This tutorial shows how to run Cloudflare Tunnels as a DaemonSet to expose services with zero open inbound ports, using liveness probes, Kubernetes Secrets, and GitOps with ArgoCD. More: https://ku.bz/RYlKnctWf
About us
News and links on Kubernetes security curated by the Learnk8s team
- Website
-
https://kubesploit.io
External link for Kubesploit
- Industry
- Internet News
- Company size
- 2-10 employees
- Headquarters
- London
- Specialties
- Kubernetes and Security
Updates
-
This article reviews Kubermatic SecureGuard (KubeSG), a Kubernetes-native open source secrets manager built on OpenBao and the External Secrets Operator that automates secret rotation and delivery without app rewrites or proprietary SDKs. More: https://ku.bz/wD-DcVMBD
-
-
🚦 Readiness probes are a good example of a Kubernetes setting that only seems obvious after someone explains it. A pod might be running but not ready to handle traffic. This affects startup, rolling updates, shutdown, autoscaling, and failed deployments. I still see experienced teams get caught by this in advanced Kubernetes workshops. If your team does not know a readiness check is missing, who or what tells you? What reveals a missing Kubernetes readiness check? 📋 Checklist/review 👥 Engineer spots it 🔥 Incident/user report 🤷 Nobody checks 💡 We (LearnKube) released a Kubernetes production-readiness checklist to help teams find gaps before production finds them. It includes 10k+ words of guidance, an interactive checklist, a PDF worksheet, and a GitHub repo with the raw checklist data: https://ku.bz/tDr3SjWJk I’m using this poll series to collect community data for a report on how teams actually discover, review, and fix Kubernetes readiness gaps.
-
This article shows how to sign every container image using Cosign keyless signing in GitHub Actions and enforce signatures at pod admission with Kyverno, using the chalk/debug npm attack as the real-world motivation. More: https://ku.bz/7WkPPBjwH
-
-
🎙️ What is Brandt bringing to KCD New York? A practical session on software assurance at scale, why verification material becomes harder to manage across organizational boundaries, and why runtime is where trust and verification matter most. If you're interested in supply chain security, cloud-native platform engineering, observability, AI-enabled infrastructure, and practical Kubernetes operations, KCD New York is the place to be. We also have 10 free tickets available. Email hello@kube.events to claim one before they are gone. Register for KCD New York and claim your spot. 🔗 https://ku.bz/JkjmffBzw
-
Learn Kubernetes Weekly 185 just landed. In this edition you will find: 🔥 A One-Line Kubernetes Fix That Saved 600 Hours a Year 🔐 Why Kubernetes Has No Login — And How We Solved It for AuditRadar ⚙️ Durable Workflows Beyond Vercel: Version-Safe Orchestration for Kubernetes 🧩 The Missing Layers in Your Kubernetes Operator 🚨 Why Your KServe InferenceService Won't Become Ready: Four Production Failures and Fixes Read it now: https://lnkd.in/d3JtKWW5 ⭐️ This issue is brought to you by Qodo, the AI code integrity platform helping teams review, test, and ship reliable infrastructure code faster https://ku.bz/NvLHsnl-6
-
The right AI governance pattern for Kubernetes is not one agent doing everything. It is multiple agents doing specific work well. Henrik Rexed of Dynatrace says teams should think in terms of specialized review lanes: one AI system for infrastructure-heavy changes, another for observability concerns, and a human reviewer to confirm the final result. That reduces the chance of subtle platform-specific issues being missed by a generic review pass. Watch the full interview: https://ku.bz/KGQ_b20nQ
-
This article explains Kubernetes secrets management from an SRE angle by comparing: - Sealed Secrets, - External Secrets Operator, - and Vault-based approaches with examples. More: https://ku.bz/l5fy3crYf
-
Alessandro, Research Software Engineer @ IBM, explains his team's strategic approach to selecting open source tools from the CNCF landscape for their research computing platform. Alessandro details their decision-making process for policy enforcement, comparing Kyverno and Gatekeeper. They ultimately chose Kyverno because it uses YAML and "truly speaks Kubernetes," making it more accessible for researchers who manage clusters as a secondary responsibility rather than their primary job. Watch the full episode: https://ku.bz/5sK7BFZ-8
-
This tutorial shows how to set up TLS-terminated ingress on EKS Auto Mode using ACM and an ALB, skipping the traditional AWS Load Balancer Controller installation and OIDC setup. More: https://ku.bz/sbhYbmWNb
-