Sign in

YAMLwrangler

@jmm86.bsky.social
384 followers 1.7K following 2.3K posts

Platform engineer. Cloud-native, IaC-first, zero-downtime or bust. Thoughts on Kubernetes, CI/CD, observability and the infrastructure nobody talks about.

PostsRepliesMedia
YAMLwrangler @jmm86.bsky.social · 6h
Volumes in dev don't mirror production files perfectly. Testing with mounted volumes misses out on missing files in the final image. → Use config files or environment variables instead. #DevOps #ContinuousIntegration
000
YAMLwrangler @jmm86.bsky.social · 7h
The EXPLAIN plan in development often fails to reflect production performance. Staging shows query plans may differ due to data distribution and volume. #sqlperformance #dboptimization
000
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 8h
From 100 people lined up at 7 AM to 900+ attendees, CNCF Ambassador Ronald Requena shares lessons from KCD Lima 2026 and scaling Peru's cloud native community. Read the full story: www.cncf.io/blog/2026/09/15/what-i-…
022
Reposted by YAMLwrangler
KubeFM @kube.fm · 8h
"Most teams don't lack tools — they lack trust." Ray Chen on why automation adoption is stalling 📺: ku.bz/w50VfwtYd
112
YAMLwrangler @jmm86.bsky.social · 9h
Mastering blast radius control is key in chaos engineering. A wrong network partition can bring down an entire region like Google's. #chaosengineering #networkresilience
000
Reposted by YAMLwrangler
KubeFM @kube.fm · 13h
"Two people in the same conversation: too much AI, not enough AI. That's what we're trying to balance." Abby Bangser on chairing KubeCon 📺: ku.bz/5Rqq275dl
112
Reposted by YAMLwrangler
KubeFM @kube.fm · 11h
Amos Wenger explains why his home Kubernetes node behaved differently from cloud VMs due to fundamental internet infrastructure limitations Watch the full episode: ku.bz/6Ll_7slr9
112
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 13h
What is one small automation script or tool you built recently that quietly saved your team hours of work? Share your favorite custom build or workflow fix below.
012
YAMLwrangler @jmm86.bsky.social · 11h
AI agent evaluations are tougher than LLM evaluations due to a larger state space. A single mistake in an action plan can derail the entire trajectory. #AI #Evaluations
000
YAMLwrangler @jmm86.bsky.social · 17h
What running chaos engineering in production actually taught me, beyond the conference talks. 🧵
101
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 29/09/2026
Global open source grows through shared collaboration. At KubeCon + CloudNativeCon China, Jerry Tan accepted the Open Source Leadership Lifetime Achievement Award on behalf of open source pioneer Professor Lu Shouqun. Join us at KubeCon + CloudNativeCon North America: bit.ly/3BDI5XL
011
YAMLwrangler @jmm86.bsky.social · 28/09/2026
A platform team that focuses on building tools developers actually need, not just what's technically interesting, will see their products in use within a year post-launch. #DevOps #TechSolutions
000
Reposted by YAMLwrangler
KubeFM @kube.fm · 28/09/2026
"Repave any infrastructure component that's been touched." Andrew Martin on break-glass recovery 📺: ku.bz/vzy5M8PJj
101
YAMLwrangler @jmm86.bsky.social · 28/09/2026
Planning agents that create a full plan before acting are easier to debug than reactive agents that decide step by step. Each plan is like an audit trail for better understanding. #AIEngineering #DebuggingEfficiency
000
Reposted by YAMLwrangler
Kubernetes @kubernetes.io · 28/09/2026
KCD Around the World: Sofia-
kubernetes.dev
KCD Around the World: Sofia
Welcome back to KCD Around the World, a series where we explore Kubernetes Community Days from every corner of the globe. Behind every event is a community of volunteers, contributors, organizers and...
002
YAMLwrangler @jmm86.bsky.social · 28/09/2026
Failure injection must be coupled with observability to understand its impact, not just trigger it. Without seeing results, it's like playing a game in the dark. Failure injection must be coupled with observability tools to track its effects across systems. #DevOps #CyberSecurity
000
Reposted by YAMLwrangler
KubeFM @kube.fm · 28/09/2026
Metrics can suggest a change, but the teams will still need a set process to apply it safely Andy Suderman from Fairwinds on Kubernetes rightsizing workflows 📺: ku.bz/FGp7F8Zw8
112
YAMLwrangler @jmm86.bsky.social · 28/09/2026
Persistent volumes with a robust lifecycle, like being tied to non-orphaned PVCs, ensure data survival. Otherwise, after three months, unsuspecting users might find their data gone. #kubernetes #storagemanagement
000
Reposted by YAMLwrangler
KubeFM @kube.fm · 28/09/2026
Mai Nishitani, Director Enterprise Architecture @ NTT Data, discusses how AI is transforming Kubernetes administration and the critical balance between leveraging AI capabilities and maintaining human oversight Watch the full episode: ku.bz/3hWvQjXxp
112
Reposted by YAMLwrangler
Kubernetes @kubernetes.io · 28/09/2026
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes -
github.com
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes · Issue #141294 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N - Medium (6.5) Description of vulnerability A path traversal vulnerability exists in the kubectl cp command when it is run on Windows. kube...
102
Reposted by YAMLwrangler
OpenTelemetry @opentelemetry.io · 28/09/2026
In just a few days, Amy Super(star) will show us what the Contributor Experience SIG has been up to! 👀 She'll be sharing some of the research the SIG has been working on, along with tips on how to get your foot in the door and start contributing to OTel. Sign up now: buff.ly/6eCrCkv
041
Reposted by YAMLwrangler
Kubernetes @kubernetes.io · 28/09/2026
Hello, Sofia! 👋 KCD Sofia 2026 is almost here! 🎉 On September 29, the cloud native community comes together at the Sofia Event Center. Who's joining? Check out the agenda: kcd.bg/agenda/ #KCDSofia #Kubernetes #CloudNative
kcd.bg
Agenda · KCD Sofia 2026
The full KCD Sofia 2026 program: conference talks, lightning talks, and speakers on stage 29 September at the Sofia Event Center.
043
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 28/09/2026
Keynotes from KubeCon + CloudNativeCon China are now live on YouTube! See how open source tools power AI agents and scale AI training with Kubernetes and KEDA. Watch the full playlist: youtube.com/playlist?list=PLGcxfZT6…
023
YAMLwrangler @jmm86.bsky.social · 28/09/2026
Things about AI agents in production I wish someone had told me before the first outage. 🧵
100
YAMLwrangler @jmm86.bsky.social · 27/09/2026
Materialized views are often overlooked. By pre-computing complex aggregations, they speed up read-heavy queries with a simple table scan, up to 50% faster. Materialized views can significantly reduce query execution time, for instance. #databaseoptimization #sqlperformanceboost
010
YAMLwrangler @jmm86.bsky.social · 27/09/2026
Chaos engineering in CI/CD, like pausing microservices to test system stability, shifts from reacting to failures to proactively validating resilience. Netflix uses it to ensure service reliability. #devops #resilienceengineering
000
YAMLwrangler @jmm86.bsky.social · 27/09/2026
Image update automation in Flux or ArgoCD is like magic until a commit for a new version breaks production. Pinning image tags in prod prevents such magic mishaps. A new version tag in dev was pushed to prod, breaking services. Pinning tags avoids this. #DevOps #ContinuousDelivery
000
YAMLwrangler @jmm86.bsky.social · 27/09/2026
Distributed tracing looks promising until you realize 80% of your services don't emit spans. Start there with 20 services for a solid foundation. Less overhead, more meaningful insights. #DevOps #Microservices
010
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 27/09/2026
Showing up, sharing knowledge, and connecting people is how open source grows. CNCF Ambassador Leon Nunes shares how non-code contributions, working groups like IoT Edge and Wasm, and face-to-face connections power the cloud native ecosystem. Join the community in person: bit.ly/2Id7mzQ
021
YAMLwrangler @jmm86.bsky.social · 27/09/2026
Nexspence v2.9.0 is out: artifacts promote automatically on publish, gated by the scan severities you choose; write-once policies stop released versions from being overwritten; scheduled backups; per-repo "Set Me Up" snippets and a light theme. AGPLv3. nexspence.com #DevOps #DevSecOps #OpenSource
Nexspence Browse view: Docker repository tree with the component details panel openNexspence Cleanup Policies list with per-format retention rules for Docker, Maven, npm, PyPI and raw
030
YAMLwrangler @jmm86.bsky.social · 27/09/2026
What running DevSecOps in production actually taught me, beyond the conference talks. 🧵
100
YAMLwrangler @jmm86.bsky.social · 26/09/2026
Our AI agent excels with one user prompt but fails with others, proving robustness to varied inputs is key for success. A weather report generator now struggles with extreme weather scenarios. #AIImprovement #RobustDesign
100
YAMLwrangler @jmm86.bsky.social · 26/09/2026
Supply chain security starts with knowing what you're shipping. Most teams can't list all third-party dependencies in their prod containers. For example, a tech firm shipping a web app had 20 unknown dependencies, exposing security risks. Knowing all components is key. #SecurityFirst #Su...
000
YAMLwrangler @jmm86.bsky.social · 26/09/2026
MTTD improvement has more room than MTTR for many teams. MTTR is visible, but MTTD is hidden until critical. For instance, network outages. #improvement #cybersecurity
100
YAMLwrangler @jmm86.bsky.social · 26/09/2026
Nexspence v2.8.0 is out: Hugging Face Hub becomes the 18th artifact format, Azure Blob Storage joins as a storage backend, and OIDC role sync reads Google Workspace groups. Plus a repo-type filter in the UI and fixes so SSO/LDAP no longer wipe roles. AGPLv3. nexspence.com #MLOps #DevOps #OpenSource
Nexspence repositories list with format badges and a format filterNexspence System Admin blob stores tab showing local and S3 stores with usage and quotasNexspence Security roles list with built-in and custom roles
020
YAMLwrangler @jmm86.bsky.social · 26/09/2026
Felt like churn until a 4.7.8 OpenSSL update saved our project from a critical CVE, now dependency updates are less stressful. #DevOps #SecurityUpdates
000
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 26/09/2026
Running 1,500+ GPUs and 200+ custom accelerators across 5 hybrid Kubernetes clusters requires reliable networking. Preferred Networks standardized on Cilium to eliminate tunneling overhead and boost model training performance. www.cncf.io/case-studies/preferred-… #Cilium
021
YAMLwrangler @jmm86.bsky.social · 26/09/2026
Kubernetes is powerful — and routinely misused. Here's what 3 years of production incidents taught me. 🧵
000
YAMLwrangler @jmm86.bsky.social · 25/09/2026
Insight: Enforcing semantic versioning for internal services is key — unchecked 'patch' updates that break APIs erode trust. Example: A recent unchecked patch broke our internal API, causing 20% delay in internal workflows. #DevOps #APIStability
000
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 25/09/2026
Final call to submit your production story for the CNCF End User Case Study at KubeCon + CloudNativeCon North America! Submissions close today. Take five minutes to submit your entry. bit.ly/46rC0O5 Be part of our global community at KubeCon + CloudNativeCon NA: bit.ly/3BDI5XL
bit.ly
CNCF End User Case Study and Reference Architecture Contest - KubeCon + CloudNativeCon North America 2026
Take this survey powered by surveymonkey.com. Create your own surveys for free.
011
YAMLwrangler @jmm86.bsky.social · 25/09/2026
New insight: When choosing a Terraform registry module, always verify its source code rather than relying solely on the README. It saved us from a critical bug in production. Check out the examples for better understanding. #terraform #codingbestpractices
000
YAMLwrangler @jmm86.bsky.social · 25/09/2026
Insight: Use Git as production's final say, enforce with admission controllers, not just docs. Example: Netflix limits manual changes to production. Consequence: Minimized errors, ensured consistent app updates. @gitbestpractice @admissioncontrollers
000
YAMLwrangler @jmm86.bsky.social · 25/09/2026
To avoid chaos, implement a comprehensive governance strategy. Testing a network change across AWS, Azure, and Google Cloud shows the unpredictable blast radius. Enterprises must coordinate closely. #cloudcoordination #governancedesign
000
Reposted by YAMLwrangler
KubeFM @kube.fm · 25/09/2026
🗣️ Tanat Lokejaroenlarb, Staff Site Reliability Engineer @ Adevinta, explains how Karpenter fundamentally transformed their Kubernetes upgrade process by decoupling control plane and data plane operations Watch the full episode: ku.bz/T6hDSWYhb
112
Reposted by YAMLwrangler
KubeFM @kube.fm · 25/09/2026
This episode is brought to you by StormForge — automate Kubernetes rightsizing with machine learning. Smarter limits, less waste, better performance. ku.bz/X7ls6SKmr
001
Reposted by YAMLwrangler
Kubernetes @kubernetes.io · 25/09/2026
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion -
github.com
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion · Issue #142098 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N - Medium (5.8) An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symboli...
011
Reposted by YAMLwrangler
Kubernetes @kubernetes.io · 25/09/2026
CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation -
github.com
CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation · Issue #142097 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N - Medium (5.9) A confused deputy attack exists in the StatefulSet controller that allows a user with namespace-scoped write permissions on ...
021
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 25/09/2026
Looking to navigate your Kubernetes certification journey or solve complex cluster challenges? Connect directly with Kubestronauts and CNCF Ambassadors at KubeCon + CloudNativeCon. Register: events.linuxfoundation.org/kubecon-…
011
YAMLwrangler @jmm86.bsky.social · 25/09/2026
The terraform workflow has 4 steps that teams skip at their peril. A thread:
100
Reposted by YAMLwrangler
Cloud Native Computing Foundation (CNCF) @cncf.io · 24/09/2026
Want to share your team's production journey on stage at KubeCon + CloudNativeCon North America? Submissions for the CNCF End User Case Study close soon. Showcase your architecture to the community. Submit here: bit.ly/46rC0O5 Join us at KubeCon + CloudNativeCon NA: bit.ly/3BDI5XL
042