Skip to content
Control Plane Labs

The Control Plane — Week of Mon Sep 21, 2026

Kubernetes PVC idle tracking, S/MIME key changes, GitHub Actions protections, Chrome DevTools updates, a cloud incident review, and a CT certificate sample.

Control Plane Labs Staff

Published September 24, 2026

The useful pattern is explicit state. A storage object can tell you when it became idle. A workflow can declare who may run it. A browser test can record its CPU tier. A certificate monitor can preserve the two timestamps behind its expiry alert. These details turn a broad platform change into a check an operator can run and explain.

Kubernetes and cloud

Kubernetes 1.37 promotes PersistentVolumeClaimUnusedSinceTime to Beta and enables it by default. The Kubernetes announcement describes an Unused condition managed by the PVC protection controller. It is True with reason NoPodsUsingPVC when no non-terminal Pod references the claim, and False with reason PodUsingPVC when at least one running or pending Pod does. A pending Pod counts as a user; completed and failed Pods do not.

The condition’s lastTransitionTime is the useful operational field. It lets a storage controller or review job find claims that have been idle for a chosen period, such as 30 days, without maintaining a separate Pod-to-claim database. Treat it as a candidate signal, not an automatic deletion instruction: validate the workload owner, backup state, reclaim policy, and namespace before removing storage. Use the Kubernetes YAML linter to review the manifests that create the claim and its consuming workload.

TLS and certificates

The CA/Browser Forum’s current S/MIME requirements mark an important boundary for certificate inventories. For Root and Subordinate CA RSA keys created after September 15, 2026, the minimum is now 4096 bits. Subscriber certificates retain a 2048-bit minimum for now, but by September 15, 2027 a CA must not issue Subscriber certificates from a Subordinate CA whose RSA modulus is below 3072 bits.

Keep those classes separate in an inventory. A check that flags every 2048-bit certificate today will produce the wrong remediation list; a check that ignores the issuing CA key will miss the future constraint. Record key creation dates, issuing paths, modulus sizes, and the applications that depend on each intermediate. Let’s Encrypt’s profile documentation also shows why renewal automation matters: its standard profile remains 90 days, while shorter profiles are designed for systems that can renew more frequently.

Security

GitHub made workflow execution protections generally available on September 17. Actor and event rules are evaluated before a run starts, and rules can now target one workflow file rather than an entire repository. That lets an organization restrict deploy.yml to a release team while leaving ordinary CI available to contributors. Evaluate mode and Insights provide a way to measure the effect before enforcement.

The change also deserves a specific pull_request_target review. GitHub is introducing a default rule that disables that event for affected public repositories, initially in evaluate mode, with enforcement scheduled for November 2, 2026. The event can expose base-repository secrets to code from a fork, so a workflow that checks out untrusted code needs a deliberate policy rather than an inherited default. Review event triggers, checkout boundaries, secret contexts, and reusable-workflow permissions. Keep deployment workflows narrow and require an explicit owner for exceptions.

Web development and tooling

Chrome’s move to a two-week Stable cadence changes the size of a browser compatibility window. The Chrome release update says the cadence began with Chrome 153 on September 8, with Chrome 154 scheduled for September 22. The September DevTools update confirms that Chrome 153 and 154 are now Stable and adds full soft-navigation support, CPU performance-tier overrides, and more direct controls for inactive styles and source maps.

For an operator, the answer is a tighter browser matrix rather than a larger pile of screenshots. Run a pinned regression lane, current Stable, and Beta; record the browser build, operating system, and CPU tier with failures. Exercise soft navigation and route transitions, not only first-load performance. When a UI change fronts an API, use the HTTP header inspector to check that caching and security headers remain correct while the browser test moves between channels.

SRE and reliability

Google’s final us-central1 incident report is a useful change-management case study. On September 1, network degradation and instance isolation affected parts of us-central1-b and us-central1-f for 4 hours and 11 minutes. During scheduled router capacity work, incompatible optical transceivers were installed after fiber paths were disconnected; the report says the required light verification step was not followed. Traffic drop rates reached 100% on affected paths, with unreachable VMs, API timeouts, and elevated latency.

The corrective lesson is procedural and testable. A maintenance runbook needs a physical-link verification step, a stop condition when redundant paths disappear, and a canary before the next batch of hardware changes. A service-level review should also separate control-plane health from application reachability: a successful API response does not prove that every zonal data path is usable. Rehearse traffic diversion and record the first observable signal that tells responders the blast radius is expanding.

Chart of the week: observed certificate lifetimes

We queried the currently valid certificate for four public domains in CertIndex on September 24 and calculated not_after - not_before. This is a reproducible sample, not a population estimate. The Certificate Transparency log directory explains the public, append-only ecosystem behind these observations, and CertIndex provides the indexed certificate records.

Host Issuer Not before (UTC) Not after (UTC) Lifetime (days)
google.com Google Trust Services WR2 2026-08-05 20:42 2026-10-28 20:42 84.00
cloudflare.com Google Trust Services WE1 2026-07-08 21:47 2026-10-06 22:47 90.04
github.com Sectigo Public Server Authentication CA DV E36 2026-08-30 00:00 2026-11-27 23:59 90.00
kubernetes.io Let’s Encrypt YE1 2026-08-12 08:23 2026-11-10 08:23 90.00

Three rows are effectively 90 days, while the Google certificate is 84 days. The difference may reflect issuance and renewal policy rather than a trend. Store the validity timestamps, issuer, SAN set, observation time, and certificate fingerprint together. Alert on remaining lifetime and unexpected issuer or SAN changes; an expiry date without its source certificate is hard to investigate.

From the workshop

The workshop produced two practical guides this week. Prometheus no-data alert policy separates an empty query result from a failed scrape and gives each case an explicit response. The curl command builder guide covers shell quoting, payload flags, redirects, and the checks that keep a generated request from being copied blindly into production. Both fit the same operating habit: define the expected state, capture the evidence that distinguishes it, and test the rollback before expanding the change.

For the next review, pair the PVC Unused condition with an owner and retention policy, inspect workflow event rules before the November deadline, and add browser build plus CPU tier to performance reports. Keep the certificate table small enough to reproduce and the incident runbook specific enough to stop a rollout.

Frequently asked questions

What does the Kubernetes PVC Unused condition mean?+
Unused=True with reason NoPodsUsingPVC means no non-terminal Pod references the claim. Unused=False with reason PodUsingPVC means at least one running or pending Pod references it.
What S/MIME key-size change took effect on September 15, 2026?+
Newly created Root and Subordinate CA RSA keys must be at least 4096 bits. Subscriber certificates retain a 2048-bit minimum, with a 3072-bit Sub-CA requirement taking effect in 2027.
What should teams review in GitHub Actions?+
Review actor and event rules, workflow-file targeting, fork checkout boundaries, secret contexts, and any use of pull_request_target. Use evaluate mode before enforcing a change.
How should teams test the faster Chrome release cadence?+
Keep pinned, Stable, and Beta lanes. Record browser build and CPU tier, exercise soft navigation and route transitions, and retain a tested fallback for browser-dependent features.
What was the main lesson from the us-central1 incident?+
Hardware maintenance needs physical-link verification, a stop condition when redundant paths disappear, and a canary before the next batch. Test traffic diversion rather than assuming redundancy is intact.
How were the certificate lifetimes calculated?+
For each currently valid certificate, subtract the not-before timestamp from the not-after timestamp. The result is that certificate's validity period, not an ecosystem-wide average.

Tags: #weekly-recap, #kubernetes, #tls, #security, #sre, #web-development