en
Feedback
Kubesploit

Kubesploit

Open in Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Show more
2 132
Subscribers
No data24 hours
+27 days
+1330 days
Posts Archive
In this tutorial, you will learn how to write Kubernetes policies using JavaScript/Typescript with the help of jsPolicy and d
In this tutorial, you will learn how to write Kubernetes policies using JavaScript/Typescript with the help of jsPolicy and deploy them via GitOps using Flux. More: https://blog.ediri.io/writing-kubernetes-policies-with-jspolicy

This article summarizes a list of recommendations for hardening Kubernetes clusters (both on-prem and cloud) with Admission a
This article summarizes a list of recommendations for hardening Kubernetes clusters (both on-prem and cloud) with Admission and Mutation webhooks using the open-source tool Gatekeeper. More: https://faun.pub/gatekeeper-k8-hardening-backlog-956d1b6860b6

RBAC-police is a CLI tool that lets you evaluate the RBAC permissions of service accounts, pods and nodes in Kubernetes clusters through policies written in Rego. More: https://github.com/PaloAltoNetworks/rbac-police

A short and visual thread on how Kubernetes RBAC works in Kubernetes. More: https://medium.com/@danielepolencic/how-does-rbac
A short and visual thread on how Kubernetes RBAC works in Kubernetes. More: https://medium.com/@danielepolencic/how-does-rbac-work-in-kubernetes-d50dd34771ca

Azure Key Vault Provider for Secrets Store CSI Driver maps a Kubernetes resource called SecretProviderClass to an Azure Key V
Azure Key Vault Provider for Secrets Store CSI Driver maps a Kubernetes resource called SecretProviderClass to an Azure Key Vault and lets you select which secrets, keys, and/or certificates you'd like to expose. Learn more in this article. More: https://medium.com/dzerolabs/kubernetes-saved-today-f-cked-tomorrow-a-rant-azure-key-vault-secrets-%C3%A0-la-kubernetes-fc3be5e65d18

Repost from Kube Careers
What does it take to get a job as a Kubernetes engineer? Do you need a Kubernetes certification to apply for a job? What's th
What does it take to get a job as a Kubernetes engineer? Do you need a Kubernetes certification to apply for a job? What's the average salary for a Kubernetes engineer? We analyzed 93 Kubernetes jobs for the first three months of 2022 and found that: - The average Kubernetes job pays €83,722 in Europe and $143,684 in North America. - The majority of the job listings are for Senior DevOps Engineers (no junior roles, unfortunately). - 64% of the jobs mention remote working! - As usual, AWS, Python, Terraform, Prometheus and Jenkins are the top mentions in any Kubernetes job descriptions. You can read the full report here: https://kube.careers/kubernetes-trend-report-2022-q2

kconnect is a CLI utility that can be used to discover and securely access Kubernetes clusters across multiple operating environments. More: https://github.com/fidelity/kconnect

This article contains a collection of best practices and tips regarding securing containerized environments. More: https://medium.com/technology-hits/incomplete-guide-for-securing-containerized-environment-78b57fc3238

The best way to know if something works is to test it. In this article, you will cover how to install and run the Atomic Red
The best way to know if something works is to test it. In this article, you will cover how to install and run the Atomic Red Team environment on Kubernetes to generate suspicious events based on ATT&CK techniques and see how Falco triggers alerts. More: https://sysdig.com/blog/atomic-red-team-falco

This article shows how to enable secure HTTPS on Kubernetes for Spring Boot applications using Istio and Cert Manager. More: https://piotrminkowski.com/2022/06/01/https-on-kubernetes-with-spring-boot-istio-and-cert-manager

Infra enables you to discover and access infrastructure (e.g. Kubernetes, databases). It helps you connect an identity provid
Infra enables you to discover and access infrastructure (e.g. Kubernetes, databases). It helps you connect an identity provider such as Okta or Azure active directory, and map users/groups with the permissions you set to your infrastructure. More: https://github.com/infrahq/infra

Repost from Kube Builders
kubeval is a tool for validating a Kubernetes YAML or JSON configuration file. It does so using schemas generated from the Kubernetes OpenAPI specification, and therefore can validate schemas for multiple versions of Kubernetes. More: https://github.com/instrumenta/kubeval

Learn how the team at Xendit found an issue with Linkerd and TLS on Kubernetes and how they did (not) fix it. More: https://b
Learn how the team at Xendit found an issue with Linkerd and TLS on Kubernetes and how they did (not) fix it. More: https://blog.xendit.engineer/debugging-k8s-issues-intermittent-outbound-tls-issues-with-linkerd-7476f02f3cea

Tales from a recent pentest of a product hosted on the AWS cloud backed by Kubernetes (EKS) and a whole lot of secure design
Tales from a recent pentest of a product hosted on the AWS cloud backed by Kubernetes (EKS) and a whole lot of secure design goodness that withstood the attack attempts. More: https://blog.appsecco.com/hacking-an-aws-hosted-kubernetes-backed-product-and-failing-904cbe0b7c0d

[PDF] In this whitepaper, you will discuss the security aspects of different base images for containers. In other words, the same container (i.e. python) could have more or fewer issues depending on the underlying OS (i.e. Alpine, Debian, etc.) More: https://chainguard.dev/blog-static/chainguard-all-about-that-base-image.pdf

This operator scans all SBOMs from a git-repository for vulnerabilities using Grype. The result-list can be emitted as JSON-file served via an endpoint and/or as Prometheus metrics. More: https://github.com/ckotzbauer/vulnerability-operator

Trousseau uses the Kubernetes KMS provider framework to provide an envelope encryption scheme to encrypt secrets on the fly b
Trousseau uses the Kubernetes KMS provider framework to provide an envelope encryption scheme to encrypt secrets on the fly before they reach etcd. The project is modular and you can plug your own KMS tool (e.g. Vault). More: https://github.com/ondat/trousseau

Starboard integrates security tools by incorporating their outputs into Kubernetes CRDs (Custom Resource Definitions) and mak
Starboard integrates security tools by incorporating their outputs into Kubernetes CRDs (Custom Resource Definitions) and making security reports accessible through the Kubernetes API. More: https://github.com/aquasecurity/starboard

Repost from LearnKube news
undefined You can sign up here: https://learnk8s.io/online-advanced-july-2022
undefined You can sign up here: https://learnk8s.io/online-advanced-july-2022

Vulnscan is a suite of reporting and analysis tools built on top of Anchore's syft utility (to create software bills of mater
Vulnscan is a suite of reporting and analysis tools built on top of Anchore's syft utility (to create software bills of material) and Grype utility (to scan those SBOMs for vulnerabilities). This suite is designed to be run on a kubernetes cluster. More: https://github.com/davideshay/vulnscan#readme

Kubesploit - Statistics & analytics of Telegram channel @kubesploit