TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1838 285

Forwarded from KubeFM

Alessandro Pomponio, Research Software Engineer @ IBM Research, explains how his team used Kyverno policies to solve GPU resource monopolization in their Kubernetes clusters. He describes a common anti-pattern where researchers were creating idle pods with commands like sleep infinity and using SSH to treat them as virtual machines, causing GPU starvation for other users, especially during conference deadlines.

Alessandro walks through their policy-based solution using Kyverno to block pod exec commands while maintaining necessary exceptions for cluster administrators.

Watch the full episode: https://ku.bz/5sK7BFZ-8
More from @kubesploit
  1. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  2. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
  3. Sep 22, 2026This article explains what an attacker can really do with leaked Kubernetes credentials, f…
  4. Sep 22, 2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mis…
  5. Sep 21, 2026This article walks through making a container image safe before it ever reaches the cloud,…
  6. Sep 21, 2026We just published Kubernetes Architecture in Financial Services, a free technical book abo…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →