🛡️ containerd security patches for CVE-2026-53493 released. * containerd: Multiple versions (v2.4.1, v2.3.6, v2.2.9, v2.0.13, v1.7.36) released with fix for CVE-2026-53493. * KEDA v2.21.0: Introduces three breaking changes. * kubewarden-controller v1… https://lwcn.dev/newsletter/2026-week-40/
Mario Fahlandt
@mfahlandt.bsky.social
Tech freak, working at Kubermatic, CNCF Ambassador, organizer of GDG Cloud Munich, GDE for cloud dev.to/mfahlandt thoughts are usually owned by one of my persona
📦 Kubernetes v1.37 features advanced to Beta. * Container storage hardening, Pod-Level Resource Managers, Memory QoS now Beta. * Podman, Skopeo, Buildah patched CVE-2025-11395. * Jaeger v2.21.0 removed v1 HTTP endpoints (breaking change). Full breakd… https://lwcn.dev/newsletter/2026-week-39/
⚙️ Last Week in Cloud Native (W38) update. - K8s v1.37: Native Histograms Beta, In-Place Pod Resize Preemption Alpha. - Kyverno v1.19.1 addressed CVE-2026-39821, CVE-2026-56853. - Prometheus v3.13.3 addressed GO-2026-5841, GO-2026-6303. Full breakdown: https://lwcn.dev/newsletter/2026-week-38/
🚀 Kubernetes v1.37: KubeletInUserNamespace graduated to Beta. containerd (multi-version) received security updates for CVE-2026-53495. Podman v6.1.1 fixed CVE-2026-17106 (archive extraction security). Full breakdown: https://lwcn.dev/newsletter/2026-week-37/
🚀 Kubernetes v1.37.0 released. - Pod Certificates and Cluster Trust Bundles introduced. - Metrics API graduated to stable. - Envoy v1.39.1+ fixed CVE-2026-73511 (URL normalization vulnerability). - K3s v1.36.4+k3s1+ upgraded embedded Traefik to v40.x, chan… https://lwcn.dev/newsletter/2026-week-36/
🛡️ Last Week in Cloud Native: Security updates and key project releases. - Rook patch releases address Ceph CVE-2025–30156. - Kyverno v1.19.0 fixes CVE-2026-32280. - Strimzi Kafka Operator 1.2.0 exclusively supports v1 CRD API, deprecating older APIs. Full… https://lwcn.dev/newsletter/2026-week-35/
☁️ Cloud Native Buildpacks graduates from CNCF. Antrea v2.7.0 changes default: Agent gossip traffic now authenticated/encrypted. Podman v5.8.6 fixes CVE-2026-19730 (file truncation). containerd v2.3.4 disables checkpoint restore in CreateContainer by defau… https://lwcn.dev/newsletter/2026-week-34/
🛣️ Gateway API v1.6 graduates TCPRoute and UDPRoute to Standard. k3s v1.36.3+k3s1 upgrades Traefik to v40.x, includes provider name breaking change. cosign v3.1.3 and v2.6.5 resolve GHSA-fx35-mq7g-6g98 (verification bypass). Full breakdown: https://lwcn.dev/newsletter/2026-week-33/
🚀 LWCN Week 32: Cilium v1.20.0 released. - Cilium v1.20.0: Major release. - Prometheus v3.13.2: Security updates (CVE-2026-56852, GHSA-hrxh-6v49-42gf) + PromQL bug fix. - OPA v1.19.0: SQL injection vulnerability addressed, cgo-free WebAssembly runtime adde… https://lwcn.dev/newsletter/2026-week-32/
⚠️ OpenTelemetry Collector v0.157.0 modifies histogram metric boundaries. - OpenTelemetry Collector v0.157.0: Histogram bucket definitions changed for specific metrics. Monitoring dashboards may require updates. - Crossplane v2.3.4: Fixes Usage controller… https://lwcn.dev/newsletter/2026-week-31/
🚀 Envoy v1.39.0 released with Bazel 8 build requirement. * Envoy v1.39.0: Requires Bazel 8 for source builds. * Jaeger v2.20.0: Removed Elasticsearch v6 support. * Flux2 v2.9.2: Fixed Kustomization URL reconciliation. Full breakdown: https://lwcn.dev/newsletter/2026-week-30/
⚙️ etcd v3.7.0 released this week. * etcd v3.7.0: New features, consult upgrade guide for potential breaking changes. * Prometheus v3.5.5: Fixes security issue CVE-2026-53606 in `sanitize-html` UI dependency. * Flux v2.9.1: Disables variable substitu… https://lwcn.dev/newsletter/2026-week-29/
Hello Istanbul, looking forward to open KCD Istanbul tomorrow
🛡️ LWCN Week 27: Strimzi 1.1.0 removes older CRD APIs. * Strimzi Kafka Operator 1.1.0 removes support for v1beta2, v1beta1, v1alpha1 CRD APIs. * Podman v6.0.0/v5.8.4 addressed CVE-2026-57231 (host env var leak). * Envoy patch releases resolved CVE-20… https://lwcn.dev/newsletter/2026-week-27/
⚠️ Strimzi Kafka Operator 1.0.1 removes older CRD API support. - Strimzi 1.0.1: Drops v1beta2, v1beta1, v1alpha1 CRD APIs. - containerd: Fixes CVE-2026-50195, CVE-2026-53488. - Prometheus v3.5.4: Addresses GHSA-39j6-789q-qxvh. Full breakdown: https://lwcn.dev/newsletter/2026-week-26/
🛡️ LWCN 2026, Week 25 highlights: * Podman v5.8.3 addresses CVE-2026-44517 (Dockerfile build file inclusion). * OPA v1.17.1 fixes Go stdlib CVEs GO-2026-5039, GO-2026-5037. * Dapr v1.18.0 introduces workflow history signing and verification. Full breakdown: https://lwcn.dev/newsletter/2026-week-25/
🛡️ Cloud Native Security Updates (Week 24, 2026). Envoy v1.38.1+ mitigates CVE-2026-47774 (HTTP/2 stream header size). containerd v2.1.8 fixes CVE-2026-46680 & `host.containerd.io` mounts. Longhorn v1.12.0: V2 Data Engine reaches GA status. Full breakdown: https://lwcn.dev/newsletter/2026-week-24/
⚠️ Capsule v0.13.0 changes default webhook cert management. Capsule v0.13.0: Webhooks now default to cert-manager self-signed certificates. Prometheus v3.12.0: Security fixes, PromQL features, TSDB performance. Full breakdown: https://lwcn.dev/newsletter/2026-week-23/
⭐ Last Week in Cloud Native (2026, Week 22): * OpenTelemetry graduates as a CNCF project. * containerd v2.3.1, v2.2.4, v2.0.9, v1.7.32 released, fixing CVE-2026-46680. * OpenTelemetry Collector v0.153.0 stabilizes `configoptional.AddEnabledField`, a… https://lwcn.dev/newsletter/2026-week-22/
🚨 Kubernetes v1.36 removes Service ExternalIPs. - Kubernetes v1.36: `Service.spec.externalIPs` field removed. - Skopeo v1.11.5: Fixes CVE-2025-65637 and CVE-2026-34986. - Helm v3: End-of-life warning issued. Full breakdown: https://lwcn.dev/newsletter/2026-week-21/
🚀 Kubernetes v1.36.0 released. - Volume Group Snapshots graduated to GA. - Declarative Validation graduated to GA. - Volcano v1.14.2, v1.13.3, v1.12.4 addressed CVE-2026-44247. Full breakdown: https://lwcn.dev/newsletter/2026-week-20/
⚠️ Strimzi Kafka Operator 1.0.0: `v1` CRD API enforced, older APIs removed. - Argo CD v3.3.9/v3.2.11: Fixes critical vulnerability GHSA-3v3m-wc6v-x4x3. - Prometheus v3.11.3/v3.5.3: Fixes remote-read & AzureAD OAuth vulnerabilities. Full breakdown: https://lwcn.dev/newsletter/2026-week-19/
⚙️ Kubernetes v1.36 released. - User Namespaces & Fine-Grained Kubelet API Authorization reached GA. - Kyverno v1.16.4 fixed CVE-2025-68121. - cert-manager v1.19.5 resolved several CVEs. Full breakdown: https://lwcn.dev/newsletter/2026-week-18/
🛡️ Dapr, Containerd, Prometheus security updates. * Dapr v1.17.5+ fixed critical service invocation path traversal. * Containerd v2.2.3+ patched CVE-2026-35469 (spdystream). * Prometheus v3.11.2+ fixed Stored XSS in web UI. Full breakdown: https://lwcn.dev/newsletter/2026-week-17/
🤯 AI coding is undergoing a massive merger! Key highlights this week: 🤖 Cursor, Claude Code, & Codex unite! 🛡️ Urgent Envoy security patches released. 🎤 KubeCon EU insights: Platform engineering & diverse voices. Don't miss a beat! Read all about it in t… https://lwcn.dev/newsletter/2026-week-16/
🏗️ Cloud Native City: Security Reinforcement! Last Week in Cloud Native: 🔹 Gateway API & kube-ovn updates 🔹 'distribution' v3.1.0 CVE fix 🔹 Go 1.26.2 patches (OPA, Spire) Full report: lwcn.dev/newsletter/2... #CloudNative #Kubernetes #K8s #InfoSec
Week 16 - April 2026: Cluster-Api, Gateway-Api & Helm Updates | Last Week in Cloud Native
Cloud Native updates for Week 16 - April 2026. Featuring releases from Cluster-Api, Gateway-Api & Helm and more Kubernetes ecosystem news.
lwcn.dev
I almost forgot I have this account - yeah social media game still bad. Too much happened so in short tomorrow I will speak at ContainerDays London Also I launched www.lwcn.dev basically a tl;Dr; of cloud native follow if you are interested
Last Week in Cloud Native - Weekly Cloud Native Newsletter
Weekly newsletter covering Cloud Native releases, Kubernetes news, and CNCF ecosystem updates. Stay informed about the latest in the CNCF ecosystem, including Kubernetes, Helm, ArgoCD, and more.
lwcn.dev
Was great to catch up with so many fellow @cncf.io Ambassadors at @containerdays.bsky.social ! 💙 (This isn’t even all the ambassadors, we just couldn’t get everyone together in one place 🤣) Feat @kaspernissen.xyz @dotanhaim.bsky.social @carlagg.bsky.social @mfahlandt.bsky.social & more
🚀 etcd v3.6.0 is LIVE! Our first minor release in nearly 4 years ✅ Full Downgrade ✅ v3store Migration (v2 gone!) 📉 ~50% Less Memory 📈 ~10% Faster 🛡️ Now a @kubernetes.bsky.social SIG! ⚠️IMPORTANT: Upgrade to v3.5.20+ BEFORE v3.6! Read more: etcd.io/blog/2025/an... #etcd #Kubernetes #CloudNative
etcd.io