Kubesploit
2.13K subscribers
953 photos
206 videos
1.9K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about.

More: https://ku.bz/tdxnc5S4r
Forwarded from Kube Builders
Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management.

More: https://ku.bz/3hC23K79L
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production.

More: https://ku.bz/SWl3-LNty
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Moving to Kubernetes doesn't replace your security practices, but it adds a layer on top.

Rodrigo Bersa at AWS breaks down what carries over and what must change.

What stays: least privilege, perimeter security, network access control, authentication and authorization.

What changes:

- Supply chain security — you're managing hundreds of images, not just VMs
- Multi-tenancy by default — workloads share nodes; namespace isolation and network policies keep them separate
- In-cluster auth needs its own model, separate from infrastructure-layer controls





Watch the full interview: https://ku.bz/dB7PDNt0v
This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials.

More: https://ku.bz/mdkryD536
Forwarded from LearnKube news
We just published Kubernetes Architecture in Financial Services, a free technical book about platform design and operations.

Drawing on public engineering talks and case studies from seven banks, it examines:

- Tenant boundaries beyond namespaces.
- Shared delivery controls and application ownership.
- Policy maintenance, exceptions, adoption, and reporting.
- Cross-cluster identity, reliability, external dependencies, and cluster replacement.

Each chapter starts with a real platform problem, compares different boundaries, and examines the operational cost of each option.

Thank you to Buoyant, Sysdig, and Nirmata for supporting the book and its research.

Download it for free:
https://learnkube.com/kubernetes-architecture-financial-services
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down.

More: https://ku.bz/99rk_nQ-T
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mistake."

Tsahi Duek puts security first when it comes to AI agents. Unlike regular workloads, AI agents execute actions on your behalf — sometimes running code. That means locking them into isolated sandbox environments, scoping their access to specific services, and never giving broad permissions to your entire AWS account.



Watch the full interview: https://ku.bz/2r41YKBZb
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down.

More: https://ku.bz/ppRKVtXsb
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 202:

🔥 We Replaced etcd with Google Cloud Spanner
😌 How We Made Deploying a New Service Boring
🐘 Running Zookeeper on GKE with Local SSD (Z4D)
🚀 Kubernetes v1.36: Mixed Version Proxy Graduates to Beta
🌍 Building a Multi-Region EKS Platform with Crossplane, FluxCD, and GitOps

Read it now: https://kube.today/issues/202

⭐️ This newsletter is brought to you by Buoyant — The Buoyant Enterprise for Linkerd service mesh runs in production at Xbox (22,000 pods), Imagine Learning (40% cross-zone cost cut), and IntelliGRC 4× MRR after FedRAMP https://ku.bz/BwZYjDryv
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime.

More: https://ku.bz/YdMc3KBZ6