Operations | Monitoring | ITSM | DevOps | Cloud

The latest News and Information on DevOps, CI/CD, Automation and related technologies.

Golden paths: how to ship securely without slowing developers

The secure path and the easy path should be the same path. Ralph McTeggart (Principal Engineer), Alex Franzmann (Customer Onboarding Team Lead), and Claire McDyre (Product Manager) at Cloudsmith lay out how platform teams can deliver supply chain security as a capability rather than a checklist. The argument runs from first principles: make a private registry the default, automate policy enforcement at the global level, and extend that same logic to compliance – so SBOM generation happens in the pipeline, not as a developer's manual task.

Supply chain hit: the first hours are about "am I affected?"

The first two to three hours after a supply chain compromise aren't about remediation – they're about figuring out whether you're affected at all. That requires two things: a feed of compromised packages you can cross-reference against what you're using, and an audit trail showing which developers pulled which packages and when. Teams that can answer "are we affected?" in 30 minutes have that data pre-built into their platform. Teams that don't are still piecing it together at hour three. Protect your supply chain with Cloudsmith.

Public mTLS client-auth certificates stop renewing in October

Chrome’s root program decides what certificates will be trusted by Chrome, and what they are allowed to do. Recently, Google decided that client authentication isn’t on the list. Under Chrome Root Program Policy v1.8, every certificate issued on or after March 15, 2027 can assert only one Extended Key Usage (EKU): server authentication. Let’s Encrypt moved early.

Why Written AI Policies Alone Won't Protect Your Organization

Most organizations have responded to the rapid growth of AI by creating written policies that define acceptable use. A clear AI policy can establish expectations, assign responsibilities, and help employees understand how AI should and shouldn’t be used. But policy alone can’t provide oversight and is almost impossible to enforce at scale without the right tools.

Why We Built Kepler: One Engineer's Frustration With Fifteen Open Terminals

We didn’t set out to build a new category of product. We set out to stop juggling. That’s the word Gyo, the senior engineer who built the first version of Kepler, keeps coming back to when he talks about where it started. “I have a lot of terminals opened, and with all those tabs, it was very difficult for me to keep focused on what I was doing,” he says. “I’m not a juggler.”

Your Production System Is Now in Your Pocket | Harness Blog

In April, Harness announced the Harness Cursor Plugin, a native integration that lets developers manage CI/CD pipelines, deployments, and security posture using natural language inside Cursor, governed by the same RBAC, OPA policies, and audit trails already enforced across the Harness platform. That experience has, until now, lived entirely at a desk.

Ubuntu's virtualization hardware enablement (HWE) stack: a new model for confidential computing enablement

Confidential computing is moving quickly. The foundation is already here: AMD SEV-SNP and Intel TDX have made it possible to run confidential virtual machines (VMs) with stronger protection for data in use. Ubuntu 26.04 Long Term Support (LTS) brings integrated host and guest support for both of these technologies, making confidential computing a native part of the Ubuntu virtualization offering..