Join us

ContentUpdates and recent posts about IncusOS..
Link
@faun shared a link, 3 months, 2 weeks ago

How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets

Truffle Security dropped a sharp new open-source tool that digs through GitHub’s public commit history looking forzero-commit force pushes—a tactic devs use to erase mistakes, usually secrets. Problem is, they don’t go quietly. By tapping into historical GitHub PushEvents via GH Archive, the tool h..

Link
@faun shared a link, 3 months, 2 weeks ago

Zero Trust and Cloud-Native Windows

Microsoft’s moving the cheese again—this time steering Windows deep into the cloud. The old on-prem management playbook? Getting dusty. At the core:Intune, pushingZero Trustlike it means it. Identity-based access, always-on compliance, real-time config—no more trusting the device just because it’s ..

Link
@faun shared a link, 3 months, 2 weeks ago

Cloudflare and the infinite sadness of migrations

A recent Cloudflare DNS outage traced back to legacy gear tangled with global config changes. Turns out, incomplete migrations can still pack a punch. Their newer topology system does support progressive rollouts—but running it side-by-side with the old one just made the blast radius bigger. System..

Cloudflare and the infinite sadness of migrations
Link
@faun shared a link, 3 months, 2 weeks ago

Creating a GitHub App based Azure DevOps Pipelines Service Connection

Azure DevOps made it easier to link up with GitHub—no more re-installing the Azure Pipelines GitHub App to kick things off. Teams can spin up aGitHub App–based service connectiondirectly from a dummy pipeline setup. The service connection comes GitHub App–authenticated out of the gate. Super handy ..

Creating a GitHub App based Azure DevOps Pipelines Service Connection
Link
@faun shared a link, 3 months, 2 weeks ago

Beyond IAM access keys: Modern authentication approaches for AWS

AWS wants long-term IAM access keys gone. In their place:temporary creds via IAM roles,IAM Identity Center,CloudShell, andOIDC integrations. The push covers everything—CLI tools, local dev, compute, CI/CD, even old-school on-prem. The message is clear: rotate automatically, grant minimally, and sto..

Link
@faun shared a link, 3 months, 2 weeks ago

Supply chain attack compromises npm packages to spread backdoor malware

A fresh supply chain ambush—Scavenger—slipped into npm through the front door. Attackers phished maintainers of high-profile packages likeis,eslint-plugin-prettier, andsynckit, then dropped cross-platform JavaScript malware straight into the codebase. Real-time C2 channels included. They typosquatt..

Link
@faun shared a link, 3 months, 2 weeks ago

Amazon DocumentDB Serverless is now available

Amazon DocumentDB Serverless is out of preview and ready to roll. It auto-scales compute and memory usingDCUsfor MongoDB-compatible clusters. No migration needed—just upgrade your existing instance and go. Available starting in version5.0, with per-second billing based on DCU burn. What’s new:Fixed..

Link
@faun shared a link, 3 months, 2 weeks ago

From Borg to Broken: why Kubernetes 2.0 is an apology letter

Kubernetes 2.0 is kicking YAML to the curb.After years of living and breathing.yamlfiles, the project is eyeing a hard break. Maintainers haven’t said it outright, but the message is clear: YAML isn’t cutting it anymore. System shift:This could signal a real usability reboot—maybe even a less painf..

From Borg to Broken: why Kubernetes 2.0 is an apology letter
Link
@faun shared a link, 3 months, 2 weeks ago

vCluster: The Performance Paradox – How Virtual Clusters Save Millions Without Sacrificing Speed

vClustercuts Kubernetes infra costs by running virtual clusters as pods inside a shared host. No more spinning up full control planes for every tenant. Itslean Syncerfilters API traffic to keep clusters from melting down.Shared controllersand a built-insleep modekeep idle workloads quiet—and cheap...

Link
@faun shared a link, 3 months, 2 weeks ago

I've been using Talos Linux for Kubernetes, and I'll never look back

Talos Linux—an OS stripped down to the essentials and locked tighter than a production firewall—now boots cleanly as a VM onProxmox, playing nice with fullKVM/QEMUsupport. No shell, read-only filesystem, all wired forKubernetesviatalosctl. System shift:Devs are tossing old-school VM stacks for bare..

I've been using Talos Linux for Kubernetes, and I'll never look back
IncusOS, released is a lightweight Linux distribution built on Debian 13 with a focus on security, reliability, and reproducibility. It implements atomic A/B updates for safe rollbacks, UEFI Secure Boot, TPM 2.0 integration, and full-disk encryption to ensure a trusted boot process and data protection.

The system departs from traditional management models by eliminating shell access entirely. Administration occurs exclusively through authenticated APIs using TLS client certificates or OIDC. This design enforces consistency and limits attack surfaces across server fleets and virtualized environments.

IncusOS supports an online image customizer and a fully automated installation process, applying configuration at first boot. Hardware requirements align with modern systems such as Windows 11. Future updates will deliver new kernel versions, expanded configuration options, and integrations with tools like Linstor and Netbird.

By standardizing deployment and management through uniform images, IncusOS simplifies auditing, maintenance, and support for organizations operating large or distributed infrastructures.