ch
Feedback
Kubesploit

Kubesploit

前往频道在 Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

显示更多
2 132
订阅者
+124 小时
无数据7 天
+1430 天
帖子存档
A HIGH severity vulnerability was found in Kubernetes in which users may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem More: https://armosec.io/blog/kubescape-checks-if-kubernetes-exposed-to-k8s-symlink-vulnerability-cve202125741

Verifying Container image signatures in Kubernetes using Notary or Cosign or both More https://medium.com/sse-blog/verify-con
Verifying Container image signatures in Kubernetes using Notary or Cosign or both More https://medium.com/sse-blog/verify-container-image-signatures-in-kubernetes-using-notary-or-cosign-or-both-c25d9e79ec45

Kubernetes Network Policies for isolating Namespaces Read on https://loft.sh/blog/kubernetes-network-policies-for-isolating-namespaces

2 Widespread attacks (Man-in-the-Middle, Cryptojacking attack) on your containerized wnvironment and 7 rules to prevent it Re
2 Widespread attacks (Man-in-the-Middle, Cryptojacking attack) on your containerized wnvironment and 7 rules to prevent it Read more: https://itnext.io/2-widespread-attacks-on-your-containerized-environment-and-7-rules-to-prevent-it-957aa7dfa5e0

Enforcing image trust on Docker containers using Notary More https://infracloud.io/blogs/enforcing-image-trust-docker-containers-notary

The ClusterSecret operator makes sure that all the matching namespaces have a secret available. New namespaces, if they match
The ClusterSecret operator makes sure that all the matching namespaces have a secret available. New namespaces, if they match a pattern, will also have the secret. Any change on the ClusterSecret will update all related secrets Read more https://github.com/zakkg3/ClusterSecret

Kubestriker is a platform-agnostic tool designed to tackle Kuberenetes cluster security issues due to misconfigurations and w
Kubestriker is a platform-agnostic tool designed to tackle Kuberenetes cluster security issues due to misconfigurations and will help strengthen the overall IT infrastructure of any organisation More https://github.com/vchinnipilli/kubestriker

Connaisseur is a Kubernetes admission controller to integrate container image signature verification and trust pinning into a
Connaisseur is a Kubernetes admission controller to integrate container image signature verification and trust pinning into a cluster More https://github.com/sse-secure-systems/connaisseur

gsm-controller is a Kubernetes controller that copies secrets from Google Secrets Manager into Kubernetes secrets. The controller watches Kubernetes secrets looking for an annotation, if the annotation is not found on the secret nothing more is done More https://github.com/jenkins-x/gsm-controller

HashiCorp Vault provider for the Secrets Store CSI driver allows you to get secrets stored in Vault and use the Secrets Store CSI driver interface to mount them into Kubernetes pods Read more https://github.com/hashicorp/vault-csi-provider

Google Secret Manager Provider for Secret Store CSI Driver allows you to access secrets stored in Secret Manager as files mounted in Kubernetes pods. More https://github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp

Can you jailbreak rootless Docker-in-Docker? Read more https://gist.github.com/protosam/0d263bba98d45601df022b70ef308dbf

Best practices for cluster isolation in Azure Kubernetes Service (AKS) → https://docs.microsoft.com/en-us/azure/aks/operator-
Best practices for cluster isolation in Azure Kubernetes Service (AKS) → https://docs.microsoft.com/en-us/azure/aks/operator-best-practices-cluster-isolation

How to inject secrets from AWS, GCP, or Vault into a Kubernetes Pod More: https://blog.doit-intl.com/injecting-secrets-from-aws-gcp-or-vault-into-a-kubernetes-pod-d5a0e84ba892

In this blog, you'll explore different container isolation techniques and whether their strengths and weaknesses make them a
In this blog, you'll explore different container isolation techniques and whether their strengths and weaknesses make them a practical choice 👉 https://blog.aquasec.com/container-isolation-techniques

Azure Key Vault to Kubernetes (akv2k8s) makes Azure Key Vault secrets, certificates and keys available in Kubernetes and/or y
Azure Key Vault to Kubernetes (akv2k8s) makes Azure Key Vault secrets, certificates and keys available in Kubernetes and/or your application - in a simple and secure way Read more https://akv2k8s.io/

Top 9 open source DevSecOps Tools for Kubernetes: 1. Anchore 2. Checkov 3. Clair 4. Falco … More: https://stackrox.io/blog/top-9-open-source-devsecops-tools-for-kubernetes

State of Cloud Native Application Security: how cloud native adoption transforms the way organizations defend against security threats More: https://snyk.io/state-of-cloud-native-application-security