TLDR DevOps 2024-05-06

Rust 1.78.0 🦀, DockerHub Compromise 🥷, AWS Internet Weather Map ☀️

📱
News & Trends

Dependabot on GitHub Actions and self-hosted runners is now generally available (2 minute read)

Administrators using GitHub.com accounts now have the option to activate Dependabot update jobs for their repositories and/or organizations as a GitHub Actions workflow using both hosted and self-hosted runners. Utilizing Dependabot does not contribute to GitHub Actions minutes - Dependabot usage remains free for all.

Announcing Rust 1.78.0 (3 minute read)

Rust 1.78.0 introduces a new diagnostic attribute mechanism, adjustments in handling assertions around unsafe blocks, and additional changes.
🚀
Opinions & Tutorials

How to set up dynamic secrets for Postgres using Vault and Spring Boot on Kubernetes (19 minute read)

This article provides a comprehensive guide on how to integrate a Spring Boot application with Kubernetes, Vault, and Postgres to manage dynamic credentials.

Container Runtime Interface streaming explained (8 minute read)

This blog post provides a detailed explanation of Container Runtime Interface (CRI) streaming in Kubernetes, focusing on the functionality and history of Remote Procedure Calls (RPCs).
🎁
Miscellaneous

JFrog Reveals Docker Hub Compromise Spanning Millions of Repositories (2 minute read)

Since the first half of 2021, large-scale malware campaigns have infected millions of repositories on Docker Hub. Approximately 2.8 million compromised repositories were detected containing content ranging from spam to links to more dangerous malware and phishing sites. JFrog and Docker, Inc. collaborated to remove the malicious content, which was injected into repository descriptions and documentation on Docker Hub.

Why Full Text Search Is Hard (4 minute read)

This article demonstrates some of the challenges with building full text search and the use cases that are easy to handle and those that are tricky to handle.

OpenTofu Amiable to a Terraform Reconciliation (3 minute read)

OpenTofu would be open to merging with Terraform if it were reverted back to open source. Discussions are underway between OpenTofu and IBM regarding the acquisition, suggesting potential collaboration under the Linux Foundation. IBM's plans for its acquisition of Terraform remain undecided, but early indications point towards utilizing the HashiCorp stack for a hybrid cloud offering, potentially in partnership with Red Hat's enterprise software.
⚡️
Quick Links

Introducing Premium Memory-Optimized and Premium Storage-Optimized Droplets for Faster Networking Performance (2 minute read)

DigitalOcean now offers Premium Memory-Optimized and Premium Storage-Optimized Droplets to deliver enhanced performance for memory-intensive applications and large data set applications.

AWS Introduces CloudWatch Internet Weather Map (2 minute read)

The Internet Weather Map AWS introduced within CloudWatch enables users to view a 24-hour global snapshot of internet latency and availability outages, facilitating analysis of performance and availability issues across different regions and service providers.
Get our free daily newsletter with curated tools 💻, trends 📈, and insights 💡, for DevOps Engineers 👨‍💻
Join 200,000 readers for