uz
Feedback
Kubesploit

Kubesploit

Kanalga Telegram’da o‘tish

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Ko'proq ko'rsatish
2 126
Obunachilar
-324 soatlar
+17 kun
+1130 kun
Obunachilarni jalb qilish
Sentabr '26
Sentabr '26
+26
1 kanalda
Avgust '26
+50
2 kanalda
Get PRO
Iyul '26
+45
2 kanalda
Get PRO
Iyun '26
+41
3 kanalda
Get PRO
May '26
+49
3 kanalda
Get PRO
Aprel '26
+36
3 kanalda
Get PRO
Mart '26
+65
5 kanalda
Get PRO
Fevral '26
+35
1 kanalda
Get PRO
Yanvar '26
+29
1 kanalda
Get PRO
Dekabr '25
+44
3 kanalda
Get PRO
Noyabr '25
+35
2 kanalda
Get PRO
Oktabr '25
+23
2 kanalda
Get PRO
Sentabr '25
+18
2 kanalda
Get PRO
Avgust '25
+22
2 kanalda
Get PRO
Iyul '25
+38
2 kanalda
Get PRO
Iyun '25
+18
3 kanalda
Get PRO
May '25
+28
2 kanalda
Get PRO
Aprel '25
+18
2 kanalda
Get PRO
Mart '25
+23
3 kanalda
Get PRO
Fevral '25
+23
1 kanalda
Get PRO
Yanvar '25
+28
2 kanalda
Get PRO
Dekabr '24
+49
1 kanalda
Get PRO
Noyabr '24
+106
2 kanalda
Get PRO
Oktabr '24
+103
2 kanalda
Get PRO
Sentabr '24
+94
2 kanalda
Get PRO
Avgust '24
+147
3 kanalda
Get PRO
Iyul '24
+62
2 kanalda
Get PRO
Iyun '24
+66
3 kanalda
Get PRO
May '24
+91
2 kanalda
Get PRO
Aprel '24
+122
3 kanalda
Get PRO
Mart '24
+76
3 kanalda
Get PRO
Fevral '24
+57
2 kanalda
Get PRO
Yanvar '24
+56
2 kanalda
Get PRO
Dekabr '23
+79
2 kanalda
Get PRO
Noyabr '23
+21
3 kanalda
Get PRO
Oktabr '23
+23
2 kanalda
Get PRO
Sentabr '23
+28
0 kanalda
Get PRO
Avgust '23
+12
0 kanalda
Get PRO
Iyul '23
+26
0 kanalda
Get PRO
Iyun '23
+30
0 kanalda
Get PRO
May '23
+42
0 kanalda
Get PRO
Aprel '23
+27
0 kanalda
Get PRO
Mart '23
+81
0 kanalda
Get PRO
Fevral '23
+17
0 kanalda
Get PRO
Yanvar '23
+35
0 kanalda
Get PRO
Dekabr '22
+22
0 kanalda
Get PRO
Noyabr '22
+34
0 kanalda
Get PRO
Oktabr '22
+23
0 kanalda
Get PRO
Sentabr '22
+32
0 kanalda
Get PRO
Avgust '22
+19
0 kanalda
Get PRO
Iyul '22
+32
0 kanalda
Get PRO
Iyun '22
+22
0 kanalda
Get PRO
May '22
+104
0 kanalda
Get PRO
Aprel '22
+36
0 kanalda
Get PRO
Mart '22
+33
0 kanalda
Get PRO
Fevral '22
+18
0 kanalda
Get PRO
Yanvar '22
+22
0 kanalda
Get PRO
Dekabr '21
+12
0 kanalda
Get PRO
Noyabr '21
+45
0 kanalda
Get PRO
Oktabr '21
+388
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
16 Sentabr0
15 Sentabr0
14 Sentabr+3
13 Sentabr+1
12 Sentabr+3
11 Sentabr0
10 Sentabr+1
09 Sentabr+1
08 Sentabr+5
07 Sentabr0
06 Sentabr+2
05 Sentabr+2
04 Sentabr+3
03 Sentabr+3
02 Sentabr+1
01 Sentabr+1
Kanal postlari
Repost from LearnKube news
Kubernetes problems often hide in controller timing, implicit defaults, and capacity assumptions. This week in Learn Kubernet
Kubernetes problems often hide in controller timing, implicit defaults, and capacity assumptions. This week in Learn Kubernetes Weekly: 🔎 A production race condition left orphaned pods blocking new deployments. 📦 Source Hydrated Infrastructure Models commit rendered manifests for explicit GitOps audits. 🖥 Headlamp replaces the archived Kubernetes Dashboard and maps familiar workflows to a maintained UI. ⚙️ Kubernetes 1.36 adds pod-level CPU and memory management. 📊 The k8s-overcommit operator reclaims idle capacity according to priority classes. Read issue 201: https://kube.today/issues/201 This issue is brought to you by LearnKube — understand how Kubernetes works, and what to do when it breaks. Live training with 60% hands-on labs: https://ku.bz/hypSbyc-V

2
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isola
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help. More: https://ku.bz/tYzhJx61Q
105
3
Guardrails are not one-size-fits-all. David Parry argues that AI systems touching Kubernetes need deterministic rules that ma
Guardrails are not one-size-fits-all. David Parry argues that AI systems touching Kubernetes need deterministic rules that match the company, the deployment model, and the compliance requirements around sensitive data. He points to code review and YAML inspection as places where these guardrails should be explicit and enforceable, not left to improvisation. Watch the full interview: https://ku.bz/c5J05syX3 This interview is a reaction to Mai Nishitani's episode https://ku.bz/3hWvQjXxp.
114
4
A pizza order became a 15-container, 200-trace system. In Kube Signals episode two, Brian Teller and Mauricio (Salaboy) Salat
A pizza order became a 15-container, 200-trace system. In Kube Signals episode two, Brian Teller and Mauricio (Salaboy) Salatino examine observability, state management, governance, and trust for non-deterministic agents. They discuss: - Why multi-agent runtimes can recreate monolith scaling - How OpenTelemetry exposes prompts, completions, and decisions - Why execution history turns agent trust into measurable evidence Watch: https://ku.bz/TlVjXdnb6 Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
67
5
This article explains why three old Kubernetes CVEs will never get a code fix, and what to change in your cluster now that scanners are about to start flagging them again. More: https://ku.bz/22Rr95v9F
135
6
On-prem apps talking to cloud services need a path — and there are three. Raglin Anthony explains: public internet with HTTPS
On-prem apps talking to cloud services need a path — and there are three. Raglin Anthony explains: public internet with HTTPS (simple, but at the mercy of variability), AWS Site-to-Site VPN (private and encrypted), or AWS Direct Connect (a physical cable that bypasses the internet entirely — suitable for production and compliance workloads). Whichever path you pick, DNS resolution across environments is always the last thing you have to sort out. Watch the full interview: https://ku.bz/2XqMJnLVx
146
7
This article explains a new alpha feature in Kubernetes 1.36 that loads admission policies from files on disk at startup, so they are live before anything else and nobody can delete them. More: https://ku.bz/B9JxC5dVt
212
8
This article shows how a default AWS EKS setting lets any pod reach the node's metadata service and steal its IAM credentials, then walks through the simple fix. More: https://ku.bz/DXYZGjvf2
239
9
This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path. More: https://ku.bz/CTv-Yf60c
271
10
200 issues. More than 77,000 Kubernetes engineers. Thank you to all of you reading it 🎉 In Learn Kubernetes Weekly 200: 🤖 B
200 issues. More than 77,000 Kubernetes engineers. Thank you to all of you reading it 🎉 In Learn Kubernetes Weekly 200: 🤖 Benchmarking LLM Inference with Production Agent Traces 🔌 Two New Headlamp Plugins 🌐 Migrating from ingress-NGINX to Envoy Gateway 🐘 Building High-Availability PostgreSQL on Kubernetes Read it: https://kube.today/issues/200
195
11
AI does not just make the requested change. It often expands the scope. Pronomita Dey describes how AI-generated code can tur
AI does not just make the requested change. It often expands the scope. Pronomita Dey describes how AI-generated code can turn a simple automation into a much larger diff filled with comments, exceptions, and extra logic. That makes review harder, increases trust too early, and raises the need for guardrails, policy as code, and stronger pre-merge checks. Watch the full interview: https://ku.bz/lm5jTjdVN
215
12
This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves. More: https://ku.bz/j_H7dxLV6
174
13
Kubernetes is ready for databases. Most teams are not. In KubeSelect episode two, Salman Iqbal and Bart Farrell test this cla
Kubernetes is ready for databases. Most teams are not. In KubeSelect episode two, Salman Iqbal and Bart Farrell test this claim with Kat Cosgrove of VillageSQL. Kat covers: - Modern Kubernetes storage - Operators and database expertise - Team readiness - Managed database tradeoffs Kat's verdict: this is now a people problem. Watch the episode: https://ku.bz/7yDWlP8T5 Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
137
14
NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run. More: https://ku.bz/CKghZJGt1
238
15
This case study shows how to implement a HIPAA-compliant CI/CD pipeline using Cosign for artifact signing, OPA Gatekeeper for admission control on EKS, and long-term evidence storage in S3. More: https://ku.bz/TYS0yf264
336
16
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only al
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened. More: https://ku.bz/wd7SCHC3l
378
17
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview A
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview API, then makes it safer with audience-bound projected tokens. More: https://ku.bz/rz69JFBdZ
648
18
Security culture around CRA and SBOMs is built in day-to-day engineering, not in policy documents alone. Przemysław Wojtunik
Security culture around CRA and SBOMs is built in day-to-day engineering, not in policy documents alone. Przemysław Wojtunik explains how Spectro Cloud helps his team move faster on security and SBOM work, while stressing that every organization still needs a practical path to make compliance part of daily life. Watch the full interview: https://ku.bz/TJRYGMWV2
295
19
This week on Learn Kubernetes Weekly 199: 🔥 How Netflix Simplified Batch Compute with Kueue 💡 Server-side Apply: What Happe
This week on Learn Kubernetes Weekly 199: 🔥 How Netflix Simplified Batch Compute with Kueue 💡 Server-side Apply: What Happens When You Run kubectl apply 🌐 Kubernetes Is Migrating from SPDY to WebSockets 🔁 How I Learned to Stop Worrying and Love the Reconciliation Loop 🔒 Securing CI/CD for an Open Source Project: Lessons from Cilium Read it now: https://kube.today/issues/199 ⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
180
20
Multikube is a reverse proxy that sits in front of several Kubernetes API servers, terminating TLS and handling authenticatio
Multikube is a reverse proxy that sits in front of several Kubernetes API servers, terminating TLS and handling authentication and authorization centrally so kubectl talks to one endpoint. More: https://ku.bz/lMRhZQGJy
203