Technology worth knowing today.
Cloud Computing
Cloudflare moves to become a public certificate authority with GlobalSign root and post‑quantum plans
What happened. Cloudflare announced its intention to become a public certificate authority, saying it has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs and reached a deal to buy an existing, widely trusted root certificate from GlobalSign. The company also said it plans to be among the first CAs to offer post‑quantum certificates, aligning with Chrome’s newly announced Quantum‑resistant Root Program. Cloudflare stressed that it is not issuing certificates yet and will share further milestones as the work progresses.
Why it matters. By seeking trusted‑root status, Cloudflare could issue TLS certificates that are automatically trusted by major browsers and operating systems, reducing reliance on third‑party CAs. Adding a GlobalSign root would give immediate wide device compatibility. Planning post‑quantum certificates signals preparation for future‑proof encryption as quantum‑resistant standards emerge.
Who should care. Developers · Cloud architects · Platform engineers · Security teams · Administrators · Technology leaders · Students and career changers
Source: Cloudflare
Cloudflare launches free Threat Signals AI tool for all accounts
What happened. Cloudflare introduced Threat Signals, an agentic AI skill that automates summarizing open-source threat reports, extracting IOCs, applying tags, and storing results in a private threat intelligence dataset per account. The feature is available at no cost to every Cloudflare account. Additionally, Cloudflare is expanding free access to its Cloudforce One Threat Events Platform, providing API and dashboard access to Threat Signals and the ability to attach one RSS feed.
Why it matters. Threat Signals reduces the manual effort required to convert unstructured threat reporting into usable indicators of compromise, preserving context while automating summarization, tagging and IOC extraction. By storing results in a private threat intelligence dataset, teams can instantly apply them in WAF policies without leaving the Cloudflare environment. The complementary free access to Cloudforce One’s Threat Events Platform broadens availability of similar capabilities, helping more organizations operationalize threat intelligence without additional cost.
Who should care. Security teams · Platform engineers · Cloud architects · Technology leaders · Administrators
Source: Cloudflare
ADK Introduces Graph-Based Workflows for AI Agent Orchestration
What happened. The Agent Development Kit (ADK) now lets developers design AI agent tasks as graphs, where nodes represent steps and edges define control flow. A refund‑processing example shows how to run actions in parallel, route decisions with deterministic or agent‑driven routers, pause for human review, and dynamically orchestrate work as results arrive. Developers can declare static graphs or let Python schedule additional steps on the fly.
Why it matters. By treating AI agent logic as a graph, teams can visualize complex processes, reuse components, and automatically handle concurrency without manual threading. The built‑in support for human‑in‑the‑loop checkpoints and dynamic routing lets applications adapt to uncertain outcomes, which is valuable for cloud‑native services that must balance automation with oversight. This approach simplifies scaling and maintenance of agent‑driven workloads.
Who should care. Developers · Cloud architects · Platform engineers · Technology leaders · People learning AI
Source: Google Cloud
DevOps
Google releases GKE Agent Sandbox to speed agentic RL workloads
What happened. Google announced the general availability of GKE Agent Sandbox, a Kubernetes-based sandbox layer optimized for agentic reinforcement learning and evaluation workloads. The release includes an Agent Sandbox RL orchestration SDK and native integrations with popular RL gyms and harnesses. Google says the sandbox addresses a bottleneck where costly GPU clusters sit idle waiting for CPU sandbox cold starts and large image pulls, by using performance‑driven benchmarks to refine GKE primitives and deliver a purpose‑built environment for parallel agentic rollouts.
Why it matters. By cutting the latency of sandbox start‑up and image transfers, GKE Agent Sandbox lets expensive GPU/TPU resources stay busy instead of idling while workloads prepare. This can shorten experiment cycles for agentic RL, lower compute waste, and make large‑scale parallel evaluation more feasible on existing Kubernetes clusters. The improvement is grounded in Google’s benchmark‑driven refinement of core GKE primitives for agentic workloads.
Who should care. Developers · Cloud architects · Platform engineers · Technology leaders · People learning AI · Students and career changers
Source: Google Cloud
Software & Systems
Dasha 1.8 Adds Index Recommendations and I/O Analysis for PostgreSQL Fleets
What happened. Dasha 1.8, an open‑source performance dashboard for PostgreSQL, now reads pg_stat_statements on every host in a cluster to suggest missing B‑tree indexes, including column order and ready‑to‑run CREATE INDEX CONCURRENTLY statements. It also introduces an I/O page built on pg_stat_io (PostgreSQL 16+) that breaks down server I/O by backend type, object and context, and adds schema checks and log‑based insights such as auto_explain plans. All features work with a read‑only connection and require no agents or extensions on the database hosts.
Why it matters. These updates give operators a unified view of workload patterns and storage behavior across primary and replica nodes, helping them spot indexes that are unused on the primary but valuable on standbys. By exposing I/O breakdowns and linking index candidates to actual query costs, Dasha enables data‑engineers and platform teams to prioritize tuning actions that improve query performance and reduce unnecessary disk activity without installing extra software on the servers.
Who should care. Developers · Platform engineers · Administrators · Data engineers
Source: PostgreSQL
Today’s takeaway
The releases this week reveal a shared focus on tightening the loop between AI agent development and the infrastructure that runs them. Google’s GKE Agent Sandbox removes GPU idle time by accelerating sandbox start‑up for reinforcement‑learning workloads, while the Agent Development Kit adds graph‑based orchestration that lets agents split work, pause for human review, and resume dynamically. Cloudflare’s move to become a public certificate authority and its free Threat Signals AI tool show that securing and monitoring agent communications is being baked into the network layer, with post‑quantum readiness and real‑time threat intelligence offered at no cost. Finally, Dasha’s PostgreSQL dashboard supplies deep index and I/O insights without agents, giving developers observable data‑store performance to match the compute optimizations. Together, they suggest a practical judgement: when building agentic systems, treat compute orchestration, security, threat intelligence, and database observability as co‑designed layers rather than after‑thoughts.