Reposted by KubesploitKubeFM @kube.fm · 1h"More security focus, more compliance, more standardization. That's what happens when things get boring." Mauro Morales on the next decade of Kubernetes 📺: ku.bz/8cpgjFfjn 112
Reposted by KubesploitLearnKube @learnkube.com · 6hThis week on the Learn Kubernetes Weekly: 🔥 Building Modelplane on Crossplane 🚪 Why Ingress Is Being Replaced 🛡️ Fragile VMs to Bulletproof GitOps 💾 500 MB Buffer Killed Our Job 🎮 GPU MIG + Kueue ⭐️ LearnKube Read it now: kube.today/issues/203 077
Kubesploit @kubesploit.io · 23hThis tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server ➜ ku.bz/jgr5PbzgS 000
Reposted by KubesploitKube Architect @kube.archi · 29/09/2026This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool definitions and auth as four separate layers, plus the RBAC and deployment work needed before it touches a real cluster ➜ ku.bz/6c5t89LYj 021
Kubesploit @kubesploit.io · 28/09/2026Cordium runs isolated sandboxes on Kubernetes for developers and AI agents, and gives them secretless, identity-based access to SSH, databases and internal APIs ➤ ku.bz/Y8RNGkY16 000
Kubesploit @kubesploit.io · 28/09/2026This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registrar, the SecretProviderClass and the provider plugin It also covers syncing back into a native Kubernetes Secret for env vars ➜ ku.bz/m70bP2hJs 011
Reposted by KubesploitLearnKube @learnkube.com · 28/09/2026Join us for LearnKube Day in Salt Lake City on November 9 A free day of hands-on Kubernetes, AI SRE agents, technical talks, and YAML Games Register: learnkube.com/learnkube-day-salt-la… 086
Kubesploit @kubesploit.io · 27/09/2026This case study shows how Cilium implements defense-in-depth supply chain security for open source CI/CD It covers access controls, dependency pinning, credential isolation, and cryptographic verification ➤ ku.bz/dB6Bj2sKw 110
Kubesploit @kubesploit.io · 26/09/2026Warden is a secure gateway that brokers connections between AI agents and enterprise systems by authenticating agent identity and injecting short-lived credentials at request time ➤ ku.bz/knyfjtYg7 010
Kubesploit @kubesploit.io · 25/09/2026This case study shows how to stabilize Harbor on VMware VKS by expanding storage, upgrading the Supervisor Service, and configuring Trivy scanning to receive vulnerability results ➤ ku.bz/cScZ7ZQ8d 000
Kubesploit @kubesploit.io · 25/09/2026This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it, and pulls it back out with docker history, jq and tar ➜ ku.bz/S8r6yFdbS 011
Kubesploit @kubesploit.io · 24/09/2026PII-Shield is a log sanitization sidecar that redacts personal data before logs ever leave the pod, using entropy scoring and custom regex rules ➤ ku.bz/8nJ7hSf5b 000
Kubesploit @kubesploit.io · 24/09/2026This article explains how Vault piles up unexpired leases when pods keep re-authenticating with default service tokens, why that destabilises the HA cluster, and how batch tokens and shorter TTLs fix it ➜ ku.bz/Cn61TJM1G 000
Kubesploit @kubesploit.io · 23/09/2026This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime ➜ ku.bz/YdMc3KBZ6 000
Reposted by KubesploitLearnKube @learnkube.com · 23/09/2026This week on the Learn Kubernetes Weekly: 🔥 From etcd to Spanner 😌 Deploying Made Boring 🐘 Zookeeper on GKE 🚀 Mixed Version Proxy Graduates to Beta 🌍 Multi-Region EKS with Crossplane & FluxCD ⭐️ Buoyant Read it now: kube.today/issues/202 067
Kubesploit @kubesploit.io · 22/09/2026This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down ➜ ku.bz/ppRKVtXsb 010
Reposted by KubesploitKubeFM @kube.fm · 22/09/2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mistake." Tsahi Duek on why AI agent security isn't optional 📺: ku.bz/2r41YKBZb 112
Kubesploit @kubesploit.io · 21/09/2026Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives The README lists affected and fixed versions ➤ ku.bz/PQSlZ7Khl 000
Kubesploit @kubesploit.io · 21/09/2026This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down ➜ ku.bz/99rk_nQ-T 000
Reposted by KubesploitLearnKube @learnkube.com · 21/09/2026New free book: Kubernetes Architecture in Financial Services Platform lessons from seven banks on tenancy, delivery, policy, reliability, and cluster replacement Supported by Buoyant, Sysdig, and Nirmata: learnkube.com/kubernetes-architectu… 087
Kubesploit @kubesploit.io · 20/09/2026Kloak swaps placeholders for real secrets inside the kernel with eBPF, just before TLS encryption, so applications never hold credentials and need no sidecars or code changes Secrets can be pinned to specific hosts and ports ➤ ku.bz/2tGP1vSc3 000
Kubesploit @kubesploit.io · 19/09/2026IPMan is a Kubernetes operator that automates IPSec VPN setup (via StrongSwan) so your workloads can securely connect across networks ➤ ku.bz/Stkf6J4qr 000
Kubesploit @kubesploit.io · 18/09/2026Hubble is a fully distributed networking and security observability platform for cloud native workloads It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure ➤ ku.bz/fmj0PvVgk 022
Kubesploit @kubesploit.io · 18/09/2026This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials ➜ ku.bz/mdkryD536 000
Reposted by KubesploitKubeFM @kube.fm · 18/09/2026Kubernetes is multi-tenant by default. Workloads share nodes. Perimeter security still applies — but namespace isolation and network policies are what keep them from interfering Rodrigo Bersa on container security 📺: ku.bz/dB7PDNt0v 112
Kubesploit @kubesploit.io · 17/09/2026This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic ➤ ku.bz/GNLh0bWKs 000
Kubesploit @kubesploit.io · 17/09/2026Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production ➜ ku.bz/SWl3-LNty 011
Reposted by KubesploitKube Builders @kube.builders · 17/09/2026Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management ➜ ku.bz/3hC23K79L 011
Kubesploit @kubesploit.io · 17/09/2026This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates ➤ ku.bz/DFLtYT8zG 000
Kubesploit @kubesploit.io · 16/09/2026This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about ➜ ku.bz/tdxnc5S4r 000
Reposted by KubesploitLearnKube @learnkube.com · 16/09/2026Kubernetes race conditions, rendered GitOps manifests, Headlamp migration, pod-level resources, and hidden cluster capacity Brought to you by LearnKube: ku.bz/hypSbyc-V Learn Kubernetes Weekly 201: kube.today/issues/201 067
Kubesploit @kubesploit.io · 15/09/2026This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help ➜ ku.bz/tYzhJx61Q 000
Reposted by KubesploitKubeFM @kube.fm · 15/09/2026“AI guardrails have to be deterministic.” David Parry on why Kubernetes automation needs rules that match your company, your deployments, and your compliance needs 📺: ku.bz/c5J05syX3 112
Reposted by KubesploitKubeFM @kube.fm · 15/09/2026“When you run one pizza order, you get 200 traces.” On Kube Signals episode two, Mauricio (Salaboy) Salatino shows @brianteller.bsky.social why the demo needed 15 containers Watch: ku.bz/TlVjXdnb6 Presented by Learn Kubernetes Weekly 067
Kubesploit @kubesploit.io · 14/09/2026This article explains why three old Kubernetes CVEs will never get a code fix, and what to change in your cluster now that scanners are about to start flagging them again ➜ ku.bz/22Rr95v9F 000
Reposted by KubesploitKubeFM @kube.fm · 14/09/2026"Either which way you go, you've got to still figure out DNS." Raglin Anthony on on-prem to cloud networking 📺: ku.bz/2XqMJnLVx 112
Reposted by KubesploitDaniele Polencic @danielepolencic.com · 14/09/2026When does Kubernetes make sense? It is one of the questions we ask during private Kubernetes courses at @learnkube.com. My controversial answer is one application. 198
Kubesploit @kubesploit.io · 12/09/2026This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements ➤ ku.bz/YRcVzxByx 022
Kubesploit @kubesploit.io · 11/09/2026This article explains a new alpha feature in Kubernetes 1.36 that loads admission policies from files on disk at startup, so they are live before anything else and nobody can delete them ➜ ku.bz/B9JxC5dVt 000
Kubesploit @kubesploit.io · 10/09/2026This article shows how a default AWS EKS setting lets any pod reach the node's metadata service and steal its IAM credentials, then walks through the simple fix ➜ ku.bz/DXYZGjvf2 000
Kubesploit @kubesploit.io · 09/09/2026This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path ➜ ku.bz/CTv-Yf60c 000
Reposted by KubesploitLearnKube @learnkube.com · 09/09/2026Learn Kubernetes Weekly reached issue 200. 🎉 🤖 LLM inference benchmarks 🔌 New Headlamp plugins 🌐 ingress-NGINX to Envoy 🐘 PostgreSQL HA Read it: kube.today/issues/200 077
Reposted by KubesploitKubeFM @kube.fm · 08/09/2026AI is writing a lot of code. It is making it bulky by default Pronomita Dey on governing AI-written code 📺: ku.bz/lm5jTjdVN 112
Kubesploit @kubesploit.io · 08/09/2026This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves ➜ ku.bz/j_H7dxLV6 001
Reposted by KubesploitKubeFM @kube.fm · 08/09/2026“It is not a technical problem anymore. It is a people problem.” Kat Cosgrove of VillageSQL gives her verdict with hosts Salman Iqbal and Bart Farrell Watch: ku.bz/7yDWlP8T5 Presented by Learn Kubernetes Weekly 086
Kubesploit @kubesploit.io · 07/09/2026NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run ➜ ku.bz/CKghZJGt1 001
Kubesploit @kubesploit.io · 05/09/2026This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➤ ku.bz/cD6Lg9ppD 000
Kubesploit @kubesploit.io · 04/09/2026This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation ➤ ku.bz/z9DNn9t1D 000
Kubesploit @kubesploit.io · 04/09/2026This case study shows how to implement a HIPAA-compliant CI/CD pipeline using Cosign for artifact signing, OPA Gatekeeper for admission control on EKS, and long-term evidence storage in S3 ➜ ku.bz/TYS0yf264 000
Kubesploit @kubesploit.io · 03/09/2026AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened ➜ ku.bz/wd7SCHC3l 000