
Hetzner DNS Makes the RRSet TTL Required on September 30: Audit Your DNS Automation Before Updates Start Failing
On September 30, 2026, Hetzner starts rejecting RRSet TTL updates that omit the ttl field. Here is which callers are already safe, which break, and a 20-minute audit to prove your DNS automation is compliant before the cutoff.

Bare-IP TLS Is GA: Instant HTTPS for Preview URLs Without a DNS Round-Trip
Let's Encrypt's generally available 160-hour IP certificates let a preview environment serve valid HTTPS on a bare node IP with no DNS records. Here is the cert-manager plus Gateway API wiring, the renewal math, and when a subdomain still wins.

containerd 1.7 Is Dead: The Node-Image Audit Your Fleet Owes Itself Before the Next Kubernetes Upgrade
containerd 1.7 left support in September 2026, and Kubernetes 1.38 drops the kubelet fallback that kept it working. A fifteen-minute audit to find every 1.7 node in your fleet, a table of what the 2.x jump breaks, and the upgrade order that keeps kubelets healthy.

FerretDB v2 Speaks Mongo on Top of Your Existing CloudNativePG — If Postgres Carries the DocumentDB Extension
FerretDB v2 turns your existing CloudNativePG fleet into a MongoDB-compatible endpoint — but only if Postgres carries Microsoft's DocumentDB extension. The concrete CNPG recipe, what consolidation buys ops, and the verify-before-you-promise checklist.

Hetzner Pulled openSUSE 15 and Deprecated Debian 11: Rebuild Your CAPH Node Images Before November 30
Hetzner removed openSUSE 15 for new servers on July 30 and will do the same to Debian 11 after November 30. This runbook shows Cluster API (CAPH) operators how to audit pinned images, pick a replacement base, and roll the fleet before scale-up starts failing.

Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned
Hetzner's July datacenter removal was only the headline: unassigned Primary IPs flipped to assignee_type unassigned on August 1, Prometheus 3.14 dropped the Hetzner datacenter label, and the datacenters API goes 410 on October 1. A per-break fix table plus a six-grep audit runbook for CAPH fleets.

Block the Training Bots, Welcome the Answer Bots: A robots.txt Default for the AI-Crawler Era
Publishers now block AI training bots while welcoming the same vendors' answering crawlers. A copy-paste three-tier robots.txt default for docs sites and tenant apps, with the traffic data and gotchas behind it.

Ingress-NGINX Is Retired: Your Gateway API Migration Playbook for the Rest of 2026
Ingress-nginx stopped receiving security patches in March 2026. A migration playbook for self-hosted teams: the five translation traps, which annotations survive the move to Gateway API, and a TLS cutover checklist.

Railway's Guardrails, Rebuilt in Kubernetes: Two Admission Policies That Keep Internal Services Off the Public Internet
Railway's April 2026 Guardrails stop non-admins from exposing internal services via public domains or TCP proxies. Here is how to enforce the same two policies on a self-hosted Kubernetes platform with ValidatingAdmissionPolicy and Kyverno.