
Free Daily Podcast Summary
by Teller's Tech - DevOps, SRE and Cloud Podcast
Ship It Weekly is a short, practical recap of what actually matters in DevOps, SRE, cloud infrastructure, and platform engineering. Each episode, your host Brian Teller walks through the latest outages, releases, tools, and incident writeups, then translates them into “here’s what this means for your systems” instead of just reading headlines. Expect a couple of main stories with context, a quick hit of tools or releases worth bookmarking, and the occasional segment on on-call, burnout, or team culture. This isn’t a certification prep show or a lab walkthrough. It’s aimed at people who are already working in the space and want to stay sharp without scrolling status pages, cloud updates, and blogs all week. You’ll hear about things like cloud provider incidents, Kubernetes and platform trends, Terraform and infrastructure changes, and real postmortems that are actually worth your time. Most episodes are 15–30 minutes, so you can catch up on the way to work or between meetings. Every now and then there will be a “special” focused on a big outage or a specific theme, but the default format is simple: what happened, why it matters, and what you might want to do about it in your own environment. If you’re the person people DM when something is broken in prod, or you’re building the cloud and platform everyone else ships on top of, Ship It Weekly is meant to be in your rotation.
The most recent episodes — sign up to get AI-powered summaries of each one.
This week on Ship It Weekly: AWS is retiring Amazon DevOps Guru and pointing customers toward CloudWatch and the newer Amazon DevOps Agent. Kubernetes disclosed a vulnerability where StatefulSet and ControllerRevision permissions can allow cross-namespace pod creation under specific conditions. A vulnerability in Undici can let a malicious WebSocket server crash a Node.js process through compressed data. And Cloudflare launched a new CLI as AI agents grow from 25 percent to 48 percent of Wrangler usage.The bigger theme this week is how the systems around our infrastructure are changing. Managed cloud services still have lifecycles that eventually become migration work. Kubernetes authorization can depend on what controllers do with the resources users are allowed to manipulate. Applications acting as clients still process untrusted data. And infrastructure tooling is starting to treat AI agents as first-class users rather than humans who happen to automate commands.In the lightning round: another Kubernetes vulnerability affecting Windows nodes can expose NetNTLMv2 credentials through NTLM coercion. GitHub now supports custom runners for Dependabot version and security updates. And external systems like a CMDB or internal developer portal can push repository properties into GitHub while remaining the source of truth.And the human closer comes from Lorin Hochstein and SRE Weekly. Some availability risks are probably never going away. Resources are finite, networks fail, security controls can affect availability, and production systems have to change. Preventing individual failures still matters, but incident response is part of reliability engineering too. Sometimes improving reliability means getting better at handling the failures you cannot eliminate.LinksAmazon DevOps Guru End of Support - https://tsn.io/GQHN8Kubernetes CVE-2026-2270: Cross-Namespace Pod Creation - https://tsn.io/BsNs8Undici CVE-2026-85024: WebSocket Denial of Service - https://tsn.io/LncLdCloudflare: Introducing the cf CLI - https://tsn.io/Wk3maCloudflare Forge - https://tsn.io/bAPJuLightning RoundKubernetes CVE-2026-76654: Windows NTLM Coercion - https://tsn.io/36Kc3GitHub: Custom Runners for Dependabot - https://tsn.io/tYl9KGitHub: External Custom Properties - https://www.tellerstech.com/go/s-1fd1396d/Human CloserOmnipresent Availability Risks in Cloud Software - https://www.tellerstech.com/go/s-076db9dd/Our LinksThis Week’s On Call Brief - https://tsn.io/fKB9VShip It Weekly - https://tsn.io/NqkdPOn Call Brief - https://tsn.io/Gpz2d
This week on Ship It Weekly: AWS introduced Elastic Beanstalk Cluster Mode, allowing multiple applications to run on shared EKS infrastructure while AWS handles much of the Kubernetes complexity. CrowdSec published how a software supply-chain compromise led to attackers copying roughly 170 private repositories using a stolen OAuth token. A critical Next.js vulnerability in ImageResponse can lead to remote code execution through attacker-controlled SVG data. And Microsoft disrupted EvilTokens, a cybercrime platform linked to more than 12,000 compromised inboxes across 10,000 organizations.The bigger theme this week is what happens after trust has been established. Elastic Beanstalk Cluster Mode puts more infrastructure behind a managed abstraction, but shared infrastructure still means understanding isolation and blast radius. CrowdSec shows how an initial compromise can become a credential problem long after the malicious code is gone. Next.js shows how something as ordinary as generating a social preview image can expose a server-side execution path. And EvilTokens shows how attackers can use valid access to move faster once inside an account.In the lightning round: F5 has a critical BIG-IP APM vulnerability under active exploitation. GitHub Enterprise Cloud can now export an inventory of credentials with enterprise access, including PATs, SSH keys, OAuth tokens, and GitHub App credentials. Zyxel patched a vulnerability affecting GS1900 switches. And Veeam Agent for Microsoft Windows has a privilege-escalation vulnerability that can lead to SYSTEM access.And the human closer comes back to CrowdSec. Removing the malicious package, patching the server, or reimaging the workstation does not necessarily end the incident. If an attacker already stole an OAuth token, cloud credential, SSH key, session, or registry credential, that access can survive long after the original compromise is gone. Containment means understanding not only how the attacker got in, but what they took with themLinksAWS Elastic Beanstalk Cluster Modehttps://tsn.io/1xaV7CrowdSec Supply-Chain Attack Analysishttps://tsn.io/7yq2fNext.js ImageResponse Security Advisoryhttps://tsn.io/8JvHpMicrosoft: Disrupting EvilTokenshttps://tsn.io/DtbC9Microsoft: EvilTokens and Device-Code Phishinghttps://tsn.io/ZzwtDF5 BIG-IP APM CVE-2026-94127https://tsn.io/sFuKWGitHub Enterprise Credential Inventoryhttps://tsn.io/7bpMnZyxel GS1900 Security Advisoryhttps://www.tellerstech.com/go/s-b2595852/Veeam Agent for Microsoft Windows Vulnerabilityhttps://www.tellerstech.com/go/s-166d3119/This Week’s On Call Briefhttps://tsn.io/Nnd8gShip It Weeklyhttps://tsn.io/NqkdPOn Call Briefhttps://tsn.io/Gpz2d
This week on Ship It Weekly: GitHub Actions workflow execution protections are now generally available, giving organizations more control over who and what can trigger individual workflows. Cisco is patching critical vulnerabilities in Secure Email Gateway, including an actively exploited issue that can lead to remote command execution as root. Helm 3 has reached its final minor release and is heading toward end-of-life in February 2027. And GitHub’s ubuntu-latest Actions runner is preparing to move from Ubuntu 24.04 to 26.04.The bigger theme this week is infrastructure that changes even when your code does not. GitHub is making CI execution permissions more explicit, Helm teams now have a defined migration deadline, and the ubuntu-latest transition is a good example of how a completely unchanged workflow can suddenly be running in a different environment. Pinning everything forever is not necessarily the answer. The important part is knowing which dependencies are allowed to move and testing those changes deliberately.In the lightning round: GitHub Actions checks, workflow runs, and statuses will begin following your configured retention period on October 1. GitHub Advanced Security can now enforce configurations from the enterprise level. GitHub added API support for tracking when self-hosted Actions runner versions lose support. And AI Scan for pull requests can now be used without requiring CodeQL default setup.And the human closer starts with a sentence almost every infrastructure engineer has heard during an incident: “But nothing changed.” Maybe nothing changed in the application, but the runner image changed, a dependency moved, a certificate expired, DNS changed, or an external service behaved differently. Latest tags, loose version constraints, external APIs, and even support windows are dependencies. The goal is not to freeze everything forever. It is to avoid accidental mutability, where something can change without the team realizing it was ever allowed to change.LinksGitHub Actions Workflow Execution Protectionshttps://tsn.io/fbqifCisco Secure Email Gateway Security Advisoryhttps://tsn.io/jX2wkHelm 3 End of Lifehttps://tsn.io/Ii7jbUbuntu 26.04 GitHub Actions Runners and ubuntu-latest Migrationhttps://tsn.io/7IJ9kGitHub Actions Retention Changeshttps://tsn.io/idFxyGitHub Advanced Security Configuration Enforcementhttps://tsn.io/8vRMxGitHub Actions Self-Hosted Runner Lifecycle APIhttps://tsn.io/9UhY1GitHub Code Scanning AI Scanhttps://tsn.io/ULAVWThis Week’s On Call Briefhttps://www.tellerstech.com/go/26w38/Ship It Weeklyhttps://tsn.io/NqkdPOn Call Briefhttps://tsn.io/Gpz2d
This week on Ship It Weekly: Amazon Linux 2027 enters public preview with kernel 7.1+, SELinux enforcing by default, DNF5, newer language runtimes, AWS-LC, and an x86-64-v3 baseline. GitHub Actions adds explicit cache permissions to reduce cache-poisoning risk. GitHub can now block pull requests from merging when they introduce exposed secrets. And N-able N-central has a critical pre-auth RCE that Huntress says is being actively exploited in the wild. The bigger theme this week is catching problems before they turn into incidents. Amazon Linux 2027 gives teams time to test AMIs, bootstrap scripts, agents, Terraform, CloudFormation, and CI/CD before the next platform generation becomes production reality. GitHub’s new cache controls make workflow trust boundaries explicit instead of leaving them implied. And secret-scanning rulesets move credential detection directly into the merge path, where developers can actually act on it. In the lightning round: Karmada graduates from the CNCF as multi-cluster and distributed AI scheduling grow, ShieldCrash research claims another Microsoft Defender patch bypass with SYSTEM-level access, CodeQL 2.27 adds native Linux ARM64 support, and Dependabot can now read private GitHub Packages without another personal access token.And the human closer is about what happens when observability shares the same failure domain as the thing it is watching. A full disk is bad enough. It gets worse when logs stop writing, monitoring data disappears, and the tools used to diagnose the outage start failing too. The takeaway is not that every monitoring component needs total isolation. It is that you should know what can blind you, and make sure at least one useful signal survives the failures you care about most.LinksAmazon Linux 2027 Public Previewhttps://tsn.io/NHlEaAmazon Linux 2027 Overview and Preview Detailshttps://tsn.io/izDYxAmazon Linux 2027 Known Issues and Preview Limitationshttps://tsn.io/tdugdGitHub Actions Cache Permissions with cache-modehttps://tsn.io/8p94nBlock Pull Requests with Exposed Secrets from Merginghttps://tsn.io/BspA2N-able N-central 2026.3 Hotfix 4https://tsn.io/xredGHuntress: N-able N-central Vulnerability and Active Exploitationhttps://tsn.io/QjNd5Karmada Graduates from the CNCFhttps://tsn.io/lcJGhMicrosoft Defender ShieldCrash Zero-Day Researchhttps://tsn.io/YfsJ6CodeQL 2.27 Adds Linux ARM64 Supporthttps://tsn.io/lxfnFAutomatic Dependabot Access to GitHub-Hosted Registrieshttps://tsn.io/pSilAShip It Weeklyhttps://www.tellerstech.com/go/siw/On Call Briefhttps://www.tellerstech.com/go/ocb/
This week on Ship It Weekly: AWS Gateway Load Balancer gets TCP Reset, giving applications a faster way to recover when firewalls or other inline appliances fail instead of waiting minutes for TCP retries to time out. Microsoft puts Enterprise Live Migrations into public preview for moving Azure DevOps repositories to GitHub Enterprise Cloud with data residency while developers keep working. GitHub is beginning enforcement against outdated self-hosted Actions runners. And Omarchy fixes a Docker configuration that effectively gave normal desktop processes a path to root.The bigger theme this week is failure modes hiding inside infrastructure we already trust. A dead network path can look like a slow application. A repository migration involves far more than copying Git history. A self-hosted runner can quietly become unsupported while it continues looking healthy. And giving a developer access to the Docker socket may sound like convenience until you remember that the Docker group is effectively a root-level privilege.In the lightning round: Lambda gets full IAM resource-based policies, AWS warns that circular PostgreSQL role memberships can stall major RDS and Aurora upgrades, a researcher releases the FalconFlank CrowdStrike privilege-escalation PoC while CrowdStrike investigates, and SonicWall patches two SMA1000 zero-days after confirming active exploitation.LinksAWS Gateway Load Balancer TCP Resethttps://www.tellerstech.com/go/s-d7e609ab/Azure DevOps Enterprise Live Migrations Public Previewhttps://www.tellerstech.com/go/s-ea05aff9/GitHub Actions Self-Hosted Runner Minimum Version Enforcementhttps://www.tellerstech.com/go/s-6e8540c4/Omarchy: Any User Process Can Escalate to Roothttps://www.tellerstech.com/go/s-d22971c3/AWS Lambda Full IAM Resource-Based Policieshttps://www.tellerstech.com/go/s-ff2a04b5/Fix Circular Role Dependencies Before Upgrading RDS and Aurora PostgreSQLhttps://www.tellerstech.com/go/s-e4578f52/FalconFlank CrowdStrike Privilege Escalation PoChttps://www.tellerstech.com/go/s-8c21b00b/SonicWall SMA1000 Zero-Day Advisoryhttps://www.tellerstech.com/go/s-559ffc8b/Remote Incident Reviews: Async First, Live Later?https://www.tellerstech.com/go/s-68ca9f5e/This Week’s On Call Briefhttps://tsn.io/L95NSShip It Weeklyhttps://www.tellerstech.com/go/siw/On Call Briefhttps://www.tellerstech.com/go/ocb/
This week on Ship It Weekly: Cloudflare explains how five low-level optimizations to the cache behind 1.1.1.1 freed roughly 100 terabytes of RAM while also improving performance. OVHcloud is raising infrastructure prices as AI demand reshapes the memory supply chain. AWS adds a fourth Availability Zone to London, exposing automation that quietly assumed there would always be three. And Route 53 Global Resolver gets a cleaner cross-account model for DNS self-service.The bigger theme this week is assumptions. A few wasted bytes do not matter until you have 250 billion cache entries. A Region having three Availability Zones feels permanent until AWS adds a fourth. And centralized DNS governance works fine until every application team needs a networking ticket just to make a private zone resolvable.In the lightning round: new research looks at manipulating DRAM controller translation registers and the assumptions that creates for memory isolation, AKS eBPF Host Routing reaches general availability, CloudFront Functions can now put custom context directly into access logs, and Go 1.27 lands generic methods along with runtime, tooling, and standard-library improvements.And the human closer looks at an easy Kubernetes mistake: running kubectl against the wrong cluster. Because the active context belongs to the kubeconfig rather than a terminal tab, changing it in one shell can silently affect another. It is a good reminder that some friction is worth keeping around production, and that the safest guardrails live somewhere stronger than operator memory.LinksCloudflare: How We Saved 100 Terabytes of Memory by Optimizing 1.1.1.1’s DNS Cache https://www.tellerstech.com/go/s-9d6c2943/OVHcloud Raises Prices as AI Memory Demand Reprices Non-AI Infrastructure https://tsn.io/tnaYjAWS Adds a Fourth Availability Zone to Europe (London) https://tsn.io/YfGxaShared DNS Views with Amazon Route 53 Global Resolver https://tsn.io/WEyigDRAM Controller Register Manipulation Breaks CPU Memory Isolation https://tsn.io/QKr1xAKS eBPF Host Routing https://tsn.io/T3PMhCloudFront Functions Unified Logging https://tsn.io/nTXLnGo 1.27 https://tsn.io/vfXITkubectl Ran on the Wrong Cluster? Fix Your Context Switching https://tsn.io/6LxfGThis Week’s On Call Brief https://tsn.io/064QEShip It Weekly https://www.tellerstech.com/go/siw/On Call Brief https://www.tellerstech.com/go/ocb/
This is a guest conversation episode of Ship It Weekly, separate from the weekly news recaps.In this Ship It Conversations episode, I talk with Justin Garrison of Sidero Labs about Kubernetes, platform engineering, bare metal, AI, golden paths, and why knowing what to say no to may be one of the most important skills a platform team can develop.Justin is Field CTO at Sidero Labs, the company behind Talos Linux, and co-host of Fork Around and Find Out.We start with the evolution of Kubernetes and how managed services like EKS and GKE made Kubernetes easier to consume while also pulling teams deeper into proprietary cloud ecosystems. Justin explains why on-prem and bare metal are getting renewed attention, especially as teams look at cloud costs, data sovereignty, and the operational overhead that comes with constantly optimizing cloud environments.We also get into where Kubernetes helps and where it becomes self-inflicted pain. Justin talks about abstraction, cognitive load, and why teams tend to use familiar tools for problems they were never really designed to solve.A big part of the conversation is platform engineering and golden paths. Justin argues that every organization needs its own path, but platforms become dangerous when they try to centralize everything. He shares why one of the best decisions his team made at Disney Plus was simply saying no to stateful workloads.We also talk about what really belongs in a platform: security controls, logging, monitoring, software supply chain visibility, and cost management. Justin explains why centralization can help in those areas, but can become a bottleneck when applied too broadly.Near the end, we get into AI, security, tooling dependency, and engineering culture. Justin makes the point that people have always formed strong attachments to tools, and AI is another version of that. The challenge is knowing where AI actually helps versus where it becomes another dependency teams stop questioning.The big takeaway: good platform engineering is not about supporting everything. It is about understanding what should be standardized, what should stay flexible, and what your team should explicitly refuse to own.Highlights• Why Kubernetes has become increasingly productized• Why some teams are moving back toward on-prem and bare metal• Where cloud cost optimization starts to become its own operational burden• Why Kubernetes helps with abstraction and cognitive load• Why familiar tools often get used for the wrong workloads• What golden paths actually represent inside an organization• Why platform teams need to know what to say no to• What should and should not be centralized• How AI changes engineering workflows without changing the need for judgment• Why finding work you actually enjoy matters for avoiding burnoutLinksSidero Labs: https://www.siderolabs.comTalos Linux: https://www.talos.devJustin Garrison: https://justingarrison.comFork Around and Find Out: https://www.forkaroundandfindout.comMore episodes and show notes: https://shipitweekly.fmOn Call Brief: https://oncallbrief.comLMGT Awards: https://lmgt.org
This week on Ship It Weekly: GitHub suffers another widespread outage affecting the web interface, APIs, Actions, authentication, Copilot, and other critical developer workflows. Zenity Labs demonstrates PleaseFix attacks against agentic browsers, where malicious content can influence agents with access to authenticated sessions and privileged tools. AWS Certificate Manager is moving away from email validation, and Cloudflare is experimenting with CI pipelines defined as TypeScript instead of YAML.The bigger theme this week is dependencies and boundaries we tend to ignore until something breaks. GitHub is no longer just where the code lives. Agentic browsers are no longer just displaying webpages. Certificate renewal is not something you want depending on someone checking an inbox. And CI pipelines have become software systems of their own.LinksGitHub Hit by Widespread Outage https://devops.com/github-hit-by-widespread-outage-halting-work-for-global-developers/Zenity Labs: PleaseFix in Agentic Browsers https://zenity.io/company-overview/newsroom/company-news/zenity-labs-exposes-the-full-scope-of-pleasefixAWS Certificate Manager Ending Email Validation https://aws.amazon.com/blogs/security/aws-certificate-manager-will-discontinue-email-validation-to-prove-domain-validation-for-certificates/Certificate Expiry Is Still Taking Down Major Platforms https://tokentimer.ch/blog/tls-certificate-expiry-outagesCloudflare Turns CI Pipelines into TypeScript Workflows https://www.infoq.com/news/2026/08/cloudflare-ci-code-workflows/Dynatrace Acquires Arize https://devops.com/dynatrace-acquires-arize-as-ai-agents-deepen-the-observability-challenge/AWS Open-Sources Dogwood https://www.infoq.com/news/2026/08/aws-dogwood-agent-policy/Pulumi v3.258.0 https://github.com/pulumi/pulumi/releases/tag/v3.258.0AWS Key Breach and Data-Transfer Signal https://assets.theregister.com/2026/08/13/20267/Mario Saved the EU but Broke My System https://www.uptimelabs.io/articles/hamed-2012-outage-reflectionsThis week’s On Call Brief https://www.tellerstech.com/on-call-brief-news/2026-W34/Ship It Weekly https://shipitweekly.fm/
Free AI-powered daily recaps. Key takeaways, quotes, and mentions — in a 5-minute read.
Get Free Summaries →Free forever for up to 3 podcasts. No credit card required.
Listeners also like.

Latent Space: The AI Engineer Podcast
Explores AI engineering breakthroughs in foundation models, code generation, and AI agents through interviews with researchers and developers.

TechLinked
A weekly news show covering technology and gaming culture.

Lenny's Podcast: Product | Career | Growth
Conversations with top product and growth leaders offering practical strategies for building, launching, and scaling successful products.

Tech News Daily
Daily summaries of the latest developments in artificial intelligence, robotics, cybersecurity, gadgets, and apps.

Cybersecurity Today
Latest cybersecurity threats, data breaches, and practical steps to protect businesses in high-risk environments.

The Engineering Leadership Podcast
Insights and practices from top software engineering leaders to advance leadership skills in the tech industry.

Cyberside Chats: Cybersecurity Insights from the Experts
Cybersecurity experts discuss emerging threats, AI-driven attacks, and defense strategies for professionals and executives.

The Best One Yet
A daily 20-minute podcast breaking down the three key business stories with sharp, accessible takes.

Shell Game
A journalist builds a startup staffed entirely by AI to explore how artificial intelligence is reshaping work and entrepreneurship.

Daily Tech News Show
Daily tech news coverage with analysis from Tom Merritt and team.

Everyday AI Podcast – An AI and ChatGPT Podcast
Covers practical uses of AI tools like ChatGPT and Midjourney to help people work more efficiently and advance their careers.

"The Cognitive Revolution"
Explores the transformative impact of artificial intelligence through interviews with innovators shaping its future.
Ship It Weekly is a short, practical recap of what actually matters in DevOps, SRE, cloud infrastructure, and platform engineering. Each episode, your host Brian Teller walks through the latest outages, releases, tools, and incident writeups, then translates them into “here’s what this means for your systems” instead of just reading headlines. Expect a couple of main stories with context, a quick hit of tools or releases worth bookmarking, and the occasional segment on on-call, burnout, or team culture. This isn’t a certification prep show or a lab walkthrough. It’s aimed at people who are already working in the space and want to stay sharp without scrolling status pages, cloud updates, and blogs all week. You’ll hear about things like cloud provider incidents, Kubernetes and platform trends, Terraform and infrastructure changes, and real postmortems that are actually worth your time. Most episodes are 15–30 minutes, so you can catch up on the way to work or between meetings. Every now and then there will be a “special” focused on a big outage or a specific theme, but the default format is simple: what happened, why it matters, and what you might want to do about it in your own environment. If you’re the person people DM when something is broken in prod, or you’re building the cloud and platform everyone else ships on top of, Ship It Weekly is meant to be in your rotation.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Teller's Tech - DevOps, SRE and Cloud Podcast.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News publishes 2x weekly. Our AI generates a summary within hours of each new episode.
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News covers topics including News, Technology. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.