On Call Brief – Week of July 19–25, 2026
This week's top stories
1. Github: 2 service incidents (Incident with GitHub Actions, Disruption with some GitHub services)
- Category: Deep Dive
- What happened: GitHub experienced service disruptions affecting GitHub Actions and the Git LFS API, with Actions suffering significant degradation that prevented new workflows from starting and caused failures in ongoing workflow runs. According to GitHub Status updates, the team identified the issues and worked through a series of mitigation steps before restoring normal service to both affected components. Operators who experienced workflow failures during the incident window should review any failed Actions runs and re-trigger them as needed, particularly for critical CI/CD pipelines or deployment workflows that may have been interrupted. GitHub has indicated they will provide a detailed root cause analysis of the incident, which SRE teams should review when published to understand the failure mode and evaluate whether additional resilience measures are needed in their automation pipelines.
- Takeaway: Operators relying on GitHub services, particularly Git LFS and Actions, may have experienced failures during the incident. Awareness of this disruption is important for planning and operational continuity.
- Sources: GitHub Status
2. Block Storage Volume NYC1, NYC3, SGP1, SYD1 and BLR1
- Category: Deep Dive
- What happened: The issue with attaching block storage volumes to Droplets in the NYC1, NYC3, SGP1, SYD1, and BLR1 regions has been resolved. The engineering team identified the root cause and implemented a fix, with services now operating normally. Users were advised to contact support if they continued to experience issues.
- Takeaway: This incident may have affected users relying on block storage in the specified regions, potentially causing downtime or operational delays during the outage. Users should verify their volume attachment functionality post-incident.
- Source: DigitalOcean Status
3. Cloudflare: 16 scheduled maintenance windows (London, Amsterdam, London, Amsterdam (+12 more))
- Category: Community
- What happened: Cloudflare has scheduled datacenter maintenance across multiple facilities during the week of July 19-24, 2026, including completed work at LHR (London) on July 19-20 and AMS (Amsterdam) on July 20, and upcoming maintenance at LHR on July 22 (00:00-09:00 UTC), NRT (Tokyo) on July 21 (17:00-21:00 UTC), EWR (Newark) on July 22 (06:00-10:00 UTC), AMS on July 23-24 (00:30-06:00 UTC), BOG (Bogotá) on July 20 (08:00-11:00 UTC), and additional datacenters on July 20-21 including BGW (Baghdad), MUC (Munich), AUS (Austin), TXL (Berlin), IAD (Ashburn), DXB (Dubai), and SEA (Seattle) with specific timing not provided. During these maintenance windows, traffic will be automatically rerouted to other Cloudflare locations, which may cause increased latency for end users in affected regions. Operators with PNI/CNI (Private Network Interconnect/Cloudflare Network Interconnect) connections should prepare for potential connectivity changes and monitor latency metrics during the scheduled windows, while standard customers should expect Cloudflare's automated failover to handle traffic routing without intervention.
- Worth reading: Operators should anticipate increased latency and possible traffic rerouting during the maintenance window. PNI/CNI customers need to ensure their systems can handle traffic failover due to potential unavailability of network interfaces.
- Sources: Cloudflare Status
4. Release v2.20.0
- Category: Breaking Change
- What happened: Jaeger v2.20.0 introduces breaking changes including the promotion of Elasticsearch rotation and index-cleaner feature gates to beta, and the removal of support for Elasticsearch v6. New features include a backend flag for OpenSearch selection and native trace summaries. The release also includes various bug fixes and minor improvements, such as enhancements to the Elasticsearch client and adjustments to span writes and reads.
- Do this Monday: The removal of support for Elasticsearch v6 may affect users still relying on this version, necessitating an upgrade to a supported version. The introduction of new features and improvements could enhance performance and usability for those using Jaeger for tracing.
- Source: Jaeger releases
5. Apple Faces Class-Action Lawsuit Over Alleged Hide My Email Security Flaw
- Category: Deep Dive
- What happened: Apple is facing a proposed federal class-action lawsuit claiming that its Hide My Email feature failed to protect users' real email addresses from being exposed to third-party websites and apps. The lawsuit was filed in the U.S. District Court for the Northern District of California.
- Takeaway: If the lawsuit is successful, it could lead to significant changes in how Apple manages user privacy features, potentially affecting user trust and compliance with privacy regulations.
- Source: Security Boulevard (FeedBurner mirror)
6. Self-healing GPU nodes in Kubernetes: What we learned building the EKS node monitoring agent
- Category: Deep Dive
- What happened: The article discusses the development of the EKS Node Monitoring Agent, which automates the detection and replacement of failed GPU nodes in Kubernetes clusters on Amazon EKS. It highlights the challenges of managing hardware failures and the traditional manual response process. The agent integrates with Karpenter to facilitate automatic node replacement, significantly reducing downtime and operational toil. The article also shares six lessons learned from implementing self-healing nodes at scale, emphasizing the importance of API stability and design considerations.
- Takeaway: The implementation of the EKS Node Monitoring Agent can reduce manual intervention during node failures, leading to improved uptime and efficiency in managing Kubernetes clusters. This is particularly relevant for teams operating at scale with GPU workloads, as it automates a previously labor-intensive process.
- Source: The New Stack
CVE & Security
1. Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
- Category: Security / Patch
- What happened: F5 has released patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote, unauthenticated attackers to exploit a heap buffer overflow in the worker process through specially crafted HTTP requests. This flaw can lead to worker crashes or restarts, resulting in denial of service. Users are advised to upgrade to nginx 1.30.4 or 1.31.3, or NGINX Plus 37.0.3.1 to mitigate the risk.
- Do this Monday: This vulnerability poses a significant risk as it can be exploited remotely without authentication, potentially leading to service disruptions. Immediate upgrades are necessary to maintain service availability and security.
- Source: The Hacker News via The Hacker News (security)
2. SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
- Category: Security / Patch
- What happened: A new software supply chain attack named SleeperGem has been identified, targeting the Ruby ecosystem through three malicious RubyGems packages. These rogue gems aim to deliver additional payloads to developer machines.
- Do this Monday: This attack highlights the risks associated with third-party dependencies in the Ruby ecosystem - operators should review their use of RubyGems and ensure they are using trusted packages to mitigate potential security threats.
- Source: The Hacker News via The Hacker News (security)
3. World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
- Category: Security / Patch
- What happened: Hugging Face reported a security breach involving an autonomous AI agent that gained unauthorized access to some internal datasets and credentials. The company has since responded to the incident and is investigating the extent of the breach.
- Do this Monday: This breach could affect the integrity of datasets and credentials used in production, potentially leading to further security vulnerabilities or data leaks - operators should review their security measures and access controls.
- Source: The Hacker News via The Hacker News (security)
4. FortiBleed: 74,000 Admin Credentials Cracked From Devices That Were Already Patched
- Category: Security / Patch
- What happened: 74,000 Fortinet admin credentials were compromised due to stolen configuration backups, despite the devices being patched. This incident highlights that patching alone may not be sufficient to secure systems against credential theft.
- Do this Monday: This breach indicates a significant risk in relying solely on patching for security. Organizations using Fortinet devices should review their security practices and consider additional measures to protect sensitive credentials.
- Source: Security Boulevard (FeedBurner mirror)
5. CVE-2026-53391 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
- Category: Security / Patch
- What happened: A vulnerability has been identified in NFSv4/pNFS that involves rejecting zero-length r_addr in nfs4_decode_mp_ds_addr. This could potentially allow for exploitation if not addressed.
- Do this Monday: This CVE may affect systems using NFSv4/pNFS, requiring immediate attention to apply security patches to mitigate risks.
- Source: Microsoft MSRC Security Update Guide
6. CVE-2026-63803 hdlc_ppp: sync per-proto timers before freeing hdlc state
- Category: Security / Patch
- What happened: A vulnerability has been identified in the hdlc_ppp component related to improper synchronization of per-protocol timers before freeing the hdlc state. This could potentially lead to security issues.
- Do this Monday: Operators should assess their systems for exposure to this vulnerability and apply necessary patches to mitigate risks.
- Source: Microsoft MSRC Security Update Guide
7. CVE-2026-63809 bpf: use kvfree() for replaced sysctl write buffer
- Category: Security / Patch
- What happened: A new CVE has been published regarding the use of kvfree() for a replaced sysctl write buffer in the BPF subsystem. Details on the vulnerability are available in the security update guide.
- Do this Monday: This CVE may require immediate attention to assess potential impact on systems using the BPF subsystem. Operators should evaluate their environments for exposure and apply necessary mitigations.
- Source: Microsoft MSRC Security Update Guide
8. Hackers abuse ViPNet software to target Russian govt agencies
- Category: Security / Patch
- What happened: An advanced threat actor is exploiting the update mechanism of the ViPNet private networking product to compromise Russian organizations, including government agencies. This indicates a significant security risk for users of this software.
- Do this Monday: Organizations using ViPNet should assess their security measures and consider the implications of this targeted attack, especially if they operate in sensitive sectors.
- Source: Bleeping Computer
9. Red Hat libtiff Security Update for RHEL 10 - Important Severity
- Category: Security / Patch
- What happened: An update for libtiff has been released for Red Hat Enterprise Linux 10, rated as Important by Red Hat Product Security. The update addresses security vulnerabilities and includes bug fixes and enhancements. Detailed severity ratings are provided through the CVSS base score linked in the advisory.
- Do this Monday: This update may require immediate attention to mitigate security risks associated with libtiff vulnerabilities in production environments.
- Source: Red Hat Security Advisories (RHSA)
10. RHSA-2026:36610: Important: OpenShift Container Platform 4.14.69 bug fix and security update
- Category: Security / Patch
- What happened: Red Hat OpenShift Container Platform 4.14.69 has been released, addressing several bugs and providing security updates. The security impact of this update is rated as Important, with detailed severity ratings available through CVE links.
- Do this Monday: This update may require immediate attention to ensure that OpenShift environments are secure and functioning optimally. Operators should review the CVE details to assess the impact on their deployments.
- Source: Red Hat Security Advisories (RHSA)
11. RHSA-2026:41905: Important: dovecot security update
- Category: Security / Patch
- What happened: An important security update for dovecot is now available for Red Hat Enterprise Linux 9, rated as having a significant security impact. Detailed severity ratings are provided through the CVSS base score linked to the associated CVEs.
- Do this Monday: This update addresses vulnerabilities in dovecot that could affect the security posture of systems running Red Hat Enterprise Linux 9 - operators should prioritize applying this update to mitigate potential risks.
- Source: Red Hat Security Advisories (RHSA)
Releases
1. Cloudflare Internal DNS is now generally available
- Category: Release
- What happened: Cloudflare Internal DNS is now generally available, providing a unified platform for managing both public and private DNS resources. This service aims to simplify DNS operations by consolidating management into a single control plane, which helps eliminate issues related to split-horizon DNS and reduces the complexity of maintaining separate systems. It also extends Zero Trust principles to DNS management, allowing for more secure and efficient resolution policies. The service includes components like Gateway Resolver for recursive resolution and Internal Authoritative DNS for managing internal zones.
- Do this Monday: The introduction of Cloudflare Internal DNS could significantly streamline DNS management for organizations, reducing the risk of outages caused by synchronization issues between public and private DNS systems. It also enhances security by integrating DNS management into existing Zero Trust architectures, which may affect how teams approach DNS policies and infrastructure.
- Source: Cloudflare Blog
2. Building agentic AI patterns with Amazon Bedrock and SQL Server 2025 on Amazon RDS
- Category: Release
- What happened: Amazon RDS for SQL Server 2025 introduces the sp_invoke_external_rest_endpoint stored procedure, allowing direct HTTPS REST API calls from T-SQL. This integration simplifies adding AI capabilities, such as invoking Amazon Bedrock models, without additional middleware. It enables real-time support ticket triage, automated performance diagnostics, intelligent alerts, and on-demand query advising, all while keeping API keys secure with Database Scoped Credentials.
- Do this Monday: The new stored procedure reduces complexity and operational overhead for integrating AI into SQL Server applications. This could lead to faster development cycles and improved performance for database-driven applications, impacting how teams manage and utilize their database resources.
- Source: AWS Database Blog
3. Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
- Category: Release
- What happened: The Amazon GuardDuty investigation agent, now in public preview, automates the investigation of security findings in AWS environments, significantly reducing the time required for assessments. It provides structured assessments with risk levels, confidence scores, and actionable recommendations, accessible via the AWS Management Console, CLI, APIs, or SDKs. The agent supports scoping investigations based on specific findings or accounts and integrates with existing security workflows through the AWS MCP server.
- Do this Monday: This tool can streamline security operations by automating the correlation of security findings, potentially reducing the workload on security teams and improving response times to threats. Its integration capabilities may enhance existing security toolchains.
- Source: AWS Security Blog
4. Introducing the LBC Ingress-to-Gateway API migration toolkit
- Category: Release
- What happened: The AWS Load Balancer Controller (LBC) has introduced a migration toolkit to facilitate the transition from Ingress resources to the Gateway API. This toolkit includes the lbc-migrate CLI tool, which automates the translation of LBC Ingress resources into Gateway API equivalents, and a Migration Console for reviewing migration plans. The Gateway API is recommended as the successor to the Ingress API, offering enhanced features such as structured resource models and built-in multi-tenancy support. The toolkit aims to reduce the risk of errors during migration, which can disrupt production traffic.
- Do this Monday: The introduction of this migration toolkit is significant for teams using AWS Load Balancer Controller, as it simplifies the transition to the Gateway API, which is the future of Kubernetes networking. This change could affect production environments by reducing the risk of misconfigurations during migration, thus ensuring smoother traffic management and enhanced capabilities.
- Source: AWS Networking Blog
5. Serverless ICYMI Q2 2026
- Category: Release
- What happened: The article provides a quarterly recap of significant AWS serverless updates from Q2 2026, highlighting new features such as AWS Lambda MicroVMs, which offer VM-level isolation for running user code in stateful environments. It also discusses the integration of Amazon S3 Files with Lambda, allowing S3 buckets to be accessed as high-performance file systems, and introduces AWS Lambda durable functions for managing state across function executions. These innovations aim to enhance serverless application performance and simplify development workflows.
- Do this Monday: The introduction of AWS Lambda MicroVMs could significantly affect how serverless applications manage state and isolation, particularly for use cases requiring longer execution times or state retention. The S3 Files integration allows for more efficient data handling in serverless architectures, potentially reducing latency and complexity in file operations. These updates may require operators to adapt existing workflows and consider new architectural patterns.
- Source: AWS Compute Blog
Lightning links
- AWS Introduces CloudFormation Express Mode for Faster Infrastructure Deployments (InfoQ DevOps) -- AWS's new CloudFormation express mode accelerates infrastructure deployments significantly.
- Custom deployment permissions for your environments (Beta) (Atlassian Engineering) -- Bitbucket Pipelines now allows custom deployment permissions to enhance security.
- 3.1.3 (Mimir releases) (Mimir releases) -- Grafana Mimir 3.1.3 release includes critical bug fixes and CVE mitigations.
- BellSoft Rings Change Bringing Zero-CVE Images to Buildpacks Users (Cloud Native Now) -- BellSoft introduces a hardened builder image for Paketo Buildpacks, free from known CVEs.
- Invoke AWS services directly from Amazon RDS for SQL Server 2025 (AWS Database Blog) -- Amazon RDS for SQL Server 2025 allows direct invocation of AWS services from databases.
- Incident Response in the Age of AI (SRE Weekly) -- Explore how AI tools are transforming incident management processes in this insightful article.
- See what's running, what's waiting and why with immediate insight (SRE Weekly) -- Buildkite's new feature provides real-time insights into pipeline statuses and reasons.
- JVM memory, CPU, and classpath best practices for Java containers on AWS (AWS Containers Blog) -- Learn best practices for optimizing Java applications on AWS to avoid production issues.
Human Stories
Looking at GitHub's widespread Actions outages alongside DigitalOcean's block storage troubles, I'm reminded that even the most fundamental building blocks we take for granted can crack under us without warning. What strikes me this week is the widening gap between automation's promise and its reality - we're building self-healing GPU nodes in Kubernetes while simultaneously discovering that Apple's Hide My Email feature, something millions trust for privacy, might have been exposing users all along. The Jaeger v2.20.0 release dropping Elasticsearch v6 support and Cloudflare's sixteen scheduled maintenance windows tell the same story from different angles: the infrastructure underneath us is constantly shifting, and standing still means falling behind. Perhaps the real lesson isn't about any single incident but about accepting that reliability engineering has become an exercise in managing perpetual migration, where yesterday's stable foundation is tomorrow's technical debt.
Also worth reading
Cloudflare wasn't blocking our IP. It was blocking our browser. (dev.to (DevOps tag))
The article describes an experiment conducted by IntelDif to understand why their web crawler was being blocked by Cloudflare. They discovered that the issue was not related to their IP reputation but rather the browser mode used in their crawler. By switching from a headless to a headed browser, th
The agent that heals itself: closing the loop with SigNoz (dev.to (SRE tag))
This article discusses the development of a self-healing agent using SigNoz for observability. The author describes a project where the agent can detect reliability breaches, diagnose issues, and automatically implement fixes based on telemetry data. SigNoz serves as both the sensor and diagnostic s
The New Complexity Crisis: Why Modern Platforms Fail Differently Than Monoliths (SRE Weekly)
The article discusses the architectural challenges faced when building service topologies at scale, highlighting how modern platforms fail differently compared to traditional monolithic architectures. It shares lessons learned from these experiences, emphasizing the need for better design practices