TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1680 353

Forwarded from KubeFM

Nicholaos Mouzourakis, Staff Product Security Engineer at Gusto, breaks down the common deployment patterns for Open Policy Agent (OPA) in Kubernetes environments. He explains the tradeoffs between individual pods, auto-scaling groups, daemon sets, sidecars, and WASM modules.

He outlines critical considerations for selecting the right deployment option:

- Latency requirements
- Bandwidth constraints
- Development overhead
- Feature compatibility (noting WASM modules lack full standard library support)
- Cloud costs and policy size implications

He notes that co-located pods typically achieve a few milliseconds of latency, and suggests WASM modules for those requiring even better performance.

Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4
More from @kubesploit
  1. Sep 25, 2026This tutorial builds a Docker image with a secret, then shows how it still sits in an earl…
  2. Sep 24, 2026This article explains how Vault piles up unexpired leases when pods keep re-authenticating…
  3. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  4. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
  5. Sep 22, 2026This article explains what an attacker can really do with leaked Kubernetes credentials, f…
  6. Sep 22, 2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →