Kubesploit – Telegram
Kubesploit
1.96K subscribers
828 photos
129 videos
1.61K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Harsha Koushik, a Security Researcher and Technical Product Manager at Palo Alto Networks, explores the practical and security benefits of Distroless containers.

He debunks the myth surrounding their security and explains the fundamental differences between Distroless containers and traditional distributions, highlighting the absence of package managers, shells, and OS-level utilities in Distroless containers.

Watch the full episode: https://ku.bz/n_sJ04xMY
This article presents three Vault integration mechanisms in Kubernetes: Banzai Cloud's Vault Secrets Webhook, CSI Provider, and Agent Sidecar Injector

It evaluates each based on key features, advantages, and limitations.

More: https://medium.com/@denisgorokhov/vault-integration-mechanisms-in-kubernetes-comparative-analysis-61e3f582e2f4
In this ebook you will learn how to establish secure communication between clusters and pods, and discover the best practices for implementing zero-trust security in your Kubernetes environment.

More: https://kubecrash.io/download/zero-trust-ebook
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Michael Levan explains how specialized teams and smart abstractions can lead to better outcomes.

You will learn:

- How to use Internal Developer Platforms (IDPs) and abstractions to empower teams without requiring everyone to be a Kubernetes expert.
- How to balance specialization and collaboration using platform engineering practices and smart abstractions
- Practical strategies for managing cognitive load in engineering teams and why not everyone needs to know YAML.

Watch (or listen to) it here: https://ku.bz/qlZPfM-zr

🌟 This episode is brought to you by Testkube — scale all of your tests with Kubernetes, integrate seamlessly with CI/CD and centralize test troubleshooting and reporting https://ku.bz/r8JZXNd2f

With @Birthmarkb "Farm boy" Farrell
This article explains the security risks of running containers as root in Kubernetes, including downloading malware and accessing host resources, and shows how running as a non-root user can mitigate these risks.

More: https://dev.to/wasiucionekm/kubernetes-security-in-practice-implications-of-running-containers-as-root-474n
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 108:

0️⃣ Zero trust ebook
📦 OpenAI's code execution runtime & replicating sandboxing infrastructure
🆙 How we seamlessly transitioned our node services to Kubernetes
⚖️ Load balancing Airbyte workloads across multiple Kubernetes clusters
🐍 Sneaky write hook: Git clone to root on Kubernetes node
🧪 GenAI experiments: monitoring and debugging Kubernetes cluster health

Read it now: https://learnk8s.io/issues/108

🌟 This newsletter is brought to you by simplyblock, your intelligent Kubernetes data platform https://ku.bz/2zZ_pL34y
This tutorial teaches how to set up SPIRE Federation on kind clusters, enabling secure communication between microservices with SPIFFE/SPIRE.

More: https://medium.com/@nishant.apatil3/spiffe-spire-federation-implementation-on-kind-clusters-d5f3b7c4c062
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with xAI
💰 $180K to $440K a year

🏠 From the office in San Francisco / Palo Alto, CA, USA

DevSecOps Engineer with Gemini
💰 $248K to $310K a year

👨‍💻 Remote from the United States

DevSecOps Engineer with Uniswap Labs
💰 $264K to $294K a year

🏠 From the office in New York, NY, USA

Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year

🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA

👉 Browse all 1387 Kubernetes jobs on Kube Careers https://kube.careers
Forwarded from LearnKube news
We are now (also) on 🦋!

You can find all Kubernetes news, jobs, events, interviews, and podcasts, here: https://bsky.app/starter-pack/learnk8s.io/3lbobkb35vx2a

And if you missed any of those accounts, you can find a recap here: https://learnk8s.io/news
This article explores the security risks of exposed Kubelet APIs and presents real-world attacks observed through a honeypot setup, highlighting techniques used by attackers and providing measures to protect Kubernetes clusters.

More: https://blog.aquasec.com/kubernetes-exposed-exploiting-the-kubelet-api
In this article, you will learn why Kubernetes does not manage its own users and instead integrates with existing authentication systems.

More: https://www.armosec.io/blog/kubernetes-user-management
Learn how confidential containers securely retrieve secrets, including the authentication process, resource retrieval flow, and workload requests to the Confidential Data Hub endpoint, and how this process prevents unauthorized access to sensitive data.

More: https://itnext.io/how-your-confidential-containers-can-securely-retrieve-secrets-93d6f55b7b42
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Stefan Roman shares his experience building Labs4Grabs, a platform that gives students root access to Kubernetes clusters.

You will learn:

- Why namespace isolation isn't sufficient for untrusted users and the limitations of tools like vCluster when running privileged workloads.
- How to use KubeVirt to achieve complete workload isolation and the trade-offs.
- Practical approaches to implementing network security with NetworkPolicies and managing resource allocation across multiple student environments.

Watch (or listen to) it here: https://ku.bz/Xz-TrmX2F

🌟 This episode is brought to you by Kusari — gain complete visibility into your software components and secure your supply chain through comprehensive tracking and analysis https://ku.bz/1MZKgXQHt

With @Birthmarkb "Capitan Falcon" Farrell
This article discusses the Confidential Containers Attestation process in the Trustee project, the Request-Challenge-Attestation-Response handshake and the roles of the Key Broker Service and Attestation Service.

More: https://pradiptabanerjee.medium.com/confidential-containers-attestation-implementation-2b88f66dac1e
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 109:

🦋 The Karpenter transformation
❤️ Sharing is caring: how to make the most of your GPUs
🛠️ How we fixed API downtime during spot instance reclaims
🏎️ Karpenter's drift detection
😀 Kubernetes CRD: the versioning joy

Read it now: https://learnk8s.io/issues/109

🌟 This newsletter is sponsored by Intuit to celebrate Numaproj — a Kubernetes-native, serverless platform designed for building scalable and reliable event-driven applications https://ku.bz/PQ-hn3ZCm
trust-manager is a tool for managing trust bundles in Kubernetes and OpenShift clusters.

It combines a list of trusted certificates into a bundle that applications can directly trust.

More: https://github.com/cert-manager/trust-manager
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with xAI
💰 $180K to $440K a year

🏠 From the office in San Francisco / Palo Alto, CA, USA

DevSecOps Engineer with Gemini
💰 $248K to $310K a year

👨‍💻 Remote from the United States

DevSecOps Engineer with Uniswap Labs
💰 $264K to $294K a year

🏠 From the office in New York, NY, USA

Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year

🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA

👉 Browse all 1388 Kubernetes jobs on Kube Careers https://kube.careers
Learn how to set up AWS IRSA on a self-hosted Kubernetes Cluster, including creating a Discovery Service, an AWS Identity Provider, and configuring a Kubernetes cluster.

More: https://levelup.gitconnected.com/aws-irsa-on-a-self-hosted-kubernetes-cluster-02d2bfa4e824
Forwarded from Kube Architect
Not all CPU and memory in your Kubernetes nodes can be used to run Pods.

The node has to run processes such as the Kubelet, daemons such as kube-proxy, and the operating system.

Explore the best instance types for your Kubernetes cluster interactively.

More: https://learnk8s.io/kubernetes-instance-calculator
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 110:

🔎 Container interference detection and mitigation
🧮 Kubernetes instance calculator
👍 Comparison of networking solutions for Kubernetes
🪣 Using S3 as a container registry
🏎️ Benchmarking what actually drives our containers

Read it now: https://learnk8s.io/issues/110

🌟 Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop in January: https://learnk8s.io/training
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with xAI
💰 $180K to $440K a year

🏠 From the office in San Francisco / Palo Alto, CA, USA

DevSecOps Engineer with Gemini
💰 $248K to $310K a year

👨‍💻 Remote from the United States

DevSecOps Engineer with Uniswap Labs
💰 $264K to $294K a year

🏠 From the office in New York, NY, USA

Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year

🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA

👉 Browse all 1415 Kubernetes jobs on Kube Careers https://kube.careers