Mattias Gess's Avatar

Mattias Gess

@mattiasgees.bsky.social

โ˜ธ๏ธ All things #Kubernetes #SPIFFE #SPIRE #cert-manager โค๏ธ Open-source ๐Ÿƒ Runner ๐Ÿ’ป Director of Tech Workload Identity @CyberArk | Previously @Jetstack @Skyscrapers ๐Ÿ•ธ๏ธ https://gees.dev

44 Followers  |  87 Following  |  25 Posts  |  Joined: 07.11.2024  |  1.9152

Latest posts by mattiasgees.bsky.social on Bluesky

I agree that the TOC shouldn't allow the external-secrets-operator to become an Incubating project as is, but a bit more empathy towards maintainers would be nice.

14.08.2025 18:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Something that is one my mind for quite some time, but I do wonder what the value is of donating an open-source project to the #CNCF. In reality a lot of the donated projects are being contributed by only 1 or 2 companies.

14.08.2025 08:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
[Incubation] external-secrets-operator Incubation Application ยท Issue #1486 ยท cncf/toc external-secrets-operator Incubation Application Project Repo(s): https://github.com/external-secrets/external-secrets Project Site: https://external-secrets.io/latest Sub-Projects: https://github....

CNCF TOC reaction when the maintainers of external-secrets-operator ask for help in the community is a bit baffling. They propose to close the application for incubation status for the time being #noempathy github.com/cncf/toc/iss...

14.08.2025 08:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

I went with Karakeep over the weekend for the same reason. No off-line reading functionality but they are working on it

27.05.2025 06:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Security Features

PostgreSQL 18 introduces oauth authentication, which lets users authenticate using OAuth 2.0 mechanisms supported through PostgreSQL extensions. Additionally, PostgreSQL 18 adds several features to validate and enforce FIPS mode behavior, and also adds the ssl_tls13_ciphers to let users configure which TLS v1.3 cipher suites the server can use.

This release deprecates md5 password authentication in favor of using SCRAM authentication that was first added in PostgreSQL 10. md5 authentication will be fully removed in a future major version release. Additionally, PostgreSQL 18 adds support for SCRAM passthrough authentication with both postgres_fdw and dblink when authenticating to remote PostgreSQL instances.

Security Features PostgreSQL 18 introduces oauth authentication, which lets users authenticate using OAuth 2.0 mechanisms supported through PostgreSQL extensions. Additionally, PostgreSQL 18 adds several features to validate and enforce FIPS mode behavior, and also adds the ssl_tls13_ciphers to let users configure which TLS v1.3 cipher suites the server can use. This release deprecates md5 password authentication in favor of using SCRAM authentication that was first added in PostgreSQL 10. md5 authentication will be fully removed in a future major version release. Additionally, PostgreSQL 18 adds support for SCRAM passthrough authentication with both postgres_fdw and dblink when authenticating to remote PostgreSQL instances.

PostgreSQL, the open source database that continues to get better, is introducing oauth support. This should help with database automation and hopefully bring us one step closer to moving away from static credentials and copying usernames and passwords around. www.postgresql.org/about/news/p...

12.05.2025 22:52 โ€” ๐Ÿ‘ 382    ๐Ÿ” 61    ๐Ÿ’ฌ 7    ๐Ÿ“Œ 4

I was at RSA for the first time last year and found it interesting how many people were wearing their badges in public outside of the conference venue.

29.04.2025 13:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

More comparable to the first guides on how to get started with Kubernetes.

16.04.2025 09:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Any good technical or product book recommendations?

16.04.2025 08:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - MattiasGees/spiffe-demo: Showcasing the potential of SPIFFE with real-life services Showcasing the potential of SPIFFE with real-life services - MattiasGees/spiffe-demo

Updated my #SPIFFE demos with support for AWS IAM Roles Anywhere next to JWT Federation
github.com/MattiasGees/...

06.02.2025 14:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

The year delay was already factored in, the month exploring wasnโ€™t planned ๐Ÿ˜€

27.11.2024 22:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - MattiasGees/spiffe-demo: Showcasing the potential of SPIFFE with real-life services Showcasing the potential of SPIFFE with real-life services - MattiasGees/spiffe-demo

I added a demo on using Google Cloud with my #spiffe demos. Thanks to Raf for doing most of the hard work github.com/MattiasGees/...

27.11.2024 10:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The #kubecon jetlag is real after returning yesterday! Slowly getting back into everyday life.

18.11.2024 10:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What a #kubecon, so great to see so many familiar faces and hang out with them. Currently I am very tired, but I am so energised.

16.11.2024 04:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Last talk of #kubecon for me. #SPIFFE the easy way with #cert-manager

15.11.2024 23:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Open source 2.0 the maintainers perspective #kubecon

15.11.2024 18:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Massive queue for the #cert-manager booth at #kubecon last chance to get your physical certificate

15.11.2024 17:56 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Heroku had an early concept of the 12 Factor App, and in a Cloud Native world, it's time for an update. Twelve-Factor is now an open source project! And the Maintainers have plans with how it's going to change.

15.11.2024 16:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Solo.io contributes Gloo to the CNCf as K8sGateway - they released the PR live on stage #KubeCon

14.11.2024 16:48 โ€” ๐Ÿ‘ 11    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Intro to SPIRE and the upcoming forced rotation feature #kubecon

14.11.2024 18:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Day 2 keynotes are happening at #kubecon

14.11.2024 16:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you again @dfeldman.org for the great talk in the history of Workload Identity

12.11.2024 18:34 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Louis Bailleul talking about running SPIRE on actual ships

12.11.2024 18:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Kicking of the Workload Identity Day Zero with @dfeldman.org and a journey through Workload Identity

12.11.2024 17:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Starting the #kubecon week with some #SPIFFE and #SPIRE training.

11.11.2024 16:43 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

My first #Rejekts and I have to say I like the vibe ๐Ÿ˜€

10.11.2024 17:40 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Made it to the first day of #Rejekts2024 #cncf

10.11.2024 16:47 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Right on time for #Kubecon SLC. Really looking forward to see the community again and talk all things #Kubernetes

09.11.2024 07:53 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Finally excited the other platform and trying out Bluesky.

09.11.2024 07:52 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@mattiasgees is following 19 prominent accounts