
Hey {{first name | there}}. GitHub is reworking its storage after a surge in AI agent traffic exposed problems with the old design. Meanwhile, IBM and Red Hat have uncovered more than 400 previously unknown Java vulnerabilities, and AI is making it cheaper to find bugs that might have gone unnoticed for years.
Plenty is happening across infrastructure and security this week. Here’s what caught our attention.
In today’s roundup:
GitHub rebuilds its Git storage after agent traffic broke the old design
Copilot starts running locally, but what still goes to the cloud?
AWS open-sources Strands Box to limit what AI agents can do
OpenTelemetry’s Kubernetes processor goes stable, with some changes to watch for
IBM and Red Hat uncover 400+ previously unknown Java vulnerabilities
LATEST DEVELOPMENT
🧠TOGETHER WITH SPACELIFT
AWS, Spacelift, and Checkout.com are hosting Day of Containers!
A half-day event designed to advance your IaC practice and foster collaboration with other practitioners.
Hari Charan Ayada from AWS is speaking, so is Ovidiu Moise, along with our very own CNCF Ambassador Emin Alemdar, is running the workshops, which I already know are going to be good.
The talk I'm most excited about 👇🏾
Abdu Odhav from Checkout.com is doing a session on guardrails, and I can't wait for this one.
Checkout.com runs 35+ Spacelift instances so their product teams can spin up and manage their own infrastructure (EKS, AKS, ECS, even containers on Lambda) without sitting around waiting on a central platform team.
If you've ever been stuck in that queue, or been the team everyone's queuing for, you'll get why I'm excited.
And yes, you know Spacelift and me. I've been using it since 2022 and written 20+ articles for their blog 😅
It's completely free, but spots are limited, so grab yours before they go:
Besides the talks, it's a really nice chance to meet other engineers and swap war stories.
If you come, please find me and say hi. I'd genuinely love to meet you in person.
Divine
The Rollout: GitHub is rebuilding its Git storage architecture from scratch, driven by the surge in AI agent traffic. Early internal tests show a 35x write improvement. The redesign decouples writes from reads, offloads maintenance, and lets object storage handle redundancy, without changing developer workflows.
The details:
The numbers behind it are steep. GitHub traffic doubled from 218 billion monthly events in September 2025 to 473 billion a year later, and September commits hit 7.38 billion, 5x the year before.
The old architecture, Spokes, used a three-phase commit storing full repo copies across local disks, so every push was bounded by the slowest replica needed for quorum.
The new design writes each commit once to Azure Blob Storage, which handles replication itself, and splits read requests onto lightweight workers. Reads and writes only coordinate over branch pointers.
Why this matters: This is the fix for the reliability problems that hit GitHub through the spring, April alone had ten performance incidents, caused by agent-driven traffic the original design never anticipated. GitHub is not alone: Cursor and a former GitHub CEO's new service reworked Git storage for the same reason. No migration timeline was given.
The Rollout: AWS has introduced Strands Box, an open-source sandbox for AI agents that lets developers restrict an agent's actions based on its earlier behavior. Released in developer preview on October 7 under Apache 2.0, it pairs OS-level isolation with policies, and currently runs only on Apple Silicon Macs on macOS 15 or later.
The details:
It uses Dogwood, an AWS policy language, whose engine weighs an agent's recorded activity across tools. A file read through a shell command can, for instance, tighten restrictions on later network requests.
It checks actions routed through its shell and Python interpreters and its MCP broker. The network gateway can attach credentials to approved requests without exposing the secrets to the agent.
The gaps are acknowledged. Files touched through an agent harness's own built-in tools skip Dogwood's engine, and the shell and Python interpreters run outside the sandbox as trusted processes.
Why this matters: The idea is behavioral control that sits outside any one agent framework, so security teams can enforce the same rules everywhere. Analysts note the underlying tech is not new and the value is consistency, not novelty. It also does not replace IAM, monitoring, or human oversight, since it cannot stop a harmful decision an agent makes within its allowed permissions.
The Rollout: OpenTelemetry has promoted its Kubernetes Attributes Processor to v1.0.0, the component that tags logs, metrics, and traces with Kubernetes metadata like pods, namespaces, and nodes. Reaching stable means it now meets OpenTelemetry's requirements for testing, benchmarking, documentation, and API stability for teams redistributing it.
The details:
It is stable for logs, metrics, and traces, with profiles still in development. Hitting stable also meant stabilizing the Kubernetes semantic conventions the processor depends on, which reached stable in June.
The upgrade is not fully backwards compatible. Several attribute names change, container.image.tag becomes container.image.tags, and label and annotation attributes move from plural to singular forms.
Dashboards, alerts, recording rules, and queries referencing the old names may break. Feature gates let you emit both old and new conventions during the migration.
Why this matters: For teams standardizing on OpenTelemetry, stable means safe to build on, but the schema changes make this more than a version bump. Anything referencing the old attribute names needs updating, so plan the migration rather than just upgrading the Collector.
🧠PRESENTED BY EVERYTHINGDEVOPS
Some tech skills are much harder to turn into a job than people realise.
So we ranked the most common beginner skills from S tier to F tier based on four things: how quickly you can become useful, how high the earning ceiling is, how exposed the skill is to AI, and where it can take you next.
If you're starting from zero in 2026, this should help you decide what to learn first.
Subscribe: @EverythingDevOpsHQ for deeper dives on agents, Kubernetes, MLOps, and AI infrastructure.
The Rollout: GitHub Copilot will soon decide on its own whether a coding task runs on a local model or gets sent to the cloud, with automatic routing expected by the end of October. Microsoft outlined the plan alongside making its new sandboxing controls generally available.
The details:
The open question is data. Microsoft has not said how much repository context or conversation history Auto sends to the cloud, whether developers can inspect the routing decisions, or whether inference can be locked to local only.
Picking a local model keeps inference on-device but does not stop the agent from reaching external services through its tools, so a truly offline session also means locking down what those tools can access.
Sandbox coverage is uneven. Shell commands and local MCP servers get OS-level restrictions, while built-in file tools rely on harness checks, and remote MCP servers sit outside the sandbox entirely.
Why this matters: For teams with strict data-handling rules, "local inference" sounds like data stays put, but as Microsoft itself notes, a local session is not an offline one. Without visibility into what Auto routes to the cloud, those teams cannot actually verify where their code goes.
The Rollout: IBM and Red Hat say they have identified and fixed more than 400 previously unknown vulnerabilities in Java libraries since launching their Lightwell initiative this year. They also made Lightwell Clearinghouse generally available, letting teams submit specific open-source dependencies for priority review and remediation.
The details:
Red Hat says the 400 figure is twice what they expected, and more will surface as AI tools analyze more legacy code. They expect similar counts in libraries written in other languages.
Fixes developed for paying customers are contributed back upstream under responsible disclosure, and delivered as verified patches through repositories that plug into existing build and deploy workflows.
The economics have shifted. Red Hat puts the cost of discovering a vulnerability as low as $30, which they argue tilts application security further toward attackers.
Why this matters: The practical warning is about pace. If AI is surfacing vulnerabilities this fast, a monthly patch cycle cannot keep up, and teams that take three months to validate a fix will fall behind. Red Hat frames continuous patching as the new baseline, which points to wider adoption of scanners and test automation.
QUICK LINKS
📅EVENTS
🇪🇺 🇬🇧Europe
Title | Date | Location |
October 19 | John McIntyre Conference Centre, The University of Edinburgh, 18 Holyrood Park Road, Edinburgh, EH16 5AY | |
October 15, 2026 | Alte Turnhalle, Holteistraße 6-9, Berlin | |
October 15, 2026 | The BALTIC, Gateshead |
🇺🇸🇨🇦North America
Title | Date | Location |
October 10, 2026 | Rafael Landívar University, Zone 16 | |
October 12–14, 2026 | New York | |
October 13 – 15, 2026 | San Francisco |
🇳🇬Africa
Title | Date | Location |
October 23–24, 2026 | Ho, Volta Region, Ghana | |
October 24 | Lagos, Nigeria |








