TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1623 308

Forwarded from KubeFM

Dilshan discusses a real incident where migrating EKS nodes to AL2023 caused the cluster autoscaler to lose AWS permissions silently.

You will learn:

- Why AL2023 blocks pod access to instance metadata by default, breaking components that relied on node IAM roles
- How to implement IRSA correctly by configuring IAM roles, Kubernetes service accounts, and OIDC trust relationships, and why both AWS IAM and Kubernetes RBAC must be configured independently
- How to audit which pods currently rely on node roles and clean up legacy IAM permissions to reduce attack surface after migration

Watch (or listen to) it here: https://ku.bz/T_YPfTfDb

🌟 This episode is brought to you by LearnKube — join their 4-day hands-on Advanced Kubernetes course starting January 29th and finally get comfortable with production clusters. https://learnkube.com/training

With @Birthmarkb "Keep Working Harder" Farrell
More from @kubesploit
  1. Sep 25, 2026This tutorial builds a Docker image with a secret, then shows how it still sits in an earl…
  2. Sep 24, 2026This article explains how Vault piles up unexpired leases when pods keep re-authenticating…
  3. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  4. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
  5. Sep 22, 2026This article explains what an attacker can really do with leaked Kubernetes credentials, f…
  6. Sep 22, 2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →