This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➜ https://ku.bz/cD6Lg9ppD
Kubesploit
@kubesploit.io
News and links on Kubernetes security curated by the @Learnk8s.io team More K8s news, events, jobs → https://kube.today
This week on the Learn Kubernetes Weekly: 🔍 Baselining Audit Logs 🤖 AI Agent for SRE Ops 🛡️ OSS Security Console 🧩 Implementing User Namespaces 🔀 Vlan Migration Without Downtime ⭐️ daily.dev Read it now: https://kube.today/issues/195
This tutorial shows how to connect on-prem Kubernetes workloads to Google Cloud without service account keys using Workload Identity Federation, OIDC, Terraform, Kyverno, and IAM attribute conditions ➤ https://ku.bz/1YVD6c3FP
This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation ➜ https://ku.bz/z9DNn9t1D
Define the criteria before choosing the tool Fabián Sellés Rosa from Adevinta on balancing flexibility, maturity, and operational effort https://ku.bz/R_06hwnCn 🌟 LearnKube 🎙 🎙Bart
This article explains how Falcon Shield extends CrowdStrike security into SaaS applications through posture management, identity governance, OAuth visibility, permission drift detection, and identity threat response ➜ https://ku.bz/XvW_Xp6X0
We’ve just confirmed 3 private Kubernetes training engagements for September alone Want to level up your team’s Kubernetes and platform engineering skills? Teams: https://learnkube.com/corporate-training Individuals: https://learnkube.com/training
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns ➜ https://ku.bz/XNmQ2X-7T
For many edge deployments, the cloud is not the default Przemysław Wojtunik on sovereign requirements and on-premise installation 📺: https://ku.bz/TJRYGMWV2
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping ➜ https://ku.bz/nN1m_5FXK
This article explains how to build a Kubernetes security console that turns CRD-based security findings and runtime events into one MCP-backed triage surface ➜ https://ku.bz/ZHmHZys-n
🗣️ Alessandro Pomponio, Research Software Engineer @ IBM Research, explains how his team used Kyverno policies to solve GPU resource monopolization in their Kubernetes clusters Watch the full episode: https://ku.bz/5sK7BFZ-8
This week on the Learn Kubernetes Weekly: 🤖 So We Built an AI SRE 💸 The GPU Bill Was $40,000 🔓 PSS Restricted Did Not Block AF_ALG 📦 One Registry for 6 AKS Clusters ⚙️ GitOps with tofu-controller ⭐️ Isovalent Read it now: https://kube.today/issues/194
"You don't need to be a rocket scientist to implement security in Kubernetes." Abhishek Rao on making platform security practical 📺: https://ku.bz/_q9XBgY2c
This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access ➜ https://ku.bz/gMzL4pXNq
🗣️ Federico Iezzi from Google Cloud explains how his team reached 1M output tokens/s using Qwen 3.5 27B, vLLM, GKE Autopilot, and B200 GPUs https://ku.bz/1xD9Md0mb 🌟 LearnKube 🎙 🎙Bart
Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs ➜ https://ku.bz/DLKSbPlGK
This article explains how to use Gatekeeper to enforce in-cluster admission policies, such as rejecting `:latest` images, mandating labels, and disallowing privileged workloads ➤ https://ku.bz/1Zskfkkvg
This tutorial shows how to run OWASP ZAP scans inside GitHub Actions using SecureCodeBox on a Kubernetes kind cluster ➤ https://ku.bz/nDZJpmg5F
This tutorial explains how to sign and verify Docker images in Amazon ECR using Cosign and AWS KMS It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security ➜ https://ku.bz/NG8185Rvq
This guide walks through deploying Istio via Terraform and Helm to secure service-to-service and external communication with mTLS, automatic sidecar injection, and encrypted ingress via Istio Gateway ➤ https://ku.bz/wxcXWRYy2
This case study explains how a privileged Kubernetes pod with host access can lead to container escape, control plane disruption, service account theft, and cloud resource takeover ➜ https://ku.bz/LXMBJmlKp
"Many people think the registry is just storage, but it's a lot more than that." Meg Sarros on why registries belong in the CI/CD control plane 📺: https://ku.bz/k_r1B0Rwj
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production ➤ https://ku.bz/_DdDJ5wzj
This article explains why Kubernetes PSS Restricted and RuntimeDefault seccomp did not block AF_ALG access during Copy Fail testing It shows why kernel attack surface still matters even when pods follow strict runtime defaults ➜ https://ku.bz/j-pzF0QZb
This week on the Learn Kubernetes Weekly: 🔍 Which of our Containers are Chainguard? 💸 $1,800 for One Notebook 🔄 Syncing Clusters with GitOps 📉 Spark Cost Optimization 🚪 Migrating to Kgateway ⭐️ LearnKube Read it now: https://kube.today/issues/193
This article explains how Kubernetes zero-trust egress policy can contain the Axios npm supply-chain attack by blocking C2 traffic, data exfiltration, and lateral movement from compromised pods ➜ https://ku.bz/kz47HBml6
This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService ➜ https://ku.bz/lNmNzN4HW
Netfence runs as a daemon, injecting eBPF filter programs into cgroups and network interfaces, with a built-in DNS server that resolves allowed domains and populates IP allowlists, and connecting to a central control plane to synchronize network rules ➤ https://ku.bz/wCc37BMNY
This article covers network security fundamentals in Kubernetes, explaining how clusters default to a flat pod network, how network policies enforce segmentation, and best practices like “default deny” and restricting host networking ➤ https://ku.bz/T2VfCvjdJ