In this tutorial, you will learn how to use Kyverno to inject fields into Kubernetes resources to remove dangling jobs automatically.
More: https://blog.wtcx.dev/2022/07/09/automatically-clean-up-dangling-jobs-with-policy-engine
More: https://blog.wtcx.dev/2022/07/09/automatically-clean-up-dangling-jobs-with-policy-engine
Forwarded from LearnKube news
Master Kubernetes with Learnk8s' Advanced Kubernetes workshop!
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The course starts the 30th of October in Amsterdam and you can sign up here: https://learnk8s.io/amsterdam-advanced-october-2023
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The course starts the 30th of October in Amsterdam and you can sign up here: https://learnk8s.io/amsterdam-advanced-october-2023
Kubewarden policy deprecated-api-versions is a Kubewarden policy that detects usage of Kubernetes resources that have been deprecated or removed.
More: https://github.com/kubewarden/deprecated-api-versions-policy
More: https://github.com/kubewarden/deprecated-api-versions-policy
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:
🔍 How to traceroute pod-to-pod traffic
🔦 VPN tunnels: how we used them to migrate to
🗺️ Container Checkpointing
📦 kube-image-keeper
✅ Verifying container image signatures
Read it now: https://learnk8s.io/issues/47
🔍 How to traceroute pod-to-pod traffic
🔦 VPN tunnels: how we used them to migrate to
🗺️ Container Checkpointing
📦 kube-image-keeper
✅ Verifying container image signatures
Read it now: https://learnk8s.io/issues/47
In this detailed write-up, you will uncover how the botnet run by TeamTNT attacks vulnerable Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and others.
More: https://blog.aquasec.com/teamtnt-reemerged-with-new-aggressive-cloud-campaign
More: https://blog.aquasec.com/teamtnt-reemerged-with-new-aggressive-cloud-campaign
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with Tubi
💰 $197K to $259K a year
👨💻 Remote from the United States
→ https://kube.careers/t/fbfd93b4-e284-47f8-89a9-6e7cfa4c82ad?s=55
DevSecOps Engineer with Robinhood
💰 $169K to $255K a year
🏠 From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
→ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55
DevSecOps Engineer with Pure Storage
💰 $167K to $251K a year
🏠 From the office in Santa Clara, CA, USA
→ https://kube.careers/t/611fe80e-6e6d-4ece-b428-4af7561f7af7?s=55
DevSecOps Engineer with Verkada
💰 $120K to $285K a year
🏠 From the office in San Mateo, CA, USA
→ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55
DevSecOps Engineer with Voltron Data
💰 $170K to $220K a year
🌎 Fully remote
→ https://kube.careers/t/f2509a98-e72c-4444-a44e-7f9502b58e1a?s=55
👉 Browse all 477 Kubernetes jobs on Kube Careers https://kube.careers
DevSecOps Engineer with Tubi
💰 $197K to $259K a year
👨💻 Remote from the United States
→ https://kube.careers/t/fbfd93b4-e284-47f8-89a9-6e7cfa4c82ad?s=55
DevSecOps Engineer with Robinhood
💰 $169K to $255K a year
🏠 From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
→ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55
DevSecOps Engineer with Pure Storage
💰 $167K to $251K a year
🏠 From the office in Santa Clara, CA, USA
→ https://kube.careers/t/611fe80e-6e6d-4ece-b428-4af7561f7af7?s=55
DevSecOps Engineer with Verkada
💰 $120K to $285K a year
🏠 From the office in San Mateo, CA, USA
→ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55
DevSecOps Engineer with Voltron Data
💰 $170K to $220K a year
🌎 Fully remote
→ https://kube.careers/t/f2509a98-e72c-4444-a44e-7f9502b58e1a?s=55
👉 Browse all 477 Kubernetes jobs on Kube Careers https://kube.careers
Forwarded from Kube Architect
In this tutorial, you will learn how to implement chaos testing for your backend services in Kubernetes using k6 to observe how they behave when unexpected incidents happen.
More: https://semaphoreci.com/blog/chaos-testing-k6
More: https://semaphoreci.com/blog/chaos-testing-k6
Forwarded from Kube Architect
Learn how to rebalance workloads in your Kubernetes cluster to optimize resource allocations.
In this webinar, you'll learn:
- What the Decheduler is and how it works
- Policies to reallocate pods in your nodes
📅 12 Oct
⏰ 8am PT | 5pm CET
👉 https://kube.events/t/33c89654-e376-4a7f-8a43-15619a3502da
In this webinar, you'll learn:
- What the Decheduler is and how it works
- Policies to reallocate pods in your nodes
📅 12 Oct
⏰ 8am PT | 5pm CET
👉 https://kube.events/t/33c89654-e376-4a7f-8a43-15619a3502da
This media is not supported in your browser
VIEW IN TELEGRAM
Zarf eliminates the complexity of air gap software delivery for Kubernetes clusters and cloud-native workloads using a declarative packaging strategy to support DevSecOps in offline and semi-connected environments.
More: https://github.com/defenseunicorns/zarf
More: https://github.com/defenseunicorns/zarf
In this 2-part article, you will learn how to set up and use the Pod Security Admission Controller and apply policies to a specific namespace and the entire cluster.
More: https://faun.pub/pod-security-admission-controller-cluster-level-bda83b80d916
More: https://faun.pub/pod-security-admission-controller-cluster-level-bda83b80d916
Forwarded from LearnKube news
Puzzlefs is a container filesystem designed to address the limitations of the existing OCI format.
The project's primary goals are reduced duplication, reproducible image builds, direct mounting support and memory safety guarantees.
More: https://github.com/project-machine/puzzlefs
The project's primary goals are reduced duplication, reproducible image builds, direct mounting support and memory safety guarantees.
More: https://github.com/project-machine/puzzlefs
In this tutorial, you will find a demo of a Kubernetes Dynamic Validating Admission controller.
You will learn how to write a webhook server in Go and plan for its reliability and availability.
More: https://dev.to/gkampitakis/kubernetes-dynamic-admission-control-1f9p
You will learn how to write a webhook server in Go and plan for its reliability and availability.
More: https://dev.to/gkampitakis/kubernetes-dynamic-admission-control-1f9p
Forwarded from KubeFM
Gazal hinted at a 40% reduction in compute capacity when combining Bottlerocket OS and Karpenter (and 30% lower response times).
This and more on the new episode of the KubeFM podcast with Bart Farrell!
👉 https://kube.fm/gazal-eks-bottlerocket-karpenter
This and more on the new episode of the KubeFM podcast with Bart Farrell!
👉 https://kube.fm/gazal-eks-bottlerocket-karpenter
Forwarded from Kube Events
Learn how to rebalance workloads in your Kubernetes cluster to optimize resource allocations.
In this webinar, you'll learn:
- What the Decheduler is and how it works
- Policies to reallocate pods in your nodes
📅 12 Oct
⏰ 8am PT | 5pm CET
👉 https://kube.events/t/33c89654-e376-4a7f-8a43-15619a3502da
In this webinar, you'll learn:
- What the Decheduler is and how it works
- Policies to reallocate pods in your nodes
📅 12 Oct
⏰ 8am PT | 5pm CET
👉 https://kube.events/t/33c89654-e376-4a7f-8a43-15619a3502da
In this tutorial, you will learn how to set up an auto-rotating secret for a database connection using the External Secret Operator and Vault.
Secrets refresh every hour, and your apps stay connected to the database with new valid credentials.
More: https://dev.to/canelasevero/true-secrets-auto-rotation-with-eso-and-vault-1g4o
Secrets refresh every hour, and your apps stay connected to the database with new valid credentials.
More: https://dev.to/canelasevero/true-secrets-auto-rotation-with-eso-and-vault-1g4o
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:
🏃🏻♂️ Migrating etcd between clouds
🤔 What happens when… Kubernetes edition!
⚒️ Build your own Docker
💰 Upgrading 100s of clusters
🔙 S3 backups with Crossplane
Read it now: https://learnk8s.io/issues/48
🏃🏻♂️ Migrating etcd between clouds
🤔 What happens when… Kubernetes edition!
⚒️ Build your own Docker
💰 Upgrading 100s of clusters
🔙 S3 backups with Crossplane
Read it now: https://learnk8s.io/issues/48
This blog post examines Istio and how to leverage it to implement authentication and authorization policies to secure apps:
1. Native support for mTLS and JWT authentication.
2. Control and visibility over network traffic.
3. RBAC policies.
More: https://www.infracloud.io/blogs/istio-authentication-authorization-policies
1. Native support for mTLS and JWT authentication.
2. Control and visibility over network traffic.
3. RBAC policies.
More: https://www.infracloud.io/blogs/istio-authentication-authorization-policies
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with 1Password
💰 $180K to $244K a year
👨💻 Remote from the United States, Canada
→ https://kube.careers/t/b733b996-956e-4086-b0fa-514316485975?s=55
DevSecOps Engineer with Robinhood
💰 $169K to $255K a year
🏠 From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
→ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55
DevSecOps Engineer with Verkada
💰 $120K to $285K a year
🏠 From the office in San Mateo, CA, USA
→ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55
DevSecOps Engineer with Voltron Data
💰 $170K to $220K a year
🌎 Fully remote
→ https://kube.careers/t/f2509a98-e72c-4444-a44e-7f9502b58e1a?s=55
DevSecOps Engineer with Visa
💰 $167.7K to $218K a year
🏠🏃🏻♂️🌎 Foster City, CA, USA
→ https://kube.careers/t/e909c1a6-db53-4b66-927f-150f134a727a?s=55
👉 Browse all 468 Kubernetes jobs on Kube Careers https://kube.careers
DevSecOps Engineer with 1Password
💰 $180K to $244K a year
👨💻 Remote from the United States, Canada
→ https://kube.careers/t/b733b996-956e-4086-b0fa-514316485975?s=55
DevSecOps Engineer with Robinhood
💰 $169K to $255K a year
🏠 From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
→ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55
DevSecOps Engineer with Verkada
💰 $120K to $285K a year
🏠 From the office in San Mateo, CA, USA
→ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55
DevSecOps Engineer with Voltron Data
💰 $170K to $220K a year
🌎 Fully remote
→ https://kube.careers/t/f2509a98-e72c-4444-a44e-7f9502b58e1a?s=55
DevSecOps Engineer with Visa
💰 $167.7K to $218K a year
🏠🏃🏻♂️🌎 Foster City, CA, USA
→ https://kube.careers/t/e909c1a6-db53-4b66-927f-150f134a727a?s=55
👉 Browse all 468 Kubernetes jobs on Kube Careers https://kube.careers
Forwarded from LearnKube news
Master Kubernetes with Learnk8s' Advanced Kubernetes workshop!
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The course starts on the 30th of October in Amsterdam and you can sign up here: https://learnk8s.io/amsterdam-advanced-october-2023
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The course starts on the 30th of October in Amsterdam and you can sign up here: https://learnk8s.io/amsterdam-advanced-october-2023
In this blog, you'll learn what access control is and how Kubernetes manages access permissions behind the scenes.
More: https://blog.kubesimplify.com/kubernetes-access-control-with-authentication-authorization-admission-control
More: https://blog.kubesimplify.com/kubernetes-access-control-with-authentication-authorization-admission-control
Marvin is a CLI tool designed to help Kubernetes cluster administrators ensure the security and reliability of their environments.
It performs extensive checks on cluster resources, identifying potential issues, misconfigurations, and vulnerabilities.
More: https://github.com/undistro/marvin
It performs extensive checks on cluster resources, identifying potential issues, misconfigurations, and vulnerabilities.
More: https://github.com/undistro/marvin