Find upstream work
worth doing.

A curated list of cloud-native and platform-engineering issues—Kubernetes, IaC, GitOps, observability, and more—ranked against Simar’s real skills, not just a language filter.

1002open opportunities
Last checked
3 Sept, 13:36 IST
Feed last changed
3 Sept
Matching against your profile
AWS IAM and IRSAAWS compute and node lifecycleAmazon EKSCI/CD pipelinesCloud developer workspacesGitOpsGoGrafana and Prometheus observabilityHelmKeycloak and OIDCKubernetes and operatorsKubernetes networking and ingressKubernetes storage and CSITerraform
01Curate

Search trusted cloud-native and platform-engineering projects using maintainer-approved contribution labels.

02Explain

Rank with transparent domain, skill, and contribution-shape matches.

03Contribute

Track your progress locally—every interaction with upstream remains yours.

GitHub status syncOptional · 0 linked PRs

Paste a fine-grained token with public-repository read access to check your linked PRs. Browsing, manual tracking, and the public journey work without it.

The token stays in this browser tab and is sent only to api.github.com. Clear it before leaving a shared device.

Opportunity feed

Ranked for you

30 of 1002 shown

Getting Client.InvalidLaunchTemplateName.NotFoundException For Automatically Deleted Launch Template

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, Grafana and Prometheus observability, Helm, Kubernetes and operators, Kubernetes networking and ingress and Kubernetes storage and CSI; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Kubernetes storage and CSIskill+1
  • Bug fixshape+1

Reconciler error after 1.10 upgrade

Infrastructure As CodeKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: Infrastructure as code, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, Grafana and Prometheus observability, Keycloak and OIDC, Kubernetes and operators, Kubernetes storage and CSI and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • Platform toolingdomain+2
  • Infrastructure as codedomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes and operatorsskill+1
  • Grafana and Prometheus observabilityskill+1
  • Kubernetes storage and CSIskill+1
  • Terraformskill+1
  • Bug fixshape+1
cilium/cilium#36603CNCF seed

`toGroups` network policy feature only works with `eni.enabled`

Kubernetes ControllersPlatform ToolingService MeshBug Fix

Matches your domain: Kubernetes controllers, Platform tooling and Service mesh; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators, Kubernetes networking and ingress and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • Service meshdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
  • Bug fixshape+1

EC2 controller does not seem to remediate instance

Aws EcosystemKubernetes Controllers

Matches your domain: AWS ecosystem and Kubernetes controllers; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, GitOps, Grafana and Prometheus observability, Helm, Kubernetes and operators, Kubernetes networking and ingress, Kubernetes storage and CSI and Terraform.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • GitOpsskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Kubernetes storage and CSIskill+1
  • Terraformskill+1
keycloak/keycloak#42627Curated seed

Seaching users in LDAP does not scale well due to ignoring local users when processing entries returned from LDAP

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, CI/CD pipelines, Grafana and Prometheus observability, Helm, Keycloak and OIDC and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • CI/CD pipelinesskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Grafana and Prometheus observabilityskill+1
  • Terraformskill+1
  • Bug fixshape+1
cilium/cilium#35404CNCF seed

Ciliumnode stuck on ipam AWS ENI

Kubernetes ControllersPlatform ToolingService MeshBug Fix

Matches your domain: Kubernetes controllers, Platform tooling and Service mesh; skills: AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators, Kubernetes networking and ingress and Kubernetes storage and CSI; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • Service meshdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Kubernetes storage and CSIskill+1
  • Bug fixshape+1
cilium/cilium#38563CNCF seed

commonName and dns are statically wrong in hubble tls-certmanager helm template

Kubernetes ControllersPlatform ToolingService MeshBug FixChart Config

Matches your domain: Kubernetes controllers, Platform tooling and Service mesh; skills: Grafana and Prometheus observability, Helm, Kubernetes and operators, Kubernetes networking and ingress and Kubernetes storage and CSI; preferred work: Bug fix and Chart or configuration.

Why this score
  • Kubernetes controllersdomain+2
  • Service meshdomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Kubernetes storage and CSIskill+1
  • Bug fixshape+1
  • Chart or configurationshape+1

Clearer Install Instructions, Including for existing EKS Clusters

Aws EcosystemKubernetes ControllersPlatform ToolingDocs

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators and Terraform; preferred work: Documentation.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
  • Terraformskill+1
  • Documentationshape+1
cilium/cilium#32489CNCF seed

Problems with CoreDNS resolutions when BPF host routing is enabled

Kubernetes ControllersPlatform ToolingService MeshBug Fix

Matches your domain: Kubernetes controllers, Platform tooling and Service mesh; skills: Grafana and Prometheus observability, Helm, Kubernetes and operators, Kubernetes networking and ingress and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • Service meshdomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Terraformskill+1
  • Bug fixshape+1

Cert-manager certificate rotation may lead to downtime of webhooks for up to 90s

Infrastructure As CodeKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: Infrastructure as code, Kubernetes controllers and Platform tooling; skills: Helm, Kubernetes and operators, Kubernetes networking and ingress, Kubernetes storage and CSI and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • Platform toolingdomain+2
  • Infrastructure as codedomain+2
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Kubernetes storage and CSIskill+1
  • Terraformskill+1
  • Bug fixshape+1

InvalidBlockDeviceMapping (and other errors) are treated as validateRunInstancesAuthorization error, conditions do not expose error

Aws EcosystemKubernetes ControllersPlatform ToolingBug FixFeature

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, GitOps, Helm, Kubernetes and operators and Kubernetes storage and CSI; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • GitOpsskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes storage and CSIskill+1
  • Bug fixshape+1
keycloak/keycloak#46575Curated seed

Clustered LDAP: Component update triggers concurrent KEYCLOAK_GROUP inserts causing duplicate key violations

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Helm, Keycloak and OIDC, Kubernetes networking and ingress and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
  • Bug fixshape+1

Karpenter incorrectly calculates Node's memory allocable due kubeReserve assumptions

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Terraformskill+1
  • Bug fixshape+1
argoproj/argo-cd#19928CNCF seed

Add warning log if ARGOCD_CONTROLLER_REPLICAS greater than configured replicas

Gitops DeliveryPlatform ToolingFeature

Matches your domain: GitOps and delivery and Platform tooling; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, GitOps, Helm, Kubernetes and operators, Kubernetes networking and ingress and Terraform.

Why this score
  • GitOps and deliverydomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • GitOpsskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
keycloak/keycloak#43855Curated seed

LDAP authentication test with valid credentials results in bind account locked out in Active Directory

Identity AccessPlatform ToolingSecurity Policy

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Grafana and Prometheus observability, Helm, Keycloak and OIDC, Kubernetes networking and ingress and Terraform.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Terraformskill+1

bottlerocket custom cluster-dns-ip doesn't work in ec2nodeclass userdata

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators and Kubernetes networking and ingress; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Bug fixshape+1
keycloak/keycloak#12278Curated seed

LDAP user sync causes duplicate Component Config table rows

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Amazon EKS, Keycloak and OIDC, Kubernetes networking and ingress and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Amazon EKSskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#30938Curated seed

Federated users cannot delete groups they are a member of with LDAP_ONLY mode

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, CI/CD pipelines, Helm, Keycloak and OIDC and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • CI/CD pipelinesskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#39646Curated seed

Slow User query in UI with wildcard search request

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Grafana and Prometheus observability, Keycloak and OIDC, Kubernetes and operators and Kubernetes networking and ingress; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Grafana and Prometheus observabilityskill+1
  • Bug fixshape+1

Bottlerocket imageGCHighThresholdPercent

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators and Kubernetes storage and CSI; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes storage and CSIskill+1
  • Bug fixshape+1

LoadBalancer creation fails with "Multiple untagged security groups found" when following the Getting Started Guide

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, Helm, Kubernetes and operators and Kubernetes networking and ingress; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Bug fixshape+1
cilium/cilium#38828CNCF seed

Kubevirt and route-mtu don't play well: better documentation needed

Kubernetes ControllersPlatform ToolingService MeshDocs

Matches your domain: Kubernetes controllers, Platform tooling and Service mesh; skills: Helm, Keycloak and OIDC, Kubernetes and operators, Kubernetes networking and ingress and Terraform; preferred work: Documentation.

Why this score
  • Kubernetes controllersdomain+2
  • Service meshdomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
  • Documentationshape+1

Tagged helm chart values in `values.yaml` don't match image tag

Aws EcosystemKubernetes ControllersPlatform ToolingBug Fix

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: Helm, Kubernetes and operators, Kubernetes storage and CSI and Terraform; preferred work: Bug fix.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • Kubernetes and operatorsskill+1
  • Kubernetes storage and CSIskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#51831Curated seed

CORS Origin validation rejects non-browser token requests (direct grant, client credentials)

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Keycloak and OIDC, Kubernetes networking and ingress and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes networking and ingressskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#51682Curated seed

Exceptions in Kubernetes federated-client-authentication signature verification are silently swallowed with no default-level log trace

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Keycloak and OIDC, Kubernetes and operators and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Kubernetes and operatorsskill+1
  • Terraformskill+1
  • Bug fixshape+1

DaemonSet pods can remain Pending when workload pods consume Karpenter-calculated DaemonSet overhead on new nodes

Aws EcosystemKubernetes ControllersPlatform Tooling

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS compute and node lifecycle, Amazon EKS, CI/CD pipelines, Grafana and Prometheus observability and Kubernetes and operators.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • CI/CD pipelinesskill+1
  • Amazon EKSskill+1
  • Kubernetes and operatorsskill+1
  • Grafana and Prometheus observabilityskill+1

AWS Auth Failures Should Be added to Readiness

Aws EcosystemKubernetes ControllersPlatform ToolingFeature

Matches your domain: AWS ecosystem, Kubernetes controllers and Platform tooling; skills: AWS IAM and IRSA, AWS compute and node lifecycle, Amazon EKS, Helm and Kubernetes and operators.

Why this score
  • Kubernetes controllersdomain+2
  • AWS ecosystemdomain+2
  • Platform toolingdomain+2
  • AWS compute and node lifecycleskill+1
  • Amazon EKSskill+1
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Kubernetes and operatorsskill+1
keycloak/keycloak#49300Curated seed

UsernameTemplateMapper is overridden by realm setting "Email as username"

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Helm, Keycloak and OIDC and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#49299Curated seed

Microsoft identity provider does not expose ID token claims to mappers

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Helm, Keycloak and OIDC and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Terraformskill+1
  • Bug fixshape+1
keycloak/keycloak#35059Curated seed

Client-initiated account linking fails when user already has a federated identity

Identity AccessPlatform ToolingSecurity PolicyBug Fix

Matches your domain: Identity and access, Platform tooling and Security and policy; skills: AWS IAM and IRSA, Helm, Keycloak and OIDC and Terraform; preferred work: Bug fix.

Why this score
  • Identity and accessdomain+2
  • Security and policydomain+2
  • Platform toolingdomain+2
  • Helmskill+1
  • AWS IAM and IRSAskill+1
  • Keycloak and OIDCskill+1
  • Terraformskill+1
  • Bug fixshape+1