<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DevOps on Osmond van Hemert — Senior Software Engineer | AI, Security, Infrastructure</title><link>https://www.osmondvanhemert.nl/tags/devops/</link><description>Recent content in DevOps on Osmond van Hemert — Senior Software Engineer | AI, Security, Infrastructure</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© Osmond van Hemert. All rights reserved.</copyright><lastBuildDate>Thu, 02 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.osmondvanhemert.nl/tags/devops/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Cloud Next 2026 — Platform Engineering Takes Center Stage</title><link>https://www.osmondvanhemert.nl/posts/260402-google-cloud-next-2026/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260402-google-cloud-next-2026/</guid><description>Google Cloud Next 2026 put platform engineering front and center, with new tools for developer experience, Gemini-powered operations, and a maturing GKE ecosystem.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260402-google-cloud-next-2026/featured.jpg"/></item><item><title>Software Supply Chain Security Gets Serious — SLSA and SBOM Adoption Accelerates</title><link>https://www.osmondvanhemert.nl/posts/260312-supply-chain-security-slsa-adoption/</link><pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260312-supply-chain-security-slsa-adoption/</guid><description>Supply chain security frameworks like SLSA and SBOM requirements are moving from recommendations to mandates. Here&amp;rsquo;s what developers need to know about the shifting landscape.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260312-supply-chain-security-slsa-adoption/featured.jpg"/></item><item><title>OpenTofu's Growing Pains — The State of Infrastructure as Code in 2026</title><link>https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/</link><pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/</guid><description>OpenTofu has matured significantly since its fork from Terraform. Here&amp;rsquo;s where things stand and what it means for teams managing cloud infrastructure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/featured.jpg"/></item><item><title>Cloud FinOps — Why Engineers Own the Cost Conversation Now</title><link>https://www.osmondvanhemert.nl/posts/260212-cloud-finops-engineering-ownership/</link><pubDate>Thu, 12 Feb 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260212-cloud-finops-engineering-ownership/</guid><description>FinOps has evolved from a finance initiative to an engineering discipline, and the teams that treat cloud costs as a first-class engineering metric are winning.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260212-cloud-finops-engineering-ownership/featured.jpg"/></item><item><title>Platform Engineering in 2025 — A Year-End Retrospective</title><link>https://www.osmondvanhemert.nl/posts/251225-platform-engineering-2025-retrospective/</link><pubDate>Thu, 25 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251225-platform-engineering-2025-retrospective/</guid><description>Reflecting on how platform engineering matured in 2025, from internal developer platforms to the evolution of the DevOps toolchain.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251225-platform-engineering-2025-retrospective/featured.jpg"/></item><item><title>OpenTelemetry Reaches GA for Logs — The Three Pillars Are Finally Complete</title><link>https://www.osmondvanhemert.nl/posts/251204-opentelemetry-logs-ga-three-pillars/</link><pubDate>Thu, 04 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251204-opentelemetry-logs-ga-three-pillars/</guid><description>OpenTelemetry&amp;rsquo;s logging API and SDK reaching general availability completes the observability trifecta. Here&amp;rsquo;s why this matters more than you might think.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251204-opentelemetry-logs-ga-three-pillars/featured.jpg"/></item><item><title>AWS re:Invent 2025 Preview — What I'm Watching For</title><link>https://www.osmondvanhemert.nl/posts/251120-aws-reinvent-2025-preview/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251120-aws-reinvent-2025-preview/</guid><description>With re:Invent just around the corner, here&amp;rsquo;s what matters most for teams building on AWS — and what&amp;rsquo;s likely just marketing noise.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251120-aws-reinvent-2025-preview/featured.jpg"/></item><item><title>The Zero-Day Treadmill — Why Patch Tuesday Still Matters in 2025</title><link>https://www.osmondvanhemert.nl/posts/251113-zero-day-treadmill-patch-tuesday/</link><pubDate>Thu, 13 Nov 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251113-zero-day-treadmill-patch-tuesday/</guid><description>November&amp;rsquo;s Patch Tuesday brought critical zero-days being actively exploited, reminding us that patch management is still the unglamorous foundation of security.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251113-zero-day-treadmill-patch-tuesday/featured.jpg"/></item><item><title>Kubernetes 1.32 — The Platform Keeps Maturing</title><link>https://www.osmondvanhemert.nl/posts/251016-kubernetes-132-platform-maturity/</link><pubDate>Thu, 16 Oct 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251016-kubernetes-132-platform-maturity/</guid><description>Kubernetes 1.32 arrives with improvements to sidecar containers, resource management, and the continued push to simplify the platform for operators.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251016-kubernetes-132-platform-maturity/featured.jpg"/></item><item><title>Secure by Design — CISA's Push Is Finally Gaining Real Traction</title><link>https://www.osmondvanhemert.nl/posts/251009-cisa-secure-by-design-traction/</link><pubDate>Thu, 09 Oct 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251009-cisa-secure-by-design-traction/</guid><description>CISA&amp;rsquo;s Secure by Design initiative is moving from voluntary pledges to measurable industry impact, and software vendors are starting to feel the pressure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/251009-cisa-secure-by-design-traction/featured.jpg"/></item><item><title>Slack Just Raised Prices by $195K — The SaaS Cost Reckoning Is Here</title><link>https://www.osmondvanhemert.nl/posts/250918-slack-price-hike-saas-costs/</link><pubDate>Thu, 18 Sep 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250918-slack-price-hike-saas-costs/</guid><description>A viral post about Slack&amp;rsquo;s massive price increase highlights the growing problem of SaaS cost escalation and what engineering teams can do about it.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/250918-slack-price-hike-saas-costs/featured.jpg"/></item><item><title>The Bitnami Docker.io Deletion — When Your Infrastructure Disappears Overnight</title><link>https://www.osmondvanhemert.nl/posts/250828-bitnami-docker-deletion/</link><pubDate>Thu, 28 Aug 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250828-bitnami-docker-deletion/</guid><description>Broadcom&amp;rsquo;s deletion of Bitnami images from Docker Hub is a wake-up call about depending on container registries you don&amp;rsquo;t control.</description></item><item><title>QUIC Comes to the Linux Kernel — What It Means for Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/250731-quic-protocol-linux-kernel/</link><pubDate>Thu, 31 Jul 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250731-quic-protocol-linux-kernel/</guid><description>The push to bring QUIC protocol support into the Linux kernel marks a significant shift in how we think about transport-layer networking.</description></item><item><title>OpenTelemetry Reaches Full Maturity — Observability Finally Has a Standard</title><link>https://www.osmondvanhemert.nl/posts/250710-opentelemetry-full-maturity/</link><pubDate>Thu, 10 Jul 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250710-opentelemetry-full-maturity/</guid><description>With OpenTelemetry&amp;rsquo;s logging signal reaching GA status, the project now covers all three pillars of observability with stable APIs, fulfilling a long-standing promise to the industry.</description></item><item><title>OpenTofu at One — How the Terraform Fork Found Its Footing</title><link>https://www.osmondvanhemert.nl/posts/250529-opentofu-terraform-fork-maturing/</link><pubDate>Thu, 29 May 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250529-opentofu-terraform-fork-maturing/</guid><description>A year and a half after forking from Terraform, OpenTofu is proving that community-driven infrastructure tooling can thrive — but challenges remain.</description></item><item><title>Docker Model Runner — Running AI Models Alongside Your Containers</title><link>https://www.osmondvanhemert.nl/posts/250508-docker-model-runner-local-ai/</link><pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250508-docker-model-runner-local-ai/</guid><description>Docker&amp;rsquo;s new Model Runner feature brings local AI model execution into the Docker Desktop workflow, blurring the line between containers and inference.</description></item><item><title>Tech Tariffs and the Software Supply Chain — What Engineers Need to Know</title><link>https://www.osmondvanhemert.nl/posts/250501-tech-tariffs-software-supply-chain/</link><pubDate>Thu, 01 May 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250501-tech-tariffs-software-supply-chain/</guid><description>New US tariffs on technology imports are sending ripples through hardware supply chains, cloud pricing, and software infrastructure planning.</description></item><item><title>The Spring 2025 Exploit Wave — Fortinet, Ivanti, and the Perimeter Problem</title><link>https://www.osmondvanhemert.nl/posts/250424-spring-2025-exploit-wave-fortinet-ivanti/</link><pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250424-spring-2025-exploit-wave-fortinet-ivanti/</guid><description>A surge of active exploitation targeting Fortinet and Ivanti edge devices highlights the persistent vulnerability of network perimeter infrastructure.</description></item><item><title>IngressNightmare — Critical Kubernetes NGINX Vulnerability Puts Clusters at Risk</title><link>https://www.osmondvanhemert.nl/posts/250327-ingress-nightmare-kubernetes-vulnerability/</link><pubDate>Thu, 27 Mar 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250327-ingress-nightmare-kubernetes-vulnerability/</guid><description>CVE-2025-1974 and related vulnerabilities in the Kubernetes ingress-nginx controller allow unauthenticated remote code execution, affecting an estimated 40% of Kubernetes clusters.</description></item><item><title>The tj-actions Supply Chain Attack — Why Your CI/CD Pipeline Is an Attack Surface</title><link>https://www.osmondvanhemert.nl/posts/250313-github-actions-supply-chain-attack/</link><pubDate>Thu, 13 Mar 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250313-github-actions-supply-chain-attack/</guid><description>A compromised GitHub Action exposed secrets from thousands of repositories, highlighting how CI/CD pipelines have become prime targets for supply chain attacks.</description></item><item><title>Kubernetes 1.33 and the Container Security Hardening Push</title><link>https://www.osmondvanhemert.nl/posts/250227-kubernetes-container-security-hardening/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250227-kubernetes-container-security-hardening/</guid><description>With Kubernetes pushing security features to GA and CISA issuing container hardening guidance, the container ecosystem is growing up on security. Here&amp;rsquo;s what matters for platform teams.</description></item><item><title>AWS re:Invent 2024 — Amazon Bets Big on Custom Silicon and AI Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/241128-aws-reinvent-2024-highlights/</link><pubDate>Thu, 28 Nov 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/241128-aws-reinvent-2024-highlights/</guid><description>AWS re:Invent 2024 opens with major announcements around Trainium2 chips, Aurora DSQL, and Amazon&amp;rsquo;s own Nova AI models. Here&amp;rsquo;s what&amp;rsquo;s worth paying attention to.</description></item><item><title>The CrowdStrike Outage — When a Security Update Takes Down the World</title><link>https://www.osmondvanhemert.nl/posts/240718-crowdstrike-global-outage/</link><pubDate>Thu, 18 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240718-crowdstrike-global-outage/</guid><description>A faulty CrowdStrike Falcon sensor update has caused one of the largest IT outages in history, bricking millions of Windows machines worldwide.</description></item><item><title>regreSSHion — A Wake-Up Call Hiding in Plain Sight</title><link>https://www.osmondvanhemert.nl/posts/240704-regresshion-openssh-vulnerability/</link><pubDate>Thu, 04 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240704-regresshion-openssh-vulnerability/</guid><description>CVE-2024-6387 reveals a critical remote code execution flaw in OpenSSH, and it&amp;rsquo;s a regression from a fix made back in 2006.</description></item><item><title>IBM Acquires HashiCorp — What It Means for the Infrastructure-as-Code Ecosystem</title><link>https://www.osmondvanhemert.nl/posts/240425-ibm-hashicorp-acquisition/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240425-ibm-hashicorp-acquisition/</guid><description>IBM&amp;rsquo;s $6.4 billion acquisition of HashiCorp signals a major consolidation in the cloud infrastructure space. Here&amp;rsquo;s what it means for Terraform users and the broader IaC community.</description></item><item><title>Broadcom's VMware Overhaul — The Virtualization World Is Rattled</title><link>https://www.osmondvanhemert.nl/posts/240411-broadcom-vmware-licensing-shakeup/</link><pubDate>Thu, 11 Apr 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240411-broadcom-vmware-licensing-shakeup/</guid><description>Broadcom&amp;rsquo;s aggressive restructuring of VMware&amp;rsquo;s licensing and product portfolio is forcing organizations to rethink their virtualization strategies.</description></item><item><title>Jenkins Under Fire — CVE-2024-23897 and the Cost of Legacy Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/240125-jenkins-cve-2024-23897-cicd-security/</link><pubDate>Thu, 25 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240125-jenkins-cve-2024-23897-cicd-security/</guid><description>A critical Jenkins vulnerability allows arbitrary file reads through the CLI. Here&amp;rsquo;s why this matters more than your typical CVE and what it reveals about CI/CD security.</description></item><item><title>OpenTofu 1.6 GA — The Terraform Fork Grows Up</title><link>https://www.osmondvanhemert.nl/posts/240111-opentofu-1-6-terraform-fork-grows-up/</link><pubDate>Thu, 11 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240111-opentofu-1-6-terraform-fork-grows-up/</guid><description>OpenTofu hits its first GA release, proving that the open-source fork of Terraform is more than a protest — it&amp;rsquo;s a viable alternative.</description></item><item><title>OpenTofu and the Future of Open Source Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/240104-opentofu-open-source-infrastructure/</link><pubDate>Thu, 04 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240104-opentofu-open-source-infrastructure/</guid><description>As OpenTofu approaches its first stable release, the HashiCorp license change continues to reshape how we think about open source infrastructure tooling.</description></item><item><title>Kubernetes 1.29 Mandala — Sidecars Finally Graduate</title><link>https://www.osmondvanhemert.nl/posts/231214-kubernetes-129-mandala-release/</link><pubDate>Thu, 14 Dec 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/231214-kubernetes-129-mandala-release/</guid><description>Kubernetes 1.29 ships with native sidecar container support, improved networking, and a continued push toward simplifying cluster operations.</description></item><item><title>AWS re:Invent 2023 — Amazon Q and the AI-Infused Cloud</title><link>https://www.osmondvanhemert.nl/posts/231130-aws-reinvent-2023-amazon-q/</link><pubDate>Thu, 30 Nov 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/231130-aws-reinvent-2023-amazon-q/</guid><description>AWS re:Invent 2023 introduces Amazon Q, Graviton4, and a wave of AI-integrated cloud services that signal where enterprise infrastructure is heading.</description></item><item><title>OpenTofu Gains Momentum — The Terraform Fork Finding Its Feet</title><link>https://www.osmondvanhemert.nl/posts/231026-opentofu-terraform-fork/</link><pubDate>Thu, 26 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/231026-opentofu-terraform-fork/</guid><description>OpenTofu, the community fork of Terraform born from HashiCorp&amp;rsquo;s license change, is rapidly building momentum under the Linux Foundation.</description></item><item><title>HTTP/2 Rapid Reset — The Zero-Day That Hit Everyone</title><link>https://www.osmondvanhemert.nl/posts/231012-http2-rapid-reset-attack/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/231012-http2-rapid-reset-attack/</guid><description>CVE-2023-44487 exploits a fundamental aspect of HTTP/2 to enable record-breaking DDoS attacks. Here&amp;rsquo;s what you need to know and do.</description></item><item><title>OpenTofu — The Community Fights Back Against Terraform's License Change</title><link>https://www.osmondvanhemert.nl/posts/230831-opentofu-terraform-fork-open-source/</link><pubDate>Thu, 31 Aug 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230831-opentofu-terraform-fork-open-source/</guid><description>HashiCorp&amp;rsquo;s switch to the Business Source License has triggered a community fork of Terraform called OpenTofu, and the implications for infrastructure-as-code are enormous.</description></item><item><title>HashiCorp Switches Terraform to BSL — The Open Source World Reacts</title><link>https://www.osmondvanhemert.nl/posts/230810-hashicorp-terraform-bsl-license/</link><pubDate>Thu, 10 Aug 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230810-hashicorp-terraform-bsl-license/</guid><description>HashiCorp&amp;rsquo;s decision to relicense Terraform and other products under the Business Source License has sent shockwaves through the infrastructure community.</description></item><item><title>MOVEit Transfer: The Supply Chain Breach That Keeps Growing</title><link>https://www.osmondvanhemert.nl/posts/230629-moveit-breach-supply-chain-security/</link><pubDate>Thu, 29 Jun 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230629-moveit-breach-supply-chain-security/</guid><description>The MOVEit Transfer vulnerability has now impacted hundreds of organizations worldwide — a stark reminder that managed file transfer tools remain critical and under-secured attack surfaces.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230629-moveit-breach-supply-chain-security/featured.jpg"/></item><item><title>Microsoft Build 2023 — The Copilot Stack and Azure AI's Big Bet</title><link>https://www.osmondvanhemert.nl/posts/230525-microsoft-build-2023-copilot-stack/</link><pubDate>Thu, 25 May 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230525-microsoft-build-2023-copilot-stack/</guid><description>Microsoft Build 2023 reveals the &amp;lsquo;Copilot Stack&amp;rsquo; — a layered architecture that shows how Microsoft plans to embed AI into every developer workflow.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230525-microsoft-build-2023-copilot-stack/featured.jpg"/></item><item><title>GitHub Copilot X — The AI-Powered Developer Experience Takes Shape</title><link>https://www.osmondvanhemert.nl/posts/230323-github-copilot-x-ai-powered-developer-experience/</link><pubDate>Thu, 23 Mar 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230323-github-copilot-x-ai-powered-developer-experience/</guid><description>GitHub announces Copilot X with GPT-4 integration, chat, voice, pull request summaries, and docs — here&amp;rsquo;s what developers should actually expect.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230323-github-copilot-x-ai-powered-developer-experience/featured.jpg"/></item><item><title>The US National Cybersecurity Strategy — Software Liability Is Coming</title><link>https://www.osmondvanhemert.nl/posts/230309-us-national-cybersecurity-strategy-2023/</link><pubDate>Thu, 09 Mar 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230309-us-national-cybersecurity-strategy-2023/</guid><description>The Biden administration&amp;rsquo;s new cybersecurity strategy shifts liability toward software vendors, and developers need to pay attention.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230309-us-national-cybersecurity-strategy-2023/featured.jpg"/></item><item><title>ESXiArgs Ransomware — A Wake-Up Call for VMware Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/230202-esxiargs-ransomware-vmware-esxi/</link><pubDate>Thu, 02 Feb 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230202-esxiargs-ransomware-vmware-esxi/</guid><description>A massive ransomware campaign is exploiting a two-year-old VMware ESXi vulnerability, and the scale of unpatched systems is alarming.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230202-esxiargs-ransomware-vmware-esxi/featured.jpg"/></item><item><title>CircleCI's Security Incident — Rotate Your Secrets Now</title><link>https://www.osmondvanhemert.nl/posts/230105-circleci-security-incident/</link><pubDate>Thu, 05 Jan 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230105-circleci-security-incident/</guid><description>CircleCI discloses a security incident and urges all customers to immediately rotate secrets stored in the platform. A reminder of the risks in our CI/CD supply chain.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/230105-circleci-security-incident/featured.jpg"/></item><item><title>Kubernetes 1.26 — Electrifying the Platform</title><link>https://www.osmondvanhemert.nl/posts/221208-kubernetes-126-electrifying/</link><pubDate>Thu, 08 Dec 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221208-kubernetes-126-electrifying/</guid><description>Kubernetes 1.26 &amp;lsquo;Electrifying&amp;rsquo; arrives with significant improvements to storage, scheduling, and the ongoing effort to remove legacy code.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221208-kubernetes-126-electrifying/featured.jpg"/></item><item><title>AWS re:Invent 2022 — The Cloud Gets Opinionated</title><link>https://www.osmondvanhemert.nl/posts/221124-aws-reinvent-2022-cloud-opinionated/</link><pubDate>Thu, 24 Nov 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221124-aws-reinvent-2022-cloud-opinionated/</guid><description>AWS re:Invent 2022 kicks off with a clear message: the cloud giant is moving beyond primitives and toward opinionated, integrated solutions.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221124-aws-reinvent-2022-cloud-opinionated/featured.jpg"/></item><item><title>GitHub Universe 2022 — Copilot for Business and the AI-Assisted Future</title><link>https://www.osmondvanhemert.nl/posts/221110-github-universe-2022-copilot-business/</link><pubDate>Thu, 10 Nov 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221110-github-universe-2022-copilot-business/</guid><description>GitHub Universe 2022 puts AI front and center with Copilot for Business, while Codespaces and Actions get meaningful upgrades.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221110-github-universe-2022-copilot-business/featured.jpg"/></item><item><title>OpenSSL's Critical Vulnerability — Lessons From a Week of Preparation</title><link>https://www.osmondvanhemert.nl/posts/221103-openssl-critical-vulnerability-response/</link><pubDate>Thu, 03 Nov 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221103-openssl-critical-vulnerability-response/</guid><description>The OpenSSL 3.0.7 patch for CVE-2022-3602 and CVE-2022-3786 arrived this week — here&amp;rsquo;s what happened and what it teaches us about vulnerability response.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221103-openssl-critical-vulnerability-response/featured.jpg"/></item><item><title>Microsoft Ignite 2022 — Azure's Quiet Infrastructure Revolution</title><link>https://www.osmondvanhemert.nl/posts/221013-microsoft-ignite-2022-azure/</link><pubDate>Thu, 13 Oct 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221013-microsoft-ignite-2022-azure/</guid><description>Microsoft Ignite 2022 delivered a wave of Azure updates that signal where enterprise cloud infrastructure is heading next.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221013-microsoft-ignite-2022-azure/featured.jpg"/></item><item><title>Cloudflare R2 Goes GA — The S3-Compatible Storage War Heats Up</title><link>https://www.osmondvanhemert.nl/posts/221006-cloudflare-r2-storage-wars/</link><pubDate>Thu, 06 Oct 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221006-cloudflare-r2-storage-wars/</guid><description>Cloudflare R2&amp;rsquo;s general availability challenges AWS S3&amp;rsquo;s dominance with zero egress fees and full S3 API compatibility, reshaping the economics of cloud storage.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/221006-cloudflare-r2-storage-wars/featured.jpg"/></item><item><title>The Uber Breach — When MFA Isn't Enough</title><link>https://www.osmondvanhemert.nl/posts/220915-uber-breach-social-engineering/</link><pubDate>Thu, 15 Sep 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220915-uber-breach-social-engineering/</guid><description>A teenager allegedly breached Uber&amp;rsquo;s internal systems through social engineering and MFA fatigue, exposing fundamental weaknesses in how we think about authentication.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/220915-uber-breach-social-engineering/featured.jpg"/></item><item><title>Heroku Kills the Free Tier — End of an Era for Developer Onboarding</title><link>https://www.osmondvanhemert.nl/posts/220901-heroku-ending-free-tier/</link><pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220901-heroku-ending-free-tier/</guid><description>Heroku&amp;rsquo;s decision to eliminate free dynos and databases marks the end of an era. Where do developers go now for easy, free deployment?</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/220901-heroku-ending-free-tier/featured.jpg"/></item><item><title>Broadcom's $61 Billion VMware Bet — What It Means for Cloud Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/220526-broadcom-vmware-acquisition/</link><pubDate>Thu, 26 May 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220526-broadcom-vmware-acquisition/</guid><description>Broadcom&amp;rsquo;s proposed $61B acquisition of VMware could reshape the enterprise cloud and virtualization landscape for years to come.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/220526-broadcom-vmware-acquisition/featured.jpg"/></item><item><title>Kubernetes 1.24 Drops Dockershim — The End of an Era</title><link>https://www.osmondvanhemert.nl/posts/220505-kubernetes-124-dockershim-removal/</link><pubDate>Thu, 05 May 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220505-kubernetes-124-dockershim-removal/</guid><description>Kubernetes 1.24 finally removes Dockershim, completing the long-telegraphed divorce from Docker as a container runtime.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/220505-kubernetes-124-dockershim-removal/featured.jpg"/></item><item><title>Terraform 1.1 and the Maturing IaC Landscape</title><link>https://www.osmondvanhemert.nl/posts/220127-terraform-1-1-iac-maturity/</link><pubDate>Thu, 27 Jan 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220127-terraform-1-1-iac-maturity/</guid><description>Terraform 1.1 brings refactoring support and moved/imported blocks, signaling that Infrastructure as Code tooling is growing up.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/220127-terraform-1-1-iac-maturity/featured.jpg"/></item><item><title>After Log4Shell — Software Supply Chain Security Can't Wait</title><link>https://www.osmondvanhemert.nl/posts/211216-software-supply-chain-security-after-log4j/</link><pubDate>Thu, 16 Dec 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211216-software-supply-chain-security-after-log4j/</guid><description>A week after Log4Shell, the patching chaos continues. But the bigger lesson is about software supply chain security and why we need SBOMs now.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211216-software-supply-chain-security-after-log4j/featured.jpg"/></item><item><title>AWS re:Invent 2021 — The Cloud Just Got More Opinionated</title><link>https://www.osmondvanhemert.nl/posts/211202-aws-reinvent-2021-cloud-abstractions/</link><pubDate>Thu, 02 Dec 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211202-aws-reinvent-2021-cloud-abstractions/</guid><description>AWS re:Invent 2021 delivered a clear message: the cloud is moving toward higher-level abstractions, and developers should pay attention.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211202-aws-reinvent-2021-cloud-abstractions/featured.jpg"/></item><item><title>AWS re:Invent 2021 Kicks Off — Serverless and the Cloud Keep Evolving</title><link>https://www.osmondvanhemert.nl/posts/211125-aws-reinvent-2021-serverless-evolution/</link><pubDate>Thu, 25 Nov 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211125-aws-reinvent-2021-serverless-evolution/</guid><description>AWS re:Invent 2021 is underway in Las Vegas, and the announcements already hint at where cloud infrastructure is headed next.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211125-aws-reinvent-2021-serverless-evolution/featured.jpg"/></item><item><title>CentOS Stream 9 Lands — The Enterprise Linux Landscape Keeps Shifting</title><link>https://www.osmondvanhemert.nl/posts/211118-centos-stream-9-enterprise-linux-shift/</link><pubDate>Thu, 18 Nov 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211118-centos-stream-9-enterprise-linux-shift/</guid><description>CentOS Stream 9 has arrived as the successor to both CentOS 8 and the traditional CentOS model — and the enterprise Linux community is still adapting.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211118-centos-stream-9-enterprise-linux-shift/featured.jpg"/></item><item><title>GitLab Goes Public — What an IPO Means for Open Source Business Models</title><link>https://www.osmondvanhemert.nl/posts/211014-gitlab-ipo-open-source-business/</link><pubDate>Thu, 14 Oct 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211014-gitlab-ipo-open-source-business/</guid><description>GitLab&amp;rsquo;s successful IPO this week validates the open-core model and raises important questions about the future of open-source developer tooling.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211014-gitlab-ipo-open-source-business/featured.jpg"/></item><item><title>Windows 11 Arrives — What Developers Actually Need to Know</title><link>https://www.osmondvanhemert.nl/posts/211007-windows-11-developer-perspective/</link><pubDate>Thu, 07 Oct 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211007-windows-11-developer-perspective/</guid><description>Windows 11 launched this week with WSL improvements, a new Microsoft Store, and Android app support coming soon. Here&amp;rsquo;s what matters for developers.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/211007-windows-11-developer-perspective/featured.jpg"/></item><item><title>The Facebook Outage — When BGP Goes Wrong, Everything Goes Dark</title><link>https://www.osmondvanhemert.nl/posts/210930-facebook-bgp-outage-internet-fragility/</link><pubDate>Thu, 30 Sep 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210930-facebook-bgp-outage-internet-fragility/</guid><description>Facebook, WhatsApp, and Instagram went down for six hours due to a BGP misconfiguration, exposing how fragile the internet&amp;rsquo;s routing infrastructure really is.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210930-facebook-bgp-outage-internet-fragility/featured.jpg"/></item><item><title>Confluence Under Siege — CVE-2021-26084 and the Self-Hosted Software Problem</title><link>https://www.osmondvanhemert.nl/posts/210902-confluence-rce-cve-2021-26084/</link><pubDate>Thu, 02 Sep 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210902-confluence-rce-cve-2021-26084/</guid><description>The critical Confluence Server RCE vulnerability is being actively exploited in the wild, raising urgent questions about the sustainability of self-hosted enterprise software.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210902-confluence-rce-cve-2021-26084/featured.jpg"/></item><item><title>Kubernetes 1.22 — Removing the Training Wheels</title><link>https://www.osmondvanhemert.nl/posts/210805-kubernetes-1-22-release/</link><pubDate>Thu, 05 Aug 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210805-kubernetes-1-22-release/</guid><description>Kubernetes 1.22 drops several long-deprecated beta APIs and graduates key features to stable — a sign the project is maturing and cleaning house.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210805-kubernetes-1-22-release/featured.jpg"/></item><item><title>Windows 365 Cloud PC — Microsoft's Bet on the Desktop-as-a-Service Future</title><link>https://www.osmondvanhemert.nl/posts/210729-windows-365-cloud-pc-future/</link><pubDate>Thu, 29 Jul 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210729-windows-365-cloud-pc-future/</guid><description>Microsoft announces Windows 365, a full Cloud PC experience — and it might reshape how we think about developer workstations and enterprise IT.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210729-windows-365-cloud-pc-future/featured.jpg"/></item><item><title>Terraform 1.0 — Infrastructure as Code Reaches a Milestone</title><link>https://www.osmondvanhemert.nl/posts/210701-terraform-1-0-infrastructure-as-code-milestone/</link><pubDate>Thu, 01 Jul 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210701-terraform-1-0-infrastructure-as-code-milestone/</guid><description>After years of 0.x releases, Terraform hits 1.0 with stability guarantees. What this means for the IaC ecosystem and your existing workflows.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210701-terraform-1-0-infrastructure-as-code-milestone/featured.jpg"/></item><item><title>The Fastly Outage — A Masterclass in Single Points of Failure</title><link>https://www.osmondvanhemert.nl/posts/210610-fastly-cdn-outage-single-points-failure/</link><pubDate>Thu, 10 Jun 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210610-fastly-cdn-outage-single-points-failure/</guid><description>When a single configuration change at Fastly took down half the internet, it exposed uncomfortable truths about how we build on CDN infrastructure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210610-fastly-cdn-outage-single-points-failure/featured.jpg"/></item><item><title>GitOps Goes Mainstream — ArgoCD, Flux, and the CNCF Bet</title><link>https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/</link><pubDate>Thu, 03 Jun 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/</guid><description>With ArgoCD accepted into CNCF incubation and Flux reaching its own milestones, GitOps is transitioning from buzzword to standard practice for Kubernetes deployments.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/featured.jpg"/></item><item><title>Microsoft Build 2021 — The Developer Platform Play Deepens</title><link>https://www.osmondvanhemert.nl/posts/210527-microsoft-build-2021-developer-platform/</link><pubDate>Thu, 27 May 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210527-microsoft-build-2021-developer-platform/</guid><description>Microsoft Build 2021 doubled down on the developer platform strategy with Azure improvements, deeper GitHub integration, and a clearer vision for the cloud-native developer workflow.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210527-microsoft-build-2021-developer-platform/featured.jpg"/></item><item><title>Colonial Pipeline Ransomware — When Cybersecurity Meets Critical Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/210506-colonial-pipeline-ransomware/</link><pubDate>Thu, 06 May 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210506-colonial-pipeline-ransomware/</guid><description>The Colonial Pipeline ransomware attack exposes how deeply intertwined our digital infrastructure has become with physical systems we take for granted.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210506-colonial-pipeline-ransomware/featured.jpg"/></item><item><title>The Codecov Breach — When Your CI Pipeline Becomes the Attack Vector</title><link>https://www.osmondvanhemert.nl/posts/210415-codecov-supply-chain-attack/</link><pubDate>Thu, 15 Apr 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210415-codecov-supply-chain-attack/</guid><description>Codecov&amp;rsquo;s compromised Bash Uploader script exposed CI/CD secrets for thousands of organizations, highlighting a systemic weakness in how we trust third-party tools in our build pipelines.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210415-codecov-supply-chain-attack/featured.jpg"/></item><item><title>Kubernetes 1.21 — Immutable Secrets and the March Toward Maturity</title><link>https://www.osmondvanhemert.nl/posts/210408-kubernetes-1-21-release/</link><pubDate>Thu, 08 Apr 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210408-kubernetes-1-21-release/</guid><description>Kubernetes 1.21 lands with immutable Secrets and ConfigMaps going stable, CronJobs promoted to GA, and signals that the platform is maturing past its explosive growth phase.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210408-kubernetes-1-21-release/featured.jpg"/></item><item><title>OVHcloud Strasbourg Fire — When 'The Cloud' Literally Burns Down</title><link>https://www.osmondvanhemert.nl/posts/210311-ovhcloud-datacenter-fire/</link><pubDate>Thu, 11 Mar 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210311-ovhcloud-datacenter-fire/</guid><description>A catastrophic fire at OVHcloud&amp;rsquo;s Strasbourg datacenter destroys thousands of servers and raises hard questions about cloud resilience and backup strategies.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210311-ovhcloud-datacenter-fire/featured.jpg"/></item><item><title>Hafnium and the Microsoft Exchange Zero-Days — A Supply Chain Nightmare Unfolds</title><link>https://www.osmondvanhemert.nl/posts/210304-microsoft-exchange-hafnium-zero-day/</link><pubDate>Thu, 04 Mar 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210304-microsoft-exchange-hafnium-zero-day/</guid><description>Four zero-day vulnerabilities in Microsoft Exchange Server are being actively exploited at scale, and the fallout is only beginning.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210304-microsoft-exchange-hafnium-zero-day/featured.jpg"/></item><item><title>When the Grid Goes Down — Cloud Resilience Lessons from the Texas Power Crisis</title><link>https://www.osmondvanhemert.nl/posts/210218-texas-grid-cloud-resilience/</link><pubDate>Thu, 18 Feb 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210218-texas-grid-cloud-resilience/</guid><description>The Texas power grid failure is knocking out data centers and cloud services, offering hard lessons about infrastructure resilience, multi-region architecture, and the physical realities underlying our digital systems.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210218-texas-grid-cloud-resilience/featured.jpg"/></item><item><title>SolarWinds Three Months Later — Rethinking Software Supply Chain Security</title><link>https://www.osmondvanhemert.nl/posts/210211-solarwinds-supply-chain-security/</link><pubDate>Thu, 11 Feb 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210211-solarwinds-supply-chain-security/</guid><description>Three months after the SolarWinds breach disclosure, the full scope is still unfolding and the implications for software supply chain security demand fundamental changes in how we build and deploy software.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210211-solarwinds-supply-chain-security/featured.jpg"/></item><item><title>CentOS Is Dead, Long Live CentOS Stream — What Now for Enterprise Linux?</title><link>https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/</link><pubDate>Thu, 24 Dec 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/</guid><description>Red Hat&amp;rsquo;s decision to shift CentOS from a stable downstream rebuild to a rolling upstream preview has sent shockwaves through the server community.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/featured.jpg"/></item><item><title>SolarWinds Hack — Why Supply Chain Attacks Should Terrify Every Developer</title><link>https://www.osmondvanhemert.nl/posts/201217-solarwinds-supply-chain-attack/</link><pubDate>Thu, 17 Dec 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/201217-solarwinds-supply-chain-attack/</guid><description>The SolarWinds supply chain attack is a watershed moment for software security — and it has profound implications for how we build, ship, and trust code.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/201217-solarwinds-supply-chain-attack/featured.jpg"/></item><item><title>Docker Hub Rate Limits Are Coming — And Your CI Pipeline Might Break</title><link>https://www.osmondvanhemert.nl/posts/201029-docker-hub-rate-limiting/</link><pubDate>Thu, 29 Oct 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/201029-docker-hub-rate-limiting/</guid><description>Docker Hub&amp;rsquo;s new rate limits take effect November 1st. If you haven&amp;rsquo;t prepared your build pipelines, you&amp;rsquo;re about to find out the hard way.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/201029-docker-hub-rate-limiting/featured.jpg"/></item><item><title>HashiCorp Launches Waypoint and Boundary — Closing the Developer Experience Gap</title><link>https://www.osmondvanhemert.nl/posts/201015-hashicorp-waypoint-boundary/</link><pubDate>Thu, 15 Oct 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/201015-hashicorp-waypoint-boundary/</guid><description>HashiCorp announced two new open-source tools at HashiConf Digital — Waypoint for application deployment and Boundary for secure remote access. Here&amp;rsquo;s why they matter.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/201015-hashicorp-waypoint-boundary/featured.jpg"/></item><item><title>GitHub CLI 1.0 — The Terminal-First Workflow Gets Official</title><link>https://www.osmondvanhemert.nl/posts/200917-github-cli-1-developer-workflow/</link><pubDate>Thu, 17 Sep 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200917-github-cli-1-developer-workflow/</guid><description>GitHub CLI 1.0 is here, bringing pull requests, issues, and repo management to the terminal. A look at what it means for developer workflows.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200917-github-cli-1-developer-workflow/featured.jpg"/></item><item><title>Kubernetes 1.19 — The Extensibility Release That Quietly Matters</title><link>https://www.osmondvanhemert.nl/posts/200903-kubernetes-119-extensibility/</link><pubDate>Thu, 03 Sep 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200903-kubernetes-119-extensibility/</guid><description>Kubernetes 1.19 lands with extended support windows, Ingress API improvements, and a clear signal that the platform is maturing fast.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200903-kubernetes-119-extensibility/featured.jpg"/></item><item><title>Kubernetes 1.19 — Stability Takes Center Stage</title><link>https://www.osmondvanhemert.nl/posts/200827-kubernetes-1-19-release/</link><pubDate>Thu, 27 Aug 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200827-kubernetes-1-19-release/</guid><description>Kubernetes 1.19 arrives with the longest support window yet and a focus on stability features. For production operators, this is the release we&amp;rsquo;ve been asking for.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200827-kubernetes-1-19-release/featured.jpg"/></item><item><title>Terraform 0.13 — Module-Level For Each and the Provider Story</title><link>https://www.osmondvanhemert.nl/posts/200709-terraform-013-module-foreach/</link><pubDate>Thu, 09 Jul 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200709-terraform-013-module-foreach/</guid><description>Terraform 0.13 brings count and for_each to modules, automatic provider installation, and custom validation rules. A look at what changes in practice.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200709-terraform-013-module-foreach/featured.jpg"/></item><item><title>Your CI/CD Pipeline Is Your New Attack Surface — And Remote Work Made It Worse</title><link>https://www.osmondvanhemert.nl/posts/200611-cicd-pipeline-security-remote-work/</link><pubDate>Thu, 11 Jun 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200611-cicd-pipeline-security-remote-work/</guid><description>As teams rushed to enable remote development workflows, CI/CD pipelines became a prime target. Here&amp;rsquo;s what&amp;rsquo;s going wrong and how to harden your build infrastructure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200611-cicd-pipeline-security-remote-work/featured.jpg"/></item><item><title>GitHub Free for Teams — What This Means for Open Source and Beyond</title><link>https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/</link><pubDate>Thu, 16 Apr 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/</guid><description>GitHub drops pricing barriers for teams, making unlimited private repos and essential collaboration features free for everyone.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/featured.jpg"/></item><item><title>Infrastructure as Code Under Pressure — Lessons from Pandemic-Scale Scaling</title><link>https://www.osmondvanhemert.nl/posts/200409-infrastructure-as-code-pandemic-scaling/</link><pubDate>Thu, 09 Apr 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200409-infrastructure-as-code-pandemic-scaling/</guid><description>The sudden shift to remote work has stress-tested Infrastructure as Code practices at unprecedented scale. Here&amp;rsquo;s what&amp;rsquo;s working, what&amp;rsquo;s breaking, and what we should learn.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200409-infrastructure-as-code-pandemic-scaling/featured.jpg"/></item><item><title>The Remote Work Stress Test — Is Our Infrastructure Ready?</title><link>https://www.osmondvanhemert.nl/posts/200305-tech-remote-work-infrastructure/</link><pubDate>Thu, 05 Mar 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200305-tech-remote-work-infrastructure/</guid><description>As tech companies start mandating work-from-home policies amid growing COVID-19 concerns, the infrastructure supporting remote work faces its biggest test yet.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200305-tech-remote-work-infrastructure/featured.jpg"/></item><item><title>Docker's Second Act — Finding Its Place After the Enterprise Sell-Off</title><link>https://www.osmondvanhemert.nl/posts/200220-docker-desktop-new-direction/</link><pubDate>Thu, 20 Feb 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200220-docker-desktop-new-direction/</guid><description>Three months after selling Docker Enterprise to Mirantis, Docker Inc. is refocusing on developer experience. What does this mean for the container ecosystem?</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200220-docker-desktop-new-direction/featured.jpg"/></item><item><title>GitHub Actions Is Quietly Reshaping CI/CD — Two Months After GA</title><link>https://www.osmondvanhemert.nl/posts/200116-github-actions-reshaping-ci-cd/</link><pubDate>Thu, 16 Jan 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200116-github-actions-reshaping-ci-cd/</guid><description>GitHub Actions went generally available in November 2019. Two months in, the migration patterns are becoming clear — and the implications for the CI/CD landscape are significant.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200116-github-actions-reshaping-ci-cd/featured.jpg"/></item></channel></rss>