Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
The hardest part of Kubernetes security is rarely features. It is adoption.
Abhishek Rao explains why teams struggle to operationalize security and how observability tools, dashboards, and policy tooling can lower the barrier. His focus is on helping engineers gain confidence before enforcing stricter controls.
If people can use the tools comfortably, security practices stick.
Watch the full interview: https://ku.bz/_q9XBgY2c
This interview is a reaction to John Howard's episode https://ku.bz/sk-ZF1PG9
Abhishek Rao explains why teams struggle to operationalize security and how observability tools, dashboards, and policy tooling can lower the barrier. His focus is on helping engineers gain confidence before enforcing stricter controls.
If people can use the tools comfortably, security practices stick.
Watch the full interview: https://ku.bz/_q9XBgY2c
This interview is a reaction to John Howard's episode https://ku.bz/sk-ZF1PG9
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Kube Select is here. It tests one claim: more telemetry does not yield better decisions.
Henrik Rexed of Dynatrace joins hosts Salman Iqbal and Bart Farrell to test it.
You will learn:
- how service ownership gives telemetry incident context
- why proxy metrics can produce extreme data volume
- how AI agents run queries before human review
Watch: https://ku.bz/848pmBN5_
🌟 Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
Henrik Rexed of Dynatrace joins hosts Salman Iqbal and Bart Farrell to test it.
You will learn:
- how service ownership gives telemetry incident context
- why proxy metrics can produce extreme data volume
- how AI agents run queries before human review
Watch: https://ku.bz/848pmBN5_
🌟 Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
This media is not supported in your browser
VIEW IN TELEGRAM
Multikube is a reverse proxy that sits in front of several Kubernetes API servers, terminating TLS and handling authentication and authorization centrally so kubectl talks to one endpoint.
More: https://ku.bz/lMRhZQGJy
More: https://ku.bz/lMRhZQGJy
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 199:
🔥 How Netflix Simplified Batch Compute with Kueue
💡 Server-side Apply: What Happens When You Run kubectl apply
🌐 Kubernetes Is Migrating from SPDY to WebSockets
🔁 How I Learned to Stop Worrying and Love the Reconciliation Loop
🔒 Securing CI/CD for an Open Source Project: Lessons from Cilium
Read it now: https://kube.today/issues/199
⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
🔥 How Netflix Simplified Batch Compute with Kueue
💡 Server-side Apply: What Happens When You Run kubectl apply
🌐 Kubernetes Is Migrating from SPDY to WebSockets
🔁 How I Learned to Stop Worrying and Love the Reconciliation Loop
🔒 Securing CI/CD for an Open Source Project: Lessons from Cilium
Read it now: https://kube.today/issues/199
⭐️ This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
Security culture around CRA and SBOMs is built in day-to-day engineering, not in policy documents alone.
Przemysław Wojtunik explains how Spectro Cloud helps his team move faster on security and SBOM work, while stressing that every organization still needs a practical path to make compliance part of daily life.
Watch the full interview: https://ku.bz/TJRYGMWV2
Przemysław Wojtunik explains how Spectro Cloud helps his team move faster on security and SBOM work, while stressing that every organization still needs a practical path to make compliance part of daily life.
Watch the full interview: https://ku.bz/TJRYGMWV2
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview API, then makes it safer with audience-bound projected tokens.
More: https://ku.bz/rz69JFBdZ
More: https://ku.bz/rz69JFBdZ
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened.
More: https://ku.bz/wd7SCHC3l
More: https://ku.bz/wd7SCHC3l
This case study shows how to implement a HIPAA-compliant CI/CD pipeline using Cosign for artifact signing, OPA Gatekeeper for admission control on EKS, and long-term evidence storage in S3.
More: https://ku.bz/TYS0yf264
More: https://ku.bz/TYS0yf264
NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run.
More: https://ku.bz/CKghZJGt1
More: https://ku.bz/CKghZJGt1
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Kubernetes is ready for databases. Most teams are not.
In KubeSelect episode two, Salman Iqbal and Bart Farrell test this claim with Kat Cosgrove of VillageSQL.
Kat covers:
- Modern Kubernetes storage
- Operators and database expertise
- Team readiness
- Managed database tradeoffs
Kat's verdict: this is now a people problem.
Watch the episode: https://ku.bz/7yDWlP8T5
Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
In KubeSelect episode two, Salman Iqbal and Bart Farrell test this claim with Kat Cosgrove of VillageSQL.
Kat covers:
- Modern Kubernetes storage
- Operators and database expertise
- Team readiness
- Managed database tradeoffs
Kat's verdict: this is now a people problem.
Watch the episode: https://ku.bz/7yDWlP8T5
Kubernetes moves too fast to track everything. Learn Kubernetes Weekly filters out the noise to deliver one curated email with useful articles, tutorials, tools, jobs, events, and CFPs. Subscribe to Learn Kubernetes Weekly.
This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves.
More: https://ku.bz/j_H7dxLV6
More: https://ku.bz/j_H7dxLV6
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
AI does not just make the requested change. It often expands the scope.
Pronomita Dey describes how AI-generated code can turn a simple automation into a much larger diff filled with comments, exceptions, and extra logic. That makes review harder, increases trust too early, and raises the need for guardrails, policy as code, and stronger pre-merge checks.
Watch the full interview: https://ku.bz/lm5jTjdVN
Pronomita Dey describes how AI-generated code can turn a simple automation into a much larger diff filled with comments, exceptions, and extra logic. That makes review harder, increases trust too early, and raises the need for guardrails, policy as code, and stronger pre-merge checks.
Watch the full interview: https://ku.bz/lm5jTjdVN