Cybersecurity
Kubernetes security
CVEs in the Kubernetes ecosystem, hardening practices, supply-chain risks, and the policy-engine landscape.
Kubernetes security spans the cluster (RBAC, network policies, admission control), the workload (pod security standards, runtime monitoring), and the supply chain (image provenance, SBOMs, signed artifacts). Notifire tracks CVE disclosures, hardening advisories, and the policy-engine releases that change the default-secure posture.
The category most likely to drive an on-call page is supply-chain: container images pulled from public registries with no provenance verification, then deployed via Helm charts that haven't been audited. The 2024 Linux/XZ backdoor was a wake-up call that's reshaping default trust assumptions.
Latest briefings on Kubernetes security
Infra
Adobe Tool Isolates GPU Metrics for Teams
Adobe has open-sourced a new tool that lets teams safely view their own GPU performance metrics in shared Kubernetes clusters. This solves a major security challenge by preventing teams from seeing each other's sensitive operational data.
Ashish Kale ·
Infra
Uber Built a Smarter Way to Scale on Kubernetes
Uber developed a new Kubernetes tool that separates scaling decisions from the actual scaling actions. This allows multiple systems to manage capacity safely, enabling regional failover without paying for constantly running idle servers.
Ashish Kale ·
Infra
Load a 70B AI Model in 37 Seconds
Google's new GKE Pod Snapshots can load a 70-billion-parameter AI model in just 37 seconds. The feature cuts startup latency by up to 89% by saving a model's memory state to Cloud Storage for faster reloads.
Ashish Kale ·
Infra
How Modal Launches a Million Sandboxes Instantly
Modal rebuilt its entire infrastructure to support millions of concurrent sandboxes, launching tens of thousands per second. Their custom solution offers a new blueprint for massive-scale computing beyond traditional tools like Kubernetes.
Ashish Kale ·
Infra
Kubernetes Is Rethinking How You Run Apps
The Kubernetes team managing core application tools, SIG Apps, is shifting focus to handle more complex workloads like AI and databases. This signals future changes to fundamental tools like Deployments, aiming for better lifecycle management for all users.
Ashish Kale ·
Infra
Lyft Unlocks Autoscaling With Open Source Flink
Lyft migrated hundreds of production data jobs from its custom in-house system to the standard Apache Flink Kubernetes Operator. This move enables better autoscaling, resource tuning, and more efficient upgrades for its streaming data platform.
Ashish Kale ·
Infra
Kubernetes Has a Plan to Fix Your YAML Headaches
The Kubernetes project is promoting KYAML, a stricter version of YAML, to make configuration files safer and more predictable. This aims to reduce common errors that cause deployment failures for developers and DevOps teams.
Ashish Kale ·
Infra
Treat Your Virtual Machines Like Physical Hardware
A new integration lets bare-metal tools manage virtual machines inside Kubernetes. This allows infrastructure teams to use a single, unified workflow for provisioning both physical and virtual servers, simplifying automation and reducing complexity.
Ashish Kale ·
Infra
Kubernetes Update Fixes a Major Memory Headache
Kubernetes v1.37 introduces a new feature called etcd RangeStream. It significantly cuts memory usage when reading large collections, making big clusters more stable and preventing common out-of-memory errors for the API server.
Ashish Kale ·
Infra
Kubernetes Upgrades Are Now Safer and Simpler
Kubernetes v1.37 now automatically updates stored data versions, a feature called Storage Version Migration. This makes cluster upgrades safer and eliminates a major operational headache for teams managing custom resources, reducing risk and manual work.
Ashish Kale ·
Infra
Elastic on Kubernetes Gets a Major Security Upgrade
The latest Elastic Cloud on Kubernetes (ECK) update adds mutual TLS encryption across the entire stack. This boosts security and simplifies compliance for teams running Elasticsearch on Kubernetes.
Ashish Kale ·
Infra
Kubeflow Upgrades Simplify AI on Kubernetes
The open-source AI platform Kubeflow has released major updates, including better Spark support, to simplify building complex AI systems on Kubernetes. The project is also nearing official graduation from the Cloud Native Computing Foundation, signaling its maturity.
Ashish Kale ·
Infra
Netflix Scrapped Its Own Tool for Open Source
Netflix has replaced its homegrown batch processing system with Kueue, an open-source alternative. The move gives them more features and saves the high cost of maintaining a custom internal tool for managing large-scale computing jobs.
Ashish Kale ·
Infra
GKE Adds Security Rules That Don't Bother Developers
Google Cloud has launched ClusterNetworkPolicy for its Kubernetes Engine (GKE). The new feature lets platform administrators set cluster-wide security rules that work alongside developer policies, improving security without slowing down individual teams.
Ashish Kale ·
Infra
Patch All Your Containers Without Touching a Dockerfile
Cloud Native Buildpacks are shifting container security away from individual Dockerfiles to centralized "builders." This allows platform teams to apply security patches across all company applications at once, simplifying and speeding up vulnerability response.
Ashish Kale ·
Infra
GitLab Wants to Be Your Only Secrets Manager
GitLab's Secrets Manager now works with Terraform and Kubernetes via the External Secrets Operator. This lets teams stop managing separate secret stores, simplifying workflows and boosting security by having one central place for all credentials.
Ashish Kale ·
Infra
AI Agents Don't Need Their Own Kubernetes Pods
A new approach for running AI agents on Kubernetes argues that assigning one pod per agent is wasteful. Instead, a shared pool of worker pods can run many agents, saving resources and improving efficiency for AI-native applications.
Ashish Kale ·
Data
ClickHouse Cloud Autoscaling Now Reacts in Seconds
ClickHouse Cloud rebuilt its autoscaling system to react to demand in seconds instead of minutes. This new 'fast path' approach helps prevent performance bottlenecks during traffic spikes and improves resource efficiency for its cloud database service.
Taranpreet Singh ·
Infra
HashiCorp Vault Now Secures Kubernetes From the Outside
HashiCorp released a public beta of a new Vault feature for Kubernetes. It lets you manage the encryption keys for your cluster's sensitive data outside of Kubernetes itself, adding a powerful new layer of security and compliance.
Ashish Kale ·
Infra
Argo CD Now Verifies Your Code’s Origin
The popular cloud deployment tool Argo CD is getting a major security boost. Its latest update adds features to verify that your code is authentic and to encrypt internal traffic, helping to secure your software supply chain.
Ashish Kale ·
Infra
Get a Clearer View of Your Kubernetes AI Jobs
A new plugin for the Headlamp Kubernetes UI now supports Volcano, a popular batch scheduler for AI and high-performance computing. This gives developers a simple web interface to inspect and manage complex batch jobs directly within Kubernetes.
Ashish Kale ·
Infra
Azure Kubernetes Now Runs Demanding AI and Bare Metal
Microsoft has updated its Azure Kubernetes Service with new features for AI, bare metal servers, and managing multiple clusters. This helps teams run more demanding applications and simplifies large-scale operations on the cloud.
Ashish Kale ·
Infra
Old Pixel Phones Power a New Private Cloud
Google and UC San Diego are building a private cloud using 2,000 retired Pixel phones. This project explores a sustainable, low-cost way to create computing infrastructure and reduce electronic waste from discarded smartphones.
Ashish Kale ·
Infra
Getting Kubernetes Certified Just Became Much Simpler
The CNCF, Linux Foundation, and Udemy have partnered to offer a unified training and certification path. This makes it much easier for developers to purchase courses and sit for official Kubernetes exams like CKA, CKAD, and CKS.
Ashish Kale ·
Security
Container Security Threats Are Evolving
As Docker and Kubernetes become standard for modern infrastructure, attackers are developing sophisticated new methods to compromise them. Research highlights a growing trend of attacks, from container escapes to complex supply chain compromises, targeting these widely used technologies and the companies that rely on them.
Neeraj Dhiman ·
Security
Gitea Flaw Exposes Private Images
A critical vulnerability in the Gitea self-hosted Git platform allows unauthenticated attackers to access and pull private container images. The flaw, affecting all versions before 1.26.2, requires no credentials for exploitation, posing a significant risk of intellectual property and sensitive data exposure.
Neeraj Dhiman ·
Security
Critical Linux Flaw Lets Attackers Escape Containers
Two critical vulnerabilities in systemd, a core Linux component, could allow attackers to escape containers or manipulate DNS records. The flaws affect widely used distributions, including Ubuntu 22.04 LTS.
Neeraj Dhiman ·
AI
Your Team's Culture Is Its New Operating System
Kubernetes co-creator Craig McLuckie argues that as AI tools change development, a deliberate team culture becomes the most critical factor for success. This shift affects everything from open source contributions to career paths.
Neeraj Dhiman ·
Infra
Stop Manually Syncing Kubernetes Secrets
As Kubernetes environments grow, teams often copy sensitive data like API keys across accounts, creating a security risk. A tool called External Secrets Operator automates this, keeping secrets in one place and syncing them securely.
Ashish Kale ·
Infra
NGINX Ingress Controller Now Natively Secures Traffic
NGINX Ingress Controller now natively supports mutual TLS (mTLS), making it much simpler for teams to secure traffic between services. This update helps enforce zero-trust security policies directly within Kubernetes without complex workarounds.
Ashish Kale ·
Frequently asked questions
What's the single highest-impact Kubernetes security control?
Enabling Pod Security Standards at the "restricted" profile by default and using admission controllers (Kyverno, OPA Gatekeeper) to enforce them. This single change blocks the majority of container-escape patterns and forces workload teams to explicitly justify privileged exceptions.
How do you handle Kubernetes CVE patching at scale?
Maintain a managed-cluster footprint (EKS/GKE/AKS) so the control plane patches automatically; treat node images as immutable and roll them via a managed node-group rolling update; subscribe to vendor PSIRT advisories and the upstream kubernetes-security-announce list.
What's a SBOM and why does Kubernetes need it?
A software bill of materials lists every component inside a container image. With SBOMs published alongside images and signed via Sigstore/cosign, you can answer "are any of my running workloads affected by CVE-X?" in seconds instead of days. The Kubernetes project itself publishes signed SBOMs for every release.