Forwarded from LearnKube news
Master Kubernetes with Learnk8s' Advanced Kubernetes workshops!
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The next course starts on the 18th of April: https://learnk8s.io/online-advanced-april-2024
We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The next course starts on the 18th of April: https://learnk8s.io/online-advanced-april-2024
We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
This tutorial outlines securing a cluster with Kubescape, Prometheus, and Grafana for proactive risk identification, trend analysis, and improved audit processes.
A setup guide includes Terraform deployment and log management with Loki and Promtail.
More: https://araji.medium.com/proactive-kubernetes-security-unlocking-threat-detection-with-kubescape-prometheus-and-grafana-ad69593998fd
A setup guide includes Terraform deployment and log management with Loki and Promtail.
More: https://araji.medium.com/proactive-kubernetes-security-unlocking-threat-detection-with-kubescape-prometheus-and-grafana-ad69593998fd
The article delves into Google Kubernetes Engine's Workload Identity Federation and highlights the security benefits, operational simplicity, and importance of annotations and policy bindings in managing access control.
More: https://medium.com/google-cloud/whoami-the-quest-of-understanding-gke-workload-identity-federation-e951e5e4a03f
More: https://medium.com/google-cloud/whoami-the-quest-of-understanding-gke-workload-identity-federation-e951e5e4a03f
KubeMod is a universal Kubernetes mutating operator.
It introduces Custom Resource Definition (
More: https://github.com/kubemod/kubemod
It introduces Custom Resource Definition (
ModRule) that can intercept the deployment of any Kubernetes object and apply modifications or reject it before it is deployed to the cluster.More: https://github.com/kubemod/kubemod
The article discusses enhancing Kubernetes network security using iptables, covering its setup, configuring rules for different nodes, and ensuring persistent configurations for continuous protection.
More: https://dev.to/docteurrs/shielding-your-kubernetes-network-mastering-iptables-for-enhanced-security-39o7
More: https://dev.to/docteurrs/shielding-your-kubernetes-network-mastering-iptables-for-enhanced-security-39o7
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:
🐾 Journey with Cluster API
📏 Horizontal Autoscaling
⏱️ Testing Service Mesh performance
🥷 Escaping the OOM Killer
💡 From on-premise to GKE
Read it now: https://learnk8s.io/issues/74
🐾 Journey with Cluster API
📏 Horizontal Autoscaling
⏱️ Testing Service Mesh performance
🥷 Escaping the OOM Killer
💡 From on-premise to GKE
Read it now: https://learnk8s.io/issues/74
If you are an admin running a Kubernetes cluster on AWS, you already need to manage AWS IAM credentials to provision and update the cluster.
You avoid managing a separate credential for Kubernetes access by using AWS IAM Authenticator for Kubernetes.
More: https://github.com/kubernetes-sigs/aws-iam-authenticator
You avoid managing a separate credential for Kubernetes access by using AWS IAM Authenticator for Kubernetes.
More: https://github.com/kubernetes-sigs/aws-iam-authenticator
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with Anthropic
💰 $300K to $405K a year
🏠🏃🏻♂️🌎 San Francisco, CA / New York, NY, USA
→ https://kube.careers/t/6a4b5616-64d0-4855-9e10-a0c2b7cefcca?s=55
DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55
DevSecOps Engineer with Applied Intuition
💰 $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
→ https://kube.careers/t/c6291093-2e86-4446-aab7-7f34af1a3112?s=55
DevSecOps Engineer with PagerDuty
💰 $176K to $277K a year
🏠 From the office in Atlanta, GA, USA
→ https://kube.careers/t/f7204480-93a6-477a-996f-eee9e4c5f9bd?s=55
DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55
👉 Browse all 453 Kubernetes jobs on Kube Careers https://kube.careers
DevSecOps Engineer with Anthropic
💰 $300K to $405K a year
🏠🏃🏻♂️🌎 San Francisco, CA / New York, NY, USA
→ https://kube.careers/t/6a4b5616-64d0-4855-9e10-a0c2b7cefcca?s=55
DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55
DevSecOps Engineer with Applied Intuition
💰 $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
→ https://kube.careers/t/c6291093-2e86-4446-aab7-7f34af1a3112?s=55
DevSecOps Engineer with PagerDuty
💰 $176K to $277K a year
🏠 From the office in Atlanta, GA, USA
→ https://kube.careers/t/f7204480-93a6-477a-996f-eee9e4c5f9bd?s=55
DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55
👉 Browse all 453 Kubernetes jobs on Kube Careers https://kube.careers
Forwarded from LearnKube news
Master Kubernetes with Learnk8s' Advanced Kubernetes workshops!
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The next course starts next week: https://learnk8s.io/online-advanced-april-2024
We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
What should you expect?
- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.
The next course starts next week: https://learnk8s.io/online-advanced-april-2024
We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
The article compares three policy engines: OPA, Gatekeeper, Kyverno, and jsPolicy.
More: https://blogs.aftabs.co/enforcing-security-and-compliance-with-kubernetes-policy-engines
More: https://blogs.aftabs.co/enforcing-security-and-compliance-with-kubernetes-policy-engines
Forwarded from Kube Events
Kubernetes Community Days Romania starts in less than 2 weeks!
A one-day technical event loaded with exciting Kubernetes talks and networking opportunities.
📆 Thu, 25th Apr
⏰ 8am EET
📍 Bucharest, RO
👉 https://kube.events/t/b08aa779-8760-45e7-a493-4dc023871777
A one-day technical event loaded with exciting Kubernetes talks and networking opportunities.
📆 Thu, 25th Apr
⏰ 8am EET
📍 Bucharest, RO
👉 https://kube.events/t/b08aa779-8760-45e7-a493-4dc023871777
Amazon EKS Pod Identities automates the association between Kubernetes service accounts and AWS IAM roles, eliminating manual credential management.
This tutorial explains the steps involved in doing so.
More: https://medium.com/lumigo/eks-pod-identity-agent-7274e739832c
This tutorial explains the steps involved in doing so.
More: https://medium.com/lumigo/eks-pod-identity-agent-7274e739832c
In this article, you'll learn how to use RBAC and set up Roles that specify what actions are allowed and how to link these Roles to your Users and Service Accounts using RoleBindings.
More: https://medium.com/@arton.demaku/kubernetes-rbac-explained-with-examples-40e1c5e44c32
More: https://medium.com/@arton.demaku/kubernetes-rbac-explained-with-examples-40e1c5e44c32
This repository contains an extended version of the Open Policy Agent (OPA-Envoy) that allows you to enforce OPA policies with Envoy.
More: https://github.com/open-policy-agent/opa-envoy-plugin
More: https://github.com/open-policy-agent/opa-envoy-plugin
The article compares HashiCorp Vault and Banzaicloud/bank-vaults for Kubernetes Secrets Management, highlighting their advantages, potential drawbacks, and considerations for choosing between them.
More: https://medium.com/@denisgorokhov/kubernetes-secrets-management-hashicorp-vault-vs-banzaicloud-bank-vaults-5a793c4de18d
More: https://medium.com/@denisgorokhov/kubernetes-secrets-management-hashicorp-vault-vs-banzaicloud-bank-vaults-5a793c4de18d
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:
DevSecOps Engineer with Anthropic
💰 $300K to $405K a year
🏠🏃🏻♂️🌎 San Francisco, CA / New York, NY, USA
→ https://kube.careers/t/6a4b5616-64d0-4855-9e10-a0c2b7cefcca?s=55
DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55
DevSecOps Engineer with Applied Intuition
💰 $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
→ https://kube.careers/t/c6291093-2e86-4446-aab7-7f34af1a3112?s=55
DevSecOps Engineer with PagerDuty
💰 $176K to $277K a year
🏠 From the office in Atlanta, GA, USA
→ https://kube.careers/t/f7204480-93a6-477a-996f-eee9e4c5f9bd?s=55
DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55
👉 Browse all 443 Kubernetes jobs on Kube Careers https://kube.careers
DevSecOps Engineer with Anthropic
💰 $300K to $405K a year
🏠🏃🏻♂️🌎 San Francisco, CA / New York, NY, USA
→ https://kube.careers/t/6a4b5616-64d0-4855-9e10-a0c2b7cefcca?s=55
DevSecOps Engineer with Plaid
💰 $215.3K to $322.9K a year
👨💻 Remote from the United States
→ https://kube.careers/t/82ecabe4-3ee3-408e-9e59-de3130fd3475?s=55
DevSecOps Engineer with Applied Intuition
💰 $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
→ https://kube.careers/t/c6291093-2e86-4446-aab7-7f34af1a3112?s=55
DevSecOps Engineer with PagerDuty
💰 $176K to $277K a year
🏠 From the office in Atlanta, GA, USA
→ https://kube.careers/t/f7204480-93a6-477a-996f-eee9e4c5f9bd?s=55
DevSecOps Engineer with Hyperscience
💰 $190K to $260K a year
👨💻 Remote from the United States
→ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55
👉 Browse all 443 Kubernetes jobs on Kube Careers https://kube.careers
In this tutorial, you will learn how to set up the Open Policy Agent to evaluate queries against a set of policies.
More: https://medium.com/@chukmunnlee/enforcing-cluster-policy-with-open-policy-agent-part-1-b0448093248d
More: https://medium.com/@chukmunnlee/enforcing-cluster-policy-with-open-policy-agent-part-1-b0448093248d
The article explores enabling Istio to trust certificates from multiple root CAs, which is crucial for multi-cluster Istio meshes.
It details a disaster recovery use case providing a step-by-step guide for configuring trust using secrets and encryption.
More: https://medium.com/tenets/istio-assuming-trust-between-clusters-in-the-same-mesh-with-different-cas-934ec398a9b5
It details a disaster recovery use case providing a step-by-step guide for configuring trust using secrets and encryption.
More: https://medium.com/tenets/istio-assuming-trust-between-clusters-in-the-same-mesh-with-different-cas-934ec398a9b5
Forwarded from LearnKube news
Creating and deleting Pods is one of the most common tasks in Kubernetes.
In this article, you will learn how to prevent broken connections when a Pod starts up or shuts down (and how to shut down long-running tasks gracefully).
Read the full article: https://learnk8s.io/graceful-shutdown
In this article, you will learn how to prevent broken connections when a Pod starts up or shuts down (and how to shut down long-running tasks gracefully).
Read the full article: https://learnk8s.io/graceful-shutdown
If you are an admin running a Kubernetes cluster on AWS, you already need to manage AWS IAM credentials to provision and update the cluster.
You avoid managing a separate credential for Kubernetes access by using AWS IAM Authenticator for Kubernetes.
More: https://github.com/kubernetes-sigs/aws-iam-authenticator
You avoid managing a separate credential for Kubernetes access by using AWS IAM Authenticator for Kubernetes.
More: https://github.com/kubernetes-sigs/aws-iam-authenticator
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
In this KubeFM episode, Mat discusses the necessity of long-term support for Kubernetes and explores the intricacies of managing Kubernetes upgrades in a fast-evolving landscape.
You will learn:
- The importance of long-term support (LTS) for Kubernetes and how it can alleviate the challenges associated with the platform's rapid release cycles.
- Strategies for managing Kubernetes upgrades, including insights into the release cycle and the potential pitfalls of the upgrading process.
- The role of managed services and semi-automatic upgrades in simplifying Kubernetes maintenance for organizations, especially in cost optimization and resource constraints.
Watch (or listen to) it here: https://kube.fm/kubernetes-lts-mat
You will learn:
- The importance of long-term support (LTS) for Kubernetes and how it can alleviate the challenges associated with the platform's rapid release cycles.
- Strategies for managing Kubernetes upgrades, including insights into the release cycle and the potential pitfalls of the upgrading process.
- The role of managed services and semi-automatic upgrades in simplifying Kubernetes maintenance for organizations, especially in cost optimization and resource constraints.
Watch (or listen to) it here: https://kube.fm/kubernetes-lts-mat