Heard in
Conversation
"We're starting with GitHub Actions and Kubernetes because the helper layer is officially part of the trust boundary now."

GitHub Actions Hardening, Airbnb Config Rollouts, Cloudflare Rust Restarts, ECS Managed Daemons, and Terraform Access Controls
This episode of Ship It Weekly is about the quiet platform work that keeps things safe before they break. Brian covers GitHub Actions hardening in Kubernetes-related repos, Airbnb’s safer config rollouts, Cloudflare’s zero-downtime Rust restarts, Amazon ECS Managed Daemons, and HCP Terraform access controls with IP allow lists and temporary AWS permission delegation.
Links
GitHub Actions security roadmap
Airbnb config rollouts
Cloudflare graceful restarts for Rust
https://blog.cloudflare.com/ecdysis-rust-graceful-restarts/
Amazon ECS Managed Daemons
https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-ecs-managed-daemons/
HCP Terraform IP allow lists
https://www.hashicorp.com/blog/hcp-terraform-adds-ip-allow-list-for-terraform-resources
HCP Terraform AWS permission delegation
https://www.hashicorp.com/blog/aws-permission-delegation-now-generally-available-in-hcp-terraform
GitHub secret scanning updates
https://github.blog/changelog/2026-03-10-secret-scanning-pattern-updates-march-2026/
GitHub secret scanning for AI coding agents
Codespaces GA with data residency
Kubernetes v1.36 sneak peek
https://kubernetes.io/blog/2026/03/30/kubernetes-v1-36-sneak-peek/
GKE Inference Gateway
https://cloud.google.com/kubernetes-engine/docs/concepts/about-gke-inference-gateway
More episodes and show notes
On Call Briefs
