Digest #48: Kubernetes Container Security 🔐

#48: Kubernetes Container Security 

🎧 PODCAST/WEBINAR OF THE WEEK
In this episode Rich speaks with Celeste Horgan from Stripe. Topics include: How developers can get better at writing docs, what makes a good concept doc, “blank is a blank that does blank,” the difficulty with making big changes in the Kubernetes documentation, the Dockershim deprecation, inclusive naming, and many others 🔥
📖 POSTS OF THE WEEK
ArgoCD best practices you should know
In this article, you'll explore some of the best practices of Argo and learn how you can validate your custom resources against these best practices.
Read more »
"How to secure Deployments in Kubernetes?" - Security is crucial ‌for containerized applications that run on a shared infrastructure. In this post, you'll learn how to secure ‌Kubernetes deployments and applications in general - Read more »
"Build Preview Environments on AWS for CI/CD workflows with Terraform CDK" - In this tutorial, you will build preview environments on AWS using Terraform CDK and deploy a React application - Read more »
"Kubernetes ephemeral container security" - Ephemeral containers is a new concept in Kubernetes which allows attaching containers to already running Pods. It also introduces new security concerns which have to be resolved before it can be enabled - Read more »
"You probably don’t need AWS and are better off without it" - While I'm not particularly fond of AWS but I find the provided arguments baffling - you would be better off without AWS because you might forget to turn off $80k of instances? - Read more »
"Take the pain out of git conflict resolution: use diff3" - The diff3 conflict resolution strategy is a hidden gem in git that can save you an uncountable conflict-resolution headaches and turn git conflict resolution into something of a joy - Read more »
"Monitoring a garage door with a Raspberry Pi, Rust, and a 13Mb Linux system" - For geeks like me, this is a super fun project. It sends an alert via Mattermost when the garage door has been left open for more than 5 minutes - Read more »
"Codespaces for multi-repository and monorepo scenarios" - Codespaces are instant cloud-powered development environments. Now, it supports multi-repository projects and monorepos - Read more »
"AWS's Log4Shell hot patch vulnerable to container escape and privilege escalation" -  Great post that identifies severe security issues within AWS Log4Shell hot patch solutions. It provides as well the root cause analysis and overview of fixes and mitigations - Read more »
📕 BOOK OF THE WEEK
This book includes stories of many different companies. Some were successful, and others were not. One key concept from the book that hit home with me was that when you have a strong Why you will naturally attract individuals to your business who share that Why. A strong Why will allow you to market based on these beliefs instead of using manipulative tactics like price, features, and benefits.
If you’ve thought about starting or are running your own business, do you know your Why? If not, I would urge you to take some time to read Start With Why and to get clear on your Why.
🛠 PROJECTS OF THE WEEK
If you manage AWS Cloud accounts you might be interested in forwarding all your EC2 logs with ease to 3rd parties through Kinesis Firehose from one centralized place – if this is the case – check out this Rsyslog Server product made by 0x4447. The company 0x4447 builds products to increase standardization and security in AWS Organizations. They do this with automated pipelines that use well structured projects to create secure, easy to maintain and fail tolerant solutions - Read more »
Shell-operator is a tool for running event-driven scripts in a Kubernetes cluster. Shell-operator provides an integration layer between Kubernetes cluster events and shell scripts by treating scripts as hooks triggered by events. Think of it as an operator-sdk but for scripts - Read more »
The helm-docs tool auto-generates documentation from helm charts into markdown files. The resulting files contain metadata about their respective chart and a table with each of the chart's values, their defaults, and an optional description parsed from comments - Read more »
Secrets is a command-line tool to prevent committing secret keys into your source code. secrets has a few features that distinguish it from other secret scanning tools like being extremely fast, focused on pre-commit, single binary with no dependencies and low rate of false positives - Read more »
Cog is an open-source tool that lets you package machine learning models in a standard, production-ready container. With Cog, you define your environment with a simple configuration file and it generates a Docker image with all the best practices: Nvidia base images, efficient caching of dependencies, installing specific Python versions, sensible environment variable defaults, and so on - Read more »
Describe a situation in which you may or may not have been the one at fault. The AI will tell you who's in the right, and why. The project is a collection of 3 unique AI text generation models trained on posts and comments from r/AmITheAsshole and answers the questions that you've been asking on reddit for years: was my response to this reasonable, or am I the asshole in this situation? - Read more »
💼 OPEN JOBS OF THE WEEK
Site Reliability Engineer @Swile
AWS, Kubernetes, Terraform

🌎 Remote, France
Read more »
DevOps Engineer @Built
AWS/GCP, Docker, Jenkins

🌎 Remote, USA
Read more »
Senior Site Reliability Engineer @Funding Circle
AWS, Golang, Terraform

🌎 Remote, UK
Read more »
🐦 TWEET OF THE WEEK
Some killer one-liners in JavaScript 🔥
😂 MEMES OF THE WEEK
Purple pill: working remotely for a US company while living in EU 😌
Share Share
Tweet Tweet
Forward Forward
Remember to share if you enjoyed this issue!
@devopsbulletin @devopsbulletin
devopsbulletin.com devopsbulletin.com
Copyright © 2022 DevOps Bulletin, All rights reserved.
Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp

Older messages

Digest #46: Git's 17th Anniversary 🎂

Thursday, April 7, 2022

Digest #46: Git's 17th Anniversary 🎂 #46: Git's 17th Anniversary 🎧 PODCAST/WEBINAR OF THE WEEK Talos Linux is a modern Linux distribution built for Kubernetes. In this episode, Viktor Farcic

Digest #45: 600 Pods in 6 Minutes 🚀

Thursday, March 31, 2022

Digest #45: 600 Pods in 6 Minutes 🚀 #45: 600 Pods in 6 Minutes 🎧 PODCAST/WEBINAR OF THE WEEK Kubernetes become one of the favoured systems of running distributed apps among startups. The big question

Digest #43: Azure Penetration Testing 📛

Friday, March 25, 2022

Digest #43: Azure Penetration Testing 📛 #43: Azure Penetration Testing 🎧 PODCAST/WEBINAR OF THE WEEK Kubernetes won the container wars (over Swarm, CF and Mesos) and continues to grow in use across

Digest #44: You're Doing SSH Wrong 😬

Friday, March 25, 2022

Digest #44: You're Doing SSH Wrong 😬 #44: You're Doing SSH Wrong 🎧 PODCAST/WEBINAR OF THE WEEK This episode from DevOps Pradox discusses the challenges with StatesfulSet applications and the

You Might Also Like

Daily Coding Problem: Problem #1664 [Easy]

Friday, January 10, 2025

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Twitter. A permutation can be specified by an array P , where P[i] represents the

Spyglass Dispatch: The Case for a For-Profit OpenAI

Friday, January 10, 2025

RIP Venu • A More Political and Real Time Threads • An OpenAI Auction • Apple's Tough 2025 The Spyglass Dispatch is a newsletter sent on weekdays featuring links and commentary on timely topics

⌨️ 10 Mods to Improve Your Mechanical Keyboard — How to Set Up Quick Share on Windows

Friday, January 10, 2025

Also: Why Are Tech Companies Trying to Sell Me Expensive Clocks? How-To Geek Logo January 10, 2025 Did You Know Famed biologist Charles Darwin and US President Abraham Lincoln were born on the same day

Your best friends in design

Friday, January 10, 2025

​ Working With Designers Product manager & UX designer collaboration guide. How members of your product team work together is just as important as the work itself. A fundamental relationship within

Charted | How Canada Would Rank as the 51st State 📊

Friday, January 10, 2025

Donald Trump has floated the idea that Canada should be the 51st state. Here's how it compares statistically. View Online | Subscribe | Download Our App Presented by: Global X ETFs Power AI's

Pinpointing The Actual Problem 🎯

Friday, January 10, 2025

WordPress accidentally diagnoses its own business problem. Here's a version for your browser. Hunting for the end of the long tail • January 10, 2025 Pinpointing The Actual Problem A blog post from

😱Major Azure Outage in EastUS2, 🚀New AI and Azure Developer CLI Courses, azureedge.net DNS retiring

Friday, January 10, 2025

͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏

iOS Cocoa Treats

Friday, January 10, 2025

View in browser Hello, you're reading Infinum iOS Cocoa Treats, bringing you the latest iOS related news straight to your inbox every week. Adopting Swift 6 across the app codebase I've been

Issue #575: Excalibird, bird’s eye metropolis, and Stimulation Clicker

Friday, January 10, 2025

View this email in your browser Issue #575 - January 10th 2025 Weekly newsletter about Web Game Development. If you have anything you want to share with our community please let me know by replying to

22 CES products you can't miss

Friday, January 10, 2025

10 must-install Linux apps; Cybersecurity in 2025; Email encryption how-to -- ZDNET ZDNET Tech Today - US January 10, 2025 CES logo 2025 CES 2025: The 22 most impressive products you don't want to