Kubesploit – Telegram
Kubesploit
1.96K subscribers
828 photos
129 videos
1.61K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
In this article, you will learn about Traceeshark, a plugin for Wireshark that enables visual and interactive analysis of Tracee events, and discover how it simplifies the investigation of Linux runtime security issues and malware analysis.

More: https://blog.aquasec.com/go-deeper-linux-runtime-visibility-meets-wireshark
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
In this episode, William Morgan, CEO of Buoyant, explores the complex trade-offs between cost optimization and reliability in Kubernetes networking.

You will learn:

- How Topology-aware routing attempts to reduce cross-zone traffic costs but can compromise reliability by limiting inter-zone communication
- Why Layer 7 load balancing offers better traffic management through protocol awareness compared to topology-aware routing's Layer 4 approach
- How HAZL (High Availability Zonal Load Balancing) provides a more nuanced solution by balancing cost savings with reliability guarantees through intelligent traffic routing

Watch (or listen to) it here: https://ku.bz/CBwn51pl-

🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training

With @Birthmarkb "Real Chill Guy" Farrell
Forwarded from LearnKube news
In this article, you'll learn how to expose ports in Kubernetes, common misconceptions about securing your applications, and best practices for controlling port access and network traffic using Network Policies.

More: https://awsmorocco.com/exposing-ports-in-kubernetes-what-you-should-to-know-cd1a80655f6c
In this article, you'll learn how to secure sensitive data in confidential containers, including best practices for avoiding common usage patterns that compromise security and restricting Kubernetes APIs to protect your secrets.

More: https://pradiptabanerjee.medium.com/securing-secrets-in-confidential-containers-usage-patterns-to-avoid-941388cde546
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 115:

🥷 Kubernetes has its "ADCS" how to backdoor a Kubernetes in silence
🔒 GitOps secrets with Argo CD, Hashicorp Vault and the External Secret Operator
🌲 Why is running as root in kubernetes containers dangerous? @Marcin Wasiucionek
🔭 Go deeper: linux runtime visibility meets wireshark
🤫 Securing secrets in confidential containers: usage patterns to avoid

Read it now: https://learnk8s.io/issues/115

🌟 Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop next week: https://learnk8s.io/online-advanced-january-2025
In this article, you'll learn how to create and manage Seccomp profiles using Golang to control system calls and enhance security in containerized environments, reducing potential vulnerabilities and attack surfaces.

More: https://cloudchirp.medium.com/container-internals-series-part-4-seccomp-d88543988709
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27

Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275

DevSecOps Engineer with Crusoe
💰 $180K to $300K a year
🏠🏃🏻‍♂️🌎 San Francisco, CA, USA
https://kube.careers/t/cc2ab37b-4b47-4dc0-9199-04269d9e3607

DevSecOps Engineer with Attentive
💰 $200K to $270K a year
👨‍💻 Remote from the United States of America
https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912

DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻‍♂️🌎 US
https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d

👉 Browse all 1218 Kubernetes jobs on Kube Careers https://kube.careers
The Trivy Operator leverages Trivy to continuously scan your Kubernetes cluster for security issues.

The scans are summarised in security reports as Kubernetes Custom Resource Definitions, which become accessible through the Kubernetes API.

More: https://github.com/aquasecurity/trivy-operator
In this article, you'll learn how to design effective Kubernetes Network Policies to secure your cluster, including key considerations, best practices, and examples to enforce network isolation and the principle of least privilege.

More: https://medium.com/@rozdolskyvolodymyr/designing-effective-kubernetes-network-policies-key-considerations-6e70255c0ef6
AWRBACS is a tool that audits CRUD permissions in Kubernetes' RBAC, allowing users to enumerate and verify the permissions of users and service accounts.

More: https://github.com/lobuhi/awrbacs
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Platform Engineer Artem Lajko breaks down observability into three distinct layers and explains how tools like Prometheus, Grafana, and Falco serve different purposes.

You will learn:

- How to implement the three-layer model (external, internal, and OS-level) and why each layer serves different stakeholders
- How to choose and scale observability tools using a label-based approach (low, medium, high)
- How to manage observability costs by collecting only relevant metrics and logs

Watch (or listen to) it here: https://ku.bz/9sGxhmm8s

🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training

With @Birthmarkb "Kubernetes historian" Farrell
Discover how to create a secure flow for your AKS applications to access sensitive secrets, such as database credentials, using the Secret Store CSI Driver and User-Assigned Managed Identity (UAMI).

More: https://medium.com/@gharbisofiene98/automating-secure-secrets-management-in-aks-with-terraform-and-azure-key-vault-e6a71f5f6805
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 116:

💥 Node.js 20 upgrade: a journey through unexpected heap issues with Kubernetes
🐳 How to optimize Kubernetes for large Docker images
📈 How to optimize autoscaling in Kubernetes using metrics based on application workflows
🔎 Container internals series: seccomp
🛑 Preemptible pods

Read it now: https://learnk8s.io/issues/116

🌟 StormForge — the only JVM workload rightsizing solution for Kubernetes https://ku.bz/PJjcy3PwL
This repository contains a collection of AppArmor and Seccomp profiles for common Docker images.

These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.

More: https://github.com/Archguardian-io/Docker-AppArmor-Profiles
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27

Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275

DevSecOps Engineer with Attentive
💰 $200K to $270K a year
👨‍💻 Remote from the United States of America
https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912

DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻‍♂️🌎 US
https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d

DevSecOps Engineer with Glean
💰 $185K to $280K a year
🏠🏃🏻‍♂️🌎 Palo Alto, CA, USA
https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f

👉 Browse all 1151 Kubernetes jobs on Kube Careers https://kube.careers
In this article, you'll learn how to build a custom cert-manager webhook for DuckDNS to automate certificate issuance for Kubernetes clusters without public HTTP access, using the DNS-01 challenge to validate domain ownership.

More: https://medium.com/@csp33/building-my-first-go-project-a-cert-manager-webhook-for-duckdns-47db984f9bed
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Tim Miller, CEO and Co-founder at Kusari, discusses three categories of tools that are transforming the Kubernetes ecosystem.

He highlights Ko, which helps developers deploy applications with minimal friction**, Falco by Sysdig, which provides deep system visibility, and SBOM generation tools like Excalibur and Guac, which make container dependencies more transparent. These tools focus on developer experience and system observability.

Watch the full interview: https://ku.bz/-2Sqn9Jb9
In this article, you'll learn how to secure local Kubernetes apps using cert-manager, ExternalDNS, and Cloudflare to issue TLS certificates and avoid untrusted certificate errors, making it easy to manage and expose your applications securely.

More: https://itnext.io/securing-local-kubernetes-apps-a-practical-guide-with-cert-manager-externaldns-and-cloudflare-d1ee9342ed83
In this article, you'll learn about the secuirityContext setting in pod-level and container-level configurations and how to use them to run containers as non-root users, using seccomp profilesand limit filesystem access.

More: https://medium.com/@vfxbwrnnzb/i-never-understood-securitycontext-setting-in-kubernetes-but-now-i-got-it-8c07f921e403
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Yue Yin, Software Engineer at ByteDance, discusses their open-source Gödel scheduler and Katalyst resource management system. She explains how these tools address the challenges of managing online and offline workloads in large-scale Kubernetes deployments.

You will learn:

- How Gödel's distributed architecture with dispatcher, scheduler, and binder components enables the scheduling of 5,000 pods per second
- Why NUMA-aware scheduling and two-layer architecture are crucial for handling complex workloads at scale
- How Katalyst provides node-level resource insights to enable efficient workload co-location and improve CPU utilization

Watch (or listen to) it here: https://ku.bz/lMpNng_33

🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop: https://learnk8s.io/training

With @Birthmarkb "Chief Idea Officer" Farrell
This repository contains a collection of AppArmor and Seccomp profiles for common Helm deployments.

These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.

More: https://github.com/Archguardian-io/Kubernetes-AppArmor-Profiles