Kubesploit
2.13K subscribers
951 photos
206 videos
1.9K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Guardrails are not one-size-fits-all. David Parry argues that AI systems touching Kubernetes need deterministic rules that match the company, the deployment model, and the compliance requirements around sensitive data.

He points to code review and YAML inspection as places where these guardrails should be explicit and enforceable, not left to improvisation.



Watch the full interview: https://ku.bz/c5J05syX3

This interview is a reaction to Mai Nishitani's episode https://ku.bz/3hWvQjXxp.
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help.

More: https://ku.bz/tYzhJx61Q
Forwarded from LearnKube news
Kubernetes problems often hide in controller timing, implicit defaults, and capacity assumptions.

This week in Learn Kubernetes Weekly:

🔎 A production race condition left orphaned pods blocking new deployments.
📦 Source Hydrated Infrastructure Models commit rendered manifests for explicit GitOps audits.
🖥 Headlamp replaces the archived Kubernetes Dashboard and maps familiar workflows to a maintained UI.
⚙️ Kubernetes 1.36 adds pod-level CPU and memory management.
📊 The k8s-overcommit operator reclaims idle capacity according to priority classes.

Read issue 201: https://kube.today/issues/201

This issue is brought to you by LearnKube — understand how Kubernetes works, and what to do when it breaks. Live training with 60% hands-on labs: https://ku.bz/hypSbyc-V
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about.

More: https://ku.bz/tdxnc5S4r
Forwarded from Kube Builders
Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management.

More: https://ku.bz/3hC23K79L
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production.

More: https://ku.bz/SWl3-LNty
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Moving to Kubernetes doesn't replace your security practices, but it adds a layer on top.

Rodrigo Bersa at AWS breaks down what carries over and what must change.

What stays: least privilege, perimeter security, network access control, authentication and authorization.

What changes:

- Supply chain security — you're managing hundreds of images, not just VMs
- Multi-tenancy by default — workloads share nodes; namespace isolation and network policies keep them separate
- In-cluster auth needs its own model, separate from infrastructure-layer controls





Watch the full interview: https://ku.bz/dB7PDNt0v
This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials.

More: https://ku.bz/mdkryD536
Forwarded from LearnKube news
We just published Kubernetes Architecture in Financial Services, a free technical book about platform design and operations.

Drawing on public engineering talks and case studies from seven banks, it examines:

- Tenant boundaries beyond namespaces.
- Shared delivery controls and application ownership.
- Policy maintenance, exceptions, adoption, and reporting.
- Cross-cluster identity, reliability, external dependencies, and cluster replacement.

Each chapter starts with a real platform problem, compares different boundaries, and examines the operational cost of each option.

Thank you to Buoyant, Sysdig, and Nirmata for supporting the book and its research.

Download it for free:
https://learnkube.com/kubernetes-architecture-financial-services
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down.

More: https://ku.bz/99rk_nQ-T
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mistake."

Tsahi Duek puts security first when it comes to AI agents. Unlike regular workloads, AI agents execute actions on your behalf — sometimes running code. That means locking them into isolated sandbox environments, scoping their access to specific services, and never giving broad permissions to your entire AWS account.



Watch the full interview: https://ku.bz/2r41YKBZb
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down.

More: https://ku.bz/ppRKVtXsb