uz
Feedback
Kubesploit

Kubesploit

Kanalga Telegram’da o‘tish

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Ko'proq ko'rsatish
2 132
Obunachilar
+124 soatlar
Ma'lumot yo'q7 kun
+1430 kun
Postlar arxiv
In this article you will compare five open-source tools for Kubernetes security scanning: 1. Grype. 2. Trivy. 3. Kubesec. 4.
In this article you will compare five open-source tools for Kubernetes security scanning: 1. Grype. 2. Trivy. 3. Kubesec. 4. Kube-bench. 5. kubeaudit. Read more https://quesengmany.medium.com/how-to-improve-the-security-of-your-applications-with-kubernetes-security-scanners-cda97fd2f574

Repost from Kube Careers
What does it take to get a job as a Kubernetes engineer? Do you need a Kubernetes certification to apply for a job? What's th
What does it take to get a job as a Kubernetes engineer? Do you need a Kubernetes certification to apply for a job? What's the average salary for a Kubernetes engineer? We analyzed 97 Kubernetes jobs for the first three months of 2022 and found that: - The average Kubernetes job pays €83,398 in Europe and $123,126 in North America. - The majority of the job listings are for Senior DevOps Engineers. - Only 1% of the total listings offer a position to Junior Engineers 😢 - As usual, AWS, Python, Terraform, Prometheus and Jenkins!!! are the top terms mentioned in any Kubernetes job descriptions. You can read the full report here: https://kube.careers/kubernetes-trend-report-2022-q1

Using GitHub Actions, it's easy to improve the security of your containers by automating vulnerability scanning and digital s
Using GitHub Actions, it's easy to improve the security of your containers by automating vulnerability scanning and digital signing. In this post, you'll go over how to set up and secure a CI/CD pipeline using GitHub Actions, Cosign, and Trivy. Read more https://blog.aquasec.com/trivy-github-actions-security-cicd-pipeline

In this blog post, you will - Look at RBAC, what it is and how it can be used. - Create a ServiceAccount with restricted righ
In this blog post, you will - Look at RBAC, what it is and how it can be used. - Create a ServiceAccount with restricted rights in the cluster. - Create a Role and ClusterRole to allow a user to access an application namespace. Read more https://anaisurl.com/kubernetes-rbac

This repository aims to implement a CrowdSec bouncer for the router Traefik to block malicious IPs to access your services. For this, it leverages Traefik v2 ForwardAuth middleware and queries CrowdSec with the client IP. Read more https://github.com/fbonalair/traefik-crowdsec-bouncer

SimpleSecrets is a secure operator that allows you to create secrets on demand. You can commit the SimpleSecrets, which are references to a database secret, and the operator will create Kubernetes Secrets automatically for you. Read more https://github.com/Michaelpalacce/SimpleSecrets

The OWASP WrongSecrets p0wnable app is an app packed with various ways of how to not store your secrets. These can help you t
The OWASP WrongSecrets p0wnable app is an app packed with various ways of how to not store your secrets. These can help you to realize whether your secret management is fine. The challenge is to find all the different secrets. Read more https://github.com/commjoen/wrongsecrets

This post will show how Istio and OAuth2-Proxy can be used to force users to authenticate before accessing applications on Kubernetes. Read more https://elastisys.com/istio-and-oauth2-proxy-in-kubernetes-for-microservice-authentication

Grype is a vulnerability scanner for container images and filesystems. Works with Syft, the powerful SBOM (software bill of materials) tool for container images and filesystems. Read more https://github.com/anchore/grype

Docker Security Playground is an application that allows you to: - Create network and network security scenarios. - Learn pen
Docker Security Playground is an application that allows you to: - Create network and network security scenarios. - Learn penetration testing techniques by simulating vulnerability labs scenarios. - Manage a set of docker-compose projects. Read more https://github.com/DockerSecPlay/DockerSecurityPlayground

HOUDINI is a curated list of Network Security related Docker Images for Network Intrusion purposes. Read more https://github.
HOUDINI is a curated list of Network Security related Docker Images for Network Intrusion purposes. Read more https://github.com/cybersecsi/HOUDINI

Repost from LearnKube news
The team at Learnk8s is happy to announce Kube Events — a curated list of Kubernetes-related events. The website includes onl
The team at Learnk8s is happy to announce Kube Events — a curated list of Kubernetes-related events. The website includes only what we think are the meetups, conferences, training & webinars that you will find interesting to attend (e.g. no vendor pitches, with a focus on Kubernetes). You can discover the next upcoming events here: https://kube.events You can also join the Telegram channel for daily updates here: https://t.me/KubeEvents

In this blog post, you will verify cosigned container images in Amazon Elastic Container Service using Lambda, Golang, and Ev
In this blog post, you will verify cosigned container images in Amazon Elastic Container Service using Lambda, Golang, and EventBridge. Read more https://blog.chainguard.dev/cosign-verify-ecs

In this article, you will learn how the Kube-Prometheus project identified and mitigated security issues in their project usi
In this article, you will learn how the Kube-Prometheus project identified and mitigated security issues in their project using Kubescape. Read more https://arthursens.medium.com/risk-analysis-and-security-compliance-in-kube-prometheus-10c8cfb180b8

How can I run my workloads securely on top of Kubernetes? In this post, we'll be taking a look at the CIS-Benchmark, breaking
How can I run my workloads securely on top of Kubernetes? In this post, we'll be taking a look at the CIS-Benchmark, breaking the concept down to simple terms, and in the end, deploying the CIS-Operator using Helm charts and custom values. Read more https://aymen-abdelwahed.medium.com/k8s-operators-cis-benchmarks-8d7915d5cb2d

In the article, you'll discover the findings of a YOYO attack on a Kubernetes cluster with autoscaling. Read more https://med
In the article, you'll discover the findings of a YOYO attack on a Kubernetes cluster with autoscaling. Read more https://medium.com/@15daniel10/yoyo-attack-on-a-k8s-cluster-102bc1d5ca3e

This is a hands-on guide for using Dex identity provider with Google accounts and managing role-based access control in Kuber
This is a hands-on guide for using Dex identity provider with Google accounts and managing role-based access control in Kubernetes via OpenID Connect. Read more https://elastisys.com/elastisys-engineering-how-to-use-dex-with-google-accounts-to-manage-access-in-kubernetes

Repost from LearnKube news
What happens when you combine a Kubernetes RoleBinding to a ClusterRole? Are you even allowed? This article will explore the
What happens when you combine a Kubernetes RoleBinding to a ClusterRole? Are you even allowed? This article will explore the Kubernetes RBAC authorization model by rebuilding it from scratch. You will also discover different (unusual but useful) configurations for your RBAC resources. If you work in a large organization with many users and applications, you will find this article on limiting access to Kubernetes resources relevant. https://learnk8s.io/rbac-kubernetes

In this tutorial, you will create an Amazon EKS cluster, install LitmusChaos and deploy a demo application. Then, you will de
In this tutorial, you will create an Amazon EKS cluster, install LitmusChaos and deploy a demo application. Then, you will define chaos experiments to be run on it and observe the behaviour. Read more https://aws.amazon.com/blogs/containers/chaos-engineering-with-litmuschaos-on-amazon-eks

So you want to deploy an application to EKS that requires access to AWS resources like an S3 bucket or a Kinesis stream. What's the best way to allow that? Use OIDC! Read more https://medium.com/@abhinav.ittekot/granting-iam-permissions-to-pods-in-eks-using-oidc-f2044c88a53