Kubesploit
2.13K subscribers
963 photos
210 videos
1.92K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
Wardline is a self-hosted control-plane proxy for AI agents that enforces identity, policy, and budgets while using anomaly detection to block compromised agents and record auditable decisions.

More: https://ku.bz/WZY4gnMtW
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Supply chain security is easier to reason about when it has layers.

Meg Sarros frames container trust as scanning, signing, and enforcement. She shows how teams can surface CVEs, prove image provenance, and enforce policy before workloads run.

The useful mental model is defense in depth, not a single security checkbox.



Watch the full interview: https://ku.bz/k_r1B0Rwj
Falco Event Generator creates suspicious system and Kubernetes activity so teams can safely test and benchmark Falco detection rules.

More: https://ku.bz/y-WmBKLPS
This case study shows how an AKS-based GitOps platform gave on-premises clusters workload identity by publishing static OIDC discovery and JWKS files, avoiding API server changes after provisioning.

More: https://ku.bz/TpvjylBlF
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Software supply chain security should not be treated as optional extra work.

Przemysław Wojtunik explains how his team moves from build to JFrog, validation with Xray, signing, verification, and only then delivery to the customer, and why he sees that workflow as mandatory.

Watch the full interview: https://ku.bz/TJRYGMWV2
Forwarded from LearnKube news
Why can a Go service be OOM-killed while its heap looks healthy?

The heap is only part of the container's memory usage. Goroutine stacks, native allocations, and runtime overhead also count toward the container limit.

In this new article from Gulcan, you will learn:

- How CPU quotas affect Go's parallelism and why extra threads can increase throttling.
- How to measure total container memory, including goroutine stacks and native allocations.
- Why a tighter memory budget can increase garbage collection work and reduce throughput.

Read: https://learnkube.com/go-kubernetes-requests-limits

This article is also included in our book on Kubernetes rightsizing: https://learnkube.com/kubernetes-rightsizing
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Dilshan Wijesooriya, Senior Cloud Engineer at Coolblue, explains how upgrading from Amazon Linux 2 to AL2023 broke their cluster autoscaler due to stricter IMDS (Instance Metadata Service) access controls.

The autoscaler had been silently relying on the EC2 instance role instead of having its own pod-level IAM role—a hidden dependency that only surfaced when the AMI changed and blocked access to instance credentials.

Watch the full episode: https://ku.bz/T_YPfTfDb
This tutorial teaches how to preserve the real client IP behind an Istio ambient gateway with externalTrafficPolicy: Local and safely read X-Forwarded-For in Go.

More: https://ku.bz/JDVmgRYDY
Forwarded from Kube Architect
WaaS creates browser-accessible Linux and Windows desktops as Kubernetes resources, with GitOps workflows, secure remote access, quotas, and OIDC and RBAC controls.

More: https://ku.bz/TgntmDfyC
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 204:

🧠 Workload-Aware Scheduling in Kubernetes 1.37
⚙️ Automaxprocs Now Costs Your Go Binary a CPU
🔀 Your gRPC Service Only Talks to One Pod. Here’s Why.
🔐 Your Kubernetes OIDC Issuer Is Just Two Static Files
🧩 Why We Open-Sourced ZSvirt

Read it now: https://kube.today/issues/204

⭐️ This newsletter is brought to you by NeuBird — move beyond dashboards and runbooks with an AI agent that detects production issues, finds their root cause, and helps your team resolve them https://ku.bz/nh5ZFW_b9
This tutorial teaches how to secure Kubernetes AI platforms with RBAC, NetworkPolicy, secrets, resource limits, Kyverno, OPA Gatekeeper, and automatic policy checks.

More: https://ku.bz/1DWwJ78lF