DiscoverShip It Weekly - DevOps, SRE, and Platform Engineering NewsKubernetes Config Reality Check, EKS Control Planes, and GitHub Guardrails
Kubernetes Config Reality Check, EKS Control Planes, and GitHub Guardrails

Kubernetes Config Reality Check, EKS Control Planes, and GitHub Guardrails

Update: 2025-11-26
Share

Description

In this episode of Ship It Weekly, Brian digs into what’s new for people actually running infra: Kubernetes config, EKS control planes and networking, and GitHub’s latest CI/CD and Copilot updates.

We start with Kubernetes’ new configuration good practices post and how to turn it into a checklist to clean up Helm/Kustomize and kill off “hotfix from my laptop” manifests.

Then we hit AWS: EKS Provisioned Control Plane to size control plane capacity for big or noisy clusters, plus new network observability so you can see who’s talking to what across clusters and AZs instead of guessing from node metrics.

On the GitHub side, Actions OIDC tokens now include a check_run_id for tighter access control, and Copilot adds instructions files and custom agents so you can encode platform and security expectations directly into reviews and workflows.

In the lightning round, we touch on Terrascan being archived, Microsoft’s write-up of a 15.72 Tbps Aisuru DDoS attack against Azure, and AWS flat-rate CloudFront plans that bundle CDN and security into more predictable pricing.

We close with Lorin Hochstein’s “Two thought experiments” and what it looks like to write incident reports as if an AI (and your future teammates) will rely on them to debug the next outage.

If run Kubernetes in prod this one should give you a few concrete ideas for your roadmap.

Links from episode

https://kubernetes.io/blog/2025/11/25/configuration-good-practices/

https://aws.amazon.com/about-aws/whats-new/2025/11/amazon-eks-provisioned-control-plane/

https://aws.amazon.com/blogs/aws/monitor-network-performance-and-traffic-across-your-eks-clusters-with-container-network-observability/

https://github.blog/changelog/2025-11-13-github-actions-oidc-token-claims-now-include-check_run_id/

https://github.blog/ai-and-ml/unlocking-the-full-power-of-copilot-code-review-master-your-instructions-files/

https://docs.github.com/en/copilot/how-tos/use-copilot-agents/coding-agent/create-custom-agents

Lightning Round

https://github.com/tenable/terrascan

https://www.bleepingcomputer.com/news/microsoft/microsoft-aisuru-botnet-used-500-000-ips-in-15-tbps-azure-ddos-attack/

https://aws.amazon.com/about-aws/whats-new/2025/11/aws-flat-rate-pricing-plans/

https://sreweekly.com/sre-weekly-issue-498/ (Lorin's Article)

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Kubernetes Config Reality Check, EKS Control Planes, and GitHub Guardrails

Kubernetes Config Reality Check, EKS Control Planes, and GitHub Guardrails