Posts in 2023
Spotlight on SIG ContribEx
Monday, August 14, 2023 in Blog
Author: Fyka Ansari Welcome to the world of Kubernetes and its vibrant contributor community! In this blog post, we'll be shining a spotlight on the Special Interest Group for Contributor Experience (SIG ContribEx), an essential component of the …
Spotlight on SIG CLI
Thursday, July 20, 2023 in Blog
Author: Arpit Agrawal In the world of Kubernetes, managing containerized applications at scale requires powerful and efficient tools. The command-line interface (CLI) is an integral part of any developer or operator’s toolkit, offering a convenient …
Confidential Kubernetes: Use Confidential Virtual Machines and Enclaves to improve your cluster security
Thursday, July 06, 2023 in Blog
Authors: Fabian Kammel (Edgeless Systems), Mikko Ylinen (Intel), Tobin Feldman-Fitzthum (IBM) In this blog post, we will introduce the concept of Confidential Computing (CC) to improve any computing environment's security and privacy properties. …
Verifying Container Image Signatures Within CRI Runtimes
Thursday, June 29, 2023 in Blog
Author: Sascha Grunert The Kubernetes community has been signing their container image-based artifacts since release v1.24. While the graduation of the corresponding enhancement from alpha to beta in v1.26 introduced signatures for the binary …
dl.k8s.io to adopt a Content Delivery Network
Friday, June 09, 2023 in Blog
Authors: Arnaud Meukam (VMware), Hannah Aubry (Fastly), Frederico Muñoz (SAS Institute) We're happy to announce that dl.k8s.io, home of the official Kubernetes binaries, will soon be powered by Fastly. Fastly is known for its high-performance content …
Using OCI artifacts to distribute security profiles for seccomp, SELinux and AppArmor
Wednesday, May 24, 2023 in Blog
Author: Sascha Grunert The Security Profiles Operator (SPO) makes managing seccomp, SELinux and AppArmor profiles within Kubernetes easier than ever. It allows cluster administrators to define the profiles in a predefined custom resource YAML, which …
Having fun with seccomp profiles on the edge
Thursday, May 18, 2023 in Blog
Author: Sascha Grunert The Security Profiles Operator (SPO) is a feature-rich operator for Kubernetes to make managing seccomp, SELinux and AppArmor profiles easier than ever. Recording those profiles from scratch is one of the key features of this …
Kubernetes 1.27: KMS V2 Moves to Beta
Tuesday, May 16, 2023 in Blog
Authors: Anish Ramasekar, Mo Khan, and Rita Zhang (Microsoft) With Kubernetes 1.27, we (SIG Auth) are moving Key Management Service (KMS) v2 API to beta. What is KMS? One of the first things to consider when securing a Kubernetes cluster is …
Kubernetes 1.27: updates on speeding up Pod startup
Monday, May 15, 2023 in Blog
Authors: Paco Xu (DaoCloud), Sergey Kanzhelev (Google), Ruiwen Zhao (Google) How can Pod start-up be accelerated on nodes in large clusters? This is a common issue that cluster administrators may face. This blog post focuses on methods to speed up …
Kubernetes 1.27: In-place Resource Resize for Kubernetes Pods (alpha)
Friday, May 12, 2023 in Blog
Author: Vinay Kulkarni (Kubescaler Labs) If you have deployed Kubernetes pods with CPU and/or memory resources specified, you may have noticed that changing the resource values involves restarting the pod. This has been a disruptive operation for …