TGViewer
Channel Public Channel
Kubesploit

Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Subscribers
2.13K
Photos
951
Videos
206
Links
1.9K

Showing posts older than #1888 · Back to latest

Older Posts 20 shown
Post #1887 210
This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves.

More: https://ku.bz/j_H7dxLV6
Post #1886 179

Forwarded from KubeFM

Kubernetes is ready for databases. Most teams are not.

In KubeSelect episode two, Salman Iqbal and Bart Farrell test this claim with Kat Cosgrove of VillageSQL.

Kat covers:

- Modern Kubernetes storage
- Operators and database expertise
- Team readiness
- Managed database tradeoffs

Kat's verdict: this is now a people problem.

Watch the episode: https://ku.bz/7yDWlP8T5

Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
Post #1885 266
NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run.

More: https://ku.bz/CKghZJGt1
Post #1884 362
This case study shows how to implement a HIPAA-compliant CI/CD pipeline using Cosign for artifact signing, OPA Gatekeeper for admission control on EKS, and long-term evidence storage in S3.

More: https://ku.bz/TYS0yf264
Post #1883 403
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened.

More: https://ku.bz/wd7SCHC3l
Post #1882 686
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview API, then makes it safer with audience-bound projected tokens.

More: https://ku.bz/rz69JFBdZ
Post #1881 307

Forwarded from KubeFM

Security culture around CRA and SBOMs is built in day-to-day engineering, not in policy documents alone.

Przemysław Wojtunik explains how Spectro Cloud helps his team move faster on security and SBOM work, while stressing that every organization still needs a practical path to make compliance part of daily life.

Watch the full interview: https://ku.bz/TJRYGMWV2
Post #1880 186

Forwarded from LearnKube news

This week on Learn Kubernetes Weekly 199:

🔥 How Netflix Simplified Batch Compute with Kueue
💡 Server-side Apply: What Happens When You Run kubectl apply
🌐 Kubernetes Is Migrating from SPDY to WebSockets
🔁 How I Learned to Stop Worrying and Love the Reconciliation Loop
🔒 Securing CI/CD for an Open Source Project: Lessons from Cilium

Read it now: https://kube.today/issues/199

⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
Post #1879 210
Multikube is a reverse proxy that sits in front of several Kubernetes API servers, terminating TLS and handling authentication and authorization centrally so kubectl talks to one endpoint.

More: https://ku.bz/lMRhZQGJy
Post #1878 164

Forwarded from KubeFM

Kube Select is here. It tests one claim: more telemetry does not yield better decisions.

Henrik Rexed of Dynatrace joins hosts Salman Iqbal and Bart Farrell to test it.

You will learn:

- how service ownership gives telemetry incident context
- why proxy metrics can produce extreme data volume
- how AI agents run queries before human review

Watch: https://ku.bz/848pmBN5_

🌟 Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
Post #1877 202

Forwarded from KubeFM

The hardest part of Kubernetes security is rarely features. It is adoption.

Abhishek Rao explains why teams struggle to operationalize security and how observability tools, dashboards, and policy tooling can lower the barrier. His focus is on helping engineers gain confidence before enforcing stricter controls.

If people can use the tools comfortably, security practices stick.



Watch the full interview: https://ku.bz/_q9XBgY2c

This interview is a reaction to John Howard's episode https://ku.bz/sk-ZF1PG9
Post #1876 174
This case study shows how debugging a kubectl 401 error on EKS revealed that a two-year-old static IAM credential file was shadowing a valid instance profile in the AWS credential chain.

More: https://ku.bz/Mxrqy_WJg
Post #1875 146

Forwarded from LearnKube news

Running Java on Kubernetes? CPU and memory limits affect much more than scheduling.

A 4 GiB heap requires a container larger than 4 GiB. Fractional CPU limits can also change the processor count that HotSpot sees.

In our new article, you will learn:

- Why JVM heap size and container memory are different boundaries
- How CPU limits affect garbage collection, worker pools, and application performance
- Which JVM and container metrics to collect when validating resource settings under load

The article also includes practical experiments and an interactive configuration calculator.

Read: https://learnkube.com/java-jvm-kubernetes-requests-limits

Author: Gulcan!
Post #1874 215

Forwarded from KubeFM

Mac Chaffee explains why teams building custom orchestration systems often create dangerous security vulnerabilities without realizing it. He discusses how both Kubernetes and security are deeper fields than they appear, making it easy to fall into the trap of "not knowing what you don't know."

Mac emphasizes that you can't stumble your way into building a secure orchestration system - it requires deep expertise in both domains. While acknowledging that Kubernetes isn't the most secure system and doesn't solve all security problems, he points out that security experts continuously embed their expertise into Kubernetes enhancement proposals. This collective knowledge represents years of hard-won security insights that would be unwise to ignore when building from scratch.

Watch the full episode: https://ku.bz/9nFPmG85f
Post #1873 302
Cordium runs isolated sandboxes on Kubernetes for developers and AI agents, and gives them secretless, identity-based access to SSH, databases and internal APIs.

More: https://ku.bz/Y8RNGkY16
Post #1872 356
This case study shows how Cilium implements defense-in-depth supply chain security for open source CI/CD.

It covers access controls, dependency pinning, credential isolation, and cryptographic verification.

More: https://ku.bz/dB6Bj2sKw
Post #1871 344

Forwarded from KubeFM

Amos explains how TLS certificate renewal failures became the first symptom of a complex networking issue when adding a home computer to his production Kubernetes cluster.

He walks through the cert-manager HTTP challenge process with Let's Encrypt validation and demonstrates how to use K9s for debugging to trace certificate renewal problems to specific nodes.

Watch the full episode: https://ku.bz/6Ll_7slr9
Post #1870 172

Forwarded from KubeFM

What emerging Kubernetes tools are experts paying attention to right now?

Bart Farrell from KubeFM looks back across 100+ KubeFM conversations to surface the tools guests kept mentioning, including Karpenter, Dapr, Argo CD, Kagent, Agent Gateway, OpenTelemetry, KRO, KCP, KubeVirt, Kueue, Kyverno, Headlamp, KEDA, Crossplane, KServe, ACK, and more.
Post #1869 251
Warden is a secure gateway that brokers connections between AI agents and enterprise systems by authenticating agent identity and injecting short-lived credentials at request time.

More: https://ku.bz/knyfjtYg7
Post #1868 192

Forwarded from LearnKube news

This week on Learn Kubernetes Weekly 198:

🏗️ Data Lakehouse: Infrastructure
🔭 What the Popularity of Emerging Tools Tells Us About Kubernetes' Future
⚡ Kafka on Kubernetes: Performance Lessons for Any Disk-Heavy Data Service
🌐 To Centralise or Not to Centralise: The Questions That Shaped the Kubernetes CODECO Federated Architecture
🚨 Your AI Just Deleted the Wrong Deployment. Now What?

Read it now: https://kube.today/issues/198

⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →