Digest #197: AI in DevOps, AWS Security Vulnerabilities and Terraform Reviewer Agent
How AI is changing DevOps work, where AWS is headed in 2026, and the security risks exposed by recent n8n and CodeBuild vulnerabilities. AI SRE observability, and open-source tools for security.
Welcome to this week’s edition of the DevOps Bulletin.
AI isn’t replacing DevOps teams, it’s changing how they work. Learn how by joining the IaCConf Spotlight on January 28. In the news, AWS’s direction in 2026 comes under scrutiny, a critical unauthenticated RCE in n8n puts thousands of instances at risk, and Wiz uncovered a way attackers could hijack AWS accounts and GitHub repos through CodeBuild. We also cover thousands of secrets leaked via online code formatters, growing concerns around GitHub’s monopoly in open source, and why attention fragmentation (not bad AI code) may be the biggest productivity killer for engineers this year.
On the hands-on side: running projects in dev containers, rebuilding a Talos cluster from bare metal, safely limiting AI coding agents’ access to secrets, improving AI SRE workflows with better observability, and a curated set of Linux and open-source tutorials worth bookmarking. There’s also a beginner-friendly Python guide for those starting fresh in 2026.
Open-source picks this week include Snitch, a human-friendly netstat replacement; Leash, a security wrapper for running AI coding agents in locked-down containers; a CLI and MCP server for managing Lambda GPU instances; a lab of intentionally vulnerable MCP servers for learning AI agent security failures; and tusk-drift-cli, which replays real production traffic as deterministic API tests.
All this and more in this week’s DevOps Bulletin, don’t miss out!
AI isn’t replacing your team. It’s changing how they work.
Learn how platform and DevOps teams are using AI safely at scale at IaCConf Spotlight on January 28 - Register now.
Newsworthy stories
Tutorials of the week
Enjoying the Bulletin? Consider supporting it with a paid subscription. You’ll keep the free Friday issues and get extras like bonus deep-dives, templates, and the full archive.
Videos of the week
Projects of the week
A human-friendly netstat replacement with a clean TUI for inspecting live network connections.
A security wrapper that runs AI coding agents in containers and enforces real-time policies through full system monitoring.
An unofficial CLI and MCP server that lets humans and AI assistants manage Lambda cloud GPU instances.
A hands-on lab of intentionally vulnerable MCP servers for learning AI agent and tool security failures.
A CLI that replays real production traffic as deterministic API tests for local and CI environments.
Meme of the week
If you have feedback to share or are interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.






