ar
Feedback
Kubesploit

Kubesploit

الذهاب إلى القناة على Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

إظهار المزيد
2 063
المشتركون
+124 ساعات
+27 أيام
+1830 أيام
أرشيف المشاركات
Repost from LearnKube news
This week on Learn Kubernetes Weekly 176: ⚡ Go on Kubernetes: Why Your p99 Spikes with CFS CPU Throttling, Quotas, and Go 1.2
This week on Learn Kubernetes Weekly 176: ⚡ Go on Kubernetes: Why Your p99 Spikes with CFS CPU Throttling, Quotas, and Go 1.25 🔍 From 10,000 eBPF Events to 1 Alert: Don't Burn the CPU 🤖 Inside a Self-Hosted AI Coding Assistant: Architecture, Kubernetes Deployment, and llama.cpp 🔥 Kubernetes Pod Auto-Scaling: HPA and CDN 🌐 How My Client Hit Linux Kernel Network Limits on AWS EKS Read it now: https://kube.today/issues/176 ⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V

Repost from N/a
Landon Clipp built a GPU Containers as a Service platform from scratch — solving multi-tenant GPU isolation with Kata/QEMU, NVLink fabric partitioning, and Cilium network policies. You will learn: - Why standard NVIDIA tooling fails in multi-tenant setups, and how PCI topology scanning makes GPUs visible to Kubernetes without kernel drivers - How to partition the NVLink fabric between tenants using a trusted service VM running Fabric Manager - What caused 8-GPU VMs to take 30+ minutes to boot, and the fixes that brought it down to minutes Watch (or listen to) it here: https://ku.bz/jjK_yJTDz 🌟 This episode is brought to you by LearnKube — get started on your Kubernetes journey through comprehensive online, in-person or remote training. https://learnkube.com/training With @Birthmarkb

Repost from N/a
Santosh Vallurupalli, Senior Solution Architect at Amazon Web Services, discusses how organizations are solving the tension between rapid container deployments and regulatory compliance requirements. He explains how policy-as-code tools like OPA, Gatekeeper, and Kyverno enable teams to maintain an application security posture without sacrificing deployment velocity through shift-left strategies that integrate compliance checks directly into CI/CD pipelines, providing real-time alerts when applications fail to meet compliance standards at deployment time. Watch the full interview: https://ku.bz/pklYlRr80

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $405K to $485K a yea
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $405K to $485K a year Remote from the United States of America → https://ku.bz/wrrnmcjDQ DevSecOps Engineer with OpenAI 💰 $364.5K to $490K a year Remote from the United States of America → https://ku.bz/NXd17JHfV DevSecOps Engineer with Faire 💰 $268K to $368.5K a year Remote from the United States of America, Canada, the United Kingdom (+1 more) → https://ku.bz/6dD8HVYdT DevSecOps Engineer with Aurora Innovation 💰 $275K to $352K a year Hybrid in Seattle, WA, USA → https://ku.bz/xPft28bGc DevSecOps Engineer with Perplexity 💰 $220K to $405K a year Fully remote → https://ku.bz/rnYh0TMpt 👉 Browse 3785 jobs on Kube Careers https://kube.careers

Repost from LearnKube news
This week on Learn Kubernetes Weekly 175: 💰 Advanced Kubernetes: Cost-Aware Scheduling for Multi-Cluster Optimization with C
This week on Learn Kubernetes Weekly 175: 💰 Advanced Kubernetes: Cost-Aware Scheduling for Multi-Cluster Optimization with Custom Metrics 📐 System Design Series: Scaling Kubernetes Workloads with Vertical Pod Autoscaler 🕸️ Service Mesh Patterns: The Invisible Network That Makes Microservices Work 🐛 Troubleshooting Conan: ZFS ARC Container Initialization Slowness 🍓 Developing on Raspberry Pi Read it now: https://kube.today/issues/175 ⭐️ This newsletter is brought to you by vCluster — join the free livestream on March 19 to learn how to enforce policies across multi-tenant Kubernetes at scale https://lnkd.in/g7jj-CtZ

Repost from N/a
Ron Matsliah from Next Insurance built an AI assistant that cut build debugging time by 75% — combining deterministic rules with AI, delivered straight into Slack. You will learn: - Why combining deterministic rules with AI produces better results than letting an LLM guess alone - How correlating Kubernetes events with build logs catches spot instance terminations that produce misleading errors - Why integrating into existing workflows and building feedback loops from day one drove adoption - The prompt engineering lessons learned from testing with real production data instead of synthetic examples Watch (or listen to) it here: https://ku.bz/PDdYfC00w 🌟 This episode is brought to you by LearnKube — get started on your Kubernetes journey through comprehensive online, in-person or remote training. https://learnkube.com/training With @Birthmarkb

Repost from N/a
Mike Stefaniak, Head of Product, Kubernetes and Registries at Amazon Web Services (AWS), shares three key trends he's observing at KubeCon that are shaping the future of Kubernetes deployments: 1. How security and trust are becoming critical differentiators in open source projects 2. The resurgence of service mesh communication patterns, particularly around routing models and enabling communication between multiple agents within clusters. 3. The growing need for more sophisticated authorization mechanisms in Kubernetes to handle the actions that AI agents and MCP (Model Context Protocol) tools might take Watch the full interview: https://ku.bz/PzjrglcZJ

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $40.5M to $48.5M a y
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $40.5M to $48.5M a year 🏠 From the office in San Francisco, CA, USA → https://ku.bz/wrrnmcjDQ DevSecOps Engineer with Tailscale 💰 $16.1M to $20.14M a year 🌎 Fully remote → https://ku.bz/J9Cs7QBBp DevSecOps Engineer with Accenture Federal Services 💰 $11.49M to $15.13M a year 👨‍💻 Remote from → https://ku.bz/bsl59cPMh DevSecOps Engineer with OpenAI 💰 $364.5K to $490K a year 👨‍💻 Remote from the United States of America → https://ku.bz/NXd17JHfV DevSecOps Engineer with Faire 💰 $268K to $368.5K a year 🏠 From the office in San Francisco, CA, USA → https://ku.bz/Lt703grhh 👉 Browse 2543 jobs on Kube Careers https://kube.careers

Repost from LearnKube news
This week on Learn Kubernetes Weekly 174: 🤖 How We Cut Build Debugging Time by 75% with a DevEx AI Assistant 🔥 We Cut Our K
This week on Learn Kubernetes Weekly 174: 🤖 How We Cut Build Debugging Time by 75% with a DevEx AI Assistant 🔥 We Cut Our Kubernetes Pods by 60% and Doubled Traffic Capacity 📈 Scaling Django SaaS to 1M Users: Async ORM, Caching, and Horizontal Pods ⚠️ Hidden Kubernetes Bad Practices Learned the Hard Way During Incidents 🥷 Kubernetes PKI & Kubelet Credential Abuse: From Popping a Pod to Owning the Cluster Read it now: https://kube.today/issues/174 ⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V

This article shows how to use tofu-controller to manage Terraform resources with GitOps for external systems like Grafana das
This article shows how to use tofu-controller to manage Terraform resources with GitOps for external systems like Grafana dashboards and HashiCorp Vault policies with continuous reconciliation and automatic drift detection. More: https://ku.bz/B3y_Zflr7

Repost from N/a
Fernando from SadServers on how he cut his Kubernetes bill from $1,000/month on GKE to $30/month on Hetzner with Edka — a 500% cost reduction for the same capacity. You will learn: - Why Kubernetes hasn't delivered on its original promise of cost savings through bin packing — and what it actually provides instead - A real cost comparison: $1,000/month on GKE vs. $30/month on Hetzner with Edka for the same nominal capacity - What you need to bring with you (observability, logging, dashboards) when leaving a fully managed cloud provider Watch (or listen to) it here: https://ku.bz/6nSDbz9m4 🌟 This episode is brought to you by LearnKube — get started on your Kubernetes journey through comprehensive online, in-person or remote training https://learnkube.com/training With @Birthmarkb

Linnix is an eBPF + PSI-powered Kubernetes observability agent written in Rust that identifies which pod is actually stalling your services, not just consuming CPU. More: https://ku.bz/x-VQLHwSW

Repost from N/a
Zero trust in Kubernetes works best as a layered model, not a single toggle. Abhishek Rao breaks down a phased approach: start with micro-segmentation, add identity with mTLS, and enforce cluster-level ingress and egress controls. This creates security boundaries teams can reason about and maintain. Strong security comes from structure, not one-off rules. Watch the full interview: https://ku.bz/_q9XBgY2c This interview is a reaction to John Howard's episode https://ku.bz/sk-ZF1PG9

This article solves automated certificate distribution for EAP-TLS WiFi authentication using nginx-proxy on Kubernetes with s
This article solves automated certificate distribution for EAP-TLS WiFi authentication using nginx-proxy on Kubernetes with step-ca, avoiding traditional MDM by hosting mobileconfig files at an HTTPS endpoint with mTLS authentication. More: https://ku.bz/spclMhjDz

Repost from N/a
Spectro Cloud just announced Hadron Linux — a brand new Linux distribution engineered from scratch by the Kairos team. Ettore Di Giacinto explains: Hadron is purpose-built as a minimal, immutable base layer for edge infrastructure. Unlike retrofitted general-purpose distributions, it is specifically designed to eliminate common friction points when deploying Kubernetes at scale. The goal: a Linux foundation that treats edge as a first-class target, not an afterthought. Watch the announcement: https://ku.bz/wMhKpZ5bQ Read the announcement: https://ku.bz/_9RmXnjDJ

cek is a command-line tool for exploring OCI container image filesystems, reading file contents, and inspecting layer mechanics without running containers by connecting to container daemons or pulling from registries. More: https://ku.bz/VWLLdYCbb

Repost from N/a
Nicholaos Mouzourakis, Staff Product Security Engineer at Gusto, breaks down the common deployment patterns for Open Policy Agent (OPA) in Kubernetes environments. He explains the tradeoffs between individual pods, auto-scaling groups, daemon sets, sidecars, and WASM modules. He outlines critical considerations for selecting the right deployment option: - Latency requirements - Bandwidth constraints - Development overhead - Feature compatibility (noting WASM modules lack full standard library support) - Cloud costs and policy size implications He notes that co-located pods typically achieve a few milliseconds of latency, and suggests WASM modules for those requiring even better performance. Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $40.5M to $48.5M a y
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Anthropic 💰 $40.5M to $48.5M a year 🏠 From the office in San Francisco, CA, USA → https://ku.bz/wrrnmcjDQ DevSecOps Engineer with Tailscale 💰 $15.96M to $19.97M a year 🌎 Fully remote → https://ku.bz/J9Cs7QBBp DevSecOps Engineer with Accenture Federal Services 💰 $11.49M to $15.13M a year 👨‍💻 Remote from → https://ku.bz/bsl59cPMh DevSecOps Engineer with OpenAI 💰 $364.5K to $490K a year 👨‍💻 Remote from the United States of America → https://ku.bz/NXd17JHfV DevSecOps Engineer with Faire 💰 $268K to $368.5K a year 🏠 From the office in San Francisco, CA, USA → https://ku.bz/Lt703grhh 👉 Browse 2459 jobs on Kube Careers https://kube.careers

This article demonstrates how to exploit Kubernetes PKI and kubelet credentials after gaining node access to escalate from po
This article demonstrates how to exploit Kubernetes PKI and kubelet credentials after gaining node access to escalate from pod compromise to full cluster control. More: https://ku.bz/NxVxjKtt0

Repost from Kube Builders
pwru is an eBPF-based tool for tracing network packets in the Linux kernel with advanced filtering capabilities. It allows fine-grained introspection of kernel state to facilitate debugging network connectivity issues. More: https://ku.bz/Q3X1ngZGC