Rory McCune

1,033 Followers
341 Following
784 Posts
Containers, Security, Kubernetes, Hillwalking
Personal Sitehttps://www.mccune.org.uk/
Bloghttps://raesene.github.io/
Container Security Sitehttps://www.container-security.site
GitHubhttps://github.com/raesene/
Saphy is ready for her Christmas lunch

So, some time ago I was playing with the idea of adding tracking to container images (https://raesene.github.io/blog/2023/02/11/Fun-with-Containers-adding-tracking-to-your-images/) .

the idea is that you add a URL to the config section of an OCI image and then whenever the image gets pulled, the URL gets called.

I can't remember exactly where I uploaded the image with the canary token in it, but someone's been pulling that image regularly for a while now and I get a ping whenever they do :)

Another stellar bit of accuracy from AI overviews...
At #Steelcon today and the swag is impressive for their 10th anniversary run

Definitely a day to patch your git installs. There's a PoC for a new git CVE.

I wanted to test it but we all know you don't run PoC code on machines you care about... literally 1 min later on a fresh https://labs.iximiuz.com/ playground test confirms it works!

#kubecon supplies have arrived !
An interesting fact from the first talk at #insomnihack

I'm just refreshing a #kubernetes security talk today, so checking on numbers of exposed clusters. Interesting and not great that the number of cluster operators exposing their API server to the Internet is still going up.

Last time I checked it was 1.4M, now (based on this query) , it's almost 2M!

A #kubernetes distribution issuing a system:masters cert with a 15 year expiry is definitely.... an interesting choice.

At least they do offer the possibility of revoking by rotating the CA key and requiring all new certs.

Our Home battery is getting a bit of a workout today, as we've got a planned power outage from 9am-5pm. With all our network tech and a couple of lights on, the house is running at between 300W-450W and as the battery is 13.5kW we should be fine :)