Search results for: security/


The Kubernetes Surgeon’s Handbook: Precision Recovery from etcd Snapshots

Posted on May 8, 2025 | Seshachalam Y.V, etcd-druid maintainer

TL;DR: Precision Recovery from etcd in 5 Steps This guide walks you through surgical resource recovery from etcd snapshots without triggering a full cluster restore. Whether you’re troubleshooting accidental deletions or forensic debugging, this lightweight and…


Announcing OpenReports: Standardized Kubernetes Reporting

Posted on May 6, 2025

The Kubernetes ecosystem, while powerful, is a sprawling landscape of tools. As organizations scale their deployments, ensuring compliance and security becomes paramount. But how do you effectively track and report on your Kubernetes policies and scanners…


Components vs. Containers: Fight?

Posted on April 9, 2025 | Taylor Thomas, CNCF Ambassador

WebAssembly components offer a new way to deploy microservices and other applications in cloud native environments. This naturally raises the question: is the upstart component out to replace containers? Or is this one of those situations…


Kubernetes hardening made easy: Running CIS Benchmarks with kube-bench

Posted on April 8, 2025

In today’s world, where security risks and breaches are growing daily, it is crucial to maintain our applications and infrastructure’s compliance with security standards and that is where CIS benchmarks from CIS (Center for Internet Security)…


Automating NIS2 Compliance in Kubernetes with Kyverno: A Practical Guide

Posted on March 11, 2025 | Cristian Klein of Elastisys and Anusha Hegde of Nirmata

2025 is the year when NIS2 measures will start to bite. Is your platform team ready for the challenge? This post gives a brief overview of NIS2 in the context of platform engineering. Then it gives…


Falcoctl: Artifact Management for Falco

Posted on March 10, 2025 | Nigel Douglas

Artifact management is the process of storing, organising, and securing the essential components generated throughout software development. Cloudsmith defines artifacts as the tangible outputs of the development lifecycle, including compiled source code, libraries, executables, and configuration…


Kubescape becomes a CNCF incubating project

Posted on February 26, 2025

The CNCF Technical Oversight Committee (TOC) has voted to accept Kubescape as a CNCF incubating project.  Kubescape is an open-source Kubernetes security project designed to offer comprehensive security coverage throughout the entire development and deployment lifecycle….


Announcing the Kubernetes “Shift Down” Security Paper

Posted on February 25, 2025 | Jim Bugwadia, CNCF Policy WG and Nirmata

The CNCF Kubernetes Policy Working group (WG) has just released the Shift Down Security paper to help educate the community about how organizations can leverage cloud native security best practices to address key business risks and…


OSTIF Announces Linkerd Security Audit Results

Posted on February 19, 2025 | Linkerd Team

The Open Source Technology Improvement Fund (OSTIF) is proud to share the results of our security audit of Linkerd. Linkerd is an open source service mesh for Kubernetes which prioritizes reliability, security, and simplicity. Thanks to…


How to manage three top Kubernetes security vulnerabilities

Posted on February 18, 2025 | Harlin Lipman | Senior Information Security Manager | Chronosphere

This article explains: Kubernetes and security Across various organizations, Kubernetes is being adopted at lightning rates. It is estimated that 60% of organizations have adopted this technology, and the list of companies planning on transitioning to…