kondokentaro

@kondokentaro.bsky.social

PdM at Hexabase, building Kubo — deploy anything on Kubernetes, on cloud or on-prem. K3s · Proxmox · GitOps · homelab. Building in public 🛠️ 🔗 kubo.hexabase.io

No error. No alert. No metrics. A broken ServiceMonitor doesn't fail loudly — it just quietly scrapes nothing. Three usual suspects: the label match across Service/ServiceMonitor/Prometheus CR, a missing namespaceSelector, and RBAC that can't list endpoints. #Kubernetes #Prometheus #SRE

Prometheus Is Running. The Metrics Aren't. Three Reasons Your ServiceMonitor Fails Silently

Your kubernetes service monitor isn't being scraped and there's no error to explain why. The root cause is almost always one of three things: label mismatches, a missing namespaceSelector, or RBAC. He...

kubo.hexabase.io

Your SAST scan found the CVE. Your pipeline went green anyway. Your cluster deployed it. Auto DevOps scans are detection, not enforcement — "CI passed" never meant "safe to deploy." The gate has to live in the cluster: Kyverno or OPA Gatekeeper at admission. #Kubernetes #DevSecOps #CICD

Why GitLab Auto DevOps' 'It Just Works' CI Is the Closest Threat to Your Production K3s Cluster

GitLab Auto DevOps runs SAST/DAST automatically the moment you turn it on. But a scan 'running' and a vulnerable image never reaching your production K3s cluster are two completely different things. H...

kubo.hexabase.io

Your CI/CD pipeline is the fastest route to production. That's exactly why attackers love it. A practical DevSecOps guide: shift-left scanning (SAST/SCA/DAST), SLSA for supply chain integrity, Sigstore image signing, policy-as-code with Kyverno, runtime detection with Falco. #DevSecOps #CICD

ci-cd Pipeline Security: A Practical DevSecOps Guide

A practical guide to ci-cd pipeline security from a DevSecOps perspective. Covers SAST/DAST, supply chain protection, the SLSA framework, and Policy as Code.

kubo.hexabase.io

Base64 is an encoding, not encryption. Yet by default, Kubernetes stores your Secrets in etcd exactly that way — anyone with etcd access can read every credential in the cluster. Three tiers of fixes: etcd encryption → External Secrets Operator → CSI Secrets Store Driver. #Kubernetes #Security

Base64 Isn't Encryption: Why Kubernetes Secrets Pass Right Through, and the RBAC Design Traps That Make It Worse

Kubernetes Secrets are only Base64-encoded, not encrypted. Learn how plaintext-equivalent storage in etcd and over-permissioned RBAC lead to real incidents, plus the concrete Secrets management practi...

kubo.hexabase.io

By default, Kubernetes lets every pod talk to every other pod — one compromised container means network access to your entire cluster. Our new guide walks through zero trust with Network Policies: Default Deny, DNS pitfalls, Cilium vs Calico, real YAML. kubo.hexabase.io/blog/en/kube...

Zero Trust Security with Kubernetes Network Policies: A Practical Guide

Implement zero trust networking in Kubernetes with Network Policies. From Default Deny to Cilium and Calico advanced policies with real YAML examples.

kubo.hexabase.io