In this article, you'll learn how to design effective Kubernetes Network Policies to secure your cluster, including key considerations, best practices, and examples to enforce network isolation and the principle of least privilege.
More: https://medium.com/@rozdolskyvolodymyr/designing-effective-kubernetes-network-policies-key-considerations-6e70255c0ef6
More: https://medium.com/@rozdolskyvolodymyr/designing-effective-kubernetes-network-policies-key-considerations-6e70255c0ef6
AWRBACS is a tool that audits CRUD permissions in Kubernetes' RBAC, allowing users to enumerate and verify the permissions of users and service accounts.
More: https://github.com/lobuhi/awrbacs
More: https://github.com/lobuhi/awrbacs
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Platform Engineer Artem Lajko breaks down observability into three distinct layers and explains how tools like Prometheus, Grafana, and Falco serve different purposes.
You will learn:
- How to implement the three-layer model (external, internal, and OS-level) and why each layer serves different stakeholders
- How to choose and scale observability tools using a label-based approach (low, medium, high)
- How to manage observability costs by collecting only relevant metrics and logs
Watch (or listen to) it here: https://ku.bz/9sGxhmm8s
🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training
With @Birthmarkb "Kubernetes historian" Farrell
You will learn:
- How to implement the three-layer model (external, internal, and OS-level) and why each layer serves different stakeholders
- How to choose and scale observability tools using a label-based approach (low, medium, high)
- How to manage observability costs by collecting only relevant metrics and logs
Watch (or listen to) it here: https://ku.bz/9sGxhmm8s
🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop this January: https://learnk8s.io/training
With @Birthmarkb "Kubernetes historian" Farrell
Discover how to create a secure flow for your AKS applications to access sensitive secrets, such as database credentials, using the Secret Store CSI Driver and User-Assigned Managed Identity (UAMI).
More: https://medium.com/@gharbisofiene98/automating-secure-secrets-management-in-aks-with-terraform-and-azure-key-vault-e6a71f5f6805
More: https://medium.com/@gharbisofiene98/automating-secure-secrets-management-in-aks-with-terraform-and-azure-key-vault-e6a71f5f6805
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 116:
💥 Node.js 20 upgrade: a journey through unexpected heap issues with Kubernetes
🐳 How to optimize Kubernetes for large Docker images
📈 How to optimize autoscaling in Kubernetes using metrics based on application workflows
🔎 Container internals series: seccomp
🛑 Preemptible pods
Read it now: https://learnk8s.io/issues/116
🌟 StormForge — the only JVM workload rightsizing solution for Kubernetes https://ku.bz/PJjcy3PwL
💥 Node.js 20 upgrade: a journey through unexpected heap issues with Kubernetes
🐳 How to optimize Kubernetes for large Docker images
📈 How to optimize autoscaling in Kubernetes using metrics based on application workflows
🔎 Container internals series: seccomp
🛑 Preemptible pods
Read it now: https://learnk8s.io/issues/116
🌟 StormForge — the only JVM workload rightsizing solution for Kubernetes https://ku.bz/PJjcy3PwL
This repository contains a collection of AppArmor and Seccomp profiles for common Docker images.
These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.
More: https://github.com/Archguardian-io/Docker-AppArmor-Profiles
These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.
More: https://github.com/Archguardian-io/Docker-AppArmor-Profiles
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
→ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27
Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
→ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275
DevSecOps Engineer with Attentive
💰 $200K to $270K a year
👨💻 Remote from the United States of America
→ https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912
DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻♂️🌎 US
→ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d
DevSecOps Engineer with Glean
💰 $185K to $280K a year
🏠🏃🏻♂️🌎 Palo Alto, CA, USA
→ https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f
👉 Browse all 1151 Kubernetes jobs on Kube Careers https://kube.careers
Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
→ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27
Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
→ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275
DevSecOps Engineer with Attentive
💰 $200K to $270K a year
👨💻 Remote from the United States of America
→ https://kube.careers/t/9d5fda72-efd7-4b36-9432-e14b829f7912
DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻♂️🌎 US
→ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d
DevSecOps Engineer with Glean
💰 $185K to $280K a year
🏠🏃🏻♂️🌎 Palo Alto, CA, USA
→ https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f
👉 Browse all 1151 Kubernetes jobs on Kube Careers https://kube.careers
In this article, you'll learn how to build a custom cert-manager webhook for DuckDNS to automate certificate issuance for Kubernetes clusters without public HTTP access, using the DNS-01 challenge to validate domain ownership.
More: https://medium.com/@csp33/building-my-first-go-project-a-cert-manager-webhook-for-duckdns-47db984f9bed
More: https://medium.com/@csp33/building-my-first-go-project-a-cert-manager-webhook-for-duckdns-47db984f9bed
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Tim Miller, CEO and Co-founder at Kusari, discusses three categories of tools that are transforming the Kubernetes ecosystem.
He highlights Ko, which helps developers deploy applications with minimal friction**, Falco by Sysdig, which provides deep system visibility, and SBOM generation tools like Excalibur and Guac, which make container dependencies more transparent. These tools focus on developer experience and system observability.
Watch the full interview: https://ku.bz/-2Sqn9Jb9
He highlights Ko, which helps developers deploy applications with minimal friction**, Falco by Sysdig, which provides deep system visibility, and SBOM generation tools like Excalibur and Guac, which make container dependencies more transparent. These tools focus on developer experience and system observability.
Watch the full interview: https://ku.bz/-2Sqn9Jb9
In this article, you'll learn how to secure local Kubernetes apps using cert-manager, ExternalDNS, and Cloudflare to issue TLS certificates and avoid untrusted certificate errors, making it easy to manage and expose your applications securely.
More: https://itnext.io/securing-local-kubernetes-apps-a-practical-guide-with-cert-manager-externaldns-and-cloudflare-d1ee9342ed83
More: https://itnext.io/securing-local-kubernetes-apps-a-practical-guide-with-cert-manager-externaldns-and-cloudflare-d1ee9342ed83
In this article, you'll learn about the
More: https://medium.com/@vfxbwrnnzb/i-never-understood-securitycontext-setting-in-kubernetes-but-now-i-got-it-8c07f921e403
secuirityContext setting in pod-level and container-level configurations and how to use them to run containers as non-root users, using seccomp profilesand limit filesystem access.More: https://medium.com/@vfxbwrnnzb/i-never-understood-securitycontext-setting-in-kubernetes-but-now-i-got-it-8c07f921e403
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Yue Yin, Software Engineer at ByteDance, discusses their open-source Gödel scheduler and Katalyst resource management system. She explains how these tools address the challenges of managing online and offline workloads in large-scale Kubernetes deployments.
You will learn:
- How Gödel's distributed architecture with dispatcher, scheduler, and binder components enables the scheduling of 5,000 pods per second
- Why NUMA-aware scheduling and two-layer architecture are crucial for handling complex workloads at scale
- How Katalyst provides node-level resource insights to enable efficient workload co-location and improve CPU utilization
Watch (or listen to) it here: https://ku.bz/lMpNng_33
🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop: https://learnk8s.io/training
With @Birthmarkb "Chief Idea Officer" Farrell
You will learn:
- How Gödel's distributed architecture with dispatcher, scheduler, and binder components enables the scheduling of 5,000 pods per second
- Why NUMA-aware scheduling and two-layer architecture are crucial for handling complex workloads at scale
- How Katalyst provides node-level resource insights to enable efficient workload co-location and improve CPU utilization
Watch (or listen to) it here: https://ku.bz/lMpNng_33
🌟 This episode is brought to you by Learnk8s — Become an expert in Kubernetes! Join the next Advanced Kubernetes workshop: https://learnk8s.io/training
With @Birthmarkb "Chief Idea Officer" Farrell
This repository contains a collection of AppArmor and Seccomp profiles for common Helm deployments.
These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.
More: https://github.com/Archguardian-io/Kubernetes-AppArmor-Profiles
These profiles were automatically generated using Armiel, a powerful tool from ArchGuardian.io that generate AppArmor and Seccomp profiles.
More: https://github.com/Archguardian-io/Kubernetes-AppArmor-Profiles
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 117:
🪝 Building my first Go project: a cert-manager webhook for DuckDNS
🔥 From dumpster fire to sparkling clean: SaaS with Kubernetes operators and garbage collection
✨ The journey to creating our next-generation cloud control plane
🚦 Understand scheduling in Kubernetes
🔎 Overview of kubernetes CNI network models: VETH & bridge / overlay / BGP
Read it now: https://learnk8s.io/issues/117
🌟 This newsletter is brought to you by Loft Labs to announce the launch of Multitenancy March https://ku.bz/yk4mJkv34
🪝 Building my first Go project: a cert-manager webhook for DuckDNS
🔥 From dumpster fire to sparkling clean: SaaS with Kubernetes operators and garbage collection
✨ The journey to creating our next-generation cloud control plane
🚦 Understand scheduling in Kubernetes
🔎 Overview of kubernetes CNI network models: VETH & bridge / overlay / BGP
Read it now: https://learnk8s.io/issues/117
🌟 This newsletter is brought to you by Loft Labs to announce the launch of Multitenancy March https://ku.bz/yk4mJkv34
In this article, you'll learn about Kubernetes Security using eBPF and Tetragon for runtime monitoring and policy enforcement, including CO-RE, attachment types, maps, and LSM hooks to overcome security limitations and vulnerabilities.
More: https://medium.com/@noah_h/kubernetes-security-ebpf-tetragon-for-runtime-monitoring-policy-enforcement-819b6ed97953
More: https://medium.com/@noah_h/kubernetes-security-ebpf-tetragon-for-runtime-monitoring-policy-enforcement-819b6ed97953
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with OpenAI
💰 $243K to $306K a year
🏠🏃🏻♂️🌎 Washington, DC, USA
→ https://kube.careers/t/edb60c03-c2c2-44ce-9e14-5783bb959a7e
Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
→ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27
Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
→ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275
DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻♂️🌎 US
→ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d
DevSecOps Engineer with Glean
💰 $185K to $280K a year
🏠🏃🏻♂️🌎 Palo Alto, CA, USA
→ https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f
👉 Browse all 1097 Kubernetes jobs on Kube Careers https://kube.careers
DevSecOps Engineer with OpenAI
💰 $243K to $306K a year
🏠🏃🏻♂️🌎 Washington, DC, USA
→ https://kube.careers/t/edb60c03-c2c2-44ce-9e14-5783bb959a7e
Security Architect with Adobe Inc.
💰 $191.7K to $345.7K a year
🏠 From the office in Seattle, WA / San Francisco / San Jose, CA, USA
→ https://kube.careers/t/b6de3faf-adb8-462a-9dd9-260446149b27
Security Architect with Dexterity
💰 $200K to $300K a year
🏠 From the office in Redwood, CA, USA
→ https://kube.careers/t/b9a90583-a0e8-4f13-b776-839c8b1d6275
DevSecOps Engineer with Plaid
💰 $186.84K to $279.72K a year
🏠🏃🏻♂️🌎 US
→ https://kube.careers/t/65616251-5ba0-42af-af39-fb64a1c2d20d
DevSecOps Engineer with Glean
💰 $185K to $280K a year
🏠🏃🏻♂️🌎 Palo Alto, CA, USA
→ https://kube.careers/t/384dd05a-a906-4db7-933a-51b15110f87f
👉 Browse all 1097 Kubernetes jobs on Kube Careers https://kube.careers
OIDC-Guard is an API server which is used along with Ingress Controllers that support External Authentication and enables per Ingress customizable JWT validation with Cookie support for Web Applications.
More: https://github.com/IvanJosipovic/OIDC-Guard
More: https://github.com/IvanJosipovic/OIDC-Guard
Forwarded from Kube Architect
Sealed Secrets Web is a tool that provides a web interface for managing and encrypting sensitive data in Kubernetes using the Sealed Secrets service by Bitnami.
More: https://github.com/bakito/sealed-secrets-web
More: https://github.com/bakito/sealed-secrets-web
Ratify is a verification engine as a binary executable on Kubernetes that enables verification of artifact security metadata and admits for deployment only those that comply with your policies.
More: https://github.com/ratify-project/ratify
More: https://github.com/ratify-project/ratify
Forwarded from Daniele Polencic
<shameless plug>🚀 This March, we are running a free educational series on building multitenant Kubernetes platforms!
🤔 Over six sessions, we’ll explore the evolution of Kubernetes multitenancy, from comparing soft vs. hard approaches to evaluating namespace, virtual, and dedicated cluster strategies. I’ll also discuss emerging trends, the right tooling (think vCluster, Capsule, Kamaji, kcp, k3k, and more), and the trade-offs shaping the multitenancy market.
📅 I’m kicking off with “The State of Multi-Tenancy in Kubernetes” on Feb 27. Then, join Salman Iqbal (the legend) on March 13 for a session on standardizing development environments in large-scale clusters, and catch Chris Nesbitt-Smith on March 27 as we discuss balancing isolation and complexity.
If this sounds interesting, you can sign up here: https://ku.bz/multitenancy25
In this article, you'll learn how to simplify Kubernetes authentication using OpenID Connect (OIDC) and grant users or groups the correct permissions in your cluster, making it easier to manage access and maintain security.
More: https://kty.dev/blog/2024-09-19-auth-isnt-hard
More: https://kty.dev/blog/2024-09-19-auth-isnt-hard