tgindex
Kubesploit

News and links on Kubernetes security curated by the @Learnk8s team Website: https://kubesploit.io/

Последний пост
12 авг.
Последнее чтение
19:25
Постов за неделю
4
Всего постов
20
Тип
открытый
Язык
английский
Категория
Новости и СМИ
В каталоге с
13 авг.
Подписчики
2 115
+8 за 4 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
231
20 постов
Вовлечённость
10,9%
к подписчикам
Постов в день
0,6
всего 20
Упоминаний
2
каналов
Охват размещения
оценка
1/24сутки в ленте
99
1/48двое суток
113
1/72трое суток
122

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • 12 авг.871из LearnKubeNews

    This week on Learn Kubernetes Weekly 196: 🛠️ How I Rebuilt YouTube’s Load Balancing Algorithm in Go 💾 When ETCD Crashes, Check Your Disks First: A Pod CrashLoopBack Debugging Story 🧩 We Blamed CoreDNS for Weeks. The Real Culprit Was a Default We Never Questioned 🚚 Zero-Downtime EKS Migration: Production-Grade Kubernetes at Scale ⚡ Deterministic Routing: The Hidden Key to Low Latency Read it now: https://kube.today/issues/196 ⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V

  • This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements. More: https://ku.bz/YRcVzxByx

  • 11 авг.1122из LearnKubeNews

    New from LearnKube: Setting the right requests and limits in Kubernetes. CPU and memory requests and limits appear together in a Pod manifest, but Kubernetes and Linux use them at different stages. You will learn: • How the scheduler compares requests with node allocatable capacity • Why actual usage can exceed a request • How CPU quotas cause throttling even when average CPU looks low • Why an OOM kill is different from a node-pressure eviction • How requests and limits determine Kubernetes QoS classes The article is the first chapter of The Technical Guide to Kubernetes Rightsizing, co-authored by Gulcan and Daniele Polencic. Read the chapter: https://learnkube.com/setting-cpu-memory-limits-requests Download the free technical guide: https://learnkube.com/kubernetes-rightsizing This book was made possible by CloudBolt Software.

  • 10 авг.1131из KubeFM

    Karpenter can consolidate nodes and reduce cloud costs. But without Pod Disruption Budgets, those savings can expose workloads to avoidable downtime. Ahmad Asmar from Zencity explains how they use Kyverno to generate PDBs automatically instead of relying on every developer to remember the required configuration. You will learn: - Why Karpenter consolidation and Spot instances make PDB coverage critical - How Kyverno detects existing PDBs through workload labels - Why percentage-based budgets work better for scaling workloads - How ClusterRole aggregation extends Kyverno without modifying its Helm chart Watch: https://ku.bz/xrlPJg54D 🌟 This episode is sponsored by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits. https://learnkube.com/kubernetes-rightsizing With @Birthmarkb

  • This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging. More: https://ku.bz/cD6Lg9ppD

  • 5 авг.1801из LearnKubeNews

    This week on Learn Kubernetes Weekly 195: 🔍 Practical Detection Engineering for Kubernetes: Baselining Audit Logs 🤖 Building an AI Agent That Runs Your SRE Operations — What I Learned, What Works, and How You Can Do It Too 🛡️ Building an OSS Kubernetes Security Console 🧩 User Namespaces in Kubernetes: The Implementation 🔀 Vlan Migration: Moving a Live Kubernetes Cluster Without Downtime Read it now: https://kube.today/issues/195 ⭐️ This issue is brought to you by daily.dev — where developers discover what's next https://ku.bz/PrzB1cB0K

  • This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation. More: https://ku.bz/z9DNn9t1D

  • 4 авг.1661из KubeFM

    The newest tool is not automatically the right architectural choice. Before evaluating implementations, Fabián Sellés Rosa defined three criteria: flexibility, production maturity, and operational effort. This made it possible to compare Crossplane, a custom controller, and KRO with ACK on the same terms. You will learn: - Why KIAM became urgent to replace after years of stable operation - How to define evaluation criteria before comparing tools - Why Adevinta selected KRO with ACK for reconciliation - How Kyverno preserves namespace-level IAM boundaries Watch (or listen to) it here: https://ku.bz/R_06hwnCn 🌟 This episode is brought to you by LearnKube. Download The Technical Guide to Kubernetes Rightsizing to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing With @Birthmarkb

  • This article explains how Falcon Shield extends CrowdStrike security into SaaS applications through posture management, identity governance, OAuth visibility, permission drift detection, and identity threat response. More: https://ku.bz/XvW_Xp6X0

  • This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns. More: https://ku.bz/XNmQ2X-7T

  • 31 июл.2722из KubeFM

    For many edge deployments, sovereign requirements mean the cloud is not the default. Przemysław Wojtunik explains that customers want to know who stands behind the technology and where their workloads run, which is why his team continues to focus on on-premise installation. Watch the full interview: https://ku.bz/TJRYGMWV2

  • This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC. It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping. More: https://ku.bz/nN1m_5FXK

  • This article explains how to build a Kubernetes security console that turns CRD-based security findings and runtime events into one MCP-backed triage surface. More: https://ku.bz/ZHmHZys-n

  • 29 июл.2531из KubeFM

    Alessandro Pomponio, Research Software Engineer @ IBM Research, explains how his team used Kyverno policies to solve GPU resource monopolization in their Kubernetes clusters. He describes a common anti-pattern where researchers were creating idle pods with commands like sleep infinity and using SSH to treat them as virtual machines, causing GPU starvation for other users, especially during conference deadlines. Alessandro walks through their policy-based solution using Kyverno to block pod exec commands while maintaining necessary exceptions for cluster administrators. Watch the full episode: https://ku.bz/5sK7BFZ-8

  • 29 июл.1541из LearnKubeNews

    This week on Learn Kubernetes Weekly 194: 🤖 We're a 3-Person Tech Team Running Production Kubernetes — So We Built an AI SRE 💸 The GPU Bill Was $40,000. Nobody Knew Why. 🔓 Copy Fail in Kubernetes: PSS Restricted and RuntimeDefault Did Not Block AF_ALG 📦 How We Set Up One Private Container Registry for 6 AKS Clusters Across 3 Regions and What Broke Along the Way ⚙️ GitOps with Terraform Using tofu-controller: Grafana and Hashicorp Vault as Code Read it now: https://kube.today/issues/194 ⭐️ This issue is brought to you by Isovalent — enterprise-grade Kubernetes networking and security, built by the creators of Cilium and eBPF https://ku.bz/d6xF7GMzh

  • 28 июл.2422из KubeFM

    Security in Kubernetes does not have to be an expert-only discipline. Abhishek Rao shares a simple mental model for platform security: layer access and isolation step by step, just like physical security in a building. The point is not perfect complexity, but practical controls teams can actually adopt. When security feels understandable, adoption becomes realistic. Watch the full interview: https://ku.bz/_q9XBgY2c This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f

  • This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access. More: https://ku.bz/gMzL4pXNq

  • 28 июл.1731из KubeFM

    Federico Iezzi, Customer Engineer at Google Cloud, explains how his team achieved 1 million output tokens per second using Qwen 3.5 27B, vLLM, GKE Autopilot, and NVIDIA B200 GPUs. You will learn: - Why memory bandwidth limits decode performance - How Federico chose between tensor and data parallelism - What changed after enabling multi-token prediction and reducing the KV cache footprint with FP8 quantization Watch (or listen to) it here: https://ku.bz/1xD9Md0mb 🌟 This episode is brought to you by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing With @Birthmarkb

  • Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs. More: https://ku.bz/DLKSbPlGK

  • This tutorial explains how to sign and verify Docker images in Amazon ECR using Cosign and AWS KMS. It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security. More: https://ku.bz/NG8185Rvq

Kubesploit — tgindex