Kubesploit
Open in Telegram
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
Show more2 059
Subscribers
No data24 hours
-57 days
+530 days
Posts Archive
2 059
kubelogin is a kubectl plugin for Kubernetes OpenID Connect (OIDC) authentication
More: https://github.com/int128/kubelogin
2 059
Teleport is a certificate authority and access plane for SSH, Kubernetes, web applications, and databases
More https://github.com/gravitational/teleport
2 059
RBAC Manager is designed to simplify authorization in Kubernetes. This is an operator that supports declarative configuration for RBAC with new custom resources
Read on: https://github.com/FairwindsOps/rbac-manager
2 059
Kubernetes External Secrets allows you to use external secret management systems, like AWS Secrets Manager or HashiCorp Vault, to securely add secrets in Kubernetes
π https://github.com/external-secrets/kubernetes-external-secrets
2 059
This repository contains an implementation of a RBAC model for a multi project and multi tenant Kubernetes cluster
β https://github.com/clvx/k8s-rbac-model
2 059
Amazon EKS Pod Identity Webhook is a webhook for mutating pods that will require AWS IAM access
Read on: https://github.com/aws/amazon-eks-pod-identity-webhook
2 059
Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them
π https://github.com/appvia/krane
2 059
[PDF] Architecting Amazon EKS for PCI DSS Compliance
π https://d1.awsstatic.com/whitepapers/architecting-amazon-eks-for-pci-dss-compliance.pdf
2 059
Learn how to use x509 certificates to authenticate users in your cluster
Read on https://cloudhero.io/creating-users-for-your-kubernetes-cluster
2 059
Helm-scanner is a tool designed to automate discovering, templating, security scanning, then recording and providing easy access to the results for publicly available Helm charts
Read on https://github.com/bridgecrewio/helm-scanner/
2 059
The Top 5 Kubernetes Admission Control Policies:
- Trusted Repo
- Label Safety
- Privileged Mode
- Ingress
- Egress
More: https://blog.styra.com/blog/open-policy-agent-the-top-5-kubernetes-admission-control-policies
2 059
The right way to authenticate to your clusters from your CI/CD pipelines
Read more: https://tremolosecurity.com/post/pipelines-and-kubernetes-authentication
2 059
Learn how to use the nginx-ingress controller to restrict access by IP (ip whitelisting) for a service deployed to a Kubernetes (AKS) cluster
More: https://medium.com/@maninder.bindra/using-nginx-ingress-controller-to-restrict-access-by-ip-ip-whitelisting-for-a-service-deployed-to-bd5c86dc66d6
2 059
Reverse Engineering a Docker Image
More: https://theartofmachinery.com/2021/03/18/reverse_engineering_a_docker_image.html
2 059
The CVE-2021-20291 medium-level vulnerability has been found in containers/storage Go library, leading to Denial of Service (DoS) when vulnerable container engines pull an injected image from a registry.
β https://sysdig.com/blog/cve-2021-20291-cri-o-podman
2 059
10 Kubernetes Security Context settings you should understand
Read more https://snyk.io/blog/10-kubernetes-security-context-settings-you-should-understand
2 059
A detailed guide to help you to ensure that only signed images can get deployed on the cluster (with OPA and Notary)
Read on https://siegert-maximilian.medium.com/ensure-content-trust-on-kubernetes-using-notary-and-open-policy-agent-485ab3a9423c
2 059
The worst so-called βbest practiceβ for Docker
Read on: https://pythonspeed.com/articles/security-updates-in-docker
2 059
KubeEye is an open-source diagnostic tool for identifying various Kubernetes cluster issues automatically, such as misconfigurations, unhealthy components and node failures
Read more https://github.com/kubesphere/kubeeye
2 059
Learn how to set up K0s in air-gapped environment
More: https://itnext.io/k0s-cluster-without-internet-access-ac0dda08aa63?source=friends_link
Available now! Telegram Research 2025 β the year's key insights 
