Kubesploit

@kubesploit
15 Followers
1 Following
659 Posts
News and links on Kubernetes security curated by the @learnk8s team
Websitehttps://kubesploit.io
More K8s news, events, jobs →https://learnk8s.io/news-events-jobs

In this article, you'll discuss the security risks associated with the deprecation of Pod Security Policies and potential issues with webhook validation that could lead to a compromised cluster

https://medium.com/@skraga/how-to-mess-with-admission-webhooks-and-have-a-giant-security-hole-b4f3e8c0c9b9

This article will discuss how Kubernetes combines and uses several authorization modes (e.g. RBAC, Node, ABAC, etc.)

https://yuminlee2.medium.com/kubernetes-authorization-part1-authorization-modes-overview-18538759e2d5

In this tutorial, you will learn how to store your sensitive secrets in a self-hosted Vault and share them with a Kubernetes cluster

https://medium.com/@verove.clement/vault-externals-secrets-in-kubernetes-cluster-407f251a5e89

kubectl-np-viewer is a kubectl plugin to visualize network policy rules

https://github.com/runoncloud/kubectl-np-viewer

GitHub - runoncloud/kubectl-np-viewer: A kubectl plugin to visualize network policies rules.

A kubectl plugin to visualize network policies rules. - GitHub - runoncloud/kubectl-np-viewer: A kubectl plugin to visualize network policies rules.

GitHub

This week on the Learn Kubernetes Weekly:

🔌 Understanding how pods talk in Kubernetes networks
☔️ Container network packet drop in AKS
🛩️ Accessing a private GKE cluster
🥷 Secret management
🚔 Open Policy Agent

Read it now: https://learnk8s.io/issues/57

Learn Kubernetes weekly — issue #57 | Learnk8s

Weekly news, events and job opportunities on Kubernetes.

Learnk8s

In this 2-part tutorial, you'll learn how to create policies, how to build and publish them as a bundle served by Nginx and register them with OPA

You'll also look at example policies to restrict the tolerations that pods can use

https://dev.to/gitguardian/open-policy-agent-with-kubernetes-tutorial-pt-1-3lfn

Open Policy Agent with Kubernetes - Tutorial (Pt. 1)

Foreword As Kubernetes has become the de-facto platform to orchestrate containerized...

DEV Community

ChaosMeta is a chaos engineering platform that embodies the methodologies, technologies and products that Ant Group has accumulated over many years in the practice of large-scale red and blue offensive and defensive drills

https://github.com/traas-stack/chaosmeta

GitHub - traas-stack/chaosmeta: A chaos engineering platform for supporting the complete fault drill lifecycle.

A chaos engineering platform for supporting the complete fault drill lifecycle. - GitHub - traas-stack/chaosmeta: A chaos engineering platform for supporting the complete fault drill lifecycle.

GitHub

KubeHound is a Kubernetes attack graph tool that allows automated calculation of attack paths between assets in a cluster

https://github.com/DataDog/KubeHound

GitHub - DataDog/KubeHound: Tool for building Kubernetes attack paths

Tool for building Kubernetes attack paths. Contribute to DataDog/KubeHound development by creating an account on GitHub.

GitHub

Hubble is a fully distributed networking and security observability platform for cloud native workloads

It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure

https://github.com/cilium/hubble

GitHub - cilium/hubble: Hubble - Network, Service & Security Observability for Kubernetes using eBPF

Hubble - Network, Service & Security Observability for Kubernetes using eBPF - GitHub - cilium/hubble: Hubble - Network, Service & Security Observability for Kubernetes using eBPF

GitHub

In this tutorial, you will learn how to write a validating admission controller to check if Deployments have the proper liveness and readiness probes in place

https://medium.com/@ivan.herrmann89/validate-if-kubernetes-deployment-have-livenessprobe-and-readinessprobe-enabled-6424738deeec