kOps
kOps is tightening cluster defaults and dropping the platforms it no longer wants to carry.
A side-by-side editorial comparison of KubeArmor and Gloo Gateway — release velocity, themes, recent moves, and the top alternatives to consider.
Every release in the feed is a candidate — the stable line is decided elsewhere.
KubeArmor's tracked feed contains only release candidates: three for 1.7.4 and one for 1.7.5, with no stable tag among them. The work divides into eBPF-level observability (DNS visibility moved from udp_sendmsg to udp_send_skb, DNS support and a verifier for kernel 6.17), platform compatibility (Ubuntu 26.04, openEuler 24.03 LTS-SP3, RHEL kernel iov handling), and supply-chain scoring — Renovate integration, workflow token permissions and provenance generation explicitly aimed at OpenSSF Scorecard numbers. Contribution is broad, with a dozen or more named authors per candidate.
One status-churn fix, shipped to four maintenance branches inside forty minutes.
Gloo maintains four release lines at once — 1.18, 1.19, 1.20 and 1.21 — plus a 1.22 beta series, and fixes are fanned across all of them together. On 5 August, v1.18.41, v1.19.20, v1.20.22 and v1.21.13 were cut within forty-five minutes of each other carrying the same Kubernetes Gateway report-churn fix and the same Go, gRPC and kubectl dependency bumps.
KubeArmor's tracked feed contains only release candidates: three for 1.7.4 and one for 1.7.5, with no stable tag among them. The work divides into eBPF-level observability (DNS visibility moved from udp_sendmsg to udp_send_skb, DNS support and a verifier for kernel 6.17), platform compatibility (Ubuntu 26.04, openEuler 24.03 LTS-SP3, RHEL kernel iov handling), and supply-chain scoring — Renovate integration, workflow token permissions and provenance generation explicitly aimed at OpenSSF Scorecard numbers. Contribution is broad, with a dozen or more named authors per candidate.
Kernel-version chase is the dominant constraint. An eBPF enforcement agent has to track kernel internals release by release, and a meaningful share of each candidate goes to keeping probes attached across new kernels and distributions rather than adding policy capability. The one genuine capability attempt in this window — TLD and subdomain enforcement — was merged and then reverted within the same release candidate, which suggests network-identity policy is being worked on and is not yet stable.
Expect TLD and subdomain enforcement to return once the regression behind the revert is resolved, and continued kernel and distribution matrix expansion. Whether 1.7.4 ever reached a stable tag is not visible in this feed.
Gloo maintains four release lines at once — 1.18, 1.19, 1.20 and 1.21 — plus a 1.22 beta series, and fixes are fanned across all of them together. On 5 August, v1.18.41, v1.19.20, v1.20.22 and v1.21.13 were cut within forty-five minutes of each other carrying the same Kubernetes Gateway report-churn fix and the same Go, gRPC and kubectl dependency bumps.
The recurring theme is translation correctness under Kubernetes Gateway API — specifically, bugs where the translator's internal state does not behave the way its callers assume. The report-churn fix found equality checks comparing maps of pointer values, so identical output registered as changed on every recompute. The delegateOptions fix in beta11 found RouteOptions assigned by reference from the snapshot, so merging parent Virtual Service options mutated shared protos and contaminated every other route for the rest of the cycle. Both ship with the same instinct for caution: the second one is gated behind GLOO_ISOLATE_DELEGATE_ROUTE_OPTIONS so operators can revert.
The 1.22 beta line will keep collecting Gateway API translation fixes ahead of a stable release, and each one that matters will be backported across all four maintenance branches on the same day, as this window shows twice.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either KubeArmor or Gloo Gateway.
kOps is tightening cluster defaults and dropping the platforms it no longer wants to carry.
Headlamp's feed is mostly chart bumps; the plugin toolchain is where the actual work shows.
Kubeshark rebuilt its backend for V2 and is redrawing the free tier around it.
Certbot is rebuilding its API around identifiers so certificates aren't only for domain names.
electerm now ships its own free AI backend, turning a terminal client into an assistant surface.
Apptainer 1.5 adds CDI device support and builds SIF images straight from Dockerfiles.
See all KubeArmor alternatives → · See all Gloo Gateway alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Gloo Gateway is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Gloo Gateway is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top KubeArmor alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "KubeArmor alternatives" section above for the current picks, or visit /alternatives/kubearmor for the full list with editorial commentary on each.
Top Gloo Gateway alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Gloo Gateway alternatives" section above for the current picks, or visit /alternatives/gloo for the full list with editorial commentary on each.