Kubesploit – Telegram
Kubesploit
1.95K subscribers
824 photos
128 videos
1.61K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
Kubernetes External Secrets allows you to use external secret management systems, like AWS Secrets Manager or HashiCorp Vault, to securely add secrets in Kubernetes.

Read on: https://github.com/external-secrets/kubernetes-external-secrets
The right way to authenticate to your clusters from your CI/CD pipelines

More: https://tremolosecurity.com/post/pipelines-and-kubernetes-authentication
Analysing Kubernetes audit logs using Falco

Read on: https://github.com/developer-guy/falco-analyze-audit-log-from-k3s-cluster
In this guide, we are going to demonstrate what OPA Gatekeeper and Kyverno are, what are the differences between them and how we can set up and use them in the Kubernetes cluster by doing hands-on demo

Read on: https://github.com/developer-guy/policy-as-code-war
In this article you'll break the cluster, delete certificates and rejoin the nodes without causing any downtime.

More: https://itnext.io/breaking-down-and-fixing-kubernetes-4df2f22f87c3
Attacking Kubernetes clusters using the Kubelet API

Read on: https://medium.com/faun/attacking-kubernetes-clusters-using-the-kubelet-api-abafc36126ca
Kubernetes Policy Comparison: OPA/Gatekeeper vs Kyverno

Read on: https://neonmirrors.net/post/2021-02/kubernetes-policy-comparison-opa-gatekeeper-vs-kyverno
This post describes how to improve cert-manager self-check speed, by pointing the cluster to Google nameservers, and disabling DNS caching

https://usepine.com/blog/en/improving-cert-manager-self-check-speed-when-issuing-certificates
In this tutorial you'll learn how to how to integrate Kubernetes with Dex + LDAP

More https://brightzheng100.medium.com/kubernetes-dex-ldap-integration-f305292a16b9
Lockbox is a secure way to store Kubernetes Secrets offline. Secrets are asymmetrically encrypted, and can only be decrypted by the Lockbox Kubernetes controller

Read on: https://github.com/cloudflare/lockbox
Choosing the right policy-as-code solution for your Kubernetes cluster:

- OPA
- Gatekeeper
- Kyverno
- k-rail
- MagTape

More: https://aws.amazon.com/blogs/containers/policy-based-countermeasures-for-kubernetes-part-1
How monero miners target and exploit cloud native dev environments

Read more: https://blog.aquasec.com/monero-miners-target-bitbucket-dockerhub