<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloud - Category - Shengxu · Cloud Architecture &amp; DevOps</title><link>https://shengxu.pages.dev/en/categories/cloud/</link><description>Cloud architecture &amp; DevOps notes by Shengxu: Kubernetes, Cilium, observability, LLM infra, AI agents.</description><generator>Hugo 0.153.2 &amp; FixIt v0.4.0-alpha.3-20251225101113-8ffb9a95</generator><language>en</language><lastBuildDate>Sat, 03 Jan 2026 19:00:00 +0800</lastBuildDate><atom:link href="https://shengxu.pages.dev/en/categories/cloud/index.xml" rel="self" type="application/rss+xml"/><item><title>Kubernetes 1.34/1.35 Certificate Revolution: From Manual Hell to Zero-Trust Heaven</title><link>https://shengxu.pages.dev/en/posts/kubernetes-1-34-1-35-certificates/</link><pubDate>Sat, 03 Jan 2026 19:00:00 +0800</pubDate><guid>https://shengxu.pages.dev/en/posts/kubernetes-1-34-1-35-certificates/</guid><category domain="https://shengxu.pages.dev/en/categories/kubernetes/">Kubernetes</category><category domain="https://shengxu.pages.dev/en/categories/cloud/">Cloud</category><category domain="https://shengxu.pages.dev/en/categories/security/">Security</category><description>&lt;p&gt;Recently upgraded to 1.35 and discovered that &lt;strong&gt;certificate management&lt;/strong&gt; changes are nothing short of revolutionary—especially for self-managed K8s users, where operational overhead has been cut in half.&lt;/p&gt;
&lt;p&gt;In the past, certificate issues were the &amp;ldquo;silent killer&amp;rdquo; of security incidents: expired certificates causing outages, token leaks, and manual rotation consuming 30% of ops time. Versions 1.34/1.35 introduce &lt;strong&gt;native automated mTLS&lt;/strong&gt;, making zero trust no longer exclusive to Istio. Today, let&amp;rsquo;s dive into these new features and compare them in a &lt;strong&gt;self-managed K8s vs. cloud K8s&lt;/strong&gt; hands-on scenario.&lt;/p&gt;</description></item><item><title>Kubernetes v1.33–v1.35 Deep Dive: From Native Sidecar to AI Compute Foundation</title><link>https://shengxu.pages.dev/en/posts/kubernetes-v1-33-v1-35-updates/</link><pubDate>Fri, 02 Jan 2026 09:50:00 +0800</pubDate><guid>https://shengxu.pages.dev/en/posts/kubernetes-v1-33-v1-35-updates/</guid><category domain="https://shengxu.pages.dev/en/categories/kubernetes/">Kubernetes</category><category domain="https://shengxu.pages.dev/en/categories/cloud/">Cloud</category><category domain="https://shengxu.pages.dev/en/categories/security/">Security</category><description>&lt;h2 class="heading-element" id="timeline-overview"&gt;&lt;span&gt;Timeline Overview&lt;/span&gt;
 &lt;a href="#timeline-overview" class="heading-mark"&gt;
 &lt;svg class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"&gt;&lt;path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"&gt;&lt;/path&gt;&lt;/svg&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;v1.33 (Octarine)&lt;/strong&gt;: Released April 2025, Native Sidecar GA, security features enabled by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;v1.34 (Of Wind &amp;amp; Will)&lt;/strong&gt;: Released August 2025, DRA GA, marking the native era of AI/GPU scheduling.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;v1.35 (Timbernetes)&lt;/strong&gt;: Released December 2025, In-Place Pod Resize GA, zero-disruption elasticity becomes reality.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 class="heading-element" id="1-v133-octarine-sidecar-graduation-and-default-security"&gt;&lt;span&gt;1. v1.33 &amp;ldquo;Octarine&amp;rdquo;: Sidecar Graduation and Default Security&lt;/span&gt;
 &lt;a href="#1-v133-octarine-sidecar-graduation-and-default-security" class="heading-mark"&gt;
 &lt;svg class="octicon octicon-link" viewBox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"&gt;&lt;path d="m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z"&gt;&lt;/path&gt;&lt;/svg&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;The keywords for v1.33 are &amp;ldquo;&lt;strong&gt;Native Sidecar&lt;/strong&gt;&amp;rdquo; and &amp;ldquo;&lt;strong&gt;Security Enabled by Default&lt;/strong&gt;.&amp;rdquo; This release transforms long-standing experimental capabilities into dependable infrastructure for daily engineering.&lt;/p&gt;</description></item></channel></rss>