Fearless SSH: short-lived certificates bring Zero Trust to infrastructure
https://blog.cloudflare.com/intro-access-for-infrastructure-ssh
#cloudflare #ssh #security
https://blog.cloudflare.com/intro-access-for-infrastructure-ssh
#cloudflare #ssh #security
Exploring Google Cloud Default Service Accounts: Deep Dive and Real-World Adoption Trends
https://securitylabs.datadoghq.com/articles/google-cloud-default-service-accounts
#gke #google #security #cloud #k8s #kubernetes
https://securitylabs.datadoghq.com/articles/google-cloud-default-service-accounts
#gke #google #security #cloud #k8s #kubernetes
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
https://github.com/docker/docker-bench-security
#docker #security
Please open Telegram to view this post
VIEW IN TELEGRAM
WUD
https://github.com/getwud/wud
https://getwud.github.io/wud/#/introduction/
#docker #semver #security
WUD (aka What's up Docker?) gets you notified when a new version of your Docker Container is available.
https://github.com/getwud/wud
https://getwud.github.io/wud/#/introduction/
#docker #semver #security
DarkFlare
https://github.com/doxx/darkflare
#security #vpn #firewall #cloudflare #proxy
DarkFlare Firewall Piercing (TCP over CDN)
It has two parts: a client-side proxy (darkflare-client) that encodes TCP data into HTTPS requests and sends it to a Cloudflare-protected domain, and a server-side proxy (darkflare-server) that decodes the requests and forwards the data to a local service (like SSH on port 22). Itβs protocol-agnostic, secure, and uses Cloudflare's encrypted infrastructure, making it stealthy and scalable for accessing internal resources or bypassing network restrictions.
https://github.com/doxx/darkflare
#security #vpn #firewall #cloudflare #proxy
Awesome Cloud Security Labs
https://github.com/iknowjason/Awesome-CloudSec-Labs
#security #cloud #aws #azure #gcp #k8s #kubernetes #terraform
Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs. https://github.com/iknowjason/Awesome-CloudSec-Labs
#security #cloud #aws #azure #gcp #k8s #kubernetes #terraform
Seccomp-Diff
https://github.com/antitree/seccomp-diff
#container #docker #security #k8s #kubernetes
Analyze binaries and containers to extract and disassemble seccomp-bpf profiles. This tools is designed to help you determine whether or not a given seccomp-bpf profile is more or less constrained than others as well as give you the ground truth for the filters applied to a process.https://github.com/antitree/seccomp-diff
#container #docker #security #k8s #kubernetes
OSINT Toolkit
https://github.com/dev-lu/osint_toolkit
#security #osint #tool
A full stack web application that combines many tools and services for security analysts into a single tool.
https://github.com/dev-lu/osint_toolkit
#security #osint #tool
Landrum
https://github.com/Zouuup/landrun
#linux #security
Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel.
https://github.com/Zouuup/landrun
#linux #security
Copacetic
https://github.com/project-copacetic/copacetic
#docker #podman #container #buildkit #security
copa is a CLI tool written in Go and based on buildkit that can be used to directly patch container images without full rebuilds. copa can also patch container images using the vulnerability scanning results from popular tools like Trivy.
https://github.com/project-copacetic/copacetic
#docker #podman #container #buildkit #security
Minisign
https://github.com/jedisct1/minisign
#security #crypto #pgp #gpg #cryptography #signatures
A dead simple tool to sign files and verify digital signatures.
https://github.com/jedisct1/minisign
#security #crypto #pgp #gpg #cryptography #signatures
When Metrics Leak Secrets: Kubernetes CTF Lessons
https://programmerprodigy.code.blog/2025/09/01/when-metrics-leak-secrets-kubernetes-ctf-lessons
#k8s #kubernetes #security #grafana #victoriametrics #victorialogs
https://programmerprodigy.code.blog/2025/09/01/when-metrics-leak-secrets-kubernetes-ctf-lessons
#k8s #kubernetes #security #grafana #victoriametrics #victorialogs
ChopChop
https://github.com/michelin/ChopChop
#security #devsecops #tool
ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders
https://github.com/michelin/ChopChop
#security #devsecops #tool
httpjail
https://github.com/coder/httpjail
#network #tool #security #firewall
A cross-platform tool for monitoring and restricting HTTP/HTTPS requests from processes using network isolation and transparent proxy interception
https://github.com/coder/httpjail
#network #tool #security #firewall
Trivy Operator Dashboard
https://github.com/raoulx24/trivy-operator-dashboard
#trivy #security #k8s #kubernetes #operator
https://github.com/raoulx24/trivy-operator-dashboard
#trivy #security #k8s #kubernetes #operator
dalec
https://github.com/Azure/dalec
#linux #devops #containers #packages #security
Produce secure packages and containers with declarative configurations
https://github.com/Azure/dalec
#linux #devops #containers #packages #security