Join us

ContentUpdates and recent posts about Sigstore..
Link
@varbear shared a link, 2 months, 3 weeks ago
FAUN.dev()

If you're a Zoomer, this one's for you: Everything Gen Z needs to know about the 2025 tech landscape

AI investment hit $1.5T in 2025. Think dot-com energy: bloated valuations, feverish M&A. Startup acquisitions shot up 13%. Deal volume? Up 115%. Hype’s worn thin. Enterprises are done lighting money on fire with flashy tools. Focus is shifting to agents - LLMs thatdothings, not justsaythings. System.. read more  

If you're a Zoomer, this one's for you: Everything Gen Z needs to know about the 2025 tech landscape
Link
@kaptain shared a link, 2 months, 3 weeks ago
FAUN.dev()

Building Production-Grade Micro services on Azure Kubernetes

A team running microservices onAzure Kubernetes Servicegave their setup a smart overhaul: critical state stayed managed inPostgreSQL, but compute and observability went DIY. The payoff? Major cost cuts. Interrupt-friendly jobs landed onspot instances, and they ditched pricey per-GB logging for a hom.. read more  

Building Production-Grade Micro services on Azure Kubernetes
Link
@kaptain shared a link, 2 months, 3 weeks ago
FAUN.dev()

Dockhand - The Ultimate Self-Hosted Docker Management Tool

Dockhand just dropped, and it's aiming straight at the bloated SaaS stack. It’s a fully self-hosted Docker management tool with zero license walls. Local or remote? Doesn’t matter. It even plays nice behind NAT using outbound WebSocket agents. You get container lifecycle controls, a visual Compose e.. read more  

Dockhand - The Ultimate Self-Hosted Docker Management Tool
Link
@kaptain shared a link, 2 months, 3 weeks ago
FAUN.dev()

What has Docker become?

Docker’s not just about containers anymore. It’s pivoting hard into AI infrastructure - with some teeth. The newModel Runner,GPU offloading, and fresh AI-native integrations with Google Cloud and Vercel show where it’s headed: less dev environment, more AI runtime engine. Under the hood, Docker drop.. read more  

Link
@kaptain shared a link, 2 months, 3 weeks ago
FAUN.dev()

v1.35: Mutable PersistentVolume Node Affinity (alpha)

Kubernetes 1.35 (alpha) cracks openPersistentVolume node affinity. You can now update it on the fly. Before, it was locked down - once set, it stayed set. That got in the way of shifting workloads when disks were upgraded or moved across zones. Now? More flexibility. Less pain... read more  

Link
@kala shared a link, 2 months, 3 weeks ago
FAUN.dev()

How to build a Frontend for LangChain Deep Agents with CopilotKit!

LangChain recently introduced Deep Agents: a new way to build structured, multi-agent systems that can plan, delegate, and reason across multiple steps. It comes with built-in planning, a filesystem for context, and subagent spawning. But connecting that agent to a real frontend is still surprisingl.. read more  

Link
@kala shared a link, 2 months, 3 weeks ago
FAUN.dev()

Don't fall into the anti-AI hype

The writer recently left their job to explore AI and programming through various projects, including creating a YouTube channel focused on these topics. They discuss how AI is changing the landscape of programming, allowing for faster, more efficient coding methods. Despite concerns about job displa.. read more  

Link
@kala shared a link, 2 months, 3 weeks ago
FAUN.dev()

How to Train an AI Agent for Command-Line Tasks with Synthetic Data and Reinforcement Learning

NVIDIA shows how to fine-tuneNemotron-Nano-9B-V2to handle new CLI tools - without touching real user data. The trick? A mix ofsynthetic data,reinforcement learning with verifiable rewards (RLVR), and their home-grown trainer stack:NeMo GymplusGRPO. The result: an LLM agent that adapts fast, plays ni.. read more  

How to Train an AI Agent for Command-Line Tasks with Synthetic Data and Reinforcement Learning
Link
@kala shared a link, 2 months, 3 weeks ago
FAUN.dev()

The Rise of GPUOps: Where Infrastructure Meets Thermodynamics

GPU demand for AI has shot up 600% since 2020. It’s outpaced the cloud abstractions devs rely on - highlighting a growing gap between slick DevOps dashboards and the gritty realities of heat, cost, and silicon. EnterGPUOps. It's not just a trend - it’s a new layer in the stack. Think observability w.. read more  

The Rise of GPUOps: Where Infrastructure Meets Thermodynamics
Link
@devopslinks shared a link, 2 months, 3 weeks ago
FAUN.dev()

How we built an AI SRE agent that investigates like a team of engineers

Datadog just droppedBits AI SRE, an autonomous agent that thinks more like an SRE than a chatbot. It doesn't just regurgitate summaries - it investigates. It builds hypotheses, tests them against telemetry, and chases down actual root causes. Older tools leaned hard on LLMs to summarize alerts. That.. read more  

How we built an AI SRE agent that investigates like a team of engineers
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.