Blog

Notes from the AI DevOps team.

How a managed AI DevOps team replaces platform-engineering labor: capability tiers, approval gates, audit trails, and the economics of autonomous infrastructure.

A single git push owned every repo on GitHub Enterprise
Security

A single git push owned every repo on GitHub Enterprise

CVE-2026-3854 let any authenticated user inject internal headers via push options. One git push, RCE on the backend, access to every public and private repo on the same instance. Patch is GHES 3.19.3.

Jun 3, 2026 13 min read
Google I/O 2026: the second hyperscaler agentic-DevOps stack
Ai Tools

Google I/O 2026: the second hyperscaler agentic-DevOps stack

Google I/O shipped Antigravity 2.0, Managed Agents API, and ADK 2.0 — six weeks after AWS DevOps Agent GA. Two hyperscalers have now publicly shipped agentic-DevOps stacks. The category has crossed from research to GA-track.

May 26, 2026 13 min read
Microsoft Defender CVE pair on the KEV clock: June 3 deadline
Security

Microsoft Defender CVE pair on the KEV clock: June 3 deadline

Microsoft disclosed CVE-2026-41091 (LPE to SYSTEM via Defender's Malware Protection Engine) and CVE-2026-45498 (Defender DoS) on May 19. Both actively exploited. CISA added both to KEV with a June 3 deadline.

May 26, 2026 13 min read
When Microsoft patches their cloud side: the May 2026 Azure cluster
Security

When Microsoft patches their cloud side: the May 2026 Azure cluster

May 2026 Patch Tuesday shipped a cluster of cloud-side-remediated Azure CVEs: DevOps (CVSS 10), Cassandra (CVSS 9.9 and 9.0), Cloud Shell (CVSS 9.6). Microsoft patched all of them without customer action. What's left on the customer-obligation list?

May 26, 2026 13 min read
DevOpsCon London 2026: agentic developer platforms arrive
Devops

DevOpsCon London 2026: agentic developer platforms arrive

DevOpsCon London 2026 was the first major platform-engineering event to explicitly position agentic developer platforms as the successor to the DevOps tool stack — AI agents as first-class citizens with RBAC, quotas, and policies.

May 26, 2026 13 min read
How AI agents are changing on-call rotations
Devops

How AI agents are changing on-call rotations

PagerDuty added the SRE Agent to escalation policies this year. AWS DevOps Agent went GA. Gartner expects 70% of enterprises to run agentic IT operations by 2029. Here's what on-call looks like with an agent at the top of the tree.

May 14, 2026 12 min read
Internal developer platform security under FedRAMP and HIPAA
Compliance

Internal developer platform security under FedRAMP and HIPAA

Backstage, Port, Cortex, and Humanitec made internal developer platforms standard practice in 2026. Here's what an IDP looks like when the platform team also has to satisfy FedRAMP, HIPAA, PCI, and SOC 2.

May 14, 2026 12 min read
FOCUS 1.3 and the FinOps Foundation spec: what changes for practice
Cloud Cost

FOCUS 1.3 and the FinOps Foundation spec: what changes for practice

FOCUS 1.3 ratified December 5. Split cost allocation, contract commitments, and recency/completeness land as first-class fields across AWS, Azure, GCP, Oracle, and SaaS vendors. The 2026 conformance program turns it into a procurement criterion.

May 14, 2026 13 min read
Continuous threat modeling for platform teams in 2026
Security

Continuous threat modeling for platform teams in 2026

Threat modeling stopped being a quarterly Visio session in 2026. Post-IriusRisk acquisition, the combined platform pushes continuous AI-assisted modeling into the SDLC. Here's what that looks like for daily shippers.

May 14, 2026 11 min read
Red Hat Ansible 2.7 and the "trusted execution layer" frame
Compliance

Red Hat Ansible 2.7 and the "trusted execution layer" frame

At Red Hat Summit, Ansible repositioned as the "trusted execution layer for IT operations in an agentic era." 2.7 ships an AI-agent orchestrator, an MCP server, and BYOK on the assistant. It's the clearest public articulation of what an active operations layer actually is.

May 14, 2026 13 min read
What platform teams should take from ServiceNow + Accenture's FDE program
Compliance

What platform teams should take from ServiceNow + Accenture's FDE program

At Knowledge 2026, ServiceNow and Accenture launched a joint Forward Deployed Engineering program for agentic AI: 300+ pre-built agent skills, AI Control Tower governance, FDEs inside customer environments. It's the clearest public picture of the 2026 operating model.

May 14, 2026 13 min read
Why dashboards stopped being the answer in 2026
Devops

Why dashboards stopped being the answer in 2026

Datadog is a $40B company on passive dashboards. Wiz, Vantage, CloudHealth — same thesis. That era is ending. Agents that do the work are the next category.

Apr 25, 2026 11 min read
How to run a repository security audit
Security

How to run a repository security audit

Most teams don't know what's in their repos — leaked secrets, outdated dependencies, misconfigured CI. Here's how to run a thorough audit and fix what you find.

Apr 24, 2026 9 min read
Open-source LLM observability for self-hosted inference
Platform Engineering

Open-source LLM observability for self-hosted inference

Self-hosting vLLM or TGI on H100s? You need visibility into token economics, TTFT, quality drift, GPU utilization — and most LLM observability tools are SaaS. Here's the open-source stack.

Apr 22, 2026 11 min read
Automated SBOM generation for polyglot monorepos
Security

Automated SBOM generation for polyglot monorepos

A monorepo with Go, Python, Node, and Rust doesn't produce one SBOM. It produces four, and they don't agree. Here's the 2026 playbook for getting them aligned.

Apr 22, 2026 11 min read
Why your DevOps dashboard should talk back

10 sec

to answer

Ai Tools

Why your DevOps dashboard should talk back

Traditional dashboards show you data. An AI command center lets you ask questions, get answers, and take action — in one place.

Apr 1, 2026 6 min read

Talk to the team about your cloud

30 minutes with the team. We'll look at your cloud together, show you what we'd take off your plate, and scope a first month if it's a fit.