es
Feedback
Kubesploit

Kubesploit

Ir al canal en Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Mostrar más
2 132
Suscriptores
Sin datos24 horas
+27 días
+1730 días
Archivo de publicaciones
Learn how to use x509 certificates to authenticate users in your cluster Read on https://cloudhero.io/creating-users-for-your-kubernetes-cluster

Helm-scanner is a tool designed to automate discovering, templating, security scanning, then recording and providing easy acc
Helm-scanner is a tool designed to automate discovering, templating, security scanning, then recording and providing easy access to the results for publicly available Helm charts Read on https://github.com/bridgecrewio/helm-scanner/

The Top 5 Kubernetes Admission Control Policies: - Trusted Repo - Label Safety - Privileged Mode - Ingress - Egress More: https://blog.styra.com/blog/open-policy-agent-the-top-5-kubernetes-admission-control-policies

The right way to authenticate to your clusters from your CI/CD pipelines Read more: https://tremolosecurity.com/post/pipeline
The right way to authenticate to your clusters from your CI/CD pipelines Read more: https://tremolosecurity.com/post/pipelines-and-kubernetes-authentication

Learn how to use the nginx-ingress controller to restrict access by IP (ip whitelisting) for a service deployed to a Kubernetes (AKS) cluster More: https://medium.com/@maninder.bindra/using-nginx-ingress-controller-to-restrict-access-by-ip-ip-whitelisting-for-a-service-deployed-to-bd5c86dc66d6

The CVE-2021-20291 medium-level vulnerability has been found in containers/storage Go library, leading to Denial of Service (DoS) when vulnerable container engines pull an injected image from a registry. → https://sysdig.com/blog/cve-2021-20291-cri-o-podman

10 Kubernetes Security Context settings you should understand Read more https://snyk.io/blog/10-kubernetes-security-context-s
10 Kubernetes Security Context settings you should understand Read more https://snyk.io/blog/10-kubernetes-security-context-settings-you-should-understand

A detailed guide to help you to ensure that only signed images can get deployed on the cluster (with OPA and Notary) Read on
A detailed guide to help you to ensure that only signed images can get deployed on the cluster (with OPA and Notary) Read on https://siegert-maximilian.medium.com/ensure-content-trust-on-kubernetes-using-notary-and-open-policy-agent-485ab3a9423c

The worst so-called “best practice” for Docker Read on: https://pythonspeed.com/articles/security-updates-in-docker

KubeEye is an open-source diagnostic tool for identifying various Kubernetes cluster issues automatically, such as misconfigu
KubeEye is an open-source diagnostic tool for identifying various Kubernetes cluster issues automatically, such as misconfigurations, unhealthy components and node failures Read more https://github.com/kubesphere/kubeeye

An alternative approach to Secrets management in Helm 3 Read on: https://itnext.io/helm-3-secrets-management-4f23041f05c3?source=friends_link

This blog post is about an experiment to automate creation of Kubernetes Network Policies based on actual network traffic cap
This blog post is about an experiment to automate creation of Kubernetes Network Policies based on actual network traffic captured from applications running on a Kubernetes cluster More: https://itnext.io/generating-kubernetes-network-policies-by-sniffing-network-traffic-6d5135fe77db

Kubestriker is a platform-agnostic tool designed to tackle Kuberenetes cluster security issues due to misconfigurations → htt
Kubestriker is a platform-agnostic tool designed to tackle Kuberenetes cluster security issues due to misconfigurations → https://github.com/vchinnipilli/kubestriker

cosign is a tool that can sign container images. Cosign supports: - Hardware and KMS signing - Bring-your-own PKI - Our free
cosign is a tool that can sign container images. Cosign supports: - Hardware and KMS signing - Bring-your-own PKI - Our free OIDC PKI (Fulcio) → https://github.com/sigstore/cosign

kubectl-whisper-secret plugin allows users to create secrets with secure input prompt to prevent information leakages through terminal history, shoulder surfing attacks, etc. 👉 https://github.com/rewanth1997/kubectl-whisper-secret

awesome-kubernetes-security Awesome a curated list of awesome Kubernetes security resources. 👉 https://github.com/ksoclabs/awesome-kubernetes-security

Preflight is a tool to automatically perform Kubernetes cluster configuration checks using Open Policy Agent (OPA). More https://github.com/jetstack/preflight

The kube-secrets-init is a Kubernetes mutating admission webhook, that mutates any K8s Pod that is using specially prefixed environment variables, directly or from Kubernetes as Secret or ConfigMap 👉 https://github.com/doitintl/kube-secrets-init