Kubesploit
Kanalga Telegramโda oโtish
News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/
Ko'proq ko'rsatish2 063
Obunachilar
+224 soatlar
+57 kunlar
+1830 kunlar
Postlar arxiv
2 063
Repost from N/a
Self-service and governance aren't competing forces โ they work together.
Peter Kelly explains how Tigera's tiered network policies in Project Calico let platform teams lock down critical rules at an upper layer while giving developers a lower tier to manage their own policies. Security stays immutable at the top, and developers get autonomy within those guardrails.
The key: treat policy tiers like layers โ compulsory at the top, flexible at the bottom.
Full interview: https://ku.bz/xgqZJhdyn
Watch the full interview: https://ku.bz/xgqZJhdyn
This interview is a reaction to Ben Poland's episode https://ku.bz/klBmzMY5-
2 063
Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with Tailscale
๐ฐ $16.15M to $20.21M a year
๐ Fully remote
โ https://ku.bz/J9Cs7QBBp
DevSecOps Engineer with Accenture Federal Services
๐ฐ $11.49M to $15.13M a year
๐จโ๐ป Remote from
โ https://ku.bz/bsl59cPMh
DevSecOps Engineer with OpenAI
๐ฐ $364.5K to $490K a year
๐จโ๐ป Remote from the United States of America
โ https://ku.bz/NXd17JHfV
DevSecOps Engineer with Anthropic
๐ฐ $300K to $405K a year
๐จโ๐ป Remote from
โ https://ku.bz/LzVjTfYNp
DevSecOps Engineer with Point72
๐ฐ $225K to $300K a year
๐จโ๐ป Remote from
โ https://ku.bz/gG67-vdCY
๐ Browse 2029 jobs on Kube Careers https://kube.careers
2 063
This article shows how to scan Helm charts for insecure RBAC, secret leaks, and malicious templates using tools like Trivy, GitHub Search, and OPA.
More: https://ku.bz/k4MpGVLyZ
2 063
Repost from LearnKube news
This week on Learn Kubernetes Weekly 170:
๐ฆ Could lockfiles just be SBOMs?
๐ Dynamic Istio Ingress Gateway Management with Kyverno
๐ฎ Factorio in Kubernetes? Well, why not?
๐ค Running DeepSeek Models on Kubernetes: A Backend Engineer's Experiment
โก Ephemeral Infrastructure: Why Short-Lived is a Good Thing
Read it now: https://kube.today/issues/170
โญ๏ธ This issue is brought to you by vCluster and LearnKube โ join "Multi-Tenancy March" starting Feb 24: a free 3-part hands-on series on namespace isolation, virtual clusters, GPU sharing, and AI agent sandboxing on Kubernetes https://ku.bz/multitenant26
2 063
Guardon is a Kubernetes admission controller that enforces security and compliance policies in real-time before resources are created in your cluster.
More: https://ku.bz/d4hT8s9Sw
2 063
Repost from N/a
Tibo on why Kubernetes isn't just for enterprise scale โ it can be a practical choice for solo self-hosters too.
You will learn:
- Why Ansible's declarative promise fell short with the Podman collection, forcing sequential imperative steps instead of desired-state definitions
- How community Helm charts replace the need to write and maintain every manifest yourself
- Why GitOps isn't just a deployment workflow โ it's a disaster recovery strategy when your infrastructure lives in your living room
Watch (or listen to) it here: https://ku.bz/Xk5S7VqXz
๐ This episode is brought to you by LearnKube โ get started on your Kubernetes journey through comprehensive online, in-person, or remote training https://learnkube.com/training
With @Birthmarkb
2 063
Repost from N/a
Ritesh Patel, Co-founder @ Nirmata, explains how Nirmata's AI platform engineering assistant differentiates itself in the market through strategic focus rather than broad appeal.
He demonstrates a direct approach to competitive positioning by acknowledging that their solution isn't for everyone - it's specifically designed for teams that have already adopted Kyverno as their policy engine.
Watch the interview: https://ku.bz/8nkrRSG_Z
Read the announcement: https://ku.bz/8_yYZZMG4
2 063
This article explains the risks of using unmaintained Docker images and how to detect vulnerabilities with tools like Trivy, SBOM operator, and Dependency Track.
More: https://ku.bz/WJ75qXRbV
2 063
Synapse is a high-performance reverse proxy and firewall built with Rust, using XDP-based packet filtering for ultra-low latency protection at kernel level.
More: https://ku.bz/w2PFxxfN8
2 063
This case study shows how Mindbody used Kyverno policy-as-code to dynamically manage Istio ingress gateways across hundreds of applications without updating individual Helm charts.
More: https://ku.bz/F6-Xr10Yv
2 063
Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with Tailscale
๐ฐ $16.01M to $20.04M a year
๐ Fully remote
โ https://ku.bz/J9Cs7QBBp
DevSecOps Engineer with Accenture Federal Services
๐ฐ $10.84M to $20.34M a year
๐จโ๐ป Remote from
โ https://ku.bz/WdgxCrTlm
DevSecOps Engineer with OpenAI
๐ฐ $364.5K to $490K a year
๐จโ๐ป Remote from the United States of America
โ https://ku.bz/NXd17JHfV
DevSecOps Engineer with Anthropic
๐ฐ $300K to $405K a year
๐จโ๐ป Remote from
โ https://ku.bz/LzVjTfYNp
DevSecOps Engineer with Scale AI
๐ฐ $264K to $330K a year
๐จโ๐ป Remote from
โ https://ku.bz/BdXCcJX58
๐ Browse 1635 jobs on Kube Careers https://kube.careers
2 063
kubectl-rexec is a kubectl plugin that provides full audit logging for kubectl exec sessions, addressing the security gap where standard exec commands leave no trace of what happens inside containers.
More: https://ku.bz/yRQZ9Jrml
2 063
Repost from N/a
"Self-service capabilities without governance is how you get outages at 3 AM."
Zain Malik from ExoStellar tackles the tension between developer empowerment and platform governance. A mature platform provides standardized interfaces that give users access to what they needโkernel layers, node layers, DOS systemsโwithout compromising reliability.
The key insight: centralization isn't about restriction, it's about creating reliable building blocks that scale.
Watch the full interview: https://ku.bz/rwttMCncv
2 063
Repost from N/a
Nicholaos Mouzourakis, Staff Product Security Engineer at Gusto, explains how Open Policy Agent (OPA) integrates with Kubernetes for authorization. He highlights OPA's versatility and performance characteristics, noting that a single node can handle numerous requests with proper optimization.
He describes multiple deployment options, including:
- Standing up multiple OPA instances
- Setting up auto-scaling groups
- Co-locating OPA with server pods
- Running OPA as a WASM module for lower latency
Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4
2 063
Repost from LearnKube news
This week on Learn Kubernetes Weekly 169:
๐ฅ When High Availability Brings Downtime
๐ Upgrade AWS CSI Drivers in Your Multi-Tenant Kubernetes Cluster
๐ค How We Serve AI/ML Models at Scale in SAP AI Core
โ
Container Readiness Checks for Spring Boot Deployments
๐ CoreDNS in OpenShift
Read it now: https://kube.today/issues/169
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
2 063
This tutorial teaches how to deploy HashiCorp Vault Secrets Operator on Google Kubernetes Engine to synchronize Vault secrets into Kubernetes Secret resources automatically.
More: https://ku.bz/QnvFmQp8h
2 063
Repost from N/a
Ziv Yatzik manages 600+ Postgres clusters in a closed network environment with no public cloud. After existing backup solutions proved unreliable โ causing downtime when disks filled up โ his team built a new architecture using pgBackRest, Argo CD, and Kubernetes CronJobs.
You will learn:
- Why storing WAL files on shared NAS storage prevents backup failures from cascading into database outages
- How GitOps with Argo CD lets them manage backups for hundreds of clusters by adding a single YAML file
Watch (or listen to) it here: https://ku.bz/Rg_sQYSmw
๐ This episode is sponsored by LearnKube โ get started on your Kubernetes journey through comprehensive online, in-person, or remote training https://learnkube.com/training
With @Birthmarkb
2 063
Kaniop is a Kubernetes operator written in Rust for managing Kanidm identity management clusters, providing declarative identity management through GitOps workflows.
More: https://ku.bz/D1JBBy0B3
2 063
This article explains a critical security issue where AWS CSI drivers gave DaemonSet service accounts the ability to patch nodes, completely breaking node isolation in multi-tenant clusters.
More: https://ku.bz/xGP7ymMvW
2 063
Dockadvisor is a lightweight Dockerfile linter built in Go that validates your Dockerfiles with over 60 rules covering syntax, security, and best practices.
More: https://ku.bz/2DT4TqRRk
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
