en
Feedback
Kubesploit

Kubesploit

Open in Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Show more
2 132
Subscribers
+124 hours
No data7 days
+1430 days
Posts Archive
So you want to deploy an application to EKS that requires access to AWS resources like an S3 bucket or a Kinesis stream. What's the best way to allow that? Use OIDC! Read more https://medium.com/@abhinav.ittekot/granting-iam-permissions-to-pods-in-eks-using-oidc-f2044c88a53

Commonly, an application requires access to data and, usually, such access must be restricted. So, you need to provide your p
Commonly, an application requires access to data and, usually, such access must be restricted. So, you need to provide your pod/deployment/replicaSet/DaemonSet with secrets. Learn how you can do so in AKS. Read more https://mehighlow.medium.com/hardened-aks-secrets-82351c43eac4

A guide on how to stay safe when pushing Helm values files containing passwords and other sensitive data to the version control. Read more https://dev-vibe.medium.com/encrypt-helm-sensitive-data-9d7622e41d00

Generally, operators of the cluster are assigned to the cluster-admin ClusterRole. This gives the user access and permission to do all operations on all resources in the cluster. But what if you need to block an action performed by cluster admins? Read more https://marcusnoble.co.uk/2022-01-20-restricting-cluster-admin-permissions

In this post, you will learn how to simplify the process of setting up and running controlled fault injection experiments on
In this post, you will learn how to simplify the process of setting up and running controlled fault injection experiments on Amazon EKS using pre-built templates as well as custom faults to find hidden weaknesses in your Amazon EKS workloads. Read more https://aws.amazon.com/blogs/devops/chaos-engineering-on-amazon-eks-using-aws-fault-injection-simulator

Cloud Custodian enables us to write simple YAML policies for creating well-managed cloud infrastructure which is secure and c
Cloud Custodian enables us to write simple YAML policies for creating well-managed cloud infrastructure which is secure and cost-optimized in real-time. Read more https://infracloud.io/blogs/cloud-governance-code-cloud-custodian

In this article, you learn how to exploit the Log4j vulnerability (log4shell) in an application deployed on Kubernetes Read m
In this article, you learn how to exploit the Log4j vulnerability (log4shell) in an application deployed on Kubernetes Read more https://ankur-katiyar.medium.com/cve-2021-44228-proof-of-concept-on-kubernetes-34c7337e8a89

In this 2 part article, you will explore Kubernetes RBAC with a few hands-on demo labs. Read more https://medium.com/@badawek
In this 2 part article, you will explore Kubernetes RBAC with a few hands-on demo labs. Read more https://medium.com/@badawekoo/using-rbac-in-kubernetes-for-authorization-complete-demo-part-1-83f0a1fb8f

In this post, you will explore the different methods of integrating HashiCorp Vault with Kubernetes and learn how to choose t
In this post, you will explore the different methods of integrating HashiCorp Vault with Kubernetes and learn how to choose the best solution for your use case. Read more https://www.hashicorp.com/blog/kubernetes-vault-integration-via-sidecar-agent-injector-vs-csi-provider

ArgoCD-Vault-plugin is an Argo CD plugin to retrieve secrets from various Secret Management tools (HashiCorp Vault, IBM Cloud Secrets Manager, AWS Secrets Manager, etc.) and inject them into Kubernetes resources. Read more https://github.com/argoproj-labs/argocd-vault-plugin

In this post, you will learn how to incorporate the Kong Ingress Controller, KeyCloak and Kubernetes to have an initial OIDC
In this post, you will learn how to incorporate the Kong Ingress Controller, KeyCloak and Kubernetes to have an initial OIDC flow to front our external services (API or web endpoints). Read more https://dev.to/robincher/securing-your-site-via-oidc-powered-by-kong-and-keycloak-2ccc

A high-severity CVE was released that affects the Linux kernel, allowing unprivileged users to escalate those rights to root and escape from the container. Learn how you can protect your cluster with a seccomp filter. Read more https://blog.aquasec.com/cve-2022-0185-linux-kernel-container-escape-in-kubernetes

Repost from LearnKube news
A typical web application responds to requests from bots, health checks, and various attempts to circumvent security and gain
A typical web application responds to requests from bots, health checks, and various attempts to circumvent security and gain unauthorized access. Examples include: - SQL injections. - XSS attacks. So, how can you filter out those malicious attempts in Kubernetes? You have at least 2 solid options: 1. You can filter the traffic before it reaches the container. 2. You can filter the traffic at the Ingress. Chris Nesbitt-Smith will dive into the details this coming Monday at 8am PT / 4pm CET in a live webinar. After the session, you will have access to the code, a step-by-step tutorial and interactive labs to test the configuration (provided by NGINX). You can register here (it's free): https://www.nginx.com/c/microservices-march-2022-kubernetes-networking-agenda/

Learn how to run Regula on a Kubernetes manifest to detect an insecure pod, and then learn how to secure it. Read more https:
Learn how to run Regula on a Kubernetes manifest to detect an insecure pod, and then learn how to secure it. Read more https://fugue.co/blog/securing-a-kubernetes-pod-with-regula-and-open-policy-agent

Learn how to use eBPF and the Security Profiles Operator to automatically generate seccomp profiles, a Linux kernel security
Learn how to use eBPF and the Security Profiles Operator to automatically generate seccomp profiles, a Linux kernel security feature for Kubernetes. Read more https://developers.redhat.com/articles/2021/12/16/secure-your-kubernetes-deployments-ebpf#what_is_the_security_profiles_operator_

Kubernetes 1.23 includes security features to enhance cluster security: - Support for ephemeral containers - HostProcess containers for Windows - PodSecurity admission controller And more. Read more https://blog.aquasec.com/kubernetes-version-1.23-security-features

This article discusses two Open Source tools for auditing cluster security: kube-bench and kube-hunter. Read more https://blo
This article discusses two Open Source tools for auditing cluster security: kube-bench and kube-hunter. Read more https://blog.flant.com/kubernetes-security-with-kube-bench-and-kube-hunter

In this repository, you will find a curated list of awesome Kubernetes security resources. Read more https://github.com/ksoclabs/awesome-kubernetes-security

After reading this article, you will learn: - How not to run pods as root. - How to use immutable root fs (lock the root filesystem). - How to do Docker image scan locally and with your CI pipelines. - How to use PSP. Read more https://blog.gitguardian.com/kubernetes-tutorial-part-1-pods

In this article, you will learn how to enable IAM users and roles access on Amazon EKS. Read more https://medium.com/@radha.s
In this article, you will learn how to enable IAM users and roles access on Amazon EKS. Read more https://medium.com/@radha.sable25/enabling-iam-users-roles-access-on-amazon-eks-cluster-f69b485c674f