# Amazon S3 Files, Malicious npm Plugins, Trivy Fallout, and Kubernetes’ Gateway Shift Page: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift Text version: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift.md Podcast: [Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News](https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275) Published: 2026-04-10T04:00:00+00:00 Episode link: https://rss.com/podcasts/ship-it-weekly/2710524 Audio file: https://content.rss.com/episodes/356364/2710524/ship-it-weekly/2026_04_08_19_26_01_5b77e7ff-1445-45e0-bd83-7d45363c9449.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift Duration seconds: 904 ## Resource This episode of Ship It Weekly is about the interface layer becoming the story. Brian covers Amazon S3 Files and why it feels more like a managed filesystem layer in front of S3 than “S3 is EFS now,” including how it relates to the old s3fs and FUSE-style approach. He also digs into 36 malicious npm packages posing as Strapi plugins, the uglier follow-on to the Trivy incident he discussed previously, Kubernetes Ingress2Gateway 1.0 and the push toward Gateway API, and Kubernetes Agent Sandbox as a sign that newer AI-style workloads are starting to reshape the platform itself. Links Amazon S3 Files https://aws.amazon.com/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems/ Malicious npm packages posing as Strapi plugins https://thehackernews.com/2026/04/36-malicious-npm-packages-exploited.html Trivy follow-on incident discussion https://github.com/aquasecurity/trivy/discussions/10425 RoseSecurity on Trivy / typosquatting angle https://rosesecurity.dev/2026/03/20/typosquatting-trivy.html Earlier episode covering the first Trivy incident https://www.tellerstech.com/ship-it-weekly/aws-bahrain-uae-data-center-issues-amid-iran-strikes-argocd-vs-flux-gitops-failures-github-actions-hackerbot-claw-attacks-trivy-roguepilot-codespaces-prompt-injection-block-ai-remake/ Kubernetes Ingress2Gateway 1.0 https://kubernetes.io/blog/2026/03/20/ingress2gateway-1-0-release/ Kubernetes Agent Sandbox https://kubernetes.io/blog/2026/03/20/running-agents-on-kubernetes-with-agent-sandbox/ Fortinet FortiClient EMS emergency patch https://www.fortiguard.com/psirt/FG-IR-26-099 Karpathy post https://x.com/karpathy/status/2036487306585268612 ProofShot https://github.com/AmElmo/proofshot More episodes and show notes https://shipitweekly.fm On Call Briefs https://oncallbrief.com ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/amazon-s3-files-malicious-npm-plugins-trivy-fallout-and-kubernetes-gateway-shift.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.