TGViewer
Channel Public Channel
Kubesploit

Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Subscribers
2.13K
Photos
961
Videos
208
Links
1.9K

Showing posts older than #1286 · Back to latest

Older Posts 20 shown
Post #1285 583
Trivy is a comprehensive and versatile security scanner.

What Trivy can scan:

- Container Images.
- Filesystem.
- Git Repository (remote).
- Virtual Machine Image.
- Kubernetes.
- AWS.

More: https://ku.bz/J7cTQ8HBf
Post #1284 668
In this article, you will learn about TeamTNT's new campaign targeting exposed Docker daemons to deploy malware and cryptominers.

They are using compromised Docker Hub accounts and leveraging cloud-native capabilities.

More: https://ku.bz/tQR0YvSL1
Post #1283 901
Paralus is a tool that enables controlled, audited access to Kubernetes infrastructure.

It comes with just-in-time service account creation and user-level credential management that integrates with your RBAC and SSO.

Ships as a GUI, API, and CLI.

More: https://ku.bz/D2-92bdW4
Post #1282 432

Forwarded from LearnKube news

Master Kubernetes with Learnk8s' Advanced Kubernetes workshop!

What should you expect?

- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.

The next online courses start in 2 weeks: https://ku.bz/DX6TPV4P_

We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
Post #1281 471
In this article, you will learn how to simplify image pulls in on-premise Kubernetes using the kubelet-credential-provider-api, mimicking managed Kubernetes features.

More: https://ku.bz/0D8gqV4V6
Post #1280 389

Forwarded from LearnKube news

This week on Learn Kubernetes Weekly 121:

⚖️ Kubernetes networking: service, kube-proxy, load balancing
🆙 How Canonical Kubernetes CAPI providers handle in-place upgrades
🎡 Migrating from DC/OS to Kubernetes: a deep dive into the challenges and opportunities
👮‍♀️ Extend Kubernetes Service accounts auth scope to application APIs
🥷 Securing continuous delivery: Argo CD threat detection

Read it now: https://learnk8s.io/issues/121

⭐️ This newsletter is brought to you by Spectro Cloud: the Kubernetes management platform for enterprise, public sector — and you https://ku.bz/TjrMw39yF
Post #1279 1.98K
Reflector is a Kubernetes addon designed to monitor changes to resources (Secrets and ConfigMaps) and reflect changes to mirror resources in the same or other namespaces.

More: https://ku.bz/-chnMYTMc
Post #1278 401

Forwarded from KubeFM

John Howard, Senior Software Engineer at Solo.io, explains the complexities of implementing Mutual TLS (mTLS) in Kubernetes.

You will learn:

- Why DIY mTLS implementation in Kubernetes is challenging at scale, requiring certificate management, application updates, and careful transition planning
- How Service Mesh solutions offload security concerns from applications, allowing developers to focus on business logic while infrastructure handles encryption
- The advantages of Ambient Mesh's approach to simplifying mTLS implementation with its node proxy and waypoint proxy architecture

Watch (or listen to) it here: https://ku.bz/sk-ZF1PG9

🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop: https://learnk8s.io/training

With @Birthmarkb "Nessie" Farrell
Post #1277 2.25K
Detect and prevent threats in Argo CD pipelines.

Learn how to identify and mitigate initial admin password compromise, unauthorized application deployment, and other security risks with detection rules and hunting searches.

More: https://ku.bz/7Ly_ykVk6
Post #1275 633
Learn how to extend Kubernetes Service accounts auth scope to application APIs using JWT and Envoy gateway for secure authentication between services in different clusters

More: https://ku.bz/VJ1TRHMn5
Post #1274 546
Improve your Kubernetes cluster security with Kyverno, an open-source tool that helps you validate deployments and secure resources.

Learn how to apply best practices and ensure a secure cluster.

More: https://ku.bz/WRklTnMWz
Post #1273 398

Forwarded from LearnKube news

This week on Learn Kubernetes Weekly 120:

🏎️ Ingesting F1 telemetry UDP real-time data in AWS EKS
🏆 Scaling infrastructure for millions: from challenges to triumphs
🥷 Pentesting Docker 101
⚛️ Atomic ConfigMap updates in Kubernetes: how symlinks and kubelet make it happen
🪫 Not enough resources? How to manage CPU and RAM!

Read it now: https://learnk8s.io/issues/120

⭐️ Don't let infrastructure block your teams. StackGen deterministically generates secure cloud infrastructure from any input - existing cloud environments, IaC or application code https://ku.bz/ftNR3t-XL
Post #1272 455
In this article, you will learn how to test RBAC policies using a custom-made Python script to ensure that only authorized users or service accounts have access to specific resources!

More: https://ku.bz/ZW6dFbLcb
Post #1271 382

Forwarded from KubeFM

Isala Piyarisi, Senior Software Engineer at WSO2, shares how his team discovered that Cilium's default Pod CIDR (10.0.0.0/8) was conflicting with their Azure Firewall subnet assignments, causing traffic disruptions in their staging environment.

You will learn:

- How Cilium's default CIDR allocation can create routing conflicts with existing infrastructure
- A methodical process for debugging network issues using packet tracing, routing table analysis, and firewall logs
- The procedure for safely changing Pod CIDR ranges in production clusters

Watch (or listen to) it here: https://ku.bz/kJjXQlmTw

🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop: https://learnk8s.io/training

With @Birthmarkb "Nessie" Farrell
Post #1267 380

Forwarded from LearnKube news

Why can't you ping a Kubernetes service?

Learnk8s runs a 4-day Advanced Kubernetes course on Mar 20, and you will get to the bottom of questions like this (spoiler: services only exist in etcd).
You will also learn the nitty-gritty details of Kubernetes networking:

- How to plan and design a cluster network.
- How do the four Kubernetes services extend each other, and what do you gain from each?
- How CoreDNS, Ingress, and kube-proxy consume the Kubernetes currency: endpoints.

This (and much more) is covered on the third day of the course.

You can find the full agenda, a breakdown of the modules and how to sign up here: https://ku.bz/DX6TPV4P_

Are you training your team?
Customize the workshop in full with corporate training https://learnk8s.io/corporate-training
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →