TGViewer
Channel Public Channel
Kubesploit

Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Subscribers
2.13K
Photos
965
Videos
211
Links
1.9K

Showing posts older than #825 · Back to latest

Older Posts 20 shown
Post #823 342

Forwarded from KubeFM

Structured Authentication Config is the most significant Kubernetes authentication system update in the last six years.

In this KubeFM episode, Maksim explains how this is going to affect you:

1. You can use multiple authentication providers simultaneously (e.g., Okta, Keycloak, GitLab) — no need for Dex.
2. You can change the configuration dynamically without restarting the API server.
3. You can use any JWT-compliant token for authentication.
4. You can use CEL (Common Expression Language) to determine whether the token's claims match the user's attributes in Kubernetes (username, group).

Watch (or listen to) it here: https://kube.fm/structured-authentication-maksim
Post #822 445
Constellation is a Kubernetes engine that wraps your cluster into a single confidential context that is shielded from the underlying cloud infrastructure.

Everything inside is always encrypted, including at runtime in memory.

More: https://github.com/edgelesssys/constellation
Post #821 339

Forwarded from LearnKube news

When planning your infrastructure, one of the fundamental questions is: how many Kubernetes clusters should you have?

One big cluster or multiple smaller clusters?

Should the team share resources, or to each their own?

This Thursday, Dan investigates the pros and cons of different approaches and compares cost efficiency, ease of management resilience and security for different setups.

In this session, you will learn:

- How Kubernetes design is intended for sharing resources and the consequence for isolation and security.
- How can you isolate your workloads with different security trade-offs depending on how trustworthy your tenants are?
- How to estimate costs and efforts in building a single shared cluster vs multiple clusters.

📆 Thu, 29th Feb
⏰ 8am PT | 5pm CET

👉 https://www.vcluster.com/event/workshop-series-1/
Post #819 860
The Otterize intents operator is a tool used to easily automate the creation of network policies and Kafka ACLs in a Kubernetes cluster using a human-readable format via a custom resource.

More: https://github.com/otterize/intents-operator
Post #818 511

Forwarded from Kube Careers

This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55

DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

Security Architect with Apollo
💰 $190K to $250K a year
🏠🏃🏻‍♂️🌎 Alhambra, CA, USA
→ https://kube.careers/t/8a1ea5dc-5d25-4ab0-95c8-d893bdb6249b?s=55

Security Architect with Sigma Computing
💰 $190K to $250K a year
🏠 From the office in San Francisco, CA, USA
→ https://kube.careers/t/e6a8ff9b-834f-4e57-bd6f-13b3be3d3b7a?s=55

DevSecOps Engineer with Palo Alto Networks
💰 $180.2K to $236.5K a year
🏠🏃🏻‍♂️🌎 Santa Clara, CA, USA
→ https://kube.careers/t/c50a52bc-e5ec-43f7-9f4c-bc0103fb9632?s=55

👉 Browse all 459 Kubernetes jobs on Kube Careers https://kube.careers
Post #816 352

Forwarded from LearnKube news

This week on the Learn Kubernetes Weekly:

💥 Health check crashes when over-loaded with requests
☕️ Kubernetes & JVM
⏰ Supply chain attack bomb
🏎️ Speeding up CI with Buildkit
🤔 Native sidecar containers

Read it now: https://learnk8s.io/issues/67
Post #814 363

Forwarded from KubeFM

Is sharing a cluster with multiple tenants worth it?

Should you share or have a single dedicated cluster per team?

In this KubeFM episode, Artem revisits his journey into Kubernetes multi-tenancy and discusses how the landscapes (and opinions) on multi-tenancy have changed over the years.

Here's what you will learn:

- The trade-offs of multi-tenancy and the tooling necessary to make it happen (e.g. vCluster, Argo CD, Kamaji, etc.).
- The challenges of providing isolated monitoring and logging for tenants.
- How to design and architect a platform on Kubernetes to optimise your developer's experience.

Watch (or listen to) it here: https://kube.fm/multitenancy-artem
Post #810 492

Forwarded from Kube Careers

This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55

DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

Security Architect with Apollo
💰 $190K to $250K a year
🏠🏃🏻‍♂️🌎 Alhambra, CA, USA
→ https://kube.careers/t/8a1ea5dc-5d25-4ab0-95c8-d893bdb6249b?s=55

Security Architect with Sigma Computing
💰 $190K to $250K a year
🏠 From the office in San Francisco, CA, USA
→ https://kube.careers/t/e6a8ff9b-834f-4e57-bd6f-13b3be3d3b7a?s=55

DevSecOps Engineer with Palo Alto Networks
💰 $180.2K to $236.5K a year
🏠🏃🏻‍♂️🌎 Santa Clara, CA, USA
→ https://kube.careers/t/c50a52bc-e5ec-43f7-9f4c-bc0103fb9632?s=55

👉 Browse all 455 Kubernetes jobs on Kube Careers https://kube.careers
Post #808 375

Forwarded from LearnKube news

This week on the Learn Kubernetes Weekly:

📈 Performance testing for CoreDNS
🕵️‍♀️ Using Snowflake to detect threats
♻️ Argo workflows: proven patterns
👆 You should care about container requests and limits
📐 Memory limit and request in JVM

Read it now: https://learnk8s.io/issues/66
Post #806 375

Forwarded from KubeFM

How hard could it be to debug a network issue where pod connections time out?

It could take weeks if you are (un)fortunate like Alex.

But Alex and his team didn't despair and found strength in adversity while learning several Kubernetes networking and kubespray lessons.

In this KubeFM episode, you'll follow their journey and learn:

- How a simple connection refused led to debugging the kernel syscalls.
- How MetalLB works and uses Dynamic Admission webhooks.
- How Calico works and assigns a range of IP addresses to pods (and what you should watch out for).
- How to use tcpdump and strace to debug network traffic.

Watch (or listen to) it here: https://kube.fm/troubleshooting-kernel-alex
Post #805 753
The Otterize Credentials Operator automatically resolves pods to dev-friendly service names, registers them with a SPIRE server or with Otterize Cloud, and optionally provisions credentials as Kubernetes secrets.

More: https://github.com/otterize/credentials-operator
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →