Sign in

Kubesploit

@kubesploit.io
275 followers 1 following 715 posts

News and links on Kubernetes security curated by the @Learnk8s.io team More K8s news, events, jobs → kube.today

PostsRepliesMedia
Reposted by Kubesploit
KubeFM @kube.fm · 1h
"More security focus, more compliance, more standardization. That's what happens when things get boring." Mauro Morales on the next decade of Kubernetes 📺: ku.bz/8cpgjFfjn
112
Reposted by Kubesploit
LearnKube @learnkube.com · 6h
This week on the Learn Kubernetes Weekly: 🔥 Building Modelplane on Crossplane 🚪 Why Ingress Is Being Replaced 🛡️ Fragile VMs to Bulletproof GitOps 💾 500 MB Buffer Killed Our Job 🎮 GPU MIG + Kueue ⭐️ LearnKube Read it now: kube.today/issues/203
https://assets.learnk8s.io/linkedin-203.png
077
Kubesploit @kubesploit.io · 23h
This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server ➜ ku.bz/jgr5PbzgS
https://miro.medium.com/v2/0*MtIJXrk8MEclmTwo.png
000
Reposted by Kubesploit
Kube Architect @kube.archi · 29/09/2026
This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool definitions and auth as four separate layers, plus the RBAC and deployment work needed before it touches a real cluster ➜ ku.bz/6c5t89LYj
https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx85wqhvj7qky05z5q2oh.png
021
Kubesploit @kubesploit.io · 28/09/2026
Cordium runs isolated sandboxes on Kubernetes for developers and AI agents, and gives them secretless, identity-based access to SSH, databases and internal APIs ➤ ku.bz/Y8RNGkY16
https://octelium.com/assets/cordium-hierarchy-k-2W_obH.webp
000
Kubesploit @kubesploit.io · 28/09/2026
This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registrar, the SecretProviderClass and the provider plugin It also covers syncing back into a native Kubernetes Secret for env vars ➜ ku.bz/m70bP2hJs
https://miro.medium.com/v2/1*OdfGvHHbVi2FYvwOvqRlDA.png
011
Reposted by Kubesploit
LearnKube @learnkube.com · 28/09/2026
Join us for LearnKube Day in Salt Lake City on November 9 A free day of hands-on Kubernetes, AI SRE agents, technical talks, and YAML Games Register: learnkube.com/learnkube-day-salt-la…
https://social-planner-temp.uasabi.com/2026/10/28/5ee3-learnkube-day.png
086
Kubesploit @kubesploit.io · 27/09/2026
This case study shows how Cilium implements defense-in-depth supply chain security for open source CI/CD It covers access controls, dependency pinning, credential isolation, and cryptographic verification ➤ ku.bz/dB6Bj2sKw
110
Kubesploit @kubesploit.io · 26/09/2026
Warden is a secure gateway that brokers connections between AI agents and enterprise systems by authenticating agent identity and injecting short-lived credentials at request time ➤ ku.bz/knyfjtYg7
010
Kubesploit @kubesploit.io · 25/09/2026
This case study shows how to stabilize Harbor on VMware VKS by expanding storage, upgrading the Supervisor Service, and configuring Trivy scanning to receive vulnerability results ➤ ku.bz/cScZ7ZQ8d
000
Kubesploit @kubesploit.io · 25/09/2026
This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it, and pulls it back out with docker history, jq and tar ➜ ku.bz/S8r6yFdbS
https://miro.medium.com/v2/1*93kB4rhb30uowVch9Eykag.png
011
Kubesploit @kubesploit.io · 24/09/2026
PII-Shield is a log sanitization sidecar that redacts personal data before logs ever leave the pod, using entropy scoring and custom regex rules ➤ ku.bz/8nJ7hSf5b
000
Kubesploit @kubesploit.io · 24/09/2026
This article explains how Vault piles up unexpired leases when pods keep re-authenticating with default service tokens, why that destabilises the HA cluster, and how batch tokens and shorter TTLs fix it ➜ ku.bz/Cn61TJM1G
https://miro.medium.com/v2/1*_dn8ND7WWfSbzS1OacrWyw.png
000
Kubesploit @kubesploit.io · 23/09/2026
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime ➜ ku.bz/YdMc3KBZ6
https://miro.medium.com/v2/1*czDHfJYtw44KqIq2_D9MiA.jpeg
000
Reposted by Kubesploit
LearnKube @learnkube.com · 23/09/2026
This week on the Learn Kubernetes Weekly: 🔥 From etcd to Spanner 😌 Deploying Made Boring 🐘 Zookeeper on GKE 🚀 Mixed Version Proxy Graduates to Beta 🌍 Multi-Region EKS with Crossplane & FluxCD ⭐️ Buoyant Read it now: kube.today/issues/202
https://assets.learnk8s.io/linkedin-202.png
067
Kubesploit @kubesploit.io · 22/09/2026
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down ➜ ku.bz/ppRKVtXsb
https://storage.ghost.io/c/42/5d/425d266f-cf99-406e-9436-597a19bed011/content/images/2026/05/data-src-image-431027e6-3dd7-4398-b93f-bf8ecd1596a5.png
010
Reposted by Kubesploit
KubeFM @kube.fm · 22/09/2026
"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mistake." Tsahi Duek on why AI agent security isn't optional 📺: ku.bz/2r41YKBZb
112
Kubesploit @kubesploit.io · 21/09/2026
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives The README lists affected and fixed versions ➤ ku.bz/PQSlZ7Khl
000
Kubesploit @kubesploit.io · 21/09/2026
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down ➜ ku.bz/99rk_nQ-T
https://miro.medium.com/v2/1*al2xqrR-5z09IhiiBakY5w.png
000
Reposted by Kubesploit
LearnKube @learnkube.com · 21/09/2026
New free book: Kubernetes Architecture in Financial Services Platform lessons from seven banks on tenancy, delivery, policy, reliability, and cluster replacement Supported by Buoyant, Sysdig, and Nirmata: learnkube.com/kubernetes-architectu…
https://social-planner-temp.uasabi.com/2026/10/21/7afe-bank-grade.png
087
Kubesploit @kubesploit.io · 20/09/2026
Kloak swaps placeholders for real secrets inside the kernel with eBPF, just before TLS encryption, so applications never hold credentials and need no sidecars or code changes Secrets can be pinned to specific hosts and ports ➤ ku.bz/2tGP1vSc3
000
Kubesploit @kubesploit.io · 19/09/2026
IPMan is a Kubernetes operator that automates IPSec VPN setup (via StrongSwan) so your workloads can securely connect across networks ➤ ku.bz/Stkf6J4qr
https://github.com/user-attachments/assets/8739b49c-f77d-4c76-8091-73f427442bfb
000
Kubesploit @kubesploit.io · 18/09/2026
Hubble is a fully distributed networking and security observability platform for cloud native workloads It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure ➤ ku.bz/fmj0PvVgk
https://github.com/cilium/hubble/raw/main/Documentation/images/network_and_tcp.png
022
Kubesploit @kubesploit.io · 18/09/2026
This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials ➜ ku.bz/mdkryD536
000
Reposted by Kubesploit
KubeFM @kube.fm · 18/09/2026
Kubernetes is multi-tenant by default. Workloads share nodes. Perimeter security still applies — but namespace isolation and network policies are what keep them from interfering Rodrigo Bersa on container security 📺: ku.bz/dB7PDNt0v
112
Kubesploit @kubesploit.io · 17/09/2026
This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic ➤ ku.bz/GNLh0bWKs
https://miro.medium.com/v2/1*Bx-V9COY0aUJARCzSPRVng.png
000
Kubesploit @kubesploit.io · 17/09/2026
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production ➜ ku.bz/SWl3-LNty
011
Reposted by Kubesploit
Kube Builders @kube.builders · 17/09/2026
Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management ➜ ku.bz/3hC23K79L
011
Kubesploit @kubesploit.io · 17/09/2026
This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates ➤ ku.bz/DFLtYT8zG
https://pixelrobots.co.uk/wp-content/uploads/2026/06/2026-06-04-08-43-52.png
000
Kubesploit @kubesploit.io · 16/09/2026
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about ➜ ku.bz/tdxnc5S4r
https://miro.medium.com/v2/1*kx9CUvcvXEg03gEry8a6qw.png
000
Reposted by Kubesploit
LearnKube @learnkube.com · 16/09/2026
Kubernetes race conditions, rendered GitOps manifests, Headlamp migration, pod-level resources, and hidden cluster capacity Brought to you by LearnKube: ku.bz/hypSbyc-V Learn Kubernetes Weekly 201: kube.today/issues/201
https://social-planner-temp.uasabi.com/2026/10/16/0492-linkedin-201.png
067
Kubesploit @kubesploit.io · 15/09/2026
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help ➜ ku.bz/tYzhJx61Q
https://brainoverflow.blog/posts/copy-fail-kubernetes-escape/images/page-cache-anniversary.jpg
000
Reposted by Kubesploit
KubeFM @kube.fm · 15/09/2026
“AI guardrails have to be deterministic.” David Parry on why Kubernetes automation needs rules that match your company, your deployments, and your compliance needs 📺: ku.bz/c5J05syX3
112
Reposted by Kubesploit
KubeFM @kube.fm · 15/09/2026
“When you run one pizza order, you get 200 traces.” On Kube Signals episode two, Mauricio (Salaboy) Salatino shows @brianteller.bsky.social why the demo needed 15 containers Watch: ku.bz/TlVjXdnb6 Presented by Learn Kubernetes Weekly
067
Kubesploit @kubesploit.io · 14/09/2026
This article explains why three old Kubernetes CVEs will never get a code fix, and what to change in your cluster now that scanners are about to start flagging them again ➜ ku.bz/22Rr95v9F
000
Reposted by Kubesploit
KubeFM @kube.fm · 14/09/2026
"Either which way you go, you've got to still figure out DNS." Raglin Anthony on on-prem to cloud networking 📺: ku.bz/2XqMJnLVx
112
Reposted by Kubesploit
Daniele Polencic @danielepolencic.com · 14/09/2026
When does Kubernetes make sense? It is one of the questions we ask during private Kubernetes courses at @learnkube.com. My controversial answer is one application.
https://social-planner-temp.uasabi.com/2026/10/14/8cb1-make-sense.png
198
Kubesploit @kubesploit.io · 12/09/2026
This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements ➤ ku.bz/YRcVzxByx
https://miro.medium.com/v2/1*8EFKaeFL3inxyyMQ640JHw.png
022
Kubesploit @kubesploit.io · 11/09/2026
This article explains a new alpha feature in Kubernetes 1.36 that loads admission policies from files on disk at startup, so they are live before anything else and nobody can delete them ➜ ku.bz/B9JxC5dVt
000
Kubesploit @kubesploit.io · 10/09/2026
This article shows how a default AWS EKS setting lets any pod reach the node's metadata service and steal its IAM credentials, then walks through the simple fix ➜ ku.bz/DXYZGjvf2
000
Kubesploit @kubesploit.io · 09/09/2026
This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path ➜ ku.bz/CTv-Yf60c
000
Reposted by Kubesploit
LearnKube @learnkube.com · 09/09/2026
Learn Kubernetes Weekly reached issue 200. 🎉 🤖 LLM inference benchmarks 🔌 New Headlamp plugins 🌐 ingress-NGINX to Envoy 🐘 PostgreSQL HA Read it: kube.today/issues/200
https://social-planner-temp.uasabi.com/2026/10/09/b6ea-linkedin-200.png
077
Reposted by Kubesploit
KubeFM @kube.fm · 08/09/2026
AI is writing a lot of code. It is making it bulky by default Pronomita Dey on governing AI-written code 📺: ku.bz/lm5jTjdVN
112
Kubesploit @kubesploit.io · 08/09/2026
This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves ➜ ku.bz/j_H7dxLV6
001
Reposted by Kubesploit
KubeFM @kube.fm · 08/09/2026
“It is not a technical problem anymore. It is a people problem.” Kat Cosgrove of VillageSQL gives her verdict with hosts Salman Iqbal and Bart Farrell Watch: ku.bz/7yDWlP8T5 Presented by Learn Kubernetes Weekly
086
Kubesploit @kubesploit.io · 07/09/2026
NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run ➜ ku.bz/CKghZJGt1
001
Kubesploit @kubesploit.io · 05/09/2026
This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➤ ku.bz/cD6Lg9ppD
https://miro.medium.com/v2/resize:fit:700/1*zGlJNdPRmZDm0be4wp9JQA.png
000
Kubesploit @kubesploit.io · 04/09/2026
This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation ➤ ku.bz/z9DNn9t1D
000
Kubesploit @kubesploit.io · 04/09/2026
This case study shows how to implement a HIPAA-compliant CI/CD pipeline using Cosign for artifact signing, OPA Gatekeeper for admission control on EKS, and long-term evidence storage in S3 ➜ ku.bz/TYS0yf264
000
Kubesploit @kubesploit.io · 03/09/2026
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened ➜ ku.bz/wd7SCHC3l
https://github.com/user-attachments/assets/77205c28-7999-413f-ad99-a95da33507f8
000