60-70% of all Kubernetes exploits start with exposed credentials.
Rodrigo Bersa from AWS lays out the three security concerns every developer should address before going to production:
1. Supply chain security — build from scratch or use hardened base images with zero CVEs from the start.
2. Continuous scanning — a clean image today won't stay clean.
3. Secrets management — Kubernetes secrets are base64-encoded, not encrypted. Store secrets externally (e.g., Secrets Manager) and mount them as volumes. If there's no shell in your image, credentials stay out of reach.
Watch the full interview: https://ku.bz/dB7PDNt0v
Post #1703
326
Forwarded from KubeFM