Key events and trends
● Karmada Achieves CNCF Graduated Project Status: Karmada, an extension of the standard Kubernetes API for orchestrating applications across multiple clusters, clouds, and regions, has officially graduated from the CNCF. Originating from Huawei and accepted into the CNCF Sandbox in September 2021, it moved to Incubating in December 2023. Adopters include Alibaba Cloud, Bloomberg, Huawei, Trip.com, Vivo, and Wellhub (источник).
● Kubernetes 1.36 Introduces Alpha Feature for Admission Policies from Disk: A new alpha feature in Kubernetes 1.36 allows loading admission policies from files on disk at startup. This ensures policies are live before other components, preventing their deletion by unauthorized parties (источник).
● Automating IAM Identity Center Governance with AWS CDK: A walkthrough details the deployment of two AWS CDK stacks to automate IAM Identity Center governance. The reporting stack (EventBridge, Step Functions, Lambda, DynamoDB, API Gateway, S3) provides daily discovery and CSV export, while a remediation stack enforces compliance with real-time, event-driven actions and SNS notifications for non-compliant application assignments (источник)

● Mercado Libre Rebuilds Observability on ClickHouse Cloud for 50x Faster Trace Queries: Mercado Libre has migrated its observability platform, O11y events, to ClickHouse Cloud. This move reduced trace query times from over five minutes to approximately four seconds (a 50x speedup) and achieved up to 89% data compression. The platform scales from 7 million spans per minute to 400 million, enabling granular business-level troubleshooting (источник).
● AWS EKS Provisioned Control Planes Ensure Cluster Capacity: Provisioned control planes on Amazon Web Services (AWS) EKS allow setting a baseline for control plane infrastructure, ensuring readiness before demand spikes. Alex Kestner highlights its importance for teams managing large node counts or busy clusters with high churn (источник)
Watch video
● SREs Discuss AI Automation for Security Incidents: An article on HackerNoon explores what SREs should and should not automate with AI. It suggests automating based on impact and recoverability. The author questions the article's premise that AI might not handle security incidents if it can manage normal ones, arguing that AI could collect data while humans retain responsibility for remediation and final decisions (источник).
● Migrating from Kubernetes Dashboard to Headlamp: An article explains the process of transitioning from the archived Kubernetes Dashboard to Headlamp, detailing how familiar workflows map to Headlamp's new UI (источник)

● Point-in-Time Recovery Challenges with Patroni Clusters: Ziv Yatzik outlines the complexity of point-in-time recovery for Patroni clusters, where each WAL file requires separate storage and continuous collection from a new primary after switchover. The proposed solution involves integrating pgBackRest directly with Patroni's archive command to avoid added complexity and database availability risks (источник).
● Upcoming Q&A on Security with Anastasia Voitova: A free online Q&A session with Anastasia Voitova, Head of Security Engineering at Cossack Labs and CISSP, is scheduled for September 15th at 19:00. Topics will include cyber threats, AI & Security, real-world cases, and Security Engineering (источник)

Final analytics
The day's news highlights significant advancements in Kubernetes ecosystem maturity and cloud security automation. The graduation of Karmada to a CNCF Graduated project underscores the growing demand for robust multi-cluster management solutions, reflecting a trend towards distributed and hybrid cloud environments. Kubernetes itself continues to evolve with new security features, such as admission policies loaded from disk, indicating a focus on strengthening the platform's core security posture.
Cloud security remains a critical area, with practical examples of automating IAM governance on AWS, showcasing proactive measures to ensure compliance and reduce operational overhead. Observability and monitoring solutions are also seeing performance gains and scaling improvements, as demonstrated by Mercado Libre's migration to ClickHouse Cloud, emphasizing the need for high-performance analytics in complex microservices architectures. The discussion around AI's role in SRE and security incidents suggests an ongoing exploration of how artificial intelligence can augment, rather than replace, human expertise in incident response and automation within DevSecOps.