Search results for: security


CNCF On-Demand Webinar: Introduction to Tetragon

Posted on September 29, 2022

Tetragon provides eBPF-based transparent security observability combined with real-time runtime enforcement. Learn more in this webinar!


CNCF On-Demand Webinar: Pull request or it didn’t happen – hardening Kubernetes through GitOps

Posted on September 29, 2022

Remediation at the source is the new path forward for security, developers, operations teams looking to harden their Kubernetes environments. Join KSOC’s CTO and co-founder, Jimmy Mesta, and Director of Sales Engineering, Jack Zarris, along with…


CNCF On-Demand Webinar: Best practices for Calico installation

Posted on September 29, 2022

There are multiple ways to install Calico, such as manifest and helm. However, the recommended way is to install Calico through the free/opensource Tigera-Operator. In this session, we will talk about some basic Kubernetes networking concepts…


Istio sails into the Cloud Native Computing Foundation

Posted on September 28, 2022

The CNCF Technical Oversight Committee (TOC) has voted to accept Istio as a CNCF incubating project.  Istio is an open source service mesh that transparently provides a uniform and efficient way to secure, connect, and monitor…


Getting started with gVisor support in Falco

Posted on September 27, 2022

Project post originally published on the Falco blog by Luca Guerra, Lorenzo Susini, Vicente J. Jiménez Miras In version 0.32.1, Falco first introduced support for gVisor. So, what is it and how can we use it? gVisor, quoting the official…


How to think about securing Kubernetes with WAF and DoS protection

Posted on September 22, 2022

Guest post originally published by Jenn Gile of NGINX To best protect cloud-native apps, you need to deploy flexible, Kubernetes‑friendly WAF and DoS protections at the right places in your infrastructure.  For any team deploying applications,…


10 ways to make your software pipeline more observable

Posted on September 21, 2022

Guest post originally published on the Cloudsmith blog by Ciara Carey Ciara lists 10 ways to make your software pipelines more transparent and observable to gain insights, identify unusual behavior and possibly prevent a software supply…


SPIFFE and SPIRE Projects Graduate from Cloud Native Computing Foundation Incubator

Posted on September 20, 2022

Projects are used by leading cloud native companies including Bloomberg, ByteDance, Pinterest, and Twilio, among others San Francisco, CA – September 20, 2022 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud…


New research says cert-manager is vital for production environments that are scaling

Posted on September 20, 2022 | Richard Collins

Guest post from Richard Collins, Jetstack In recent months the cert-manager user community has been surveyed to understand how this CNCF Sandbox project is being used in production environments. As a highly popular developer-centric tool used…


An open source policy engine that automates remediation: Polaris 

Posted on September 16, 2022 | Robert Brennan

Guest post by Robert Brennan, VP of product development, Fairwinds Polaris is an open source policy engine that runs dozens of checks to ensure that your Kubernetes pods and controllers are configured using best practices in…