This article explains how Kubernetes zero-trust egress policy can contain the Axios npm supply-chain attack by blocking C2 traffic, data exfiltration, and lateral movement from compromised pods.
More: https://ku.bz/kz47HBml6
More: https://ku.bz/kz47HBml6
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 193:
๐ Which of our Containers are Chainguard?
๐ธ One Forgotten Notebook on an A100. $1,800 a Month.
๐ How an Admin Cluster Keeps Application Clusters in Sync with GitOps
๐ Cost Optimization of Spark on Kubernetes Batch Workloads on Public Clouds
๐ช ingress-nginx Is Archived: How We Migrated to kgateway (and Didn't Break Prod)
Read it now: https://kube.today/issues/193
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
๐ Which of our Containers are Chainguard?
๐ธ One Forgotten Notebook on an A100. $1,800 a Month.
๐ How an Admin Cluster Keeps Application Clusters in Sync with GitOps
๐ Cost Optimization of Spark on Kubernetes Batch Workloads on Public Clouds
๐ช ingress-nginx Is Archived: How We Migrated to kgateway (and Didn't Break Prod)
Read it now: https://kube.today/issues/193
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
This article explains why Kubernetes PSS Restricted and RuntimeDefault seccomp did not block AF_ALG access during Copy Fail testing.
It shows why kernel attack surface still matters even when pods follow strict runtime defaults.
More: https://ku.bz/j-pzF0QZb
It shows why kernel attack surface still matters even when pods follow strict runtime defaults.
More: https://ku.bz/j-pzF0QZb
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Container registries are often treated like storage, but they sit in the middle of delivery.
Meg Sarros explains why the registry is part of the CI/CD control plane: teams build an image, push it to a central place, and rely on that same place to manage access, encryption, and auditing.
The key point is that registry choices shape both deployment flow and governance.
Watch the full interview: https://ku.bz/k_r1B0Rwj
Meg Sarros explains why the registry is part of the CI/CD control plane: teams build an image, push it to a central place, and rely on that same place to manage access, encryption, and auditing.
The key point is that registry choices shape both deployment flow and governance.
Watch the full interview: https://ku.bz/k_r1B0Rwj
This case study explains how a privileged Kubernetes pod with host access can lead to container escape, control plane disruption, service account theft, and cloud resource takeover.
More: https://ku.bz/LXMBJmlKp
More: https://ku.bz/LXMBJmlKp
This tutorial explains how to sign and verify Docker images in Amazon ECR using Cosign and AWS KMS.
It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security.
More: https://ku.bz/NG8185Rvq
It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security.
More: https://ku.bz/NG8185Rvq
Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs.
More: https://ku.bz/DLKSbPlGK
More: https://ku.bz/DLKSbPlGK
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Federico Iezzi, Customer Engineer at Google Cloud, explains how his team achieved 1 million output tokens per second using Qwen 3.5 27B, vLLM, GKE Autopilot, and NVIDIA B200 GPUs.
You will learn:
- Why memory bandwidth limits decode performance
- How Federico chose between tensor and data parallelism
- What changed after enabling multi-token prediction and reducing the KV cache footprint with FP8 quantization
Watch (or listen to) it here: https://ku.bz/1xD9Md0mb
๐ This episode is brought to you by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
You will learn:
- Why memory bandwidth limits decode performance
- How Federico chose between tensor and data parallelism
- What changed after enabling multi-token prediction and reducing the KV cache footprint with FP8 quantization
Watch (or listen to) it here: https://ku.bz/1xD9Md0mb
๐ This episode is brought to you by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access.
More: https://ku.bz/gMzL4pXNq
More: https://ku.bz/gMzL4pXNq
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Security in Kubernetes does not have to be an expert-only discipline.
Abhishek Rao shares a simple mental model for platform security: layer access and isolation step by step, just like physical security in a building. The point is not perfect complexity, but practical controls teams can actually adopt.
When security feels understandable, adoption becomes realistic.
Watch the full interview: https://ku.bz/_q9XBgY2c
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
Abhishek Rao shares a simple mental model for platform security: layer access and isolation step by step, just like physical security in a building. The point is not perfect complexity, but practical controls teams can actually adopt.
When security feels understandable, adoption becomes realistic.
Watch the full interview: https://ku.bz/_q9XBgY2c
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 194:
๐ค We're a 3-Person Tech Team Running Production Kubernetes โ So We Built an AI SRE
๐ธ The GPU Bill Was $40,000. Nobody Knew Why.
๐ Copy Fail in Kubernetes: PSS Restricted and RuntimeDefault Did Not Block AF_ALG
๐ฆ How We Set Up One Private Container Registry for 6 AKS Clusters Across 3 Regions and What Broke Along the Way
โ๏ธ GitOps with Terraform Using tofu-controller: Grafana and Hashicorp Vault as Code
Read it now: https://kube.today/issues/194
โญ๏ธ This issue is brought to you by Isovalent โ enterprise-grade Kubernetes networking and security, built by the creators of Cilium and eBPF https://ku.bz/d6xF7GMzh
๐ค We're a 3-Person Tech Team Running Production Kubernetes โ So We Built an AI SRE
๐ธ The GPU Bill Was $40,000. Nobody Knew Why.
๐ Copy Fail in Kubernetes: PSS Restricted and RuntimeDefault Did Not Block AF_ALG
๐ฆ How We Set Up One Private Container Registry for 6 AKS Clusters Across 3 Regions and What Broke Along the Way
โ๏ธ GitOps with Terraform Using tofu-controller: Grafana and Hashicorp Vault as Code
Read it now: https://kube.today/issues/194
โญ๏ธ This issue is brought to you by Isovalent โ enterprise-grade Kubernetes networking and security, built by the creators of Cilium and eBPF https://ku.bz/d6xF7GMzh
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Alessandro Pomponio, Research Software Engineer @ IBM Research, explains how his team used Kyverno policies to solve GPU resource monopolization in their Kubernetes clusters. He describes a common anti-pattern where researchers were creating idle pods with commands like sleep infinity and using SSH to treat them as virtual machines, causing GPU starvation for other users, especially during conference deadlines.
Alessandro walks through their policy-based solution using Kyverno to block pod exec commands while maintaining necessary exceptions for cluster administrators.
Watch the full episode: https://ku.bz/5sK7BFZ-8
Alessandro walks through their policy-based solution using Kyverno to block pod exec commands while maintaining necessary exceptions for cluster administrators.
Watch the full episode: https://ku.bz/5sK7BFZ-8
This article explains how to build a Kubernetes security console that turns CRD-based security findings and runtime events into one MCP-backed triage surface.
More: https://ku.bz/ZHmHZys-n
More: https://ku.bz/ZHmHZys-n
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC.
It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping.
More: https://ku.bz/nN1m_5FXK
It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping.
More: https://ku.bz/nN1m_5FXK
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
For many edge deployments, sovereign requirements mean the cloud is not the default.
Przemysลaw Wojtunik explains that customers want to know who stands behind the technology and where their workloads run, which is why his team continues to focus on on-premise installation.
Watch the full interview: https://ku.bz/TJRYGMWV2
Przemysลaw Wojtunik explains that customers want to know who stands behind the technology and where their workloads run, which is why his team continues to focus on on-premise installation.
Watch the full interview: https://ku.bz/TJRYGMWV2
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns.
More: https://ku.bz/XNmQ2X-7T
More: https://ku.bz/XNmQ2X-7T
This article explains how Falcon Shield extends CrowdStrike security into SaaS applications through posture management, identity governance, OAuth visibility, permission drift detection, and identity threat response.
More: https://ku.bz/XvW_Xp6X0
More: https://ku.bz/XvW_Xp6X0
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
The newest tool is not automatically the right architectural choice.
Before evaluating implementations, Fabiรกn Sellรฉs Rosa defined three criteria: flexibility, production maturity, and operational effort. This made it possible to compare Crossplane, a custom controller, and KRO with ACK on the same terms.
You will learn:
- Why KIAM became urgent to replace after years of stable operation
- How to define evaluation criteria before comparing tools
- Why Adevinta selected KRO with ACK for reconciliation
- How Kyverno preserves namespace-level IAM boundaries
Watch (or listen to) it here: https://ku.bz/R_06hwnCn
๐ This episode is brought to you by LearnKube. Download The Technical Guide to Kubernetes Rightsizing to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
Before evaluating implementations, Fabiรกn Sellรฉs Rosa defined three criteria: flexibility, production maturity, and operational effort. This made it possible to compare Crossplane, a custom controller, and KRO with ACK on the same terms.
You will learn:
- Why KIAM became urgent to replace after years of stable operation
- How to define evaluation criteria before comparing tools
- Why Adevinta selected KRO with ACK for reconciliation
- How Kyverno preserves namespace-level IAM boundaries
Watch (or listen to) it here: https://ku.bz/R_06hwnCn
๐ This episode is brought to you by LearnKube. Download The Technical Guide to Kubernetes Rightsizing to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation.
More: https://ku.bz/z9DNn9t1D
More: https://ku.bz/z9DNn9t1D
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 195:
๐ Practical Detection Engineering for Kubernetes: Baselining Audit Logs
๐ค Building an AI Agent That Runs Your SRE Operations โ What I Learned, What Works, and How You Can Do It Too
๐ก๏ธ Building an OSS Kubernetes Security Console
๐งฉ User Namespaces in Kubernetes: The Implementation
๐ Vlan Migration: Moving a Live Kubernetes Cluster Without Downtime
Read it now: https://kube.today/issues/195
โญ๏ธ This issue is brought to you by daily.dev โ where developers discover what's next https://ku.bz/PrzB1cB0K
๐ Practical Detection Engineering for Kubernetes: Baselining Audit Logs
๐ค Building an AI Agent That Runs Your SRE Operations โ What I Learned, What Works, and How You Can Do It Too
๐ก๏ธ Building an OSS Kubernetes Security Console
๐งฉ User Namespaces in Kubernetes: The Implementation
๐ Vlan Migration: Moving a Live Kubernetes Cluster Without Downtime
Read it now: https://kube.today/issues/195
โญ๏ธ This issue is brought to you by daily.dev โ where developers discover what's next https://ku.bz/PrzB1cB0K