💬 Host Commentary

Episode 5 is one of those weeks where the headlines hit three totally different layers of the stack… but they all land on the same people: the folks responsible for keeping systems safe, stable, and shippable.

We start with IBM buying Confluent. Coming right after the HashiCorp deal, it’s a pretty loud signal about where IBM is going: control plane plus data plane, all aimed at enterprise AI and “smart infrastructure.” If you’re on Confluent Cloud or evaluating it, the real question isn’t “is Confluent good.” It’s “what’s our vendor concentration story, and do we have a plan B if packaging, pricing, or priorities shift post-acquisition.”

Then we move to React2Shell, a critical RCE in React Server Components that’s already being exploited in the wild. Even if you’ve never written a line of React, this matters if you run Kubernetes or platforms for teams building modern web apps. It’s server-side code execution. That means patch windows, WAF/rule coverage, and making sure the blast radius of a compromised app pod isn’t “cool, now they own the cluster.”

Third, Netflix’s Aurora write-up. They consolidated a chunk of their relational database fleet onto Aurora PostgreSQL and reported big performance improvements plus meaningful cost savings. The interesting part isn’t “Aurora is magic.” It’s the reminder that self-managed database fleets quietly become an ops tax over time, and sometimes the grown-up move is standardizing on a managed path so you can spend your energy on the parts that actually differentiate your product.

Lightning round is a mix of tools and ecosystem signals: OpenTofu 1.11 shipping new language features, a practical Terraform “tips from the trenches” post, Ghostty moving under a non-profit model, and a quick look at spec-driven development with AI (Spec Kit and OpenSpec) as a saner alternative to free-form “let the agent do whatever.”

We close with a human note: incidents, vendor changes, and security fire drills all land on the same small set of people. The tech is one thing, but the mental load is real, and platform work increasingly includes managing that constant drip of surprise.

Show notes below have all the links if you want to go deeper on the acquisition, the vuln details, and the Netflix architecture story.

📝 Show Notes

In this episode of Ship It Weekly, Brian powers through a cold and digs into a very “infra grown-up” week in DevOps.

First up, IBM is buying Confluent for $11B. We talk about what that means if you’re on Confluent Cloud today, still running your own Kafka, or trying to choose between Confluent, MSK, and DIY. It’s part of a bigger pattern after IBM’s HashiCorp deal, and it has real implications for vendor concentration and “plan B” strategies.

Then we shift to React2Shell, a 10.0 RCE in React Server Components that’s already being exploited in the wild. Even if you never touch React, if you run platforms or Kubernetes for teams using Next.js or RSC, you’re on the hook for patching windows, WAF rules, and blast-radius thinking.

We also look at Netflix’s write-up on consolidating relational databases onto Aurora PostgreSQL, with big performance gains and cost savings. It’s a good excuse to step back and ask whether your own Postgres fleet still makes sense at the scale you’re at now.

In the lightning round, we hit OpenTofu 1.11’s new language features, practical Terraform “tips from the trenches,” Ghostty becoming a non-profit project, and two spec-driven dev tools (Spec Kit and OpenSpec) that show what sane AI-assisted development might look like.

For the human side, we close with “Your Brain on Incidents” and what high-stress outages actually do to people, plus a few concrete ideas for making on-call less brutal.

If you’re on a platform team, own SLOs, or you’re the person people ping when “something is wrong with prod,” this one should give you a mix of immediate to-dos and longer-term questions for your roadmap.

Links:

IBM + Confluent https://www.confluent.io/blog/ibm-to-acquire-confluent/ https://newsroom.ibm.com/2025-12-08-ibm-to-acquire-confluent-to-create-smart-data-platform-for-enterprise-generative-ai

React2Shell (CVE-2025-55182) https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Netflix on Aurora PostgreSQL https://aws.amazon.com/blogs/database/netflix-consolidates-relational-database-infrastructure-on-amazon-aurora-achieving-up-to-75-improved-performance/

Tools & tips https://opentofu.org/blog/opentofu-1-11-0/ https://rosesecurity.dev/2025/12/04/terraform-tips-and-tricks.html https://mitchellh.com/writing/ghostty-non-profit https://github.com/github/spec-kit https://github.com/Fission-AI/OpenSpec

Human side https://uptimelabs.io/your-brain-on-incidents/