Microsoft made Azure Container Apps Express generally available on a sandbox layer that starts isolated microVMs from prewarmed pools in under a second. The agent-oriented engineering sits in that layer, while Express on top keeps a narrow slice of Container Apps features.
Reality
- Evidence55
- Adoption30
- Hype gap+15
- Incentives55
- Confidence60
containerd's September 1 advisory says a container restored from an untrusted checkpoint can run as root with full capabilities despite a restrictive Pod spec. Admission approves the spec, and restore then replays saved state without the step that turns a spec into kernel settings.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
Google says GKE Pod snapshots, which restore saved CPU and GPU memory, cut startup latency by up to 89% and load a 70B model in 37 seconds. When a snapshot stops matching its node, the Pod starts cold with no error, so teams must keep snapshots valid across upgrades.
Reality
- Evidence55
- Adoption25
- Hype gap+20
- Incentives65
- Confidence55
Justin O'Leary's ConfigConfusion technique turns on the fact that Google's Config Connector makes every cloud call with its own service account, so a tenant who can create one IAMPolicyMember inherits whatever that account is allowed to grant.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence58
The scanner covers 20 classes of idle resource, prices each finding from the Cloud Billing Catalog API, and generates its read-only role from what every check declares. The walkthrough stops before a priced finding prints.
Reality
- Evidence58
- Adoption15
- Hype gap−12
- Incentives60
- Confidence50
Google's final report on the August 20 incident traces more than two dozen degraded products back to lost capacity on the links between data centers inside us-west1, after automated rerouting failed to move the traffic.
Reality
- Evidence58
- Adoption38
- Hype gap+15
- Incentives70
- Confidence55
Google's report on the 1 September us-central1 outage describes a 4-hour-11-minute failure that started when higher-density transceivers met fabric ends still running the old optics. Technicians fixed it by putting the original parts back.
Publishers:status.cloud.google.com
Reality
- Evidence66
- Adoption55
- Hype gap+14
- Incentives78
- Confidence64
A dev.to walkthrough of a 600GB NVFP4 model on discounted 8xH100 spot nodes traces the two crashes that arrive before the first prompt to a pip resolver replacing numpy and a KV cache sized for a million tokens.
Reality
- Evidence26
- Adoption14
- Hype gap+34
- Incentives
- Insufficient
- Confidence28
Replica count, pod size and node count each have one tool that can move them. A dev.to guide to HPA, VPA, KEDA and Karpenter puts the usual production autoscaling failures at the boundaries between those three levels.
Reality
- Evidence50
- Adoption30
- Hype gap+18
- Incentives35
- Confidence55
Cilium 1.19 puts routing, mTLS and observability in one eBPF program per node, with a single Envoy per node for Layer 7. The 100 GB of RAM the post says that frees assumes 1,000 pods at the top of the sidecar range.
Reality
- Evidence24
- Adoption38
- Hype gap+45
- Incentives
- Insufficient
- Confidence34
Kubernetes 1.37 shipped on 26 August 2026 with the containerd CRI fallback still working, because a pull request merged three months earlier moved the removal to 1.38. Two of the guides link to that pull request.
Reality
- Evidence52
- Adoption18
- Hype gap+30
- Incentives55
- Confidence45
Tunable CrashLoopBackOff is now GA on GKE, with a per-node-pool maximum restart period anywhere from 1 to 300 seconds. It retires the privileged DaemonSets teams were using to rewrite kubelet config on accelerator nodes.
Reality
- Evidence48
- Adoption18
- Hype gap+18
- Incentives78
- Confidence44
Vertical autoscaling decisions now persist as KCP_VPA control plane logs with a state and a reason on every entry. That's the record a platform team needs the morning after an overnight resize. It also bills per VPA object per minute.
Reality
- Evidence58
- Adoption12
- Hype gap+22
- Incentives82
- Confidence57
The CPU you used to pin permanently for class loading and JIT is now a boost a webhook injects at admission and the VPA updater takes back in place. Scheduling still sizes on the boosted number, so the packing math changes twice.
Reality
- Evidence46
- Adoption18
- Hype gap+34
- Incentives80
- Confidence44
Google's preview cluster-scoped policy gives platform teams a rule namespace owners cannot override. What it does not give them is a cluster that denies by default.
Reality
- Evidence54
- Adoption18
- Hype gap+24
- Incentives74
- Confidence44
The chart was identical on EKS, AKS and GKE. Only GKE's nodes had cgroup v2, and the JVM inside sized its heap from the host's memory instead of the container's.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+20
- Incentives32
- Confidence48
Google's new passthrough repository mode keeps no image copy, so every pull goes live to JFrog. That shifts the provenance boundary and parks a registry credential in Secret Manager.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+32
- Incentives88
- Confidence44