TGViewer
CatOps CatOps @catops · 5.08K subscribers
Post #2686 1.89K
Kubernetes v1.33 Fixes a 10-Year-Old Image Pull Loophole.

While technically a loophole, I wouldn't say that its impact was too high. It would be concerning only if you'd run multi-tenant clusters, where customers' pods run on the shared nodes. And even then, it could have been mitigated with pullPolicy: Always. While I never encountered this, I could imagine such setup in some PaaS company.

The gist is that previously (or still, depends on your K8s version), kubelet doesn't check the correct permissions to use a container image if this image is already present on a node.

#kubernetes #security
Kubernetes v1.33 Fixes a 10-Year-Old Image Pull Loophole Kubernetes v1.33 finally enforces image pull secrets even for cached images, closing a 10-year-old loophole in multi-tenant cluster security.
  • 👍 8
  • ❤ 1
More from @catops
  1. Oct 1, 2026​​I traded my personal information for this report, so you don’t have to! DataDog presents…
  2. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  3. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  4. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  5. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
  6. Sep 24, 2026Shopify wrote an article on them moving from React Native to the native code for their mob…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →