Kubesploit
1.98K subscribers
846 photos
140 videos
1.66K links
News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Download Telegram
In this article, you'll implement a robust approach to Kubernetes secret management with Go, AWS ParameterStore, OIDC, and Terraform.

More: https://medium.com/cloud-native-daily/eks-secret-management-with-golang-aws-parameterstore-and-terraform-b4c8c7ee1f9
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:

๐Ÿ“– The Kubernetes documentation is so wrong about namespaces
๐Ÿšฆ Topology aware hints on network traffic in EKS
๐Ÿ”Œ Istio's WASM plugins
๐Ÿงช Unit testing alerting
๐ŸŽ๏ธ Tuning server request latency

Read it now: https://learnk8s.io/issues/51
Multi Tool Kubernetes Pentest Image contains all the most popular and necessary tools for Kubernetes penetration testing.

More: https://github.com/r0binak/MTKPI
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with 1Password
๐Ÿ’ฐ $180K to $244K a year
๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States, Canada
โ†’ https://kube.careers/t/b733b996-956e-4086-b0fa-514316485975?s=55

DevSecOps Engineer with Robinhood
๐Ÿ’ฐ $169K to $255K a year
๐Ÿ  From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
โ†’ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55

DevSecOps Engineer with Verkada
๐Ÿ’ฐ $120K to $285K a year
๐Ÿ  From the office in San Mateo, CA, USA
โ†’ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55

DevSecOps Engineer with Visa
๐Ÿ’ฐ $167.7K to $218K a year
๐Ÿ ๐Ÿƒ๐Ÿปโ€โ™‚๏ธ๐ŸŒŽ Foster City, CA, USA
โ†’ https://kube.careers/t/e909c1a6-db53-4b66-927f-150f134a727a?s=55

๐Ÿ‘‰ Browse all 457 Kubernetes jobs on Kube Careers https://kube.careers
In this article, you will learn how to encrypt and store Kubernetes secrets in etcd using an external encryption provider.

More: https://techexpertise.medium.com/encrypting-the-secret-data-at-etcd-store-on-a-minikube-k8s-cluster-2338c68263a5
Forwarded from KubeFM
"The key to managing Kubernetes clusters at scale is tooling."

Learn how Pierre and the team at Qovery manage hundreds of cluster upgrades for every Kubernetes release and Helm chart in this KubeFM episode.

Watch it here: https://kube.fm/upgrading-100s-clusters-pierre

Listen on:

- Apple Podcast https://kube.fm/apple
- Spotify https://kube.fm/spotify
- Amazon Music https://kube.fm/amazon
- Overcast https://kube.fm/overcast
- Pocket casts https://kube.fm/pocket-casts
Forwarded from LearnKube news
Master Kubernetes with Learnk8s' Advanced Kubernetes workshops!

What should you expect?

- Learn how to architect and design clusters from the ground up (in the cloud or on-prem).
- Explore the Kubernetes internal component and how the system is designed with resiliency in mind.
- Deep-dive into the networking components and observe the packets flowing into the cluster.
- Hands-on labs to test the theory with real-world scenarios!
- And more.

The next (virtual) course starts next week: https://learnk8s.io/online-advanced-november-2023

We also run in-person courses and corporate training: https://learnk8s.io/corporate-training
kube-exec-controller is an admission controller for handling container drift (caused by kubectl exec, attach, cp, or other interactive requests) inside a Kubernetes cluster.

The project also includes a kubectl plugin for checking pods.

More: https://github.com/box/kube-exec-controller
You can secure internal communications in your cluster with HTTPS by generating a new TLS certificate, modifying the backend app, and making changes to the deployment and ingress.

This tutorial explains the steps (and the code) involved.

More: https://heka-ai.medium.com/how-to-secure-internal-communications-with-your-backend-via-https-using-self-signed-certificates-bf74748a18f7
RBAC Manager is an operator that supports declarative configuration for RBAC with new custom resources.

Instead of managing role bindings or service accounts directly, you can specify the desired state, and RBAC Manager will make the necessary changes.

More: https://github.com/FairwindsOps/rbac-manager
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:

๐Ÿ’ฃ๐Ÿ’ฅ Kubernetes failure stories
๐ŸŒ Slow S3 uploads from AWS EKS
๐ŸŽค KEDA: autoscale event driven
๐ŸŽ๏ธ Pod startup time improvements
โš–๏ธ loadbalance service using Cilium BGP

Read it now: https://learnk8s.io/issues/52
In this article, you'll learn how to use Cluster Role, Cluster Role Binding, and Service Account to deploy a simple application capable of accessing the cluster's resources using kubectl from within a pod.

More: https://itnext.io/unleashing-the-power-of-kubernetes-deploying-containers-with-cluster-resource-access-ee2cef29e24e
Forwarded from LearnKube news
What type of worker nodes should you use for your Kubernetes cluster?

And how many of them?

This article looks at the pros and cons.

More: https://learnk8s.io/kubernetes-node-size
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Hyperscience
๐Ÿ’ฐ $190K to $260K a year
๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States
โ†’ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

DevSecOps Engineer with 1Password
๐Ÿ’ฐ $180K to $244K a year
๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States, Canada
โ†’ https://kube.careers/t/b733b996-956e-4086-b0fa-514316485975?s=55

DevSecOps Engineer with Robinhood
๐Ÿ’ฐ $169K to $255K a year
๐Ÿ  From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
โ†’ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55

DevSecOps Engineer with Verkada
๐Ÿ’ฐ $120K to $285K a year
๐Ÿ  From the office in San Mateo, CA, USA
โ†’ https://kube.careers/t/48e3f6f7-5043-43b1-8c58-6bc81939bc19?s=55

๐Ÿ‘‰ Browse all 473 Kubernetes jobs on Kube Careers https://kube.careers
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure that applications adhere to best practices.

More: https://github.com/stackrox/kube-linter
In this tutorial, you will learn how to write a validating admission controller to check if Deployments have the proper liveness and readiness probes in place.

More: https://medium.com/@ivan.herrmann89/validate-if-kubernetes-deployment-have-livenessprobe-and-readinessprobe-enabled-6424738deeec
In this tutorial, you will learn how to store your sensitive secrets in a self-hosted Vault and share them with a Kubernetes cluster.

More: https://medium.com/@verove.clement/vault-externals-secrets-in-kubernetes-cluster-407f251a5e89
In this article, you'll discuss the security risks associated with the deprecation of Pod Security Policies and potential issues with webhook validation that could lead to a compromised cluster.

More: https://medium.com/@skraga/how-to-mess-with-admission-webhooks-and-have-a-giant-security-hole-b4f3e8c0c9b9
Forwarded from LearnKube news
This week on the Learn Kubernetes Weekly:

โš’๏ธ Choosing a worker node size
โœ… Bolstering security & automating management of EKS
๐Ÿ“Š Scaling Rails apps with the HPA
๐Ÿฅท Bypassing admission webhooks
๐Ÿ“ Containers with cluster resource access

Read it now: https://learnk8s.io/issues/53
This tutorial teaches you how to install and configure CrowdSec in a Kubernetes cluster and how to detect attacks on Kubernetes applications.

More: https://itnext.io/securing-kubernetes-applications-with-crowdsec-intrusion-detection-system-8eb2f93d3c9f
Forwarded from Kube Careers
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Hyperscience
๐Ÿ’ฐ $190K to $260K a year
๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States
โ†’ https://kube.careers/t/ab01bf82-75af-4610-ba58-d58cd09f529a?s=55

DevSecOps Engineer with 1Password
๐Ÿ’ฐ $180K to $244K a year
๐Ÿ‘จโ€๐Ÿ’ป Remote from the United States, Canada
โ†’ https://kube.careers/t/b733b996-956e-4086-b0fa-514316485975?s=55

DevSecOps Engineer with Robinhood
๐Ÿ’ฐ $169K to $255K a year
๐Ÿ  From the office in Menlo Park, CA / New York, NY / Seattle, WA / Washington, DC, USA
โ†’ https://kube.careers/t/bcecc046-9f28-4766-aaad-e8cb41ae9aa3?s=55

DevSecOps Engineer with Palo Alto Networks
๐Ÿ’ฐ $180.2K to $236.5K a year
๐Ÿ ๐Ÿƒ๐Ÿปโ€โ™‚๏ธ๐ŸŒŽ Santa Clara, CA, USA
โ†’ https://kube.careers/t/c50a52bc-e5ec-43f7-9f4c-bc0103fb9632?s=55

๐Ÿ‘‰ Browse all 449 Kubernetes jobs on Kube Careers https://kube.careers