TGViewer
Kubernative by Palark | Kubernetes news and goodies Kubernative by Palark | Kubernetes news and goodies @kubernative · 1.77K subscribers
Post #359 1.09K
Can luring random online attackers into your Kubernetes clusters be fun or even useful? At least, we have a tool to try it out with minimal effort.

Koney is a Kubernetes operator that implements so-called “deception policies” to discover and deter malicious users. Currently, it supports honeytokens as the only deception method by:

- creating fake “sensitive” files, such as /run/secrets/koney/service_token, in all selected Pods;
- monitoring the attempts to access them by collecting alerts from the Cilium’s Tetragon operator or via a smaller eBPF-powered file access monitoring tool (kivebpf);
- logging these events and, optionally, sending alerts to external systems (currently, it supports only Dynatrace).

Future project plans include adding other deceptive techniques (HTTP endpoints and payloads) and integrating the operator with Kyverno policies.

▶️ GitHub repo

Language: Go | License: AGPL 3.0 | 89 ⭐️

#tools #security
  • 👍 2
  • 🔥 2
More from @kubernative
  1. Sep 16, 2026Sharing the latest version of our curated digest showcasing prominent software updates in…
  2. Sep 15, 2026Talos gets a hypervisor, and Sidero Labs joins Yardi Big news arrived for Talos Linux, a w…
  3. Sep 11, 2026Karmada became a CNCF Graduated project Karmada extends the standard Kubernetes API, allow…
  4. Sep 7, 2026We all know (and many of us use daily) k9s as a truly flagship CLI tool for Kubernetes. Bu…
  5. Sep 4, 2026k8gb v1.0.0 k8gb, a Kubernetes Global Balancer, originated at Absa Group. More than six ye…
  6. Aug 28, 2026Happy to share our newest selection of interesting Kubernetes-related articles to consider…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →