Platform Engineering Monthly — July 2026
Welcome to the thirty-second edition of Platform Engineering Monthly. As always, if you have suggestions or ideas for the next edition, let me know!
📰 News
The call is coming from inside your pipeline: the anatomy of a Codecov attack
Another “the tool you trusted with your secrets got popped” story. If Codecov’s anywhere near your CI, you’re doing an audit today whether you planned to or not.
Cordyceps flaw pattern is more proof CI/CD is part of the attack surface
Same script, different framework. CI/CD keeps proving it’s part of your attack surface, not just plumbing.
Navigating the ingress-NGINX retirement
A real deadline, not a suggestion. If you’re still on ingress-nginx, this is the nudge you needed.
AWS will now watch Microsoft’s cloud for you
AWS Security Hub goes cross-cloud. Multi-cloud security tooling finally catching up to multi-cloud reality.
Airbus Takes Flight from AWS
A genuinely big name walking away from a hyperscaler, which is genuinely interesting. Not just a blog-post rage-quit or “I moved my personal projects off AWS and it was brilliant, you should do it for your enterprise”, this one is worth paying attention to.
Just got an AWS billing alert projecting my monthly cost at $140B
A $140 billion projected AWS bill. Yes, billion, with a B. Protect your keys, check your budgets, enjoy the schadenfreude.
How data sovereignty is changing cloud native infrastructure design
Sovereignty’s moved from a compliance checkbox to an actual architecture constraint. Plan accordingly.
Kubernetes made deploying easy. Nobody warned you about the databases.
The recurring theme: Kubernetes made deploying easy and everyone forget databases are still hard.
📚 Learning
Operating Kubernetes at scale: a few stories from running Amazon EKS
Real war stories from running EKS at scale, not the marketing version.
Understanding dynamic resource allocation in Kubernetes
A solid primer if DRA in Kubernetes is still a rumour to you rather than something you’ve actually configured.
Multi-Cluster databases on Kubernetes: Architecture and deployment
Multi-cluster databases on Kubernetes, properly architected rather than duct-taped together.
Operating OpenTelemetry at scale with OpAMP
OpenTelemetry at scale, with the OpAMP bit that actually makes fleet management bearable.
Why a five-minute sniff test is your secret supply chain defense
A five-minute sniff test that’ll catch more than most teams’ actual supply chain policy.
5 steps to build great service architecture and operational resilience
Nothing revolutionary here, just the fundamentals most outages prove nobody actually followed.
🧪 Interesting Projects
kpt, reintroduced: your toolchain for infrastructure automation
kpt gets reintroduced properly. Worth another look if you wrote it off a couple of years ago.
Google copybara: moving code between repositories
Google’s internal tool for shuffling code between repos, now something the rest of us can actually use.
I made a policy engine think it was in production
A fun writeup on tricking a policy engine into thinking it’s in prod. I think generally speaking I might start tricking more systems into “being in prod”, I wish I’d thought of this sooner.
Running a self-hosted LLM in Kubernetes with vLLM
A pretty clean walkthrough for running your own LLM on Kubernetes with vLLM.
📅 Events
PlatformEngineering.org livestream
Aug 18, 2026, online.
Testμ Conference 2026
Aug 19–21, 2026, online, free.
swampUP
Sept 1–3, 2026, New York.
SREcon26 Americas
USENIX, September 2026.
DevOpsCon New York
Incl. Platform Engineering Summit — Sept 28–Oct 2, 2026.
Open Source Summit Europe 2026
Oct 7–9, 2026, Prague.
KubeCon + CloudNativeCon North America 2026
Nov 9–12, 2026, Salt Lake City.
Have platform engineering tips to share? Reply to this email or connect with me on LinkedIn. Thanks for reading! Subscribe for free to receive new posts.

