Kubesploit
Открыть в Telegram
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
Больше2 056
Подписчики
-224 часа
-47 дней
+430 день
Архив постов
2 056
In this post, you'll learn how to achieve continuous Runtime-Security monitoring for container-based workloads running on Kubernetes through custom integration between Falco, Falco-SideKick, WebUI, and AWS CloudWatch/PagerDuty.
More: https://aymen-abdelwahed.medium.com/falco-security-at-runtime-for-kubernetes-d9176cc76020
2 056
In this article, you will learn why PodSecurityPolicies never made it as a GA feature, why they had to be replaced and what you should consider going forward.
More: https://macchaffee.com/blog/2022/psp-deprecation
2 056
Kubelogin is a Kubernetes credential (exec) plugin implementing the Azure authentication methods such as:
- Device code login.
- Non-interactive service principal login.
- Non-interactive workload identity login.
- OIDC provider for Azure AD.
And more.
More: https://github.com/Azure/kubelogin
2 056
dexter is an OIDC (OpenId Connect) helper designed to create a hassle-free Kubernetes login experience powered by Google or Azure as Identity Provider.
All you need is a properly configured Google or Azure client ID & secret.
More: https://github.com/gini/dexter
2 056
The External Secrets Operator provides an alternative to the Kubernetes Secret object.
It does this by providing Custom Resources, which define where secrets live and how to synchronize them.
Learn how to use it with the AWS secrets manager.
More: https://ptuladhar3.medium.com/getting-started-with-external-secrets-operator-on-kubernetes-using-aws-secrets-manager-6dc403d9630c
2 056
Learn how Cilium can be configured to provide sidecar-free mTLS-based authentication with excellent security and performance characteristics (without the overhead of traditional service meshes).
More: https://isovalent.com/blog/post/2022-05-03-servicemesh-security
2 056
This repository contains a reading list for software supply-chain security.
More: https://github.com/chainguard-dev/ssc-reading-list
2 056
In this article, you will compare the External Secrets Operator with Secret Storage CSI for using external secrets in a Kubernetes cluster. You will compare:
- Architecture.
- Authorization management.
- Resource usage.
- GitOps friendliness.
More: https://mixi-developers.mixi.co.jp/compare-eso-with-secret-csi-402bf37f20bc
2 056
In this article, you will learn about man-in-the-middle attacks related to downloading container images and how you can prevent them using Connaisseur — an admission controller that integrates Container Image Signature Verification.
More: https://medium.com/linkbynet/trust-but-verify-3a4852d2420
2 056
In this tutorial, you will learn how to write Kubernetes policies using JavaScript/Typescript with the help of jsPolicy and deploy them via GitOps using Flux.
More: https://blog.ediri.io/writing-kubernetes-policies-with-jspolicy
2 056
This article summarizes a list of recommendations for hardening Kubernetes clusters (both on-prem and cloud) with Admission and Mutation webhooks using the open-source tool Gatekeeper.
More: https://faun.pub/gatekeeper-k8-hardening-backlog-956d1b6860b6
2 056
RBAC-police is a CLI tool that lets you evaluate the RBAC permissions of service accounts, pods and nodes in Kubernetes clusters through policies written in Rego.
More: https://github.com/PaloAltoNetworks/rbac-police
2 056
A short and visual thread on how Kubernetes RBAC works in Kubernetes.
More: https://medium.com/@danielepolencic/how-does-rbac-work-in-kubernetes-d50dd34771ca
2 056
Azure Key Vault Provider for Secrets Store CSI Driver maps a Kubernetes resource called SecretProviderClass to an Azure Key Vault and lets you select which secrets, keys, and/or certificates you'd like to expose.
Learn more in this article.
More: https://medium.com/dzerolabs/kubernetes-saved-today-f-cked-tomorrow-a-rant-azure-key-vault-secrets-%C3%A0-la-kubernetes-fc3be5e65d18
2 056
Repost from Kube Careers
What does it take to get a job as a Kubernetes engineer?
Do you need a Kubernetes certification to apply for a job?
What's the average salary for a Kubernetes engineer?
We analyzed 93 Kubernetes jobs for the first three months of 2022 and found that:
- The average Kubernetes job pays €83,722 in Europe and $143,684 in North America.
- The majority of the job listings are for Senior DevOps Engineers (no junior roles, unfortunately).
- 64% of the jobs mention remote working!
- As usual, AWS, Python, Terraform, Prometheus and Jenkins are the top mentions in any Kubernetes job descriptions.
You can read the full report here: https://kube.careers/kubernetes-trend-report-2022-q2
2 056
kconnect is a CLI utility that can be used to discover and securely access Kubernetes clusters across multiple operating environments.
More: https://github.com/fidelity/kconnect
2 056
This article contains a collection of best practices and tips regarding securing containerized environments.
More: https://medium.com/technology-hits/incomplete-guide-for-securing-containerized-environment-78b57fc3238
2 056
The best way to know if something works is to test it.
In this article, you will cover how to install and run the Atomic Red Team environment on Kubernetes to generate suspicious events based on ATT&CK techniques and see how Falco triggers alerts.
More: https://sysdig.com/blog/atomic-red-team-falco
2 056
This article shows how to enable secure HTTPS on Kubernetes for Spring Boot applications using Istio and Cert Manager.
More: https://piotrminkowski.com/2022/06/01/https-on-kubernetes-with-spring-boot-istio-and-cert-manager
2 056
Infra enables you to discover and access infrastructure (e.g. Kubernetes, databases).
It helps you connect an identity provider such as Okta or Azure active directory, and map users/groups with the permissions you set to your infrastructure.
More: https://github.com/infrahq/infra
Уже доступно! Исследование Telegram 2025 — ключевые инсайты года 
