TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1795 322

Forwarded from KubeFM

Nicholaos Mouzourakis, Staff Product Security Engineer at Gusto, explains how they implemented auditable decision logging for Open Policy Agent (OPA) in their Kubernetes environment. He describes how Styra's Declarative Authorization Service (DAS) ingests and indexes OPA decision logs from all instances, making them searchable in a centralized location.

Nicholaos details how DAS enables:

- Searching for actions taken by specific users
- Identifying users with access to particular resources
- Tracking when and how access was granted
- Simulating policy changes against historical decision logs

He also mentions how they overcame challenges with legacy batch decision logs that weren't easily searchable by implementing a new batch API provided by Styra.

Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4
More from @kubesploit
  1. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  2. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
  3. Sep 22, 2026This article explains what an attacker can really do with leaked Kubernetes credentials, f…
  4. Sep 22, 2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mis…
  5. Sep 21, 2026This article walks through making a container image safe before it ever reaches the cloud,…
  6. Sep 21, 2026We just published Kubernetes Architecture in Financial Services, a free technical book abo…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →