en
Feedback
Kubesploit

Kubesploit

Open in Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Show more
2 132
Subscribers
No data24 hours
+27 days
+1730 days
Posts Archive
Kubernetes Network Policies: a practitioner's guide More: https://loft.sh/blog/kubernetes-network-policies-a-practitioners-guide

In this article you will learn how to secure Containers with Cosign and Distroless images Read on: https://infracloud.io/blog
In this article you will learn how to secure Containers with Cosign and Distroless images Read on: https://infracloud.io/blogs/secure-containers-cosign-distroless-images

Scheduled backup of Vault secrets with Jenkins on Kubernetes Read more https://igorzhivilo.com/vault/scheduled-backup-vault-s
Scheduled backup of Vault secrets with Jenkins on Kubernetes Read more https://igorzhivilo.com/vault/scheduled-backup-vault-secrets

Kubernetes API Access Security Hardening šŸ‘‰ https://goteleport.com/blog/kubernetes-api-access-security
Kubernetes API Access Security Hardening šŸ‘‰ https://goteleport.com/blog/kubernetes-api-access-security

Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam Read on https://github.com/walidshaari/Certified-Kubernetes-Security-Specialist

Kubestriker is a platform-agnostic tool designed to tackle Kubernetes cluster security issues due to misconfigurations and will help strengthen the overall IT infrastructure of any organisation → https://github.com/vchinnipilli/kubestriker

Quick update! We’ve updated the Kubernetes troubleshooting flowchart to include translations in Spanish, Mandarin, Korean and
Quick update! We’ve updated the Kubernetes troubleshooting flowchart to include translations in Spanish, Mandarin, Korean and Portuguese. Many thanks to @elnemesisdivina @yorchveintemil @usernametoken Marcelo & Hoon Jo! šŸ‘šŸ‘šŸ‘ You can download the poster here: https://learnk8s.io/troubleshooting-deployments

Peirates, a Kubernetes penetration tool, enables an attacker to escalate privilege and pivot through a Kubernetes cluster Rea
Peirates, a Kubernetes penetration tool, enables an attacker to escalate privilege and pivot through a Kubernetes cluster Read on https://github.com/inguardians/peirates

ā€œAnother LDAPā€ provides Authentication and Authorization for your applications running on Kubernetes šŸ‘‰ https://github.com/di
ā€œAnother LDAPā€ provides Authentication and Authorization for your applications running on Kubernetes šŸ‘‰ https://github.com/dignajar/another-ldap

Vault-CRD is a custom resource definition for holding secrets that are stored in HashiCorp Vault and kept up to date with Kubernetes secrets Read more: https://github.com/DaspawnW/vault-crd

Curiefense extends Envoy proxy to defend against a variety of threats, including SQL and command injection, cross site scripting (XSS), account takeovers (ATOs) and more Read on https://github.com/curiefense/curiefense

Kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by NSA and CISA More: https://github.com/armosec/kubescape

This repository contains various use cases of Kubernetes Network Policies and sample YAML files to leverage in your setup. If
This repository contains various use cases of Kubernetes Network Policies and sample YAML files to leverage in your setup. If you ever wondered how to drop/restrict traffic to applications running on Kubernetes, this is for you Read on: https://github.com/ahmetb/kubernetes-network-policy-recipes

Detect Malicious Behaviour on Kubernetes API Server through gathering Audit Logs by using FluentBit → https://falco.org/blog/
Detect Malicious Behaviour on Kubernetes API Server through gathering Audit Logs by using FluentBit → https://falco.org/blog/detect-malicious-behaviour-on-kubernetes-api-server-through-gathering-audit-logs-by-using-fluentbit-part-2

How to secure your Kubernetes control plane and node components Read more: https://cncf.io/blog/2021/08/20/how-to-secure-your
How to secure your Kubernetes control plane and node components Read more: https://cncf.io/blog/2021/08/20/how-to-secure-your-kubernetes-control-plane-and-node-components

Top Open Source Kubernetes security tools of 2021 Read on https://cloud.redhat.com/blog/top-open-source-kubernetes-security-t
Top Open Source Kubernetes security tools of 2021 Read on https://cloud.redhat.com/blog/top-open-source-kubernetes-security-tools-of-2021

šŸ‘‹ We’ve updated the Kubernetes instance calculator to include the recent change from the AWS-CNI. EC2 instances can have mor
šŸ‘‹ We’ve updated the Kubernetes instance calculator to include the recent change from the AWS-CNI. EC2 instances can have more pods than before, and that means running pods becomes cheaper. You can find the calculator here: https://learnk8s.io/kubernetes-instance-calculator

Creating Malicious Admission Controllers šŸ‘‰ https://blog.rewanthtammana.com/creating-malicious-admission-controllers
Creating Malicious Admission Controllers šŸ‘‰ https://blog.rewanthtammana.com/creating-malicious-admission-controllers

A Security Review of Docker Official Images: Which Do You Trust? šŸ‘‰ https://blog.aquasec.com/docker-official-images
A Security Review of Docker Official Images: Which Do You Trust? šŸ‘‰ https://blog.aquasec.com/docker-official-images