Kubesploit

@kubesploit.io

News and links on Kubernetes security curated by the @Learnk8s.io team More K8s news, events, jobs → https://kube.today

This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➜ https://ku.bz/cD6Lg9ppD

https://miro.medium.com/v2/resize:fit:700/1*zGlJNdPRmZDm0be4wp9JQA.png

This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns ➜ https://ku.bz/XNmQ2X-7T

https://miro.medium.com/v2/resize:fit:700/1*9ggxl7KviaJjZt69eS-nvA.png

🗣️ Alessandro Pomponio, Research Software Engineer @ IBM Research, explains how his team used Kyverno policies to solve GPU resource monopolization in their Kubernetes clusters Watch the full episode: https://ku.bz/5sK7BFZ-8

This article explains why Kubernetes PSS Restricted and RuntimeDefault seccomp did not block AF_ALG access during Copy Fail testing It shows why kernel attack surface still matters even when pods follow strict runtime defaults ➜ https://ku.bz/j-pzF0QZb

Netfence runs as a daemon, injecting eBPF filter programs into cgroups and network interfaces, with a built-in DNS server that resolves allowed domains and populates IP allowlists, and connecting to a central control plane to synchronize network rules ➤ https://ku.bz/wCc37BMNY

This article covers network security fundamentals in Kubernetes, explaining how clusters default to a flat pod network, how network policies enforce segmentation, and best practices like “default deny” and restricting host networking ➤ https://ku.bz/T2VfCvjdJ

https://datadog-securitylabs.imgix.net/img/kubernetes-security-fundamentals/part-6/unmanaged-net-trust-zones.png?auto=format&dpr=1.75&w=896