mlbiam :kubernetes:

236 Followers
234 Following
240 Posts
Dad, CTO of Tremolo Security, co-author Kubernetes and Docker: An Enterprise Guide 2nd Ed. Toots on all things Kubernetes, security, and identity
Kubernetes: An Enterprise Guide 2nd Edhttps://www.amazon.com/Kubernetes-Enterprise-Effectively-containerize-applications/dp/1803230037
LinkedInhttps://www.linkedin.com/in/marc-boorshtein-5979a82/
YouTubehttps://www.youtube.com/channel/UCK__yS63yrSI8vavJzainEQ
Bloghttps://www.tremolosecurity.com/pages/about-marc-boorshtein
When you think "it sure would be great to refactor that code you know you're going to need a part of" and then it turns out you already did!

NEW ACHIEVEMENT: KCD Toronto!

Your reward: Besides getting to meet and talk to lots of great people? A GREAT STICKER!!!!!!

When practicing your session's demo if it involves deleting a pod make sure you delete the pod and not the entire namespace. Don't ask me how I know.
Just added a new app's RESTful API for user management for a customer. Using our new testing harness we went from zero to production in less then a week. Tested everything offline, then quick rollout. Even integrated short lived tokens, so no API keys!
You kube cluster is on-prem, the api is in the cloud. How do you securely connect? I'll show you how at KCD Toronto! We'll step through how to design a Pod identity that can withstand an attack in the AI age. Hope to see you there! https://kcdtoronto.ca/
KCD Toronto 2026 - Kubernetes Community Days

If you need multiple manual approvals to get kubectl access or a change to YAML takes 10-15 minutes to rollout, the problem isn't kubernetes. Your security model is making the wrong assumptions and slowing you down without adding security (and probably less secure then you think)
"Eventual consistency is a lie" - Ancient Cloud Native Sith Saying
Wow, RIP to the Kubernetes Dashboard and much love to the maintainers. Headlamp is great! The next version of OpenUnison will bundle Headlamp directly and is going to be released in the next few weeks! https://groups.google.com/g/kubernetes-sig-ui/c/vpYIRDMysek/m/wd2iedUKDwAJ?utm_medium=email&utm_source=footer&pli=1
Archiving of Kubernetes Dashboard Project

Yes, I am using headlamp on my pixel fold running on EKS with hardware MFA and no, headlamp's ServiceAccount doesn't have any permissions.
Let's learn about Argo CD in a multi-tenant platform!
https://youtube.com/live/ibkZizwJjiw?feature=share
Chapter 19 Part IV: Argo CD

YouTube