uz
Feedback
Kubesploit

Kubesploit

Kanalga Telegram’da oβ€˜tish

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Ko'proq ko'rsatish
2 061
Obunachilar
Ma'lumot yo'q24 soatlar
+27 kunlar
+1530 kunlar
Postlar arxiv
In this article, you'll learn how to secure local Kubernetes apps using cert-manager, ExternalDNS, and Cloudflare to issue TLS certificates and avoid untrusted certificate errors, making it easy to manage and expose your applications securely. More: https://itnext.io/securing-local-kubernetes-apps-a-practical-guide-with-cert-manager-externaldns-and-cloudflare-d1ee9342ed83

Repost from N/a
Tim Miller, CEO and Co-founder at Kusari, discusses three categories of tools that are transforming the Kubernetes ecosystem. He highlights Ko, which helps developers deploy applications with minimal friction**, Falco by Sysdig, which provides deep system visibility, and SBOM generation tools like Excalibur and Guac, which make container dependencies more transparent. These tools focus on developer experience and system observability. Watch the full interview: https://ku.bz/-2Sqn9Jb9

In this article, you'll learn how to build a custom cert-manager webhook for DuckDNS to automate certificate issuance for Kub
In this article, you'll learn how to build a custom cert-manager webhook for DuckDNS to automate certificate issuance for Kubernetes clusters without public HTTP access, using the DNS-01 challenge to validate domain ownership. More: https://medium.com/@csp33/building-my-first-go-project-a-cert-manager-webhook-for-duckdns-47db984f9bed

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: Security Architect with Adobe Inc. πŸ’° $191.7K to $345.7K
This week's 6 best Kubernetes vacancies that focus on security are: Security Architect with Adobe Inc. πŸ’° $191.7K to $345.7K a year 🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA β†’ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27 Security Architect with Dexterity πŸ’° $200K to $300K a year 🏠 From the office in Redwood, CA, USA β†’ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275 DevSecOps Engineer with Attentive πŸ’° $200K to $270K a year πŸ‘¨β€πŸ’» Remote from the United States of America β†’ https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912 DevSecOps Engineer with Plaid πŸ’° $186.84K to $279.72K a year πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ US β†’ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d DevSecOps Engineer with Glean πŸ’° $185K to $280K a year πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ Palo Alto, CA, USA β†’ https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f πŸ‘‰ Browse all 1151 Kubernetes jobs on Kube Careers https://kube.careers

This repository contains a collection of AppArmor and Seccomp profiles for common Docker images. These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles. More: https://github.com/Archguardian-io/Docker-AppArmor-Profiles

Repost from LearnKube news
This week on Learn Kubernetes Weekly 116: πŸ’₯ Node.js 20 upgrade: a journey through unexpected heap issues with Kubernetes 🐳
This week on Learn Kubernetes Weekly 116: πŸ’₯ Node.js 20 upgrade: a journey through unexpected heap issues with Kubernetes 🐳 How to optimize Kubernetes for large Docker images πŸ“ˆ How to optimize autoscaling in Kubernetes using metrics based on application workflows πŸ”Ž Container internals series: seccomp πŸ›‘ Preemptible pods Read it now: https://learnk8s.io/issues/116 🌟 StormForge β€” the only JVM workload rightsizing solution for Kubernetes https://ku.bz/PJjcy3PwL

Discover how to create a secure flow for your AKS applications to access sensitive secrets, such as database credentials, usi
Discover how to create a secure flow for your AKS applications to access sensitive secrets, such as database credentials, using the Secret Store CSI Driver and User-Assigned Managed Identity (UAMI). More: https://medium.com/@gharbisofiene98/automating-secure-secrets-management-in-aks-with-terraform-and-azure-key-vault-e6a71f5f6805

Repost from N/a
Platform Engineer Artem Lajko breaks down observability into three distinct layers and explains how tools like Prometheus, Grafana, and Falco serve different purposes. You will learn: - How to implement the three-layer model (external, internal, and OS-level) and why each layer serves different stakeholders - How to choose and scale observability tools using a label-based approach (low, medium, high) - How to manage observability costs by collecting only relevant metrics and logs Watch (or listen to) it here: https://ku.bz/9sGxhmm8s 🌟 This episode is brought to you by Learnk8s β€” Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training With @Birthmarkb "Kubernetes historian" Farrell

AWRBACS is a tool that audits CRUD permissions in Kubernetes' RBAC, allowing users to enumerate and verify the permissions of users and service accounts. More: https://github.com/lobuhi/awrbacs

In this article, you'll learn how to design effective Kubernetes Network Policies to secure your cluster, including key consi
In this article, you'll learn how to design effective Kubernetes Network Policies to secure your cluster, including key considerations, best practices, and examples to enforce network isolation and the principle of least privilege. More: https://medium.com/@rozdolskyvolodymyr/designing-effective-kubernetes-network-policies-key-considerations-6e70255c0ef6

The Trivy Operator leverages Trivy to continuously scan your Kubernetes cluster for security issues. The scans are summarised
The Trivy Operator leverages Trivy to continuously scan your Kubernetes cluster for security issues. The scans are summarised in security reports as Kubernetes Custom Resource Definitions, which become accessible through the Kubernetes API. More: https://github.com/aquasecurity/trivy-operator

Repost from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are: Security Architect with Adobe Inc. πŸ’° $191.7K to $345.7K
This week's 6 best Kubernetes vacancies that focus on security are: Security Architect with Adobe Inc. πŸ’° $191.7K to $345.7K a year 🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA β†’ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27 Security Architect with Dexterity πŸ’° $200K to $300K a year 🏠 From the office in Redwood, CA, USA β†’ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275 DevSecOps Engineer with Crusoe πŸ’° $180K to $300K a year πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ San Francisco, CA, USA β†’ https://kube.careers/t/cc2ab37b-4b47-4dc0-9199-04269d9e3607 DevSecOps Engineer with Attentive πŸ’° $200K to $270K a year πŸ‘¨β€πŸ’» Remote from the United States of America β†’ https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912 DevSecOps Engineer with Plaid πŸ’° $186.84K to $279.72K a year πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ US β†’ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d πŸ‘‰ Browse all 1218 Kubernetes jobs on Kube Careers https://kube.careers

In this article, you'll learn how to create and manage Seccomp profiles using Golang to control system calls and enhance secu
In this article, you'll learn how to create and manage Seccomp profiles using Golang to control system calls and enhance security in containerized environments, reducing potential vulnerabilities and attack surfaces. More: https://cloudchirp.medium.com/container-internals-series-part-4-seccomp-d88543988709

Repost from LearnKube news
This week on Learn Kubernetes Weekly 115: πŸ₯· Kubernetes has its "ADCS" how to backdoor a Kubernetes in silence πŸ”’ GitOps secr
This week on Learn Kubernetes Weekly 115: πŸ₯· Kubernetes has its "ADCS" how to backdoor a Kubernetes in silence πŸ”’ GitOps secrets with Argo CD, Hashicorp Vault and the External Secret Operator 🌲 Why is running as root in kubernetes containers dangerous? @Marcin Wasiucionek πŸ”­ Go deeper: linux runtime visibility meets wireshark 🀫 Securing secrets in confidential containers: usage patterns to avoid Read it now: https://learnk8s.io/issues/115 🌟 Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop next week: https://learnk8s.io/online-advanced-january-2025

In this article, you'll learn how to secure sensitive data in confidential containers, including best practices for avoiding
In this article, you'll learn how to secure sensitive data in confidential containers, including best practices for avoiding common usage patterns that compromise security and restricting Kubernetes APIs to protect your secrets. More: https://pradiptabanerjee.medium.com/securing-secrets-in-confidential-containers-usage-patterns-to-avoid-941388cde546

Repost from LearnKube news
In this article, you'll learn how to expose ports in Kubernetes, common misconceptions about securing your applications, and
In this article, you'll learn how to expose ports in Kubernetes, common misconceptions about securing your applications, and best practices for controlling port access and network traffic using Network Policies. More: https://awsmorocco.com/exposing-ports-in-kubernetes-what-you-should-to-know-cd1a80655f6c

Repost from N/a
In this episode, William Morgan, CEO of Buoyant, explores the complex trade-offs between cost optimization and reliability in Kubernetes networking. You will learn: - How Topology-aware routing attempts to reduce cross-zone traffic costs but can compromise reliability by limiting inter-zone communication - Why Layer 7 load balancing offers better traffic management through protocol awareness compared to topology-aware routing's Layer 4 approach - How HAZL (High Availability Zonal Load Balancing) provides a more nuanced solution by balancing cost savings with reliability guarantees through intelligent traffic routing Watch (or listen to) it here: https://ku.bz/CBwn51pl- 🌟 This episode is brought to you by Learnk8s β€” Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training With @Birthmarkb "Real Chill Guy" Farrell

In this article, you will learn about Traceeshark, a plugin for Wireshark that enables visual and interactive analysis of Tra
In this article, you will learn about Traceeshark, a plugin for Wireshark that enables visual and interactive analysis of Tracee events, and discover how it simplifies the investigation of Linux runtime security issues and malware analysis. More: https://blog.aquasec.com/go-deeper-linux-runtime-visibility-meets-wireshark

In this article, you will learn about the security implications of running containers as root in Kubernetes, and how using no
In this article, you will learn about the security implications of running containers as root in Kubernetes, and how using non-root users can mitigate common attack vectors and enhance overall security. More: https://medium.com/@marcin.wasiucionek/why-is-running-as-root-in-kubernetes-containers-dangerous-e5f1a116080e

Learn how to utilize Kubernetes' certificate system for post-exploitation, including techniques for backdooring a Kubernetes cluster, exploiting ETCD certificates, and forging service account JWT tokens to gain persistent control over cluster resources. More: https://wgpsec.medium.com/en-kubernetes-has-its-adcs-how-to-backdoor-a-kubernetes-in-silence-08f382183e59