Kubesploit
Ir al canal en Telegram
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
Mostrar más2 131
Suscriptores
-224 horas
+37 días
+1230 días
Archivo de publicaciones
2 131
This article will teach you how to configure an AKS cluster to consume secrets, keys and certificates from an Azure KeyVault.
More: https://community.ops.io/javi_labs/configuring-aks-to-read-secrets-and-certificates-from-azure-keyvaults-17o1
2 131
Repost from LearnKube news
Master Kubernetes with our Advanced Kubernetes workshops next week!
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
You can sign up here: https://learnk8s.io/online-advanced-january-2023
2 131
Repost from Kube Architect
In this tutorial, you will learn how to automatically schedule Kubeflow pipeline Pods from any number of namespaces on dedicated GKE node pools.
More: https://medium.com/dkatalis/creating-a-mutating-webhook-for-great-good-b21acb941207
2 131
kubeaudit is a command line tool and a Go package to audit Kubernetes clusters for various different security concerns, such as:
- Run as non-root.
- Use a read-only root filesystem.
- Drop scary capabilities, don't add new ones.
- Don't run privileged.
More: https://github.com/Shopify/kubeaudit
2 131
argocd-vault-plugin is an Argo CD plugin that retrieves secrets from Secret Management tools and injects them into Kubernetes.
More: https://github.com/argoproj-labs/argocd-vault-plugin
2 131
In this article, you will discuss the pitfalls and alternatives of Sealed Secrets as you move your deployments to production using GitOps.
More: https://betterprogramming.pub/why-you-should-avoid-sealed-secrets-in-your-gitops-deployment-e50131d360dd
2 131
Repost from LearnKube news
In this tutorial, you'll learn how to build a simple app that lists resources on the Kubernetes cluster it runs on.
In the process, you will also learn how to utilize Service Accounts, RBAC, the Python client, Ingress and more.
More: https://devoops.blog/kubernetes-pods-extractor
2 131
In this tutorial, you'll learn how to use the Azure CSI Driver to fetch secrets and inject them in pods running on AKS.
More: https://medium.com/@shivanik111898/use-azure-key-vault-for-secret-store-with-azure-csi-driver-31bc803b7ca8
2 131
This repository contains a custom Kubernetes controller that can automatically create random secret values.
This may be used for auto-generating random credentials for applications running on Kubernetes.
More: https://github.com/mittwald/kubernetes-secret-generator
2 131
The Trivy Operator PolicyReport Adapter
maps Trivy CRDs into the unified PolicyReport and ClusterPolicyReport from the Kubernetes Policy Working Group.
This makes it possible to use tooling like Policy Reporter for the different kinds of Trivy Reports.
More: https://github.com/fjogeleit/trivy-operator-polr-adapter
2 131
This article details how to secure web traffic using TLS with a certificate issued by a trusted CA on Google Kubernetes Engine.
This will use Let's Encrypt through a popular Kubernetes add-on called cert-manager.
More: https://joachim8675309.medium.com/gke-with-certmanager-9bc00b086b73
2 131
With Kubernetes v1.24, non-expiring service account tokens are no longer auto-generated.
This blog post highlights what this means in practice, and what to do if you rely on non-expiring service account tokens.
More: https://eng.d2iq.com/blog/service-account-tokens-in-kubernetes-v1.24
2 131
Admission controllers are a key component of the admission process performed by the Kubernetes API server.
They enable fine-grained control over the object creation, update, and deletion process.
Learn how they work in this article.
More: https://pradeepl.com/blog/kubernetes/introduction-to-kubernetes-admission-controllers
2 131
In this article, you will learn how to integrate ArgoCD with HashiCorp Vault to manage secrets on Kubernetes.
To use ArgoCD and Vault together, you will use the ArgoCD Vault plugin.
More: https://piotrminkowski.com/2022/08/08/manage-secrets-on-kubernetes-with-argocd-and-vault
2 131
The Kubernetes Security Profiles Operator aims to make it easier for users to use SELinux, seccomp and AppArmor in Kubernetes clusters.
More: https://github.com/kubernetes-sigs/security-profiles-operator
2 131
Kubeconform is a Kubernetes manifests validation tool.
Similar to Kubeval, but with the following improvements:
1. High performance.
2. Remote or local schemas locations
3. Up-to-date schemas for all recent versions of Kubernetes.
More: https://github.com/yannh/kubeconform
2 131
In this tutorial, you'll learn how to create a python program that uses IAM for Service Account to search for secrets in Secrets Manager and store them in a volume.
The script can be used as an init container to inject secrets into any pod.
More: https://kymidd.medium.com/lets-do-devops-eks-k8s-python-fuzzy-staging-with-aws-secrets-manager-k8s-init-disk-secrets-b0d8022f3a5d
2 131
KSOPS is a kustomize exec plugin for SOPS encrypted resources.
KSOPS can be used to decrypt any Kubernetes resource, but is most commonly used to decrypt encrypted Kubernetes Secrets and ConfigMaps.
More: https://github.com/viaduct-ai/kustomize-sops
2 131
This article will teach you how to exploit a vulnerability in Linux containers by bypassing negative group permissions.
More: https://benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation
2 131
This project provides an OCI hook to generate seccomp profiles by tracing the syscalls made by the container.
The generated profile would allow all the syscalls made and deny every other syscall.
More: https://github.com/containers/oci-seccomp-bpf-hook
