Search results for: security/


Registry mirror authentication with Kubernetes secrets

Posted on March 9, 2026 | Sascha Grunert, Red Hat

Part I: Architecture and Implementation In production Kubernetes clusters, pulling container images from private registries happens thousands of times per day. Kubernetes distributions from major cloud vendors provide credential providers for their respective registries like AWS…


CRI-O completes second OSTIF audit

Posted on January 16, 2026 | Helen Woeste, Communications and Operations at OSTIF

The Open Source Technology Improvement Fund is proud to share the results of our security audit of CRI-O. CRI-O is an implementation of the Kubernetes Container Runtime Interface (CRI) that is OCI-compliant (-O) that provides the…


Cloud Native Computing Foundation Announces Dragonfly’s Graduation

Posted on January 14, 2026

Dragonfly graduates after demonstrating production readiness, powering container and AI workloads at scale Key Highlights: SAN FRANCISCO, Calif. – January 14, 2026 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native…


The symbiotic revolution: AI and cloud native technologies transforming the digital landscape

Posted on January 13, 2026 | Gerald Venzl, VP of Dev & AI Initiatives at Oracle

This Ambassador Blog was originally published on the writer’s blog and is republished here with permission. In the ever-evolving world of technology, few pairings have sparked as much innovation as the intersection of artificial intelligence (AI)…


Solving Kubernetes Multi-tenancy Challenges with vCluster

Posted on September 23, 2025 | Fabian Brundke, Senior Platform Engineer, Liquid Reply

Understanding Multi-tenancy When we are building Internal Developer Platforms (IDP) for our customers Kubernetes is often a solid choice as the robust core of this platform. This is due to its technical capabilities and the strong…


Chain reaction in Amsterdam: What’s new in CNCF’s 2025 supply chain security guide

Posted on August 6, 2025 | CNCF Staff

The CNCF Security TAG’s Supply Chain Security Best Practices Guide first launched in 2021, just as high-profile supply chain attacks were beginning to shake public and private sector software systems alike. In 2025, the importance of…


Automating EKS CIS compliance with Kyverno and KubeBench

Posted on August 4, 2025 | Yugandhar Suthari | Security Engineer at Cisco

A practical approach to implementing CIS security controls using CNCF cloud native tools. Introduction: The Challenge of EKS Compliance at Scale  Maintaining CIS Benchmarks compliance for Amazon EKS across multiple clusters is a common challenge in…


Why Policy as Code is a Game Changer for Platform Engineers

Posted on July 8, 2025 | Jim Bugwadia, co-founder and CEO of Nirmata

Originally posted on Nirmata’s blog. Platform engineers, let’s talk about a fundamental shift that’s revolutionizing how we build and manage internal developer platforms: Policy as Code (PaC). This isn’t just another buzzword; it’s the key to…


A Year of Envoy Gateway GA: Building, Growing, and Innovating Together

Posted on June 11, 2025 | Erica Hughberg

A year of GA What Does GA Mean? A lot can happen in a year, and a lot has happened for Envoy Gateway since it reached general availability a little over a year ago. Before exploring…


Moving secure GitOps forward with Flux

Posted on May 19, 2025 | The Flux team

Spirits were high as the Flux team came together in London for KubeCon + CloudNativeCon Europe this year. With plenty to celebrate and even more to accomplish, one theme stood out as omnipresent: project security. The…