ru
Feedback
Kubesploit

Kubesploit

Открыть в Telegram

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Больше
2 132
Подписчики
Нет данных24 часа
+27 дней
+1730 дней
Архив постов
The kube-secrets-init is a Kubernetes mutating admission webhook, that mutates any K8s Pod that is using specially prefixed environment variables, directly or from Kubernetes as Secret or ConfigMap 👉 https://github.com/doitintl/kube-secrets-init

Popeye is a utility that scans live Kubernetes cluster and reports potential issues with deployed resources and configuration
Popeye is a utility that scans live Kubernetes cluster and reports potential issues with deployed resources and configurations. It sanitizes your cluster based on what's deployed and not what's sitting on disk. → https://github.com/derailed/popeye

Kube-secret-syncer is a Kubernetes operator developed using the Kubebuilder framework that keeps the values of Kubernetes Secrets synchronised to secrets in AWS Secrets Manager Read on: https://github.com/contentful-labs/kube-secret-syncer

Trivy is a Simple and Comprehensive Vulnerability Scanner for Container Images, Git Repositories and Filesystems. Suitable fo
Trivy is a Simple and Comprehensive Vulnerability Scanner for Container Images, Git Repositories and Filesystems. Suitable for CI Read more https://github.com/aquasecurity/trivy

An interesting way to protect your Kubernetes config file on your computer against accidental or malicious change or reading Read on https://gist.github.com/PatrLind/e651d3cbc3bf68e4bd9fcc9568cbd3fb

In this article you will learn what can be done to make a Kubernetes-based environment comply with the PCI DSS Read more https://elastisys.com/pci-dss-compliance-in-kubernetes-based-platforms

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent dedicated for containerized environments written in Golang and built on top of Merlin project More: https://github.com/cyberark/kubesploit

In this article you will learn how to protect Secrets in your Kubernetes cluster More https://cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets

How monero miners target and exploit cloud native dev environments Read more: https://blog.aquasec.com/monero-miners-target-b
How monero miners target and exploit cloud native dev environments Read more: https://blog.aquasec.com/monero-miners-target-bitbucket-dockerhub

Choosing the right policy-as-code solution for your Kubernetes cluster: - OPA - Gatekeeper - Kyverno - k-rail - MagTape More:
Choosing the right policy-as-code solution for your Kubernetes cluster: - OPA - Gatekeeper - Kyverno - k-rail - MagTape More: https://aws.amazon.com/blogs/containers/policy-based-countermeasures-for-kubernetes-part-1

Kubernetes Single Sign On - A detailed guide in 9 parts Read more: http://talkingquickly.co.uk/kubernetes-sso-a-detailed-guide

Lockbox is a secure way to store Kubernetes Secrets offline. Secrets are asymmetrically encrypted, and can only be decrypted by the Lockbox Kubernetes controller Read on: https://github.com/cloudflare/lockbox

In this tutorial, you'll learn how to run Linkerd and Cilium together and how to use Cilium to apply L3 and L4 network policies to a cluster running Linkerd 👉 https://buoyant.io/2020/12/23/kubernetes-network-policies-with-cilium-and-linkerd

In this tutorial you'll learn how to how to integrate Kubernetes with Dex + LDAP More https://brightzheng100.medium.com/kuber
In this tutorial you'll learn how to how to integrate Kubernetes with Dex + LDAP More https://brightzheng100.medium.com/kubernetes-dex-ldap-integration-f305292a16b9

This post describes how to improve cert-manager self-check speed, by pointing the cluster to Google nameservers, and disablin
This post describes how to improve cert-manager self-check speed, by pointing the cluster to Google nameservers, and disabling DNS caching → https://usepine.com/blog/en/improving-cert-manager-self-check-speed-when-issuing-certificates

Kubernetes Policy Comparison: OPA/Gatekeeper vs Kyverno Read on: https://neonmirrors.net/post/2021-02/kubernetes-policy-compa
Kubernetes Policy Comparison: OPA/Gatekeeper vs Kyverno Read on: https://neonmirrors.net/post/2021-02/kubernetes-policy-comparison-opa-gatekeeper-vs-kyverno

Attacking Kubernetes clusters using the Kubelet API Read on: https://medium.com/faun/attacking-kubernetes-clusters-using-the-
Attacking Kubernetes clusters using the Kubelet API Read on: https://medium.com/faun/attacking-kubernetes-clusters-using-the-kubelet-api-abafc36126ca

Kubolt is simple utility for scanning public unauthinticated kubernetes clusters and run commands inside containers Read more https://github.com/averonesis/kubolt