Supply chain attacks and OSS sustainability go hand in hand. I've semi-seriously joked for years that OSS upstreams should periodically purposely inject full vulns into their code and let downstreams fuck around and find out. Downstreams can pay to get the non-FAFO version.
The not joke part is simply that OSS maintainers aren't a supply chain. OSS maintainers are not responsible for monitoring CVEs (because, they are not a supply chain). OSS maintainers are not at fault when bad shit happens to downstreams, because basically every OSS license (MIT, Apache, GPL, etc.) literally says: the software is provided "as-is, without warranty." You get what you pay for (that is to say: absolutely nothing!)
Now, the joke part is that I do believe there is an ethical obligation to try to prevent harm downstream. But "try" is the key word. So, this isn't a serious proposal.
But, if you're using OSS code and you're not paying for a license with a contract that promises some kind of warranty, you have no supply chain. You (the downstream user of an OSS lib) ARE the supply chain.
To use a metaphor: physical goods have a real supply chain. Car manufacturers, chips, clothes, toys, etc. You have a signed commercial agreement with all your suppliers that promises quantity AND quality and blowback if either are missed. Thats a supply chain.
If someone puts some chips on the side of the road with a "FREE" sign, then you integrate those into a product, then find out those chips are hacking customers, its your fault, not the person who dropped them on the side of the road.
Top 5 Policies for Resource Optimization 🛡️
Optimization isn't just about saving money it's about ensuring your workloads survive node drains and traffic spikes.
Stop relying on manual configuration.
▶️ Check the video for more
#Infrastructure#Kubernetes#Optimization
Inside @NirmataCloud: The Autonomous Governance Platform Enabling AI at Scale
The last generation of cloud infrastructure grew at the pace at which humans could build and operate static applications.
That world is gone.
Two things have changed at once. Applications are becoming AI-driven and dynamic, and the rate at which teams are shipping software has increased dramatically with AI-assisted development. Yet most organizations are still relying on manual platform engineering and SRE processes to govern this complexity.
That mismatch is fast becoming one of the biggest risks in modern engineering.
As cloud infrastructure becomes increasingly AI-dominated and AI-powered, this problem does not only affect teams deploying AI models. It also impacts anyone scaling and operating modern infrastructure using AI-driven tools, where systems now change faster than humans can reliably manage.
This is the problem Nirmata is built to solve.
Nirmata sits at the policy enforcement layer of modern cloud and AI infrastructure. Through policy-as-code, continuous evaluation, and automated remediation, it enables platform teams to move from manual enforcement to intent-driven governance.
Their traction reflects how urgent this shift is.
🚀Over 3 billion downloads.
✨More than 8,000 GitHub stars.
💻Adopted by 6,000+ enterprises.
@kyverno, the open-source policy engine created by the Nirmata team, is on track for CNCF graduation and is already becoming a default standard for policy enforcement in Kubernetes environments.
What matters most is the direction of travel. As AI systems scale, governance cannot remain static. Platform engineering has to move from configuration to control loops, from alerts to outcomes, from humans reacting to systems to systems that can correct themselves.
Nirmata is building for that future.
🪶This is the first spotlight in Surge Spotlight, our new series taking a closer look at the companies from Surge 11 and the category shifts they represent.
@JimBugwadia@riteshdp@RajanAnandan@aaditya@Aadith__Ramesh
🗣️ @riteshdp, Co-founder @ @NirmataCloud, explains how AI adoption focused on developers for code generation, but platform engineers have been overlooked despite being "very stretched."
Watch: https://t.co/tPmzCr9cIA
Read: https://t.co/FuOaKEOwtV
Secure K8s with Kyverno! 🔒
Join Shuting Zhao & Ekambaram Pasham (Infosys) to master policy & governance in this CNCF webinar.
Watch: https://t.co/cBlZBgZd9v
#Kubernetes#Nirmata#Kyverno
🚀 Nirmata Control Hub is now LIVE on the Azure Marketplace!
Azure users can now seamlessly deploy our AI Platform Engineering Assistant to secure and automate AKS clusters.
👉 Get started: https://t.co/1cARqYOWTm
#Nirmata#PlatformEngineering
The Kyverno project has applied for CNCF graduation! 🎉
If you are using Kyverno, please comment or like the GitHub issue to show your support: 💕
https://t.co/3CZeBXgMHe
Things we are thankful for this year:
✅ Automated Policy Management
✅ Secure Clusters
✅ The Cloud Native Community
✅ A delicious Thanksgiving feast (with 0% packet loss)
Happy Thanksgiving from the Nirmata team! 🦃🥧
#DevOps#Kubernetes#Thanksgiving#Nirmata
Devs: Simplify #Kubernetes! 🚀
At #KubeCon, see @Nirmata's NCTL AI Agent. Turn natural language into secure configs & @Kyverno policies, right from your CLI.
Demo our full AI platform with PaC & Remediator Agents! Booth 1340.
#AI#KubeCon#DevOps#Kyverno
Day 1 of #KubeCon NA 2025! 🚀
Come see live demos at booth #1340 of the Nirmata AI Platform Engineer, our new #AI assistant built on @kyverno to automate #cloudnative governance & #K8s security.
See the announcement: https://t.co/O40oIVWO1z
Say hello to the world's first AI Platform Engineer Assistant from @NirmataCloud from our current cohort of @_surgeahead. Building on #Kyvernos 3B downloads!
Introducing the world's first #AI#PlatformEngineering Assistant! 🤖
Use natural language to manage #Kubernetes policies, analyze risks, and ensure compliance. Stop scripting, start asking.
See it live at the #Nirmata booth 1340 #KubeCon Atlanta!
🔗https://t.co/teZSTipzO7
KubeCon Platform Engineers! See the future of policy-as-code with Kyverno & Nirmata AI.
🤖AI Platform Engineering Assistant
🤖Automate policy creation & remediation
📅Mon, Nov 10, 5:30 pm
📍Twin Smokers BBQ, Atlanta
Register: https://t.co/R3LUQ7tdbd
#Kyverno#Nirmata
#PolicyAsCode... EVERYWHERE. 🌎
Learn how #Kyverno simplifies UNIFIED policy for all your clusters (cloud, edge, and more).
Join @JimBugwadia & Charles-Edouard Brétéché at #KubeCon NA!
🗓️ Tues, 3:15 PM EST 📍 Georgia Ballroom 3 🔗https://t.co/aLMSXLMG4Y
The next era of #PlatformEngineering is here—fast, intelligent, and AI-native.
Today, we’re announcing a major evolution: Nirmata’s AI-Powered Governance Platform.
Built by the creators of @kyverno, we're layering AI across the entire policy & compliance ecosystem.
Our AI-native platform is a force multiplier for platform teams:
🧠 AI agents understand natural language to auto-generate policies.
⚙️ Smart guardrails detect, explain & remediate violations at machine speed.
🚀 Continuous governance across K8s, IaC, pipelines & cloud.
🪔 Happy Diwali from Nirmata! ✨
Wishing you light, joy, and new beginnings this festive season. May your year ahead shine bright with success and happiness. 🌟
#HappyDiwali#Nirmata#FestivalOfLights