Kubesploit
2.13K subscribers
963 photos
210 videos
1.92K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
Forwarded from Kube Architect
This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool definitions and auth as four separate layers, plus the RBAC and deployment work needed before it touches a real cluster.

More: https://ku.bz/6c5t89LYj
This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server.

More: https://ku.bz/jgr5PbzgS
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 203:

🔥 Building Modelplane on Crossplane
🚪 Kubernetes Gateway API: Why Ingress Is Being Replaced and Which Gateway Controller to Pick
🛡️ From Fragile VMs to Bulletproof GitOps: Modernizing a DevOps Platform on AWS EKS
💾 How a 500 MB Buffer Killed Our Archival Job, and Why Streaming Fixed It
🎮 How GPU MIG + Kueue Can Transform Multi-Tenant AI Workloads on Kubernetes

Read it now: https://kube.today/issues/203

⭐️ This newsletter is brought to you by LearnKube — understand how Kubernetes works, and what to do when it breaks. Live training with 60% hands-on labs.https://ku.bz/hypSbyc-V
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
"The next 10 years are going to be boring — in the good sense."

Mauro Morales sees Kubernetes entering its maturity phase: more security focus, more compliance, more standardization. The excitement shifts to AI tooling that helps operators manage growing complexity — like projects using Kubernetes to deploy Kubernetes.

Boring infrastructure is reliable infrastructure.



Watch the full interview: https://ku.bz/8cpgjFfjn
FQDN Network Policy turns hostnames into current IP addresses and creates standard Kubernetes NetworkPolicy rules, so teams can control outbound traffic on any CNI without replacing their network plugin.

More: https://ku.bz/NprbZjd3s
Wardline is a self-hosted control-plane proxy for AI agents that enforces identity, policy, and budgets while using anomaly detection to block compromised agents and record auditable decisions.

More: https://ku.bz/WZY4gnMtW
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Supply chain security is easier to reason about when it has layers.

Meg Sarros frames container trust as scanning, signing, and enforcement. She shows how teams can surface CVEs, prove image provenance, and enforce policy before workloads run.

The useful mental model is defense in depth, not a single security checkbox.



Watch the full interview: https://ku.bz/k_r1B0Rwj
Falco Event Generator creates suspicious system and Kubernetes activity so teams can safely test and benchmark Falco detection rules.

More: https://ku.bz/y-WmBKLPS
This case study shows how an AKS-based GitOps platform gave on-premises clusters workload identity by publishing static OIDC discovery and JWKS files, avoiding API server changes after provisioning.

More: https://ku.bz/TpvjylBlF
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Software supply chain security should not be treated as optional extra work.

Przemysław Wojtunik explains how his team moves from build to JFrog, validation with Xray, signing, verification, and only then delivery to the customer, and why he sees that workflow as mandatory.

Watch the full interview: https://ku.bz/TJRYGMWV2
Forwarded from LearnKube news
Why can a Go service be OOM-killed while its heap looks healthy?

The heap is only part of the container's memory usage. Goroutine stacks, native allocations, and runtime overhead also count toward the container limit.

In this new article from Gulcan, you will learn:

- How CPU quotas affect Go's parallelism and why extra threads can increase throttling.
- How to measure total container memory, including goroutine stacks and native allocations.
- Why a tighter memory budget can increase garbage collection work and reduce throughput.

Read: https://learnkube.com/go-kubernetes-requests-limits

This article is also included in our book on Kubernetes rightsizing: https://learnkube.com/kubernetes-rightsizing
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Dilshan Wijesooriya, Senior Cloud Engineer at Coolblue, explains how upgrading from Amazon Linux 2 to AL2023 broke their cluster autoscaler due to stricter IMDS (Instance Metadata Service) access controls.

The autoscaler had been silently relying on the EC2 instance role instead of having its own pod-level IAM role—a hidden dependency that only surfaced when the AMI changed and blocked access to instance credentials.

Watch the full episode: https://ku.bz/T_YPfTfDb
This tutorial teaches how to preserve the real client IP behind an Istio ambient gateway with externalTrafficPolicy: Local and safely read X-Forwarded-For in Go.

More: https://ku.bz/JDVmgRYDY