Kubesploit
前往频道在 Telegram
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
显示更多2 132
订阅者
无数据24 小时
+27 天
+1730 天
帖子存档
2 132
Learn how to use x509 certificates to authenticate users in your cluster
Read on https://cloudhero.io/creating-users-for-your-kubernetes-cluster
2 132
Helm-scanner is a tool designed to automate discovering, templating, security scanning, then recording and providing easy access to the results for publicly available Helm charts
Read on https://github.com/bridgecrewio/helm-scanner/
2 132
The Top 5 Kubernetes Admission Control Policies:
- Trusted Repo
- Label Safety
- Privileged Mode
- Ingress
- Egress
More: https://blog.styra.com/blog/open-policy-agent-the-top-5-kubernetes-admission-control-policies
2 132
The right way to authenticate to your clusters from your CI/CD pipelines
Read more: https://tremolosecurity.com/post/pipelines-and-kubernetes-authentication
2 132
Learn how to use the nginx-ingress controller to restrict access by IP (ip whitelisting) for a service deployed to a Kubernetes (AKS) cluster
More: https://medium.com/@maninder.bindra/using-nginx-ingress-controller-to-restrict-access-by-ip-ip-whitelisting-for-a-service-deployed-to-bd5c86dc66d6
2 132
Reverse Engineering a Docker Image
More: https://theartofmachinery.com/2021/03/18/reverse_engineering_a_docker_image.html
2 132
The CVE-2021-20291 medium-level vulnerability has been found in containers/storage Go library, leading to Denial of Service (DoS) when vulnerable container engines pull an injected image from a registry.
→ https://sysdig.com/blog/cve-2021-20291-cri-o-podman
2 132
10 Kubernetes Security Context settings you should understand
Read more https://snyk.io/blog/10-kubernetes-security-context-settings-you-should-understand
2 132
A detailed guide to help you to ensure that only signed images can get deployed on the cluster (with OPA and Notary)
Read on https://siegert-maximilian.medium.com/ensure-content-trust-on-kubernetes-using-notary-and-open-policy-agent-485ab3a9423c
2 132
The worst so-called “best practice” for Docker
Read on: https://pythonspeed.com/articles/security-updates-in-docker
2 132
KubeEye is an open-source diagnostic tool for identifying various Kubernetes cluster issues automatically, such as misconfigurations, unhealthy components and node failures
Read more https://github.com/kubesphere/kubeeye
2 132
Learn how to set up K0s in air-gapped environment
More: https://itnext.io/k0s-cluster-without-internet-access-ac0dda08aa63?source=friends_link
2 132
An alternative approach to Secrets management in Helm 3
Read on: https://itnext.io/helm-3-secrets-management-4f23041f05c3?source=friends_link
2 132
This blog post is about an experiment to automate creation of Kubernetes Network Policies based on actual network traffic captured from applications running on a Kubernetes cluster
More: https://itnext.io/generating-kubernetes-network-policies-by-sniffing-network-traffic-6d5135fe77db
2 132
Kubestriker is a platform-agnostic tool designed to tackle Kuberenetes cluster security issues due to misconfigurations
→ https://github.com/vchinnipilli/kubestriker
2 132
cosign is a tool that can sign container images. Cosign supports:
- Hardware and KMS signing
- Bring-your-own PKI
- Our free OIDC PKI (Fulcio)
→ https://github.com/sigstore/cosign
2 132
kubectl-whisper-secret plugin allows users to create secrets with secure input prompt to prevent information leakages through terminal history, shoulder surfing attacks, etc.
👉 https://github.com/rewanth1997/kubectl-whisper-secret
2 132
awesome-kubernetes-security Awesome a curated list of awesome Kubernetes security resources.
👉 https://github.com/ksoclabs/awesome-kubernetes-security
2 132
Preflight is a tool to automatically perform Kubernetes cluster configuration checks using Open Policy Agent (OPA).
More https://github.com/jetstack/preflight
2 132
The kube-secrets-init is a Kubernetes mutating admission webhook, that mutates any K8s Pod that is using specially prefixed environment variables, directly or from Kubernetes as Secret or ConfigMap
👉 https://github.com/doitintl/kube-secrets-init
