Kubesploit
Open in Telegram
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
Show more2 061
Subscribers
No data24 hours
+27 days
+1530 days
Posts Archive
2 061
Learn how Sigstore and HashiCorp Vault enable cryptographic container image signing, allowing organizations to verify image integrity and control deployments through automated, policy-driven signature validation.
More: https://ku.bz/QsG1kbj7q
2 061
Repost from N/a
Nicholas Morey, Senior Developer Advocate at Akuity, advises against managing your own secrets manager.
Drawing from personal experience, he highlights the challenges of misconfigurations, troubleshooting outages, and maintaining security.
Watch the full interview: https://ku.bz/KCX-qwJ7M
This interview is a reaction to Mac's episode https://ku.bz/rFlp8Yj9s
2 061
AWS EKS Pod Identity streamlines IAM permissions for pods, bypassing OIDC/IRSA's trust policies and scaling limits.
It uses session tags for fine-grained access, works exclusively with EKS, and coexists with IRSA.
More: https://ku.bz/rFs8Np0Gr
2 061
Dracan is a lightweight middleware for Kubernetes that enhances filtering and validation capabilities.
It ensures that only valid requests reach your applications.
More: https://ku.bz/PyX7LNrhJ
2 061
In this article, you will learn how to create a Service Account, associate it with a Role, and use it in a Pod.
Additionally, you will also verify the permissions of the Service Account to ensure it has the appropriate access.
More: https://ku.bz/_mpRnssSZ
2 061
Repost from Kube Architect
This article outlines a GitOps approach using Otterize, Kyverno, and Argo CD to manage dynamic Kubernetes Network Policies at scale across 25+ clusters, simplifying policy creation and automating updates without service disruptions.
More: https://ku.bz/gbHZPBXhR
2 061
Repost from N/a
Yakir Kadkoda and Assaf Morag from Aqua Security emphasized the importance of using multiple secret scanning tools to identify different types of vulnerabilities.
Their research revealed that most secrets were found in personal employee repositories rather than the company's official repositories, underscoring the need for comprehensive scanning practices.
Watch the full episode: https://ku.bz/5RKVBGlQR
2 061
Repost from LearnKube news
This week on Learn Kubernetes Weekly 125:
๐ฐ The infrastructure to handle 10m requests in 10 minutes for $0.0116
๐โโ๏ธ Deep Dive into Kubernetes CPU Usage, Requests, and Limits
๐ Optimizing Kubernetes Resource Utilization: CPU and Memory Requests and Limits
๐ฎ We threw away 13 years of work for EKS
0๏ธโฃ Proxyless scale-to-zero with eBPF
Read it now: https://learnk8s.io/issues/125
โญ๏ธ This newsletter is brought to you by LoftLabs โ simplify Kubernetes with vCluster, the leading solution for Kubernetes multi-tenancy and cost savings https://ku.bz/3DgN6HyWR
2 061
The ClusterSecret operator keeps matching namespaces updated with secrets:
- New matching namespaces receive the secret automatically. - Changes to the ClusterSecret update all related secrets, and deleting it also removes all cloned secrets.
More: https://ku.bz/vDWHTkPht
2 061
Sveltos simplifies secret management across Kubernetes clusters by automating distribution, storage, and propagation.
It centralizes secrets in the management cluster, reducing manual effort and enhancing security.
More: https://ku.bz/PTqdWvf_S
2 061
Tokenetes is an open-source, cloud-native Transaction Tokens (TraTs) Service that leverages the standards defined in the Transaction Tokens draft.
More: https://ku.bz/5kYH15LBX
2 061
Repost from N/a
Alexander Lawrence, Director of Cloud Security Strategy at Sysdig, explains why implementing security in Kubernetes environments is particularly challenging.
He highlights that 60% of containers live for less than a minute, making traditional security approaches ineffective. The scale and speed of Kubernetes operations create significant barriers to security adoption, with environment sprawl that makes the VMware era "look like child's play." Lawrence suggests that making security tools native, easy to use, and available out-of-the-box is essential for overcoming these adoption challenges.
Watch the full interview: https://ku.bz/-MqhJchmb
This interview is a reaction to John McBride's episode https://ku.bz/wP6bTlrFs
2 061
In this article, you will learn how Validating Admission Policy offers a native, declarative way to enforce cluster resource rules directly in the API server using CEL, replacing complex webhooks with simpler, performance-driven validation policies.
More: https://ku.bz/9L7yQfCvk
2 061
Learn how to build secure Docker images with Trivy, a tool for vulnerability scanning, and improve your application's security posture.
More: https://ku.bz/FvZDmCF5k
2 061
Repost from LearnKube news
This week on Learn Kubernetes Weekly 124:
๐ Kubernetes at Mercado Libre
๐ธ From Autopilot to Standard GKE: The Key to 15x Cheaper Istio
๐งจ How We Built a Dynamic Kubernetes API Server for the API Aggregation Layer in Cozystack
๐ฅ All my DevOps pipelines from GitLab commit to ArgoCD got beaten by FTP
๐ต๏ธโโ๏ธ Examining approaches and patterns for debuggability: ephemeral containers and Argo Workflows
And more! If you prefer to receive the newsletter every week in your inbox, you can subscribe here: https://learnk8s.io/learn-kubernetes-weekly
Read it now: https://learnk8s.io/issues/124
โญ๏ธ KubeFM published a book of battle-tested experiences from engineers who pushed Kubernetes to its limits and lived to tell the tale. Download for free here https://ku.bz/Z0j-v-pdG
2 061
Learn how to store and access sensitive data in Kubernetes with secrets securely.
Mount secrets as environment variables or files using secretKeyRef, envFrom, or secret volumes.
More: https://ku.bz/GjXlr7glV
2 061
Repost from N/a
Tim Miller CEO and Co-founder at Kusari challenges the common belief that minimal container images automatically mean better security.
He explains that while removing unnecessary binaries and shells is a good practice, the real focus should be on validating each component's purpose in the container. Tim emphasizes two key aspects of container security: ensuring transparency (knowing what's inside) and verification (confirming the image is truly minimal).
Watch the full interview: https://ku.bz/-2Sqn9Jb9
This interview is a reaction to Harsha Koushik's episode https://ku.bz/n_sJ04xMY
2 061
Repost from N/a
๐ KubeFM's first book! A compilation of raw, unfiltered experiences from cloud-native practitioners who have faced cluster outages, scaled systems beyond their designed capacities and emerged with invaluable insights.
This book combines the most interesting conversations from the KubeFM podcast, curated by Gulcan Topcu and featuring a foreword by @Birthmarkb (the Vivacious voice behind KubeFM).
Inside, you'll discover firsthand accounts from engineers at organizations like Adidas, Getir, and Mercari who have pushed Kubernetes to its breaking point and documented what they learned.
The complete book is available as a free download, and you can get your copy here: https://ku.bz/Z0j-v-pdG
For those attending KubeCon, we'll be giving away 50 physical copies at Booth N583 (StormForge)
2 061
Falco is a cloud-native security tool designed for Linux systems.
It employs custom rules on kernel events, which are enriched with container and Kubernetes metadata, to provide real-time alerts.
More: https://ku.bz/ClJryQ999
2 061
Repost from N/a
Hillai Ben-Sasson and Ronen Shustin, Security Researchers at Wiz, recommend the Peach framework, an open-source project designed to build isolated environments either in the Cloud or on-premises.
Developed with contributions from various industry experts, Peach ensures proper isolation for tenants and customers.
Watch the full episode: https://ku.bz/yr16qNTFx
Available now! Telegram Research 2025 โ the year's key insights 
