uz
Feedback
Kubesploit

Kubesploit

Kanalga Telegramโ€™da oโ€˜tish

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Ko'proq ko'rsatish
2 060
Obunachilar
-224 soatlar
-17 kunlar
+1330 kunlar
Postlar arxiv
Repost from LearnKube news
This week on Learn Kubernetes Weekly 106: โฐ How to solve the issue of network latency jitters caused by a massive number of I
This week on Learn Kubernetes Weekly 106: โฐ How to solve the issue of network latency jitters caused by a massive number of IPVS rules ๐Ÿ‹๏ธโ€โ™€๏ธ Load testing Kubernetes clients without breaking the bank ๐Ÿšฆ Terminating elegantly: a guide to graceful shutdowns ๐Ÿ“‰ How I reduced EKS Windows node start time from 5 min to ~90s ๐Ÿค” How Kubernetes Requests and Limits Really Work Read it now: https://learnk8s.io/issues/106 ๐ŸŒŸ This newsletter is brought to you by Testkube โ€” Scale all of your tests with Kubernetes, integrate seamlessly with CI/CD and centralize test troubleshooting and reporting https://ku.bz/_bByjc0mQ

Reflector is a Kubernetes addon designed to monitor changes to resources (Secrets and ConfigMaps) and reflect changes to mirror resources in the same or other namespaces. More: https://github.com/emberstack/kubernetes-reflector

Repost from N/a
@miamorecadenza shares their journey in building a "compute as a faucet" home lab where infrastructure becomes invisible and tasks can be executed without manual intervention. You will learn: - How to evaluate operating systems for your home lab โ€” from Rocky Linux to Talos Linux, and why minimal, immutable operating systems are gaining traction. - How to implement a three-tier storage strategy combining Longhorn (replicated storage), NFS (bulk storage), and S3 (cloud storage) to handle different workload requirements. - How to secure your home lab with certificate-based authentication, WireGuard VPN, and proper DNS configuration while protecting your home IP address. Watch (or listen to) it here: https://ku.bz/2kzj2MgfH ๐ŸŒŸ This episode is sponsored by Nutanix โ€” innovate faster with a complete and open cloud-native stack for all your apps and data anywhere https://ku.bz/wb_0GNHnr With @Birthmarkb "SIG-Bart" Farrell

Permify is an open-source authorization service for easily building and managing fine-grained, scalable, and extensible acces
Permify is an open-source authorization service for easily building and managing fine-grained, scalable, and extensible access controls for your applications and services. More: https://github.com/Permify/permify

Repost from Kube Careers
Is the Kubernetes job market still hot in 2024? ๐Ÿ”ฅ We analyzed 8772 Kubernetes job listings from Q3 2024 to find out: ๐Ÿ’ฐ The
Is the Kubernetes job market still hot in 2024? ๐Ÿ”ฅ We analyzed 8772 Kubernetes job listings from Q3 2024 to find out: ๐Ÿ’ฐ The average worldwide Kubernetes salary is $158,134, with North America averaging $169,627. ๐ŸŒŽ A whopping 62% of Kubernetes jobs are in North America, with Europe at 32.5%. ๐Ÿ‘ฉโ€๐Ÿ’ป Software Engineers remain the most sought-after role (42%), followed by DevOps and Platform Engineers. ๐Ÿก 68% of jobs allow some form of remote work, with hybrid roles gaining popularity. ๐Ÿ Python continues to be the most in-demand programming language for Kubernetes roles. Want to know which skills and tools are essential to land your next Kubernetes job? Check out our detailed State of the Kubernetes Job Market report for Q3 2024: https://ku.bz/vg_wXyNvj

This article introduces Azure Kubernetes Service Workload Identities and provides a step-by-step demo on enabling and impleme
This article introduces Azure Kubernetes Service Workload Identities and provides a step-by-step demo on enabling and implementing them in AKS. More: https://medium.com/@swordfish291/getting-started-with-azure-workload-identities-7f8ab78da40f

Tetragon enables powerful real-time, eBPF-based security observability and runtime enforcement. It is Kubernetes-aware and un
Tetragon enables powerful real-time, eBPF-based security observability and runtime enforcement. It is Kubernetes-aware and understands identities so that security event detection can be configured to individual workloads. More: https://tetragon.io

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Worldcoin ๐Ÿ’ฐ $236K to $323K a yea
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Worldcoin ๐Ÿ’ฐ $236K to $323K a year ๐Ÿ  From the office in San Francisco, CA, USA โ†’ https://kube.careers/t/e824f971-4831-4329-8dfd-2edcce0c9ed5?s=55 DevSecOps Engineer with Gemini ๐Ÿ’ฐ $248K to $310K a year ๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States โ†’ https://kube.careers/t/03598248-6bcb-4117-85b1-ecba6edb3070?s=55 DevSecOps Engineer with Uniswap Labs ๐Ÿ’ฐ $264K to $294K a year ๐Ÿ  From the office in New York, NY, USA โ†’ https://kube.careers/t/3d7c0bd7-abd8-4526-a376-458f65018709?s=55 Security Architect with Adobe Inc. ๐Ÿ’ฐ $191.7K to $345.7K a year ๐Ÿ  From the office in Seattle, WA / San Francisco / San Jose, CA, USA โ†’ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27?s=55 ๐Ÿ‘‰ Browse all 1375 Kubernetes jobs on Kube Careers https://kube.careers

Pinniped is the easy, secure way to log in to your Kubernetes clusters. More: https://github.com/vmware-tanzu/pinniped

Repost from LearnKube news
This week on Learn Kubernetes Weekly 105: ๐Ÿ‡จ๐Ÿ‡ณ Chinese Docker Hub complete shutdown: how far can Kubernetes image repositorie
This week on Learn Kubernetes Weekly 105: ๐Ÿ‡จ๐Ÿ‡ณ Chinese Docker Hub complete shutdown: how far can Kubernetes image repositories go? ๐Ÿคฏ Overengineering this blog's preview site with Kubernetes ๐Ÿง Taking a look at the Kube-proxy API ๐Ÿฅ‡ Kubernetes: the road to 1.0 ๐Ÿƒโ€โ™‚๏ธ Extending Kubernetes functionality: A practical guide to custom resource definitions Read it now: https://learnk8s.io/issues/105 ๐ŸŒŸ This newsletter is brought to you by Syntasso, creators of Kratix, a framework for building composable developer platforms. Deploy on Kubernetes with speed, safety, and scalability https://ku.bz/0F0XMbqgN

helmper is a Go program that reads Helm Charts from remote OCI registries and pushes the charts container images to your registries with optional OS-level vulnerability patching. More: https://github.com/ChristofferNissen/helmper

Repost from N/a
Paul Butler, founder of Jamsocket, discusses how to identify necessary vs unnecessary complexity in Kubernetes and explains how his team successfully runs production workloads by being selective about which features they use. You will learn: - Why to be cautious with features like CRDs, StatefulSets, and Helm and how to evaluate if you really need them. - How to stay on the "happy path" in Kubernetes by focusing on stable and simple resources like Deployments, Services, and ConfigMaps. - When to consider alternatives like Google Cloud Run for simpler deployments that don't need the full complexity of Kubernetes. Watch (or listen to) it here: https://kube.fm/kubernetes-hater-s-guide-paul ๐ŸŒŸ This episode is sponsored by Syntasso, the creators of Kratix, a framework for building composable internal developer platforms https://ku.bz/CJNDlLXVS With @Birthmarkb "Diet Coke Lover" Farrell

The article walks through a hands-on lab where a Flask application is exploited to gain initial access to a Kubernetes cluste
The article walks through a hands-on lab where a Flask application is exploited to gain initial access to a Kubernetes cluster. This is followed by privilege escalation using GitHub CI/CD credentials and exfiltrating sensitive data from a database. More: https://soc-inspiration.medium.com/hands-on-lab-full-kubernetes-compromise-what-will-your-soc-do-about-it-3866106cf041

kubeztl is a tool that zitifies the Kubernetes client, allowing users to access their Kubernetes cluster securely using a zero-trust overlay network. More: https://github.com/openziti-test-kitchen/kubeztl

Repost from LearnKube news
Kubernetes in action: from pods to production-ready clusters! ๐Ÿ“† Learnk8s runs a 4-day online Advanced Kubernetes course next
Kubernetes in action: from pods to production-ready clusters! ๐Ÿ“† Learnk8s runs a 4-day online Advanced Kubernetes course next week! You will learn how to: 1๏ธโƒฃ Architect and design resilient clusters (in the cloud or on-prem). 2๏ธโƒฃ Master deployment strategies and resource management. 3๏ธโƒฃ Wire the cluster network and trace packets flowing through it. 4๏ธโƒฃ Secure your cluster with the latest best practices. 5๏ธโƒฃ Autoscale, manage data and stateful workloads, monitoring and more. What you need to know: โœ… 40% lecture, 60% hands-on labs. โœ… Small groups for personalized learning. โœ… Progresses from basics to advanced topics. โœ… Lifetime access to course materials and Slack community. Ticket and info: https://kube.events/t/3ae8e890-0f78-40e8-854e-849964bb8aee Corporate training: https://learnk8s.io/corporate-training

The article examines the kube-proxy API, covering its healthz and metrics components, and the information it provides without authentication. More: https://raesene.github.io/blog/2024/06/16/Taking-A-Look-At-The-Kube-Proxy-API

Repost from N/a
Hillai Ben-Sasson and Ronen Shustin, Security Researchers at Wiz, emphasized that containers should not be solely relied upon as security barriers due to their vulnerability to kernel exploits and common misconfiguration. They also pointed out significant risks associated with strong secrets within Kubernetes environments, which can grant extensive read and write access across different cloud services and customers. Watch the full episode: https://kube.fm/hacking-alibaba-ronen-hillai

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Worldcoin ๐Ÿ’ฐ $236K to $323K a yea
This week's 6 best Kubernetes vacancies that focus on security are: DevSecOps Engineer with Worldcoin ๐Ÿ’ฐ $236K to $323K a year ๐Ÿ  From the office in San Francisco, CA, USA โ†’ https://kube.careers/t/e824f971-4831-4329-8dfd-2edcce0c9ed5?s=55 DevSecOps Engineer with Gemini ๐Ÿ’ฐ $248K to $310K a year ๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States โ†’ https://kube.careers/t/03598248-6bcb-4117-85b1-ecba6edb3070?s=55 DevSecOps Engineer with Uniswap Labs ๐Ÿ’ฐ $264K to $294K a year ๐Ÿ  From the office in New York, NY, USA โ†’ https://kube.careers/t/3d7c0bd7-abd8-4526-a376-458f65018709?s=55 Security Architect with Adobe Inc. ๐Ÿ’ฐ $191.7K to $345.7K a year ๐Ÿ  From the office in Seattle, WA / San Francisco / San Jose, CA, USA โ†’ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27?s=55 ๐Ÿ‘‰ Browse all 1231 Kubernetes jobs on Kube Careers https://kube.careers

This article provides a guide to Falco, a system threat detection engine. It covers its installation, rule creation, architec
This article provides a guide to Falco, a system threat detection engine. It covers its installation, rule creation, architecture, and use with containers and Kubernetes. More: https://a-cup-of.coffee/blog/falco

Repost from LearnKube news
This week on Learn Kubernetes Weekly 104: ๐Ÿค” Why sometimes the PID 1 process cannot be killed in a container ๐Ÿ“• Understanding
This week on Learn Kubernetes Weekly 104: ๐Ÿค” Why sometimes the PID 1 process cannot be killed in a container ๐Ÿ“• Understanding DNS in Kubernetes ๐Ÿฅ From fragile to faultless: Kubernetes self-healing in practice ๐Ÿšง The trouble with topology-aware routing: sacrificing reliability in the name of cost savings โ™ป๏ธ Taming FluxCD Helm releases: the Kustomize way approach Read it now: https://learnk8s.io/issues/104 โญ๏ธ Become an expert in Kubernetes. Join the next instructor-led Learnk8s training and learn how to master Kubernetes scaling, security and development https://learnk8s.io/training