Kubesploit
banner
kubesploit.io
Kubesploit
@kubesploit.io
News and links on Kubernetes security curated by the @Learnk8s.io team
More K8s news, events, jobs → https://kube.today
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime

https://ku.bz/YdMc3KBZ6
September 23, 2026 at 6:26 PM
Reposted by Kubesploit
This week on the Learn Kubernetes Weekly:

🔥 From etcd to Spanner
😌 Deploying Made Boring
🐘 Zookeeper on GKE
🚀 Mixed Version Proxy Graduates to Beta
🌍 Multi-Region EKS with Crossplane & FluxCD

⭐️ Buoyant

Read it now: https://kube.today/issues/202
September 23, 2026 at 11:46 AM
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down

https://ku.bz/ppRKVtXsb
September 22, 2026 at 6:26 PM
Reposted by Kubesploit
"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mistake."

Tsahi Duek on why AI agent security isn't optional

📺: https://ku.bz/2r41YKBZb
September 22, 2026 at 3:26 PM
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

https://ku.bz/PQSlZ7Khl
September 21, 2026 at 7:21 PM
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down

https://ku.bz/99rk_nQ-T
September 21, 2026 at 7:06 PM
Reposted by Kubesploit
New free book: Kubernetes Architecture in Financial Services

Platform lessons from seven banks on tenancy, delivery, policy, reliability, and cluster replacement

Supported by Buoyant, Sysdig, and Nirmata:
https://learnkube.com/kubernetes-architecture-financial-services
September 21, 2026 at 1:16 PM
Kloak swaps placeholders for real secrets inside the kernel with eBPF, just before TLS encryption, so applications never hold credentials and need no sidecars or code changes
Secrets can be pinned to specific hosts and ports

https://ku.bz/2tGP1vSc3
September 20, 2026 at 6:16 PM
IPMan is a Kubernetes operator that automates IPSec VPN setup (via StrongSwan) so your workloads can securely connect across networks

https://ku.bz/Stkf6J4qr
September 19, 2026 at 6:16 PM
Hubble is a fully distributed networking and security observability platform for cloud native workloads

It is built on top of Cilium and eBPF to enable deep visibility into the communication and behaviour of services and the networking infrastructure

https://ku.bz/fmj0PvVgk
September 18, 2026 at 6:56 PM
This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials

https://ku.bz/mdkryD536
September 18, 2026 at 6:41 PM
Reposted by Kubesploit
Kubernetes is multi-tenant by default. Workloads share nodes. Perimeter security still applies — but namespace isolation and network policies are what keep them from interfering

Rodrigo Bersa on container security

📺: https://ku.bz/dB7PDNt0v
September 18, 2026 at 5:06 PM
This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic

https://ku.bz/GNLh0bWKs
September 17, 2026 at 7:21 PM
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production

https://ku.bz/SWl3-LNty
September 17, 2026 at 7:06 PM
Reposted by Kubesploit
Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management

https://ku.bz/3hC23K79L
September 17, 2026 at 4:11 PM
This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates

https://ku.bz/DFLtYT8zG
September 17, 2026 at 12:16 PM
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about

https://ku.bz/tdxnc5S4r
September 16, 2026 at 6:26 PM
Reposted by Kubesploit
Kubernetes race conditions, rendered GitOps manifests, Headlamp migration, pod-level resources, and hidden cluster capacity

Brought to you by LearnKube: https://ku.bz/hypSbyc-V

Learn Kubernetes Weekly 201: https://kube.today/issues/201
September 16, 2026 at 11:46 AM
This article walks through a real Copy Fail pod escape on Talos Linux, showing how a shared page cache breaks container isolation and why gVisor or microVMs help

https://ku.bz/tYzhJx61Q
September 15, 2026 at 6:26 PM
Reposted by Kubesploit
“AI guardrails have to be deterministic.”

David Parry on why Kubernetes automation needs rules that match your company, your deployments, and your compliance needs

📺: https://ku.bz/c5J05syX3
September 15, 2026 at 3:31 PM
Reposted by Kubesploit
“When you run one pizza order, you get 200 traces.”

On Kube Signals episode two, Mauricio (Salaboy) Salatino shows @brianteller.bsky.social why the demo needed 15 containers

Watch: https://ku.bz/TlVjXdnb6

Presented by Learn Kubernetes Weekly
September 15, 2026 at 2:11 PM
This article explains why three old Kubernetes CVEs will never get a code fix, and what to change in your cluster now that scanners are about to start flagging them again

https://ku.bz/22Rr95v9F
September 14, 2026 at 7:26 PM
Reposted by Kubesploit
"Either which way you go, you've got to still figure out DNS."

Raglin Anthony on on-prem to cloud networking

📺: https://ku.bz/2XqMJnLVx
September 14, 2026 at 5:46 PM
Reposted by Kubesploit
When does Kubernetes make sense?

It is one of the questions we ask during private Kubernetes courses at @learnkube.com.

My controversial answer is one application.
September 14, 2026 at 4:11 PM
This article presents a three-layer tenant isolation design where each tenant gets its own control plane, VM nodes and isolated network via KubeFlex, KubeVirt and OVN-Kubernetes, with latency measurements

https://ku.bz/YRcVzxByx
September 12, 2026 at 4:16 AM