Digest #48: Kubernetes Container Security 🔐

#48: Kubernetes Container Security 

🎧 PODCAST/WEBINAR OF THE WEEK
In this episode Rich speaks with Celeste Horgan from Stripe. Topics include: How developers can get better at writing docs, what makes a good concept doc, “blank is a blank that does blank,” the difficulty with making big changes in the Kubernetes documentation, the Dockershim deprecation, inclusive naming, and many others 🔥
📖 POSTS OF THE WEEK
ArgoCD best practices you should know
In this article, you'll explore some of the best practices of Argo and learn how you can validate your custom resources against these best practices.
Read more »
"How to secure Deployments in Kubernetes?" - Security is crucial ‌for containerized applications that run on a shared infrastructure. In this post, you'll learn how to secure ‌Kubernetes deployments and applications in general - Read more »
"Build Preview Environments on AWS for CI/CD workflows with Terraform CDK" - In this tutorial, you will build preview environments on AWS using Terraform CDK and deploy a React application - Read more »
"Kubernetes ephemeral container security" - Ephemeral containers is a new concept in Kubernetes which allows attaching containers to already running Pods. It also introduces new security concerns which have to be resolved before it can be enabled - Read more »
"You probably don’t need AWS and are better off without it" - While I'm not particularly fond of AWS but I find the provided arguments baffling - you would be better off without AWS because you might forget to turn off $80k of instances? - Read more »
"Take the pain out of git conflict resolution: use diff3" - The diff3 conflict resolution strategy is a hidden gem in git that can save you an uncountable conflict-resolution headaches and turn git conflict resolution into something of a joy - Read more »
"Monitoring a garage door with a Raspberry Pi, Rust, and a 13Mb Linux system" - For geeks like me, this is a super fun project. It sends an alert via Mattermost when the garage door has been left open for more than 5 minutes - Read more »
"Codespaces for multi-repository and monorepo scenarios" - Codespaces are instant cloud-powered development environments. Now, it supports multi-repository projects and monorepos - Read more »
"AWS's Log4Shell hot patch vulnerable to container escape and privilege escalation" -  Great post that identifies severe security issues within AWS Log4Shell hot patch solutions. It provides as well the root cause analysis and overview of fixes and mitigations - Read more »
📕 BOOK OF THE WEEK
This book includes stories of many different companies. Some were successful, and others were not. One key concept from the book that hit home with me was that when you have a strong Why you will naturally attract individuals to your business who share that Why. A strong Why will allow you to market based on these beliefs instead of using manipulative tactics like price, features, and benefits.
If you’ve thought about starting or are running your own business, do you know your Why? If not, I would urge you to take some time to read Start With Why and to get clear on your Why.
🛠 PROJECTS OF THE WEEK
If you manage AWS Cloud accounts you might be interested in forwarding all your EC2 logs with ease to 3rd parties through Kinesis Firehose from one centralized place – if this is the case – check out this Rsyslog Server product made by 0x4447. The company 0x4447 builds products to increase standardization and security in AWS Organizations. They do this with automated pipelines that use well structured projects to create secure, easy to maintain and fail tolerant solutions - Read more »
Shell-operator is a tool for running event-driven scripts in a Kubernetes cluster. Shell-operator provides an integration layer between Kubernetes cluster events and shell scripts by treating scripts as hooks triggered by events. Think of it as an operator-sdk but for scripts - Read more »
The helm-docs tool auto-generates documentation from helm charts into markdown files. The resulting files contain metadata about their respective chart and a table with each of the chart's values, their defaults, and an optional description parsed from comments - Read more »
Secrets is a command-line tool to prevent committing secret keys into your source code. secrets has a few features that distinguish it from other secret scanning tools like being extremely fast, focused on pre-commit, single binary with no dependencies and low rate of false positives - Read more »
Cog is an open-source tool that lets you package machine learning models in a standard, production-ready container. With Cog, you define your environment with a simple configuration file and it generates a Docker image with all the best practices: Nvidia base images, efficient caching of dependencies, installing specific Python versions, sensible environment variable defaults, and so on - Read more »
Describe a situation in which you may or may not have been the one at fault. The AI will tell you who's in the right, and why. The project is a collection of 3 unique AI text generation models trained on posts and comments from r/AmITheAsshole and answers the questions that you've been asking on reddit for years: was my response to this reasonable, or am I the asshole in this situation? - Read more »
💼 OPEN JOBS OF THE WEEK
Site Reliability Engineer @Swile
AWS, Kubernetes, Terraform

🌎 Remote, France
Read more »
DevOps Engineer @Built
AWS/GCP, Docker, Jenkins

🌎 Remote, USA
Read more »
Senior Site Reliability Engineer @Funding Circle
AWS, Golang, Terraform

🌎 Remote, UK
Read more »
🐦 TWEET OF THE WEEK
Some killer one-liners in JavaScript 🔥
😂 MEMES OF THE WEEK
Purple pill: working remotely for a US company while living in EU 😌
Share Share
Tweet Tweet
Forward Forward
Remember to share if you enjoyed this issue!
@devopsbulletin @devopsbulletin
devopsbulletin.com devopsbulletin.com
Copyright © 2022 DevOps Bulletin, All rights reserved.
Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp

Older messages

Digest #46: Git's 17th Anniversary 🎂

Thursday, April 7, 2022

Digest #46: Git's 17th Anniversary 🎂 #46: Git's 17th Anniversary 🎧 PODCAST/WEBINAR OF THE WEEK Talos Linux is a modern Linux distribution built for Kubernetes. In this episode, Viktor Farcic

Digest #45: 600 Pods in 6 Minutes 🚀

Thursday, March 31, 2022

Digest #45: 600 Pods in 6 Minutes 🚀 #45: 600 Pods in 6 Minutes 🎧 PODCAST/WEBINAR OF THE WEEK Kubernetes become one of the favoured systems of running distributed apps among startups. The big question

Digest #43: Azure Penetration Testing 📛

Friday, March 25, 2022

Digest #43: Azure Penetration Testing 📛 #43: Azure Penetration Testing 🎧 PODCAST/WEBINAR OF THE WEEK Kubernetes won the container wars (over Swarm, CF and Mesos) and continues to grow in use across

Digest #44: You're Doing SSH Wrong 😬

Friday, March 25, 2022

Digest #44: You're Doing SSH Wrong 😬 #44: You're Doing SSH Wrong 🎧 PODCAST/WEBINAR OF THE WEEK This episode from DevOps Pradox discusses the challenges with StatesfulSet applications and the

You Might Also Like

Weekend Reading — More time to write

Sunday, November 24, 2024

More Time to Write A fully functional clock that ticks backwards, giving you more time to write. Tech Stuff Martijn Faassen (FWIW I don't know how to use any debugger other than console.log) People

🕹️ Retro Consoles Worth Collecting While You Still Can — Is Last Year's Flagship Phone Worth Your Money?

Saturday, November 23, 2024

Also: Best Outdoor Smart Plugs, and More! How-To Geek Logo November 23, 2024 Did You Know After the "flair" that servers wore—buttons and other adornments—was made the butt of a joke in the

JSK Daily for Nov 23, 2024

Saturday, November 23, 2024

JSK Daily for Nov 23, 2024 View this email in your browser A community curated daily e-mail of JavaScript news React E-Commerce App for Digital Products: Part 4 (Creating the Home Page) This component

Not Ready For The Camera 📸

Saturday, November 23, 2024

What (and who) video-based social media leaves out. Here's a version for your browser. Hunting for the end of the long tail • November 23, 2024 Not Ready For The Camera Why hasn't video

Daily Coding Problem: Problem #1617 [Easy]

Saturday, November 23, 2024

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Microsoft. You are given an string representing the initial conditions of some dominoes.

Ranked | The Tallest and Shortest Countries, by Average Height 📏

Saturday, November 23, 2024

These two maps compare the world's tallest countries, and the world's shortest countries, by average height. View Online | Subscribe | Download Our App TIME IS RUNNING OUT There's just 3

⚙️ Your own Personal AI Agent, for Everything

Saturday, November 23, 2024

November 23, 2024 | Read Online Subscribe | Advertise Good Morning. Welcome to this special edition of The Deep View, brought to you in collaboration with Convergence. Imagine if you had a digital

Educational Byte: Are Privacy Coins Like Monero and Zcash Legal?

Saturday, November 23, 2024

Top Tech Content sent at Noon! How the world collects web data Read this email in your browser How are you, @newsletterest1? 🪐 What's happening in tech today, November 23, 2024? The HackerNoon

🐍 New Python tutorials on Real Python

Saturday, November 23, 2024

Hey there, There's always something going on over at Real Python as far as Python tutorials go. Here's what you may have missed this past week: Black Friday Giveaway @ Real Python This Black

Re: Hackers may have stolen everyone's SSN!

Saturday, November 23, 2024

I wanted to make sure you saw Incogni's Black Friday deal, which is exclusively available for iPhone Life readers. Use coupon code IPHONELIFE to save 58%. Here's why we recommend Incogni for