Kubesploit

2.8K posts

Kubesploit banner
Kubesploit

Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team Mastodon: @[email protected]

More K8s news, events, jobs → Katılım Mart 2021
1 Takip Edilen20.9K Takipçiler
Kubesploit
Kubesploit@kubesploit·
This article explains how to secure production debugging in Kubernetes with least-privilege RBAC, controlled exec access, ephemeral containers, and short-lived just-in-time credentials for on-call teams ➤ ku.bz/k0qGtqj-d
English
0
1
8
487
Kubesploit
Kubesploit@kubesploit·
This article explains why vanilla Kubernetes has no real login event and shows a practical session-tracking workaround using credential-id fingerprints from audit logs, with a side-by-side comparison against OpenShift OAuth behavior ➜ ku.bz/DxYlmDBjQ
English
0
0
2
261
Kubesploit retweetledi
KubeFM
KubeFM@K8sFM·
Agent Sandbox gives Kubernetes a safer way to run AI-enabled applications Mauricio Salatino on isolation, AI-enabled applications, and the platform changes that come with them 📺: ku.bz/QXKc1tBFY
English
1
1
0
285
Kubesploit
Kubesploit@kubesploit·
k8s-mechanic watches for pod crashes, degraded Deployments, and NotReady nodes, spawns a read-only in-cluster agent that investigates the failure and opens a PR on your GitOps repo with secret redaction, prompt injection detection, and a pentest report ➤ ku.bz/Xg8shhsZb
English
1
1
10
1.2K
Kubesploit
Kubesploit@kubesploit·
Harbor is a CNCF-graduated open source container registry that stores, signs, and scans images, with built-in RBAC, LDAP/OIDC support, vulnerability scanning, policy-based replication, and a full REST API ➜ ku.bz/GjjZhkvSD
English
0
1
14
621
Kubesploit retweetledi
Kube Architect
Kube Architect@K8sArchitect·
This article explains how ListenerSet in Gateway API v1.5 separates listeners from Gateways so teams can restore self-service TLS management across namespaces and scale beyond the old listener limit ➤ ku.bz/s-5QsVS_T
English
0
3
19
2.2K
Kubesploit retweetledi
Daniele Polencic — @danielepolencic@hachyderm.io
✅ Being ready for production means knowing the right settings and being willing to adjust them. Sometimes a readiness probe returns 200 too soon. CPU requests might have too much buffer. Maybe someone copied HPA thresholds from another service, or no one has tested `terminationGracePeriodSeconds` yet. Everyone notices the risk, but making changes can also cause outages. That is where app and platform ownership gets awkward: Developers understand the code path, but it's Platform teams who see rollout safety, node pressure, and cluster-wide trade-offs.
English
1
7
18
2.5K
Kubesploit
Kubesploit@kubesploit·
This tutorial teaches how to build a cert-manager external issuer that uses a YubiHSM 2 to sign TLS certificates via Go's crypto.Signer interface ➤ ku.bz/b9GlYRS88
English
0
0
6
394
Kubesploit
Kubesploit@kubesploit·
Kubeconform is a Kubernetes manifests validation tool Similar to Kubeval, but with the following improvements: ➀ High performance ➁ Remote or local schema locations ➂ Up-to-date schemas for all recent versions of Kubernetes ➜ ku.bz/l0kD6R0TS
English
0
2
13
1.5K
Kubesploit retweetledi
LearnKube
LearnKube@learnk8s·
This week on the Learn Kubernetes Weekly: 🔥 Hunting a 4GB Native Memory Leak ⚠️ Five Ingress-NGINX Behaviors 🔀 ctx_ DevOps Context Switcher 🚀 Ingress NGINX to Istio 🐘 PostgreSQL on Kubernetes ⭐️ WeAreDevelopers Read it now: kube.today/issues/184
LearnKube tweet media
English
1
10
21
2.3K
Kubesploit
Kubesploit@kubesploit·
This tutorial shows how to use Cilium and Hubble to enforce HTTP path based network policies in Kubernetes with eBPF, so you can allow or block specific endpoints without sidecars ➜ ku.bz/Fl4tzq2J2
Kubesploit tweet media
English
0
3
17
1.1K
Kubesploit retweetledi
KubeFM
KubeFM@K8sFM·
🗣️ John Ford from Scout24 SE explains the hidden cost of slow Kubernetes autoscaling: a 25% capacity buffer kept around because nodes took up to two minutes to provision ku.bz/DdmVC2_7v 🌟 LearnKube 🎙 🎙Bart
English
2
7
11
2K
Kubesploit
Kubesploit@kubesploit·
This tutorial explains TLS and certificate debugging from root CA basics to Kubernetes secrets, with OpenSSL and curl commands for inspecting certs, validating handshakes, and fixing common production errors ➜ ku.bz/z-30r6w-V
Kubesploit tweet media
English
0
4
41
2K
Kubesploit retweetledi
KubeFM
KubeFM@K8sFM·
AI should assist the operators, not replace them YongKang He on AI as a co-pilot for SRE 📺: ku.bz/8Q7Vy60P7
English
1
2
1
326
Kubesploit retweetledi
Kube Builders
Kube Builders@KubeBuilders·
Node Healthcheck Operator automatically detects unhealthy nodes and triggers pluggable remediators like BMC, ClusterAPI, or software reboots to recover workloads without manual intervention ➜ ku.bz/8Y52rJ74q
English
0
3
9
703
Kubesploit retweetledi
LearnKube
LearnKube@learnk8s·
New on LearnKube: Kubelet Metrics. Learn how kubelet collects Kubernetes metrics from cgroups, cAdvisor, containerd, and CRI, and when pod/container stats move to the runtime. Read the full guide: learnkube.com/kubernetes-met…
LearnKube tweet media
English
1
11
23
2K
Kubesploit
Kubesploit@kubesploit·
X.509 Certificate Exporter is a Go-based Prometheus exporter that monitors certificate expiration inside Kubernetes clusters or as a standalone service, helping teams alert before TLS certificates expire ➤ ku.bz/BPXM_D-v2
English
0
6
44
1.9K
Kubesploit
Kubesploit@kubesploit·
Cilium Policy Generator, watches dropped flows in real time, and auto-generates CiliumNetworkPolicy YAML files to allow them — so you stop writing policies by hand in default-deny Cilium clusters ➤ ku.bz/hZYF4XgL_
English
0
4
18
1.5K
Kubesploit
Kubesploit@kubesploit·
This tutorial shows how to secure an ArgoCD based EKS GitOps workflow with External Secrets Operator, IRSA, and AWS SSM Parameter Store so secrets stay out of Git and sync safely into Kubernetes ➜ ku.bz/1qJT8SG1s
Kubesploit tweet media
English
0
6
36
2.3K
Kubesploit
Kubesploit@kubesploit·
This tutorial explains how to prevent, detect, and clean up leaked secrets in Git repositories using .env files, Kubernetes Secrets, Gitleaks, GitGuardian, and git-filter-repo ➜ ku.bz/PZjTtq9v8
English
0
1
4
1K