{"podcast":{"title":"Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News","slug":"ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275","podcast_index_feed_id":7591275,"rss_url":"https://media.rss.com/ship-it-weekly/feed.xml","website_url":"https://www.shipitweekly.fm/","image_url":"https://media.rss.com/ship-it-weekly/20260103_010109_fc16278a46c7b2c61123ed668a34f79d.jpg","author":"Teller's Tech - DevOps, SRE and Cloud Podcast","episode_count":55,"summary":"Ship It Weekly is a short, practical recap of what actually matters in DevOps, SRE, cloud infrastructure, and platform engineering. Each episode, your host Brian Teller walks through the latest outages, releases, tools, and incident writeups, then translates them into “here’s what this means for your systems” instead of just reading headlines. Expect a couple of main stories with context, a quick hit of tools or releases worth bookmarking, and the occasional segment on on-call, burnout, or team culture. This isn’t a certification prep show or a lab walkthrough. It’s aimed at people who are already working in the space and want to stay sharp without scrolling status pages, cloud updates, and blogs all week. You’ll hear about things like cloud provider incidents, Kubernetes and platform trends, Terraform and infrastructure changes, and real postmortems that are actually worth your time. Most episodes are 15–30 minutes, so you can catch up on the way to work or between meetings. Every now and then there will be a “special” focused on a big outage or a specific theme, but the default format is simple: what happened, why it matters, and what you might want to do about it in your own en…","last_synced_at":"2026-07-19T00:20:39.423055+00:00","page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275"},"episode":{"title":"When guardrails break prod: GitHub “Too Many Requests” from legacy defenses, Kubernetes nodes/proxy GET RCE, HCP Vault resilience in an AWS regional outage, and PCI DSS scope creep","slug":"when-guardrails-break-prod-github-too-many-requests-from-legacy-defenses-kubernetes-nodes-proxy-get-rce-hcp-vault-resilience-in-an-aws-regional-outage-and-pci-dss-scope-creep","published_at":"2026-02-13T04:45:00+00:00","page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/when-guardrails-break-prod-github-too-many-requests-from-legacy-defenses-kubernetes-nodes-proxy-get-rce-hcp-vault-resilience-in-an-aws-regional-outage-and-pci-dss-scope-creep","show_page_url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275","url":"https://rss.com/podcasts/ship-it-weekly/2545647","audio_url":"https://content.rss.com/episodes/356364/2545647/ship-it-weekly/2026_02_13_03_39_51_2cc8ffa5-a6c7-4b4b-8377-d28dc07b0c69.mp3","summary":"This week on Ship It Weekly , Brian hits four stories where the guardrails become the incident. GitHub had “Too Many Requests” caused by legacy abuse protections that outlived their moment. Takeaway: controls need owners, visibility, and a retirement plan. Kubernetes has a nasty edge case where nodes/proxy GET can turn into command execution via WebSocket behavior. If you’ve ever handed out “telemetry” RBAC broadly, go audit it. HashiCorp shared how HCP Vault handled a real AWS regional disruption: control plane wobbled, Dedicated data planes kept serving. Control plane vs data plane separation paying off. AWS expanded its PCI DSS compliance package with more services and the Asia Pacific (Taipei) region. Scope changes don’t break prod today, but they turn into evidence churn later if you don’t standardize proof. Human story: “reasonable assurance” turning into busywork. Links GitHub: When protections outlive their purpose (legacy defenses + lifecycle) https://github.blog/engineering/infrastructure/when-protections-outlive-their-purpose-a-lesson-on-managing-defense-systems-at-scale/ Kubernetes nodes/proxy GET → RCE (analysis) https://grahamhelton.com/blog/nodes-proxy-rce OpenFaaS guidance / mitigation notes https://www.openfaas.com/blog/kubernetes-node-proxy-rce/ HCP Vault resilience during real AWS regional outages https://www.hashicorp.com/blog/how-resilient-is-hcp-vault-during-real-aws-regional-outages AWS: Fall 2025 PCI DSS compliance package update https://aws.amazon.com/blogs/security/fall-2025-pci-dss-compliance-package-available-now/ GitHub Actions: self-hosted runner minimum version enforcement extended https://github.blog/changelog/2026-02-05-github-actions-self-hosted-runner-minimum-version-enforcement-extended/ Headlamp in 2025: Project Highlights (SIG UI)…","meta_description":"This week on Ship It Weekly , Brian hits four stories where the guardrails become the incident. GitHub had “Too Many Requests” caused by legacy abuse prot…","key_points":[],"chapters":[],"topics":[],"duration_seconds":949,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/when-guardrails-break-prod-github-too-many-requests-from-legacy-defenses-kubernetes-nodes-proxy-get-rce-hcp-vault-resilience-in-an-aws-regional-outage-and-pci-dss-scope-creep/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/when-guardrails-break-prod-github-too-many-requests-from-legacy-defenses-kubernetes-nodes-proxy-get-rce-hcp-vault-resilience-in-an-aws-regional-outage-and-pci-dss-scope-creep.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}