ar
Feedback
Kubesploit

Kubesploit

الذهاب إلى القناة على Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

إظهار المزيد
2 130
المشتركون
لا توجد بيانات24 ساعات
-37 أيام
+730 أيام
أرشيف المشاركات
Repost from Kube Architect
WaaS creates browser-accessible Linux and Windows desktops as Kubernetes resources, with GitOps workflows, secure remote access, quotas, and OIDC and RBAC controls. More: https://ku.bz/TgntmDfyC

This tutorial teaches how to preserve the real client IP behind an Istio ambient gateway with externalTrafficPolicy: Local and safely read X-Forwarded-For in Go. More: https://ku.bz/JDVmgRYDY

Repost from N/a
Dilshan Wijesooriya, Senior Cloud Engineer at Coolblue, explains how upgrading from Amazon Linux 2 to AL2023 broke their cluster autoscaler due to stricter IMDS (Instance Metadata Service) access controls. The autoscaler had been silently relying on the EC2 instance role instead of having its own pod-level IAM role—a hidden dependency that only surfaced when the AMI changed and blocked access to instance credentials. Watch the full episode: https://ku.bz/T_YPfTfDb

Repost from LearnKube news
Why can a Go service be OOM-killed while its heap looks healthy? The heap is only part of the container's memory usage. Gorou
Why can a Go service be OOM-killed while its heap looks healthy? The heap is only part of the container's memory usage. Goroutine stacks, native allocations, and runtime overhead also count toward the container limit. In this new article from Gulcan, you will learn: - How CPU quotas affect Go's parallelism and why extra threads can increase throttling. - How to measure total container memory, including goroutine stacks and native allocations. - Why a tighter memory budget can increase garbage collection work and reduce throughput. Read: https://learnkube.com/go-kubernetes-requests-limits This article is also included in our book on Kubernetes rightsizing: https://learnkube.com/kubernetes-rightsizing

Repost from N/a
Software supply chain security should not be treated as optional extra work. Przemysław Wojtunik explains how his team moves from build to JFrog, validation with Xray, signing, verification, and only then delivery to the customer, and why he sees that workflow as mandatory. Watch the full interview: https://ku.bz/TJRYGMWV2

This case study shows how an AKS-based GitOps platform gave on-premises clusters workload identity by publishing static OIDC
This case study shows how an AKS-based GitOps platform gave on-premises clusters workload identity by publishing static OIDC discovery and JWKS files, avoiding API server changes after provisioning. More: https://ku.bz/TpvjylBlF

Falco Event Generator creates suspicious system and Kubernetes activity so teams can safely test and benchmark Falco detection rules. More: https://ku.bz/y-WmBKLPS

Repost from N/a
Supply chain security is easier to reason about when it has layers. Meg Sarros frames container trust as scanning, signing, and enforcement. She shows how teams can surface CVEs, prove image provenance, and enforce policy before workloads run. The useful mental model is defense in depth, not a single security checkbox. Watch the full interview: https://ku.bz/k_r1B0Rwj

Wardline is a self-hosted control-plane proxy for AI agents that enforces identity, policy, and budgets while using anomaly detection to block compromised agents and record auditable decisions. More: https://ku.bz/WZY4gnMtW

FQDN Network Policy turns hostnames into current IP addresses and creates standard Kubernetes NetworkPolicy rules, so teams c
FQDN Network Policy turns hostnames into current IP addresses and creates standard Kubernetes NetworkPolicy rules, so teams can control outbound traffic on any CNI without replacing their network plugin. More: https://ku.bz/NprbZjd3s

Repost from N/a
"The next 10 years are going to be boring — in the good sense." Mauro Morales sees Kubernetes entering its maturity phase: more security focus, more compliance, more standardization. The excitement shifts to AI tooling that helps operators manage growing complexity — like projects using Kubernetes to deploy Kubernetes. Boring infrastructure is reliable infrastructure. Watch the full interview: https://ku.bz/8cpgjFfjn

Repost from LearnKube news
This week on Learn Kubernetes Weekly 203: 🔥 Building Modelplane on Crossplane 🚪 Kubernetes Gateway API: Why Ingress Is Bein
This week on Learn Kubernetes Weekly 203: 🔥 Building Modelplane on Crossplane 🚪 Kubernetes Gateway API: Why Ingress Is Being Replaced and Which Gateway Controller to Pick 🛡️ From Fragile VMs to Bulletproof GitOps: Modernizing a DevOps Platform on AWS EKS 💾 How a 500 MB Buffer Killed Our Archival Job, and Why Streaming Fixed It 🎮 How GPU MIG + Kueue Can Transform Multi-Tenant AI Workloads on Kubernetes Read it now: https://kube.today/issues/203 ⭐️ This newsletter is brought to you by LearnKube — understand how Kubernetes works, and what to do when it breaks. Live training with 60% hands-on labs.https://ku.bz/hypSbyc-V

This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 v
This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server. More: https://ku.bz/jgr5PbzgS

Repost from Kube Architect
This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool
This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool definitions and auth as four separate layers, plus the RBAC and deployment work needed before it touches a real cluster. More: https://ku.bz/6c5t89LYj

This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registra
This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registrar, the SecretProviderClass and the provider plugin. It also covers syncing back into a native Kubernetes Secret for env vars. More: https://ku.bz/m70bP2hJs

Repost from LearnKube news
Heading to KubeCon + CloudNativeCon North America? Join us the day before for our first in-person LearnKube community event.
Heading to KubeCon + CloudNativeCon North America? Join us the day before for our first in-person LearnKube community event. We have a full day planned: - A hands-on workshop: diagnose a deliberately broken application with telemetry, then explore how an in-cluster AI SRE agent responds. - Technical sessions and Q&A: Cost Optimization, Bank Grade Kubernetes, and AI Operations. - Lightning talks: featuring Artem Lajko, Diana Todea, and Viktor Farcic. - YAML Games - Drinks, canapes, and time to meet the community. Your hosts are Salman Iqbal, Amin Astaneh, and Bart Farrell. 📅 Monday, November 9, 2026 · 10:00–19:00 MST 📍 Hilton Salt Lake City · Salt Lake City, Utah Thank you to our event sponsors, StormForge by CloudBolt and vCluster, and our community sponsor, Utah Kubernetes Meetup. We can't wait to meet you in Salt Lake City! Register for free: https://learnkube.com/learnkube-day-salt-lake-city-2026

This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it
This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it, and pulls it back out with docker history, jq and tar. More: https://ku.bz/S8r6yFdbS

This article explains how Vault piles up unexpired leases when pods keep re-authenticating with default service tokens, why t
This article explains how Vault piles up unexpired leases when pods keep re-authenticating with default service tokens, why that destabilises the HA cluster, and how batch tokens and shorter TTLs fix it. More: https://ku.bz/Cn61TJM1G

This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime. More: https://ku.bz/YdMc3KBZ6

Repost from LearnKube news
This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌 How We Made Deploying a New Servic
This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌 How We Made Deploying a New Service Boring 🐘 Running Zookeeper on GKE with Local SSD (Z4D) 🚀 Kubernetes v1.36: Mixed Version Proxy Graduates to Beta 🌍 Building a Multi-Region EKS Platform with Crossplane, FluxCD, and GitOps Read it now: https://kube.today/issues/202 ⭐️ This newsletter is brought to you by Buoyant — The Buoyant Enterprise for Linkerd service mesh runs in production at Xbox (22,000 pods), Imagine Learning (40% cross-zone cost cut), and IntelliGRC 4× MRR after FedRAMP https://ku.bz/BwZYjDryv