TGViewer
Channel Public Channel
Kubesploit

Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Subscribers
2.13K
Photos
965
Videos
211
Links
1.9K

Showing posts older than #845 · Back to latest

Older Posts 20 shown
Post #843 318

Forwarded from LearnKube news

This week on the Learn Kubernetes Weekly:

✍️ Signing container images: sigstore, Notary, and Docker content trust
✉️ Envelope encryption in EKS
🏅 OWASP Kubernetes top 10
🗃️ imgpkg
🛜 webmesh-cni

Read it now: https://learnk8s.io/issues/70
Post #841 320

Forwarded from KubeFM

Service meshes and the community's opinion of them have changed drastically over the years.

From being perceived as unnecessary, complicated and bloated, they matured into security and observability powerhouses (while still retaining much of their complexity).

In this KubeFM episode, William deep dives into the world of service meshes and explains a few of the technical choices and trade-offs of service meshes in simple terms.

You will learn:

- What is a service mesh and its design (i.e. control plane and data plane).
- How Ambient mesh departs from the traditional sidecar model and how it affects reliability and security.
- Why there's more than just eBPF in sidecarless service meshes and the limitation of this technology.
- The direct costs (compute) and human factors involved in operating a service mesh.

Watch (or listen to) it here: https://kube.fm/service-mesh-william
Post #839 340

Forwarded from LearnKube news

Kubernetes: 50 namespaces vs 50 control planes vs 50 clusters.

For the last episode of "Building Kubernetes platforms", we decided to run an experiment: how much does multi-tenancy cost?

We created three scenarios:

- 50 tenants using the Hierarchical Namespace Controller.
- 50 tenants using vCluster.
- 50 dedicated clusters managed via Karmada.

Which one was the most expensive?

Spoiler: the dedicated clusters are very expensive.

But is it worth the investment?

Chris will cover it live on Thursday!

📆 Thu, 14th Mar
⏰ 8am PT | 5pm CET

👉 https://www.vcluster.com/event/workshop-series-3/
Post #836 541

Forwarded from Kube Careers

This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55

DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

Security Architect with Apollo
💰 $190K to $250K a year
🏠🏃🏻‍♂️🌎 Alhambra, CA, USA
→ https://kube.careers/t/8a1ea5dc-5d25-4ab0-95c8-d893bdb6249b?s=55

Security Architect with Sigma Computing
💰 $190K to $250K a year
🏠 From the office in San Francisco, CA, USA
→ https://kube.careers/t/e6a8ff9b-834f-4e57-bd6f-13b3be3d3b7a?s=55

DevSecOps Engineer with Palo Alto Networks
💰 $180.2K to $236.5K a year
🏠🏃🏻‍♂️🌎 Santa Clara, CA, USA
→ https://kube.careers/t/c50a52bc-e5ec-43f7-9f4c-bc0103fb9632?s=55

👉 Browse all 448 Kubernetes jobs on Kube Careers https://kube.careers
Post #835 437
In this article, you'll compare three popular container signing solutions: Sigstore Cosign, Notary v2, and Docker Content Trust (DCT).

You'll learn about their features, capabilities, and suitability for securing container image supply chains.

More: https://snyk.io/blog/signing-container-images
Post #834 376

Forwarded from LearnKube news

This week on the Learn Kubernetes Weekly:

♻️ From 0 to 10'000 Jenkins builds a week
1️⃣ Only one label to improve your security posture
🔐 Vault integration
🔨 Testing on Kubernetes with Testkube
🆙 Migrating from MetaLB to Cilium

Read it now: https://learnk8s.io/issues/69
Post #832 357

Forwarded from LearnKube news

Kubernetes namespaces are the basic building block for identity and isolation but don't provide any of those features out of the box.

In this session, you will explore in a great level of detail:

- How namespaces are (not) used during scheduling.
- How namespaces are (not) used in the cluster network and the implementation of Network Policies.
- How namespaces provide the starting point for RBAC.

The insights will help you understand the trade-offs in designing a multi-tenant platform on Kubernetes.

📆 Thu, 7th Mar
⏰ 8am PT | 5pm CET

👉 https://www.vcluster.com/event/workshop-series-2/
Post #831 335

Forwarded from KubeFM

Can you run databases on Kubernetes and survive to tell the story?

Or should you refrain from running stateful workloads as much as possible?

In this KubeFM episode, Steven argues that you should run databases on Kubernetes.

He also goes further and demonstrates how to build your custom operator to manage your database.

Listen to the episode and learn how:

- You can use Kubebuilder and the Operator Framework to build your operator.
- Custom Resources lets you create higher abstractions to manage your infrastructure as code.
- Steven's operator manages hundreds of databases at scale at QuestDB.

Watch (or listen to) it here: https://kube.fm/operators-steven
Post #827 551

Forwarded from Kube Careers

This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55

DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨‍💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

Security Architect with Apollo
💰 $190K to $250K a year
🏠🏃🏻‍♂️🌎 Alhambra, CA, USA
→ https://kube.careers/t/8a1ea5dc-5d25-4ab0-95c8-d893bdb6249b?s=55

Security Architect with Sigma Computing
💰 $190K to $250K a year
🏠 From the office in San Francisco, CA, USA
→ https://kube.careers/t/e6a8ff9b-834f-4e57-bd6f-13b3be3d3b7a?s=55

DevSecOps Engineer with Palo Alto Networks
💰 $180.2K to $236.5K a year
🏠🏃🏻‍♂️🌎 Santa Clara, CA, USA
→ https://kube.careers/t/c50a52bc-e5ec-43f7-9f4c-bc0103fb9632?s=55

👉 Browse all 455 Kubernetes jobs on Kube Careers https://kube.careers
Post #826 1.56K
The Trivy Operator leverages Trivy to continuously scan your Kubernetes cluster for security issues.

The scans are summarised in security reports as Kubernetes Custom Resource Definitions, which become accessible through the Kubernetes API.

More: https://github.com/aquasecurity/trivy-operator
Post #825 351

Forwarded from LearnKube news

This week on the Learn Kubernetes Weekly:

🦑 Custom Ink's Kubernetes journey
🤔 Slack's internal compute platform
💣 CoreDNS is going to fail you scale
📺 Workload identity on AKS
🥷 OWASP supply chain

Read it now: https://learnk8s.io/issues/68
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →