Kubesploit
@kubesploit
News and links on Kubernetes security curated by the @Learnk8s.io team More K8s news, events, jobs
This tutorial explains how to build a PCI-DSS focused GKE security framework using: - Workload Identity, - Secret Manager, - Binary Authorization, - NetworkPolicy, - VPC Service Controls, - Private Service Connect, - Istio mTLS, - and audit logging ➜ https://ku.bz/cD6Lg9ppD
This tutorial shows how to connect on-prem Kubernetes workloads to Google Cloud without service account keys using Workload Identity Federation, OIDC, Terraform, Kyverno, and IAM attribute conditions ➤ https://ku.bz/1YVD6c3FP
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns ➜ https://ku.bz/XNmQ2X-7T
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping ➜ https://ku.bz/nN1m_5FXK
This tutorial shows how to use the RBAC Overview OpenShift console plugin to audit users, service accounts, role bindings, cluster admins, and SCC access ➜ https://ku.bz/gMzL4pXNq
Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs ➜ https://ku.bz/DLKSbPlGK
This article explains how to use Gatekeeper to enforce in-cluster admission policies, such as rejecting `:latest` images, mandating labels, and disallowing privileged workloads ➤ https://ku.bz/1Zskfkkvg
This tutorial shows how to run OWASP ZAP scans inside GitHub Actions using SecureCodeBox on a Kubernetes kind cluster ➤ https://ku.bz/nDZJpmg5F
This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService ➜ https://ku.bz/lNmNzN4HW
This article covers network security fundamentals in Kubernetes, explaining how clusters default to a flat pod network, how network policies enforce segmentation, and best practices like “default deny” and restricting host networking ➤ https://ku.bz/T2VfCvjdJ
This article explains four Kubernetes isolation patterns for AI agents: no exec, sidecar exec, separate exec pod, and ephemeral job dispatchers, with OpenShift-validated threat modeling ➜ https://ku.bz/KC6H2m-VF
This tutorial teaches how to extend EKS with hybrid nodes using IAM Roles Anywhere and HashiCorp Vault for secure authentication of on-premises or edge workloads ➤ https://ku.bz/s3DxFxdHf
This tutorial shows how to modernize Kyverno policies with CEL using practical Kubernetes security examples like namespace rules, image checks, service account tokens, and safer policy testing ➜ https://ku.bz/PcpzWX_N6
This tutorial teaches how to collect Prometheus metrics from Kubernetes clusters and securely route them to remote Prometheus instances using Vector with mTLS encryption ➤ https://ku.bz/_QBDYV4t7
This tutorial teaches how to secure LLM inference services on Kubernetes using Authorino and Envoy for authentication and authorization ➤ https://ku.bz/NWFrLKFbF
This tutorial teaches how to implement container image signature verification in Kubernetes using Cosign for signing, Kyverno for policy enforcement, and Sigstore Policy Controller for admission control ➤ https://ku.bz/vT_tmP0lj
This tutorial teaches how to enforce signed container images in Kubernetes using Cosign for signing, Harbor for storage, and Kyverno admission controller for verification, including custom CA trust configuration and CI/CD integration patterns ➤ https://ku.bz/CjQLsVFWf
This article shows a Zero Trust blueprint using mutual TLS (mTLS) and Istio security policies to make internal and external APIs secure by default, with step-by-step configs and lessons from real systems ➤ https://ku.bz/Ft_3_HxjS
Sealed Secrets Web is a tool that provides a web interface for managing and encrypting sensitive data in Kubernetes using the Sealed Secrets service by Bitnami ➤ https://ku.bz/WS8Y2DHgS
This tutorial shows how to connect on-prem Kubernetes workloads to Google Cloud without service account keys using Workload Identity Federation, OIDC, Terraform, Kyverno, and IAM attribute conditions ➜ https://ku.bz/1YVD6c3FP
ESP Kubernetes Reference Implementation runs compliance scanning in Kubernetes using ESP policies with pull-based agents that execute NIST, CIS, and STIG controls and produce CUI-free attestations forwarded to SIEM or cloud functions ➤ https://ku.bz/z00YcWHVS
This article reviews Kubermatic SecureGuard (KubeSG), a Kubernetes-native open source secrets manager built on OpenBao and the External Secrets Operator that automates secret rotation and delivery without app rewrites or proprietary SDKs ➤ https://ku.bz/wD-DcVMBD
This article shows how to sign every container image using Cosign keyless signing in GitHub Actions and enforce signatures at pod admission with Kyverno, using the chalk/debug npm attack as the real-world motivation ➤ https://ku.bz/7WkPPBjwH
This tutorial shows how to set up TLS-terminated ingress on EKS Auto Mode using ACM and an ALB, skipping the traditional AWS Load Balancer Controller installation and OIDC setup ➤ https://ku.bz/sbhYbmWNb
This article explains how to use Gatekeeper to enforce in-cluster admission policies, such as rejecting `:latest` images, mandating labels, and disallowing privileged workloads ➜ https://ku.bz/1Zskfkkvg
This tutorial shows how to run OWASP ZAP scans inside GitHub Actions using SecureCodeBox on a Kubernetes kind cluster ➜ https://ku.bz/nDZJpmg5F
This tutorial shows how to use Cilium and Hubble to enforce HTTP path based network policies in Kubernetes with eBPF, so you can allow or block specific endpoints without sidecars ➤ https://ku.bz/Fl4tzq2J2
This tutorial explains TLS and certificate debugging from root CA basics to Kubernetes secrets, with OpenSSL and curl commands for inspecting certs, validating handshakes, and fixing common production errors ➤ https://ku.bz/z-30r6w-V
This article covers network security fundamentals in Kubernetes, explaining how clusters default to a flat pod network, how network policies enforce segmentation, and best practices like “default deny” and restricting host networking ➜ https://ku.bz/T2VfCvjdJ
This tutorial shows how to secure an ArgoCD based EKS GitOps workflow with External Secrets Operator, IRSA, and AWS SSM Parameter Store so secrets stay out of Git and sync safely into Kubernetes ➤ https://ku.bz/1qJT8SG1s