Episodes
Episode 12Wed, Sep 09, 2026

Ep 12 - Government Platforms in Motion: DoDNet, Secure AI, and Auditable Delivery

DevSecOps news for August 27-September 9, 2026 covering government cloud migrations, secure AI, federal identity policy, and defense software delivery. The shift is toward moving mission workloads onto shared platforms while tightening identity, authorization evidence, and controls around AI-driven work.

GovernmentGovCloudCybersecurityAIDevOps
On this episode
  1. In the News
  2. DevOps Related News
  3. Cyber Security
  4. Compliance and Government
  5. 📰 Industry News
  6. 🌐 Community News
  7. ⚙️ Fun Tools and Reads

In the News

  • Rancher Government Hauler: Hauler 2.1 adds parallel artifact pulls, audit logs for artifact transfers, and digest verification for disconnected delivery. It can also reconstruct a manifest from a store while preserving original source references, making air-gap transfers easier to trace.
  • AWS Transform in GovCloud: AWS added Transform to GovCloud on September 8, bringing its AI-assisted migration service into the government region. The GovCloud edition is available only in US-West and supports migration jobs, not the full commercial job portfolio.
  • GitLab Duo Self-Hosted: GitLab published a Microsoft Foundry integration guide for routing Duo features through a self-managed AI Gateway to selected model endpoints. The guide also covers an on-premises model-serving alternative; the Foundry configuration is not an air-gapped deployment or a new government authorization.
  • Keycloak: Keycloak 26.7.3 fixes LDAP certificate hostname verification, token-exchange restrictions, and delegated-administrator authorization in the self-hostable identity platform. It also addresses sustained high CPU and Admin API costs that grew with the number of realms.
  • Harness: Harness introduced an agent-ready repository and AI code review with scoped agent permissions, mandatory review checks, and risk-grouped diffs. Harness offers a self-managed platform, but this announcement does not establish offline or government-authorized availability for the new AI features.
  • GitHub Actions: Starting October 1, checks, workflow runs, and commit statuses will follow Actions retention settings, which default to 90 days. Older records beyond the configured period will be removed, and GitHub directs customers to export evidence they need to retain longer.

Cyber Security

  • AI model-extraction campaigns: In a September 8 joint advisory, NSA, FBI, and CISA warned that China-based AI companies use fraudulent accounts and proxy networks to extract capabilities from U.S. models at scale. The agencies describe coordinated API abuse and recommend monitoring account behavior, request patterns, and unusually large output volumes.
  • Identity for AI agents: NIST's August 27 analysis argues that agents need distinct identities, narrowly scoped permissions, and short-lived credentials rather than shared user secrets. It also warns that excessive approval prompts can create consent fatigue, making human approval an incomplete security boundary.
  • Red Hat AI 3.5: Red Hat AI 3.5 makes model-safety insights and EvalHub evaluations generally available for AI environments running on-premises or across clouds. A separate OpenShell developer preview for OpenShift AI 3.5 adds kernel-enforced agent isolation, network policy, and signed harness images with software bills of materials.
  • BREEZE COMET: Google Threat Intelligence documented intrusions into Brazilian financial and retail environments that combined privileged-account compromise, persistent backdoors, and fraudulent payment transactions. Researchers also found evidence of AI-assisted scripting for reconnaissance and credential validation, compressing the actor's preparation work.
  • Internet-exposed water controls: Government Technology's August 31 follow-up examined more than 100 incidents affecting water systems in at least seven states since late July. Attackers changed settings on exposed industrial controllers and temporarily disrupted monitoring or control; the underlying FBI/EPA advisory explains the exposure and defensive measures.
  • Risk-based federal patching: At an August 27 briefing, CISA explained how its June patch-prioritization directive is intended to reduce low-value remediation work. The approach accelerates urgent, exploited exposures while using Continuous Diagnostics and Mitigation automation to support more routine handling of lower-risk vulnerabilities.

Compliance and Government

  • DISA's DoDNet migration: DISA's latest market research asks whether industry can migrate all 11 combatant commands' common IT services into DoDNet by September 30, 2028. The questions emphasize a globally deployable workforce and migrations that preserve ongoing operations, following a bid protest and a commitment to revisit the acquisition approach.
  • Navy personnel systems move to cloud: The Navy moved personnel and promotion records, along with more than 50 applications, out of its aging Millington data center. The government-cloud migration adds continuous identity checks, encryption, and geographically distributed backups while reducing dependence on a flood-prone facility.
  • DoD encryption procurement: The department requested software-based protection for military data in transit that can work without replacing or modifying existing hardware. The request calls for government-controlled keys and DoD-approved multifactor authentication, with responses due September 27.
  • GenAI.mil expands its model roster: The Department of War launched ChatGPT Mil and Grok for Government on GenAI.mil on August 31. Both deployments are accredited for controlled unclassified information at Impact Level 5; that approval applies to these government deployments, not their commercial counterparts.
  • Login.gov universal sign-on: OMB Memorandum M-26-18 requires Login.gov on in-scope public-facing authenticated websites, with a one-year deadline for designated high-impact services and two years for other existing in-scope sites. The mandate excludes DoD/DoW, intelligence-community elements, and national security systems, so it is not a replacement order for military enterprise identity.
  • NSA's AI data-triage plans: At the September 8 Billington summit, NSA's cybersecurity chief described using AI to help analysts triage large, disparate data collections and find anomalies. The remarks describe an evaluation and adoption direction, not a measured production speedup or a newly announced authorization.
  • Army acquisition automation: Federal News Network's August 31 report detailed Army MAX testing for turning mission needs into standardized requirements and draft solicitations, with contracting staff reviewing the output. Army cloud integration and broader operations remain planned, and the service did not provide a measured time-saving result from the pilot.

📰 Industry News

  • Telos government risk-management awards: Telos announced expanded Office of Naval Intelligence support using customer-hosted Xacta.io and a NARA deployment of its FedRAMP High-authorized Xacta SaaS. The awards cover continuous monitoring and authorization workflows, with AI-assisted risk analysis included in the NARA offering.
  • GDIT and OpenAI: GDIT joined the OpenAI Partner Network as a Select Partner with plans for federal workflow automation, legacy-system integration, and Codex-assisted application modernization. The announcement targets secure federal environments, including older COBOL and Fortran systems, but does not announce blanket authorization for every model or service.
  • Everfox High Speed Guard: Everfox launched an updated cross-domain appliance for moving high-volume mission data between classification levels. The company says the release completed its NCDSMO baseline test event, allowing agencies to begin environment-specific approval and deployment rather than granting automatic approval everywhere.
  • Palantir TITAN production: The Army awarded Palantir an agreement for eight more TITAN ground stations, split between four Advanced and four Basic systems. The software-defined edge platform combines sensor data from multiple domains and integrates subsystems from several vendors, extending a prototype effort into further production and fielding.
  • Air Force software-delivery partnerships: In Chenega MIOS-sponsored industry analysis, company leaders describe embedded delivery teams and modernization services supporting Air Force hybrid software environments and Kessel Run. This is a vendor perspective on integrating development, deployment, and sustainment, not a newly issued Air Force policy or contract award.

🌐 Community News

  • GPT-6 Astra: OpenAI's September 3 release targets longer coding and computer-use workflows, with API controls for continuing work during tool calls and accepting mid-task corrections. The announcement confirms Zero Data Retention support for eligible API customers and a staged rollout through ChatGPT, the API, Azure, and Bedrock, but does not establish FedRAMP, IL5, or air-gapped availability for Astra.
  • Gemini 3.8 Flash and Flash Cyber: The earlier community rumor is now confirmed: Google announced both models on September 2, including a restricted cyber variant for vulnerability discovery and patching. Its Fairwind program prioritizes trusted government authorities, critical-infrastructure operators, and software maintainers; access is not equivalent to government-cloud authorization.
  • Claude Fable 5.1 and Mythos 5.1: Anthropic's September announcement expands Fable's defensive vulnerability-discovery support and reduces cache-read pricing, while Mythos offers more permissive safeguards through restricted access. Mythos access is currently limited to selected U.S. organizations, and the announcement does not establish general FedRAMP or IL5 availability.
  • OpenClaw 2.0: OpenClaw 2.0 simplifies setup, rebuilds the browser interface, and adds shared cloud sessions alongside memory, automation, and security updates. The open-source, self-managed path remains distinct from its hosted collaboration features.
  • Cypress 16: Cypress 16 enables HTTP/2 by default in Chromium-based browsers and improves typing, visibility checks, and memory handling for long test runs. It also removes bulk environment exposure through Cypress.env() in favor of explicitly requesting sensitive values or exposing non-sensitive configuration.

⚙️ Fun Tools and Reads

  • FeralUI Gradient Builder: This React interface experiment blends soft gradients from traditional Japanese color palettes; the project index was reviewable, but the interactive demo could not be loaded. Explore FeralUI
  • kubectl-ai: This open-source Kubernetes assistant supports local models through Ollama or llama.cpp, providing a self-hosted path for experimenting with natural-language cluster operations. Explore kubectl-ai
  • Docker image optimization: Background read: this guide covers BuildKit caches, secret mounts, layer ordering, and smaller runtime images for more efficient container builds. Read the guide
  • Claude Code subagents on Azure: Background read: this walkthrough uses scoped agents for Bicep reviews, Azure DevOps troubleshooting, AKS security checks, and cost analysis without establishing approval for sensitive government data. Read the walkthrough
  • Terraform AWS Provider 6.0: Background reference, not a new release: HashiCorp's June 2025 guide explains multi-region resources and the migration considerations for reducing aliased provider configurations. Review the release guide
  • Kubernetes runtime security tools: This member-only article's accessible introduction explains why pre-deployment scanning needs runtime detection alongside it; the full five-tool comparison was not accessible for review. Read the article
  • Vercel design.md: Vercel's design workflow combines a reusable guidance file, a constrained stylesheet, and repeatable evaluations to make agent-generated pages more consistent. Read the workflow
  • Terratest: This Go library deploys real infrastructure, checks its behavior, and cleans it up, with helpers for Terraform, containers, Kubernetes, and cloud services that can run in self-managed CI. Explore Terratest