Copy Fail Blocker deploys a privileged DaemonSet that blocks AF_ALG and AF_RXRPC socket creation cluster-wide to mitigate Copy Fail and similar Linux kernel privilege-escalation paths.
More: https://ku.bz/hMfdC6WGc
More: https://ku.bz/hMfdC6WGc
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 191:
๐ฅ What Does 4.4% GPU Utilization Actually Mean?
๐ ๏ธ GKE IP Exhaustion Fixed: The Class E Migration Guide
๐งน Evicting MCP Tool Calls from Your Kubernetes Cluster
๐ The Feedback Loops Behind Kubernetes
๐ง You Don't Have a GIL Problem โ You Have a CPU Problem
Read it now: https://kube.today/issues/191
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
๐ฅ What Does 4.4% GPU Utilization Actually Mean?
๐ ๏ธ GKE IP Exhaustion Fixed: The Class E Migration Guide
๐งน Evicting MCP Tool Calls from Your Kubernetes Cluster
๐ The Feedback Loops Behind Kubernetes
๐ง You Don't Have a GIL Problem โ You Have a CPU Problem
Read it now: https://kube.today/issues/191
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
This article explains Kubernetes v1.36 fine-grained kubelet authorization and how teams can replace broad nodes/proxy access with safer permissions for metrics, stats, logs, pods, and health checks.
More: https://ku.bz/M6WZq580X
More: https://ku.bz/M6WZq580X
This article explains the Kubernetes v1.36 SELinux volume labeling change and why clusters using SELinux should audit workloads before SELinuxMount becomes the default.
More: https://ku.bz/KGR_FN-3w
More: https://ku.bz/KGR_FN-3w
k8scout maps realistic Kubernetes escalation paths from a compromised pod to cluster-admin, node access, secret theft, or cloud IAM takeover, with graph output and reviewer mode.
More: https://ku.bz/Jt-LJm0f2
More: https://ku.bz/Jt-LJm0f2
Copy Fail Destroyer runs on Kubernetes nodes to detect and remediate Copy Fail and Dirty Frag by probing vulnerable kernel modules, unloading them, exposing metrics, and supporting Helm or ArgoCD deployment.
More: https://ku.bz/xvFl18wxv
More: https://ku.bz/xvFl18wxv
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
How do you give developers access to the Kubernetes API without letting them break things?
Peter Kelly describes staged policies in Project Calico: developers can dry-run network policies to see which flows would be affected before enforcing them. Combined with namespace-scoped policy tiers, teams get real autonomy without risking production traffic.
Instead of blocking developers, give them a safe way to test.
Full interview: https://ku.bz/xgqZJhdyn
Watch the full interview: https://ku.bz/xgqZJhdyn
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
Peter Kelly describes staged policies in Project Calico: developers can dry-run network policies to see which flows would be affected before enforcing them. Combined with namespace-scoped policy tiers, teams get real autonomy without risking production traffic.
Instead of blocking developers, give them a safe way to test.
Full interview: https://ku.bz/xgqZJhdyn
Watch the full interview: https://ku.bz/xgqZJhdyn
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
This case study explains how a Kubernetes secrets audit exposed weak secret handling and forced a move toward safer secret management.
It covers encoded secrets, RBAC, encryption, external secret stores, and audit-ready controls.
More: https://ku.bz/z0ylnRsvd
It covers encoded secrets, RBAC, encryption, external secret stores, and audit-ready controls.
More: https://ku.bz/z0ylnRsvd
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 192:
๐ง Our Kubernetes Operator Didn't Scale, So We Rebuilt It
๐ ClickHouse Shard Rebalancing on Kubernetes: From Talk to Operator
๐ฅ Invisible OOMkill: Java Pods Crashing in Kubernetes
๐๏ธ Using Kubernetes ConfigMaps as a Real-Time State Store
๐จ From Container Escape to Cloud Takeover: A Real-World Cloud Security Assessment
Read it now: https://kube.today/issues/192
โญ๏ธ This newsletter is brought to you by Buoyant, the creators of Linkerd https://ku.bz/BB-RtVFWs
๐ง Our Kubernetes Operator Didn't Scale, So We Rebuilt It
๐ ClickHouse Shard Rebalancing on Kubernetes: From Talk to Operator
๐ฅ Invisible OOMkill: Java Pods Crashing in Kubernetes
๐๏ธ Using Kubernetes ConfigMaps as a Real-Time State Store
๐จ From Container Escape to Cloud Takeover: A Real-World Cloud Security Assessment
Read it now: https://kube.today/issues/192
โญ๏ธ This newsletter is brought to you by Buoyant, the creators of Linkerd https://ku.bz/BB-RtVFWs
This article explains how a local 7B model was fine-tuned to answer cloud security, Kubernetes, Terraform, and compliance questions from a rule-based dataset.
More: https://ku.bz/NNjhbSslC
More: https://ku.bz/NNjhbSslC
This tutorial shows how to modernize Kyverno policies with CEL using practical Kubernetes security examples like namespace rules, image checks, service account tokens, and safer policy testing.
More: https://ku.bz/PcpzWX_N6
More: https://ku.bz/PcpzWX_N6
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Nicholaos Mouzourakis, Staff Product Security Engineer at Gusto, shares practical advice for Kubernetes administrators implementing Open Policy Agent (OPA). He recommends starting with Rego fundamentals using resources like Styra Academy and the Rego Playground for testing policies with real-time feedback.
He emphasizes:
- Getting team buy-in by explaining security benefits, especially for those who will read or write policies
- Using observability tools to determine scale and latency requirements
- Choosing appropriate deployment patterns (sidecar, daemon set, or standalone deployment)
- Deciding between baking configurations into Docker images, using config maps, or pulling policies from services like S3 or Styra DAS
Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4
He emphasizes:
- Getting team buy-in by explaining security benefits, especially for those who will read or write policies
- Using observability tools to determine scale and latency requirements
- Choosing appropriate deployment patterns (sidecar, daemon set, or standalone deployment)
- Deciding between baking configurations into Docker images, using config maps, or pulling policies from services like S3 or Styra DAS
Watch the full episode: https://kube.fmhttps://ku.bz/S-2vQ_j-4
This article explains four Kubernetes isolation patterns for AI agents: no exec, sidecar exec, separate exec pod, and ephemeral job dispatchers, with OpenShift-validated threat modeling.
More: https://ku.bz/KC6H2m-VF
More: https://ku.bz/KC6H2m-VF
This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService.
More: https://ku.bz/lNmNzN4HW
More: https://ku.bz/lNmNzN4HW
This article explains how Kubernetes zero-trust egress policy can contain the Axios npm supply-chain attack by blocking C2 traffic, data exfiltration, and lateral movement from compromised pods.
More: https://ku.bz/kz47HBml6
More: https://ku.bz/kz47HBml6
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 193:
๐ Which of our Containers are Chainguard?
๐ธ One Forgotten Notebook on an A100. $1,800 a Month.
๐ How an Admin Cluster Keeps Application Clusters in Sync with GitOps
๐ Cost Optimization of Spark on Kubernetes Batch Workloads on Public Clouds
๐ช ingress-nginx Is Archived: How We Migrated to kgateway (and Didn't Break Prod)
Read it now: https://kube.today/issues/193
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
๐ Which of our Containers are Chainguard?
๐ธ One Forgotten Notebook on an A100. $1,800 a Month.
๐ How an Admin Cluster Keeps Application Clusters in Sync with GitOps
๐ Cost Optimization of Spark on Kubernetes Batch Workloads on Public Clouds
๐ช ingress-nginx Is Archived: How We Migrated to kgateway (and Didn't Break Prod)
Read it now: https://kube.today/issues/193
โญ๏ธ This newsletter is brought to you by LearnKube โ master Kubernetes with hands-on training designed for engineers who want to learn the smart way https://ku.bz/hypSbyc-V
This article explains why Kubernetes PSS Restricted and RuntimeDefault seccomp did not block AF_ALG access during Copy Fail testing.
It shows why kernel attack surface still matters even when pods follow strict runtime defaults.
More: https://ku.bz/j-pzF0QZb
It shows why kernel attack surface still matters even when pods follow strict runtime defaults.
More: https://ku.bz/j-pzF0QZb
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Container registries are often treated like storage, but they sit in the middle of delivery.
Meg Sarros explains why the registry is part of the CI/CD control plane: teams build an image, push it to a central place, and rely on that same place to manage access, encryption, and auditing.
The key point is that registry choices shape both deployment flow and governance.
Watch the full interview: https://ku.bz/k_r1B0Rwj
Meg Sarros explains why the registry is part of the CI/CD control plane: teams build an image, push it to a central place, and rely on that same place to manage access, encryption, and auditing.
The key point is that registry choices shape both deployment flow and governance.
Watch the full interview: https://ku.bz/k_r1B0Rwj
This case study explains how a privileged Kubernetes pod with host access can lead to container escape, control plane disruption, service account theft, and cloud resource takeover.
More: https://ku.bz/LXMBJmlKp
More: https://ku.bz/LXMBJmlKp
This tutorial explains how to sign and verify Docker images in Amazon ECR using Cosign and AWS KMS.
It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security.
More: https://ku.bz/NG8185Rvq
It also shows how trusted image enforcement can fit into EKS and Kyverno-based supply chain security.
More: https://ku.bz/NG8185Rvq