Sign in

Kubesploit

@kubesploit.io
275 followers 1 following 716 posts

News and links on Kubernetes security curated by the @Learnk8s.io team More K8s news, events, jobs → kube.today

PostsRepliesMedia
Kubesploit @kubesploit.io · 5h
FQDN Network Policy turns hostnames into current IP addresses and creates standard Kubernetes NetworkPolicy rules, so teams can control outbound traffic on any CNI without replacing their network plugin ➜ ku.bz/NprbZjd3s
https://github.com/user-attachments/assets/f36e198b-33d0-4ddc-ba25-98a444a5e611
000
Kubesploit @kubesploit.io · 29/09/2026
This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server ➜ ku.bz/jgr5PbzgS
https://miro.medium.com/v2/0*MtIJXrk8MEclmTwo.png
000
Kubesploit @kubesploit.io · 28/09/2026
Cordium runs isolated sandboxes on Kubernetes for developers and AI agents, and gives them secretless, identity-based access to SSH, databases and internal APIs ➤ ku.bz/Y8RNGkY16
https://octelium.com/assets/cordium-hierarchy-k-2W_obH.webp
000
Kubesploit @kubesploit.io · 28/09/2026
This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registrar, the SecretProviderClass and the provider plugin It also covers syncing back into a native Kubernetes Secret for env vars ➜ ku.bz/m70bP2hJs
https://miro.medium.com/v2/1*OdfGvHHbVi2FYvwOvqRlDA.png
011
Kubesploit @kubesploit.io · 25/09/2026
This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it, and pulls it back out with docker history, jq and tar ➜ ku.bz/S8r6yFdbS
https://miro.medium.com/v2/1*93kB4rhb30uowVch9Eykag.png
011
Kubesploit @kubesploit.io · 24/09/2026
This article explains how Vault piles up unexpired leases when pods keep re-authenticating with default service tokens, why that destabilises the HA cluster, and how batch tokens and shorter TTLs fix it ➜ ku.bz/Cn61TJM1G
https://miro.medium.com/v2/1*_dn8ND7WWfSbzS1OacrWyw.png
000
Kubesploit @kubesploit.io · 23/09/2026
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime ➜ ku.bz/YdMc3KBZ6
https://miro.medium.com/v2/1*czDHfJYtw44KqIq2_D9MiA.jpeg
000
Kubesploit @kubesploit.io · 22/09/2026
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down ➜ ku.bz/ppRKVtXsb
https://storage.ghost.io/c/42/5d/425d266f-cf99-406e-9436-597a19bed011/content/images/2026/05/data-src-image-431027e6-3dd7-4398-b93f-bf8ecd1596a5.png
010
Kubesploit @kubesploit.io · 21/09/2026
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down ➜ ku.bz/99rk_nQ-T
https://miro.medium.com/v2/1*al2xqrR-5z09IhiiBakY5w.png
000
Kubesploit @kubesploit.io · 19/09/2026
IPMan is a Kubernetes operator that automates IPSec VPN setup (via StrongSwan) so your workloads can securely connect across networks ➤ ku.bz/Stkf6J4qr
https://github.com/user-attachments/assets/8739b49c-f77d-4c76-8091-73f427442bfb
000
Kubesploit @kubesploit.io · 18/09/2026
Hubble is a fully distributed networking and security observability platform for cloud native workloads It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure ➤ ku.bz/fmj0PvVgk
https://github.com/cilium/hubble/raw/main/Documentation/images/network_and_tcp.png
022
Kubesploit @kubesploit.io · 17/09/2026
This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic ➤ ku.bz/GNLh0bWKs
https://miro.medium.com/v2/1*Bx-V9COY0aUJARCzSPRVng.png
000
Kubesploit @kubesploit.io · 17/09/2026
This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates ➤ ku.bz/DFLtYT8zG
https://pixelrobots.co.uk/wp-content/uploads/2026/06/2026-06-04-08-43-52.png
000
Kubesploit @kubesploit.io · 16/09/2026
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about ➜ ku.bz/tdxnc5S4r
https://miro.medium.com/v2/1*kx9CUvcvXEg03gEry8a6qw.png
000
Kubesploit @kubesploit.io · 15/09/2026
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help ➜ ku.bz/tYzhJx61Q
https://brainoverflow.blog/posts/copy-fail-kubernetes-escape/images/page-cache-anniversary.jpg
000
Kubesploit @kubesploit.io · 12/09/2026
This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements ➤ ku.bz/YRcVzxByx
https://miro.medium.com/v2/1*8EFKaeFL3inxyyMQ640JHw.png
022
Kubesploit @kubesploit.io · 05/09/2026
This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➤ ku.bz/cD6Lg9ppD
https://miro.medium.com/v2/resize:fit:700/1*zGlJNdPRmZDm0be4wp9JQA.png
000
Kubesploit @kubesploit.io · 03/09/2026
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened ➜ ku.bz/wd7SCHC3l
https://github.com/user-attachments/assets/77205c28-7999-413f-ad99-a95da33507f8
000
Kubesploit @kubesploit.io · 02/09/2026
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview API, then makes it safer with audience-bound projected tokens ➜ ku.bz/rz69JFBdZ
https://static.learnkube.com/cfd3df73795bd076e95167747862c630.svg
021
Kubesploit @kubesploit.io · 31/08/2026
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns ➤ ku.bz/XNmQ2X-7T
https://miro.medium.com/v2/resize:fit:700/1*9ggxl7KviaJjZt69eS-nvA.png
000
Kubesploit @kubesploit.io · 30/08/2026
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping ➤ ku.bz/nN1m_5FXK
https://miro.medium.com/v2/1*j7V1HmI_Ku2fl6Mz8Wlcxw.png
000
Kubesploit @kubesploit.io · 28/08/2026
This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access ➤ ku.bz/gMzL4pXNq
https://blog.stderr.at/openshift-platform/security/RBAC/images/rbac-overview-cluster-admins.png?width=900px
000
Kubesploit @kubesploit.io · 28/08/2026
Cordium runs isolated sandboxes on Kubernetes for developers and AI agents, and gives them secretless, identity-based access to SSH, databases and internal APIs ➜ ku.bz/Y8RNGkY16
https://octelium.com/assets/cordium-hierarchy-k-2W_obH.webp
000
Kubesploit @kubesploit.io · 27/08/2026
Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs ➤ ku.bz/DLKSbPlGK
https://github.com/safe-agentic-world/nomos/raw/main/docs/assets/claude-demo.png
100
Kubesploit @kubesploit.io · 20/08/2026
This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService ➤ ku.bz/lNmNzN4HW
https://miro.medium.com/v2/1*ePRVe09d7jMQRx-V_vzMYw.png
012
Kubesploit @kubesploit.io · 19/08/2026
IPMan is a Kubernetes operator that automates IPSec VPN setup (via StrongSwan) so your workloads can securely connect across networks ➜ ku.bz/Stkf6J4qr
https://github.com/user-attachments/assets/62ac06dd-8319-432c-9512-c3eebcb54b4d
000
Kubesploit @kubesploit.io · 18/08/2026
Hubble is a fully distributed networking and security observability platform for cloud native workloads It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure ➜ ku.bz/fmj0PvVgk
https://github.com/cilium/hubble/raw/main/Documentation/images/servicemap.png
011
Kubesploit @kubesploit.io · 17/08/2026
This article explains four Kubernetes isolation patterns for AI agents: no exec, sidecar exec, separate exec pod, and ephemeral job dispatchers, with OpenShift-validated threat modeling ➤ ku.bz/KC6H2m-VF
https://miro.medium.com/v2/1*VKD9osxH7o-YTpB6E_SLQg.png
000
Kubesploit @kubesploit.io · 17/08/2026
This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic ➜ ku.bz/GNLh0bWKs
https://miro.medium.com/v2/1*Bx-V9COY0aUJARCzSPRVng.png
000
Kubesploit @kubesploit.io · 17/08/2026
This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates ➜ ku.bz/DFLtYT8zG
https://pixelrobots.co.uk/wp-content/uploads/2026/06/2026-06-04-08-43-03.png
000
Kubesploit @kubesploit.io · 16/08/2026
This tutorial shows how to modernize Kyverno policies with CEL using practical Kubernetes security examples like namespace rules, image checks, service account tokens, and safer policy testing ➤ ku.bz/PcpzWX_N6
https://miro.medium.com/v2/resize:fit:700/1*pwFLr-Xs4R7KWM4VdBTSGQ.png
020
Kubesploit @kubesploit.io · 12/08/2026
This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements ➜ ku.bz/YRcVzxByx
https://miro.medium.com/v2/1*n5Ukd-uhm7DejSPjqLggtQ.png
021
Kubesploit @kubesploit.io · 05/08/2026
This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➜ ku.bz/cD6Lg9ppD
https://miro.medium.com/v2/resize:fit:700/1*zGlJNdPRmZDm0be4wp9JQA.png
000
Kubesploit @kubesploit.io · 05/08/2026
This tutorial shows how to connect on-prem Kubernetes workloads to Google Cloud without service account keys using Workload Identity Federation, OIDC, Terraform, Kyverno, and IAM attribute conditions ➤ ku.bz/1YVD6c3FP
https://miro.medium.com/v2/1*b4zQ0NEHFiWmQCGXRpE25A.png
021
Kubesploit @kubesploit.io · 31/07/2026
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns ➜ ku.bz/XNmQ2X-7T
https://miro.medium.com/v2/resize:fit:700/1*9ggxl7KviaJjZt69eS-nvA.png
000
Kubesploit @kubesploit.io · 30/07/2026
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping ➜ ku.bz/nN1m_5FXK
https://miro.medium.com/v2/1*kBFs3DF3I6sQBvxTIFyM_Q.png
010
Kubesploit @kubesploit.io · 28/07/2026
This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access ➜ ku.bz/gMzL4pXNq
https://blog.stderr.at/openshift-platform/security/RBAC/images/rbac-overview-who-can-results.png?width=900px
011
Kubesploit @kubesploit.io · 27/07/2026
Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs ➜ ku.bz/DLKSbPlGK
https://github.com/safe-agentic-world/nomos/raw/main/docs/assets/claude-demo.png
000
Kubesploit @kubesploit.io · 25/07/2026
This article explains how to use Gatekeeper to enforce in-cluster admission policies, such as rejecting `:latest` images, mandating labels, and disallowing privileged workloads ➤ ku.bz/1Zskfkkvg
https://cdn.hashnode.com/res/hashnode/image/upload/v1737449740699/60ca346a-8ff2-474a-93cd-db1b04510e42.png
020
Kubesploit @kubesploit.io · 24/07/2026
This tutorial shows how to run OWASP ZAP scans inside GitHub Actions using SecureCodeBox on a Kubernetes kind cluster ➤ ku.bz/nDZJpmg5F
https://miro.medium.com/v2/0*qO9YgdsxXWM3GknI
000
Kubesploit @kubesploit.io · 20/07/2026
This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService ➜ ku.bz/lNmNzN4HW
https://miro.medium.com/v2/1*ai0-5ESzfL9tl91-exmG5w.png
021
Kubesploit @kubesploit.io · 18/07/2026
This article covers network security fundamentals in Kubernetes, explaining how clusters default to a flat pod network, how network policies enforce segmentation, and best practices like “default deny” and restricting host networking ➤ ku.bz/T2VfCvjdJ
https://datadog-securitylabs.imgix.net/img/kubernetes-security-fundamentals/part-6/unmanaged-net-trust-zones.png?auto=format&dpr=1.75&w=896
010
Kubesploit @kubesploit.io · 17/07/2026
This article explains four Kubernetes isolation patterns for AI agents: no exec, sidecar exec, separate exec pod, and ephemeral job dispatchers, with OpenShift-validated threat modeling ➜ ku.bz/KC6H2m-VF
https://miro.medium.com/v2/1*nGr-hefOcPAh_V8FcRiGVg.png
020
Kubesploit @kubesploit.io · 16/07/2026
This tutorial teaches how to extend EKS with hybrid nodes using IAM Roles Anywhere and HashiCorp Vault for secure authentication of on-premises or edge workloads ➤ ku.bz/s3DxFxdHf
https://d2908q01vomqb2.cloudfront.net/fe2ef495a1152561572949784c16bf23abb28057/2025/10/01/CONTAINERS-55-PKI-Arch.png
011
Kubesploit @kubesploit.io · 16/07/2026
This tutorial shows how to modernize Kyverno policies with CEL using practical Kubernetes security examples like namespace rules, image checks, service account tokens, and safer policy testing ➜ ku.bz/PcpzWX_N6
https://miro.medium.com/v2/resize:fit:700/1*_puqOj5JZ5JxOehI-sqc2w.png
010
Kubesploit @kubesploit.io · 15/07/2026
This tutorial teaches how to collect Prometheus metrics from Kubernetes clusters and securely route them to remote Prometheus instances using Vector with mTLS encryption ➤ ku.bz/_QBDYV4t7
https://miro.medium.com/v2/1*4--uIcHxlL1vkMTBjHb51A.png
021
Kubesploit @kubesploit.io · 12/07/2026
This tutorial teaches how to secure LLM inference services on Kubernetes using Authorino and Envoy for authentication and authorization ➤ ku.bz/NWFrLKFbF
https://miro.medium.com/v2/1*L_9ErJ9ikzVwRA0_SjnlvQ.png
000
Kubesploit @kubesploit.io · 11/07/2026
This tutorial teaches how to implement container image signature verification in Kubernetes using Cosign for signing, Kyverno for policy enforcement, and Sigstore Policy Controller for admission control ➤ ku.bz/vT_tmP0lj
https://cdn.hashnode.com/res/hashnode/image/upload/v1762214498308/4a6c7192-5523-444a-892a-be452e1ac534.png
010
Kubesploit @kubesploit.io · 09/07/2026
This tutorial teaches how to enforce signed container images in Kubernetes using Cosign for signing, Harbor for storage, and Kyverno admission controller for verification, including custom CA trust configuration and CI/CD integration patterns ➤ ku.bz/CjQLsVFWf
https://miro.medium.com/v2/1*tbi6uVh5t6pzs-6cKuEdcQ.png
010
Kubesploit @kubesploit.io · 08/07/2026
This article shows a Zero Trust blueprint using mutual TLS (mTLS) and Istio security policies to make internal and external APIs secure by default, with step-by-step configs and lessons from real systems ➤ ku.bz/Ft_3_HxjS
https://miro.medium.com/v2/0*3FqbnAXEkb9z2mjz
010