-account AWS environments should evaluate enabling
aft_customization_triggers = ["account_move"]this quarter to eliminate manual re-application steps and reduce compliance drift when accounts change OUs. No deadline, but the tighter logging bucket controls and enterprise-scale improvements are also worth reviewing alongside the opt-in. - CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: New secret types are now auto-detected in repo scans; review your secret scanning policy to ensure newly covered credential types (Resend, APIclub) are included in alerting and rotation workflows.
- Leader — Skip
- Platform/SRE — Plan: New Docker 29 installs default to the containerd image store rather than the classic overlay store, which changes image management behavior. Audit IaC and provisioning scripts that stand up Docker nodes to verify compatibility with the new default before rolling out Docker 29 to new infrastructure.
- CI/CD — Plan: Ephemeral CI runners provisioned fresh on Docker 29 will silently get containerd-backed image storage, which can alter layer-caching behavior and multi-platform build handling. Test existing build and image-export workflows against the new default before adopting Docker 29 runner images.
- Leader — Skip
- Platform/SRE — Plan: If you use AWS DRS for EC2 workloads, enabling this feature can meaningfully shrink your RTO with no added cost — evaluate enabling it account-wide or per server during your next DR review.
- CI/CD — Skip
- Leader — Learn: A no-cost RTO improvement of up to 65% on EC2 disaster recovery is worth noting when reviewing reliability targets and DR posture with engineering leadership.
- Platform/SRE — Plan: Teams running Amazon MQ RabbitMQ M7g cluster deployments on version 4.2+ can now right-size storage independently of instance type; evaluate current broker storage allocations and adjust during the next planned maintenance window.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA capability that can eliminate the need to export verbose logs to S3 or filter them for cost reasons — evaluate enabling account-level intelligent tiering this quarter to simplify your observability stack and reduce log storage spend.
- CI/CD — Skip
- Leader — Plan: This changes the unit economics of CloudWatch log retention, making it viable to keep high-volume logs natively rather than running export pipelines to cheaper storage; include in the next FinOps/observability cost review cycle.
- Platform/SRE — Plan: ingress-nginx is one of the most widely deployed Kubernetes ingress controllers; its retirement means planning a migration to an alternative (e.g., Envoy Gateway, NGINX Gateway Fabric, or another Gateway API-conformant controller). No forced migration date is confirmed yet, so scope the migration project now before community support winds down.
- CI/CD — Skip
- Leader — Plan: If ingress-nginx is part of the org’s Kubernetes golden path or standard stack, its retirement requires evaluating replacement ingress controllers and updating platform standards; begin that toolchain review this planning cycle before the project loses maintainer support.
- Signals: deprecation mentioned (no explicit date found)
- Platform/SRE — Skip
- CI/CD — Plan: New GA endpoints let teams manage secret scanning custom patterns as code, enabling IaC-style enforcement of scanning policies across repos; schedule adoption as part of supply-chain hardening this quarter.
- Leader — Skip
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: GitHub’s AI-powered security detections now surface on PRs for languages CodeQL doesn’t cover — worth enabling to broaden supply-chain and vulnerability coverage in existing GitHub Actions workflows.
- Leader — Learn: Expanded AI security coverage on PRs broadens GitHub’s appeal as a unified code-security platform, relevant if evaluating whether GitHub Advanced Security covers the org’s language portfolio.
- Platform/SRE — Plan: gcloud SDK 576.0.0 changes
gcloud storage rsyncto decompress gzip downloads by default, which can silently break any operational scripts relying on the previous behavior; audit usage and add--do-not-decompressor pin SDK version before upgrading. The bundled Python update for CVE-2026-34182 (EPSS 0.00, not KEV) adds low-urgency motivation to upgrade. - CI/CD — Plan: If pipelines invoke
gcloud storage rsyncto pull artifacts, the 576.0.0 default-decompress behavior change will alter what lands in the workspace; pin the gcloud SDK version or add--do-not-decompressbefore rolling out the upgrade across runners. - Leader — Learn: BigQuery conversational analytics now carries HIPAA compliance support, broadening Gemini-in-BigQuery eligibility for regulated-industry workloads — worth factoring into GCP data platform strategy for healthcare or other compliance-sensitive verticals.
- Signals: GA announcement · breaking-change flagged · CVE-2026-34182 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: New GA capability that consolidates CloudFront Function decisions (A/B variants, auth outcomes, routing) directly into access log records, eliminating cross-system correlation with CloudWatch Logs. Worth adopting in existing CloudFront Functions this quarter by replacing or augmenting console.log() with cf.logCustomData().
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: New GA capability that auto-discovers AI workloads (Bedrock, SageMaker, EC2, ECR) via Config, Inspector SBOM, and GuardDuty DNS telemetry — worth enabling this quarter for teams running AI workloads to close the visibility gap before it becomes a compliance issue.
- CI/CD — Skip
- Leader — Learn: Signals that AWS is building central AI governance tooling; relevant for leaders setting security standards around AI deployments, but no forced decision or pricing change — shapes thinking on AI risk posture policy rather than requiring action now.
- Platform/SRE — Plan: This GA capability removes the per-Region Lambda-managed storage quota for teams running large function/layer footprints; evaluate adopting
S3ObjectStorageMode=REFERENCEthis quarter for deployments approaching the old 75GB ceiling, and note the default limit has already been raised to 300GB for all accounts. - CI/CD — Skip
- Leader — Learn: Cost impact is neutral-to-positive (standard S3 rates replace implicit Lambda storage overhead) with no forced migration, but worth flagging to platform teams running high function counts so they can evaluate whether S3-backed storage fits their existing artifact management posture.
- Platform/SRE — Plan: Teams running I/O-intensive workloads (databases, etc.) on AWS DRS should evaluate setting an EBS initialization rate on DRS launch templates to reduce time-to-full-performance during recovery drills — no deadline, but worth scheduling as a DR configuration review this quarter.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Prometheus is core observability infrastructure; upgrade to v3.5.5 to patch CVE-2026-53606 in the UI’s sanitize-html dependency. Exploitation risk is low (EPSS 0.00, not KEV-listed), so this is routine patching rather than an emergency.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-53606 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Skip
- CI/CD — Plan: Two deserialization restrictions (COWL/PersistedList and Object fields by default) are meaningful security hardening in the Jenkins controller; review whether your instance is affected and schedule an upgrade within your normal maintenance window.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: Jenkins 2.568.1 carries a breaking-change flag; review the upgrade guide before updating your Jenkins controller to avoid pipeline or configuration regressions.
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Plan: Flux v2.9.2 fixes a real regression (Kustomization openapi.path URL reconcile failure) introduced in v2.9.1 — worth scheduling an upgrade this sprint if you use that feature. Also note Flux 2.6 passed EOL on 2026-06-30; if still running it, upgrade to 2.7+ now.
- CI/CD — Skip
- Leader — Skip
- Signals: Flux 2.9 supported · Flux 2.7 supported · Flux 2.6 is past EOL (2026-06-30, 13d ago)
- Platform/SRE — Plan: Fixes a meaningful regression where Kustomizations with post-build substitution enabled could corrupt Flux CRD schemas containing ${…} sequences; also patches a SOPS .ini decryption bug and a dry-run apply error. Schedule an upgrade to v2.9.1 this sprint, prioritizing clusters that use post-build variable substitution — no hard deadline, but the CRD corruption impact in affected environments is production-visible.
- CI/CD — Skip
- Leader — Skip
- Signals: Flux 2.9 supported · Flux 2.7 supported · Flux 2.6 is past EOL (2026-06-30, 13d ago) · breaking-change flagged
- Platform/SRE — Plan: etcd is a critical Kubernetes control-plane component; v3.7.0 carries flagged breaking changes requiring review of the upgrade guide before any cluster upgrade. Plan the migration this quarter — no forced deadline in the signals, but breaking changes mean this needs a scoped project, not a routine bump.
- CI/CD — Skip
- Leader — Skip
- Signals: breaking-change flagged
- Platform/SRE — Plan: etcd is the Kubernetes control-plane backing store, so any new minor release warrants a changelog review for deprecations, API changes, or breaking behavior before scheduling an upgrade cycle; no deadline or CVE signals are present to force earlier action.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: This GA major release changes how Tempo is deployed at scale — removing the RF3 requirement reduces storage overhead and the new Kafka-compatible architecture decouples read/write paths. Teams running Tempo should schedule an upgrade evaluation this quarter to assess the operational and cost impact.
- CI/CD — Skip
- Leader — Learn: The RF3 removal and new architecture lower the infrastructure cost of running distributed tracing at scale, which is a useful data point if Tempo is part of the observability standard — but no strategic decision is forced by this release.
- Signals: GA announcement · major release (3.0)
- Platform/SRE — Plan: Grafana 13.1 ships GA improvements to Git Sync — GitHub App auth, GitLab/Bitbucket support, and in-place provisioned-folder imports — that meaningfully advance dashboard-as-code workflows for teams already on Grafana. Evaluate adopting these features this quarter; EOL for 13.1 is 2027-03-20, so no immediate upgrade pressure.
- CI/CD — Skip
- Leader — Learn: Grafana’s investment in native GitOps (Git Sync) and AI-assisted querying across more data sources signals where observability tooling is heading; useful context for evaluating observability-as-code as an org standard, but no strategic decision is forced by this release.
- Signals: Grafana 13.1 EOL 2027-03-20 · GA announcement
- Platform/SRE — Plan: If running memory-intensive or high-network-throughput workloads in ap-northeast-1, eu-central-1, or eu-west-1, evaluate whether R8i-family instances offer a cost/performance improvement over existing R6i deployments — up to 43% better compute per vCPU and highest-in-class EBS/network bandwidth are meaningful for caching, NoSQL, or analytics tiers.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: If pipelines run CodeQL scanning on Kotlin 2.4.0 codebases, upgrade to CodeQL 2.26.0 this quarter to maintain scan coverage; the new AI prompt injection queries are worth enabling if building LLM-integrated apps.
- Leader — Skip
- Platform/SRE — Learn: Teams using CDKTF for IaC should read this discussion to gauge whether HashiCorp/IBM intends to maintain it long-term; no deprecation date in signals, so no action required now.
- CI/CD — Skip
- Leader — Plan: Against the backdrop of HashiCorp’s BSL relicensing and IBM acquisition, a high-signal HN discussion on CDKTF’s direction is a prompt to evaluate whether to continue standardizing on CDKTF or assess alternatives like OpenTofu CDK this planning cycle.
- Platform/SRE — Learn: Useful context for teams running Volkov Labs BI plugins on Grafana: the maintenance window is extended and Grafana 13 / React 19 compatibility is done, but no action is required now and the post-2026 path remains undefined.
- CI/CD — Skip
- Leader — Plan: If the org is standardized on Volkov Labs BI plugins, the finite maintenance window expiring at end of 2026 warrants a strategic review this quarter — engage Grafana Labs on long-term product direction or evaluate alternative BI visualization solutions before the commitment lapses.
- Platform/SRE — Plan: etcd is the Kubernetes control-plane datastore, so this GA minor release is directly relevant; evaluate adopting v3.7 this quarter, particularly if large result-set latency or v2store remnants are pain points — no forced-upgrade deadline exists yet.
- CI/CD — Skip
- Leader — Skip
- Signals: etcd 3.7 supported · etcd 3.6 supported
- Platform/SRE — Plan: This incident—an AI coding assistant given unconstrained Terraform access wiping a production database—is a concrete signal to audit and restrict AI agent permissions to production IaC state; plan to implement plan-before-apply gates, workspace isolation, and state-level protections before allowing any AI assistant to execute Terraform in production environments.
- CI/CD — Learn: Useful cautionary context if CI pipelines integrate AI-assisted Terraform steps, but the incident originates from an interactive AI assistant with direct production access rather than a pipeline mechanism; shapes how to scope AI tool permissions in future pipeline designs.
- Leader — Plan: This high-profile incident—145 upvotes, 158 comments—is a concrete risk signal for any org adopting AI coding assistants; evaluate and formalize org-wide policy on AI agent access to production systems, and mandate guardrails (dry-run gates, least-privilege IAM, human approval for destructive operations) as a standard before broader rollout.
- Platform/SRE — Plan: Teams running Timestream for InfluxDB can replace API polling with EventBridge rules to automate responses to scaling completions, failures, and maintenance events; worth building into monitoring/alerting workflows this quarter.
- CI/CD — Skip
- Leader — Skip