Kubesploit (@kubesploit) 's Twitter Profile
Kubesploit

@kubesploit

News and links on Kubernetes security curated by the @Learnk8s team
Mastodon: @[email protected]

ID: 1372044146475560963

linkhttps://learnk8s.io/news-events-jobs calendar_today17-03-2021 04:37:03

2,2K Tweet

19,19K Followers

1 Following

Learnk8s (@learnk8s) 's Twitter Profile Photo

🤝 What does it take to become part of the Kubernetes community? We're releasing "Kubernetes World: Finding Your Path," a book that explores the journey into cloud native, beyond certifications and code contributions Read it now: ku.bz/k8s-world

🤝 What does it take to become part of the Kubernetes community?

We're releasing "Kubernetes World: Finding Your Path," a book that explores the journey into cloud native, beyond certifications and code contributions

Read it now: ku.bz/k8s-world
KubeFM (@k8sfm) 's Twitter Profile Photo

🗣️ Oleksii Kolodiazhnyi, Senior Architect at Mirantis, shares his structured approach to Kubernetes workload assessment ku.bz/zDThxGQsP 🌟 StormForge 🎙 Bart Farrell

Learnk8s (@learnk8s) 's Twitter Profile Photo

This week on the Learn Kubernetes Weekly: 🔥 AI Infrastructure on K8s 🏠 HA Databases on K8s at Airbnb ⚡ Faster Node & Pod Startup 🎯 Pod Priority and Preemption ⚖️ Cost vs Resilience in Scheduling ⭐️ testkube Read it now: kube.today/issues/156

This week on the Learn Kubernetes Weekly:

🔥 AI Infrastructure on K8s
🏠 HA Databases on K8s at Airbnb
⚡ Faster Node & Pod Startup
🎯 Pod Priority and Preemption
⚖️ Cost vs Resilience in Scheduling

⭐️ <a href="/testkubeio/">testkube</a>

Read it now: kube.today/issues/156
KubeFM (@k8sfm) 's Twitter Profile Photo

🤖 Nirmata brings policy-as-code to Booth 1340 at KubeCon Atlanta! See Kyverno demos + their new AI platform engineering agent Grab swag, enter raffles for Ray-Bans, and don't miss the first in-person KyvernoCon on Nov 10 ku.bz/NcwTKq1jh

Daniele Polencic — @danielepolencic@hachyderm.io (@danielepolencic) 's Twitter Profile Photo

💰 Here's something that surprised me: most Kubernetes cost waste comes from CPU, not memory. I asked Rafa Brito (who specializes in Kubernetes cost optimization) what the data shows across their customer base: cost reductions between 35-60%, averaging around 54%. But here's

Kubesploit (@kubesploit) 's Twitter Profile Photo

This open-source tool lets you analyze connectivity, inspect applied NetworkPolicies, and generate policy YAMLs, all with an interactive fuzzy-finder UI and JSON/table outputs ➜ ku.bz/HJpY-dbmG

Learnk8s (@learnk8s) 's Twitter Profile Photo

This week on the Learn Kubernetes Weekly: ⚙️ gRPC with ALB and Traefik 🧭 Prevent Failures with Topology Spread 📜 Demystifying Kubernetes YAML 🔗 Shared Socket with eBPF 🌐 Kubernetes Networking Guide ⭐️ testkube Read it now: kube.today/issues/157

This week on the Learn Kubernetes Weekly:

⚙️ gRPC with ALB and Traefik
🧭 Prevent Failures with Topology Spread
📜 Demystifying Kubernetes YAML
🔗 Shared Socket with eBPF
🌐 Kubernetes Networking Guide

⭐️ <a href="/testkubeio/">testkube</a>

Read it now: kube.today/issues/157
Kubesploit (@kubesploit) 's Twitter Profile Photo

This case study explains how BioCatch migrated their Vault environment from costly external storage to Raft, enabling high availability, easy disaster recovery, and lower operational costs in Kubernetes ➜ ku.bz/zPwwpmMyV

Daniele Polencic — @danielepolencic@hachyderm.io (@danielepolencic) 's Twitter Profile Photo

🔍 "The direction in network policies is inverted," Ori Shoshan explained on KubeFM. "It's so much easier to say 'I am going to call these services' rather than as a server saying 'here's the list of all services that will call me.'" And I think Ori's right. When you need to

Kubesploit (@kubesploit) 's Twitter Profile Photo

Kviklet provides a secure, self-hosted tool for engineering teams to request, review, and approve production database queries with a workflow inspired by code reviews ➜ ku.bz/blQ6ybFXN

Kviklet provides a secure, self-hosted tool for engineering teams to request, review, and approve production database queries with a workflow inspired by code reviews

➜ ku.bz/blQ6ybFXN
K3sDaily (@k3sdaily) 's Twitter Profile Photo

Project Quay runs as a service inside or outside Kubernetes, storing images in S3 or local storage It scans images for vulnerabilities with Clair, supports image signing, and enforces repository access and security policies via webhooks and RBAC ➤ ku.bz/mXXL2JPl4

Project Quay runs as a service inside or outside Kubernetes, storing images in S3 or local storage

It scans images for vulnerabilities with Clair, supports image signing, and enforces repository access and security policies via webhooks and RBAC

➤ ku.bz/mXXL2JPl4
KubeFM (@k8sfm) 's Twitter Profile Photo

🗣️ Tim Miller CEO and Co-founder at kusaridev challenges the common belief that minimal container images automatically mean better security Watch: ku.bz/-2Sqn9Jb9

Kubesploit (@kubesploit) 's Twitter Profile Photo

This project provides a RESTful API interface over the Bitwarden Rust SDK to enable the External Secrets Operator to fetch vault secrets securely ➤ ku.bz/t-WF03pc3

Kubesploit (@kubesploit) 's Twitter Profile Photo

This article shows how to build enterprise-level secret management in an MLOps setup using tools like Sealed Secrets, Git encryption, and clear team boundaries for secure, scalable credential handling ➤ ku.bz/2Dlnrr0W7

Daniele Polencic — @danielepolencic@hachyderm.io (@danielepolencic) 's Twitter Profile Photo

1,317 Kubernetes practitioners shared how they manage resources: → 56% still do it manually despite wanting automation → 45% regularly hit CPU throttling/OOM kills → 57% estimate 20%+ waste in compute costs Report: kube.today/kubernetes-res…

1,317 Kubernetes practitioners shared how they manage resources:

→ 56% still do it manually despite wanting automation
→ 45% regularly hit CPU throttling/OOM kills
→ 57% estimate 20%+ waste in compute costs

Report: kube.today/kubernetes-res…
Kubesploit (@kubesploit) 's Twitter Profile Photo

Sealed Secrets provides declarative Kubernetes Secret Management in a secure way Since the Sealed Secrets are encrypted, they can be safely stored in a code repository ➜ ku.bz/M_ZTLCWtB