mozillazg's Avatar

mozillazg

@mozillazg.bsky.social

https://github.com/mozillazg

13 Followers  |  96 Following  |  10 Posts  |  Joined: 02.12.2024  |  1.6504

Latest posts by mozillazg.bsky.social on Bluesky

Preview
GitHub - mozillazg/kubelet-credential-provider-acr: A kubelet image credential provider for Alibaba Cloud Container Registry(ACR) A kubelet image credential provider for Alibaba Cloud Container Registry(ACR) - mozillazg/kubelet-credential-provider-acr

A kubelet image credential provider for Alibaba Cloud Container Registry(ACR)
github.com/mozillazg/ku...

19.10.2025 07:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If you are a volunteer maintainer of an open source project, you owe nobody a "responsible disclosure" policy. If enterprises and foundations want you to have one, tell them they can pay you.

17.10.2025 16:50 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

what happens if u cut 4 wires out of an ethernet cable & then plug it into yr PC

09.10.2025 14:04 β€” πŸ‘ 294    πŸ” 44    πŸ’¬ 16    πŸ“Œ 4
Preview
State of Cloud Security | Datadog For our 2025 report, we analyzed AWS, Google Cloud, and Azure data from thousands of organizations to understand the latest trends in cloud security posture.

Our State of Cloud Security 2025 study is out!

www.datadoghq.com/state-of-clo...

β€’ On AWS, 40% of organizations leverage data perimeters
β€’ 11% of Google Cloud GKE and 23% of Google Cloud VMs are overprivileged
β€’ On Azure, 1.3% of storage containers are public, 58% proactively block public access

08.10.2025 21:10 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 1    πŸ“Œ 1
Preview
OWASP Kubernetes Top 10 2025 Survey We're looking to update the OWASP Kubernetes Top 10 and as such want to canvas ideas on what should be included. The goal of the Top 10 is to provide awareness on the most serious risks that Kubernet...

Calling all Kubernetes security interested folk. We're planning the next version of the OWASP Kubernetes Top 10, and have a survey to solicit ideas and feedback here docs.google.com/forms/d/e/1F... . Shouldn't take more than a couple of minutes to fill out and all feedback's welcome!

06.10.2025 13:10 β€” πŸ‘ 6    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0

If you're new to the Unix or Linux command line, I just want you to know:

Me and all my colleagues with years of experience

Still get confused between `ln -s` and `ln` daily.

31.08.2025 17:36 β€” πŸ‘ 299    πŸ” 27    πŸ’¬ 30    πŸ“Œ 6
Screenshot of the eBPF workshop program, showing Session 3 ("Time for Better and Safer Programming") and the beginning of Session 4 ("Profiling meets Machine Learning and Privacy").

Screenshot of the eBPF workshop program, showing Session 3 ("Time for Better and Safer Programming") and the beginning of Session 4 ("Profiling meets Machine Learning and Privacy").

The list of papers accepted at the 3rd #eBPF workshop has been published! conferences.sigcomm.org/sigcomm/2025...

11.08.2025 15:32 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

Please please please please do not follow this advice. Sealed secrets are a terrible idea. Git is designed to be easily branchesd and not tracked. Secrets management is about tracking secrets and easy rotation. Encrypting data in git isn't more secure then keeping your secrets in etcd.

16.08.2025 18:24 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Ok, I have a rant I have to let go of.

If you generate a change to an open-source project fully with AI, didn't read, review, understand, and questioned it, then at least have the decency to say this on the PR description.

You're stealing people's time by making them review it for you.

16.08.2025 11:23 β€” πŸ‘ 40    πŸ” 7    πŸ’¬ 3    πŸ“Œ 1
Preview
GitHub - mozillazg/kube-audit-mcp: MCP Server for Kubernetes Audit Logs MCP Server for Kubernetes Audit Logs. Contribute to mozillazg/kube-audit-mcp development by creating an account on GitHub.

MCP Server for Kubernetes Audit Logs
github.com/mozillazg/ku...

10.08.2025 12:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Next eBPF acquisition in the books, this time for security

www.cyera.com/de/press-rel...

10.07.2025 08:30 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Screenshot of the top of the list, showing the interactive selectors and the three eBPF papers published at NSDI'25.

Screenshot of the top of the list, showing the interactive selectors and the three eBPF papers published at NSDI'25.

With NSDI'25 coming to an end today, I've updated the list of #eBPF papers to include the three papers published at USENIX NSDI this year! pchaigno.github.io/bpf/2025/01/...

30.04.2025 15:01 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
table of contents for tmp.0ut volume 4

table of contents for tmp.0ut volume 4

Would you look at that, it's tmp.0ut Volume 4! Happy Friday, hope you enjoy this latest issue!

tmpout.sh/4/

21.03.2025 16:26 β€” πŸ‘ 126    πŸ” 66    πŸ’¬ 2    πŸ“Œ 7

I've added talk recordings to my list of eBPF papers, when available. That's 33 videos of ~20min discussing various aspects and use cases of #eBPF!
pchaigno.github.io/bpf/2025/01/...

11.02.2025 16:01 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v0.32.1 Β· mozillazg/ptcpdump Changelog 792bbe1 fix(backend): enable process filtering for the cgroup-skb backend (#246) 020852d chore(bpf): improve detection of backported tcx/ringbuf support in older kernels (#244) d8b42a1 c...

ptcpdump v0.32.1 is released!

1. fix(backend): enable process filtering for the cgroup-skb backend
2. Use BPF ringbuf instead of perfbuf when kernel support is available
3. improve detection of backported tcx/ringbuf support in older kernels

github.com/mozillazg/pt...

10.02.2025 13:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Kubernetes security fundamentals: Networking | Datadog Security Labs A look at how network security works in Kubernetes

The next blog in our #Kubernetes #Security fundamentals series is out now. This time we're taking a look at the world of network security!

securitylabs.datadoghq.com/articles/kub...

29.01.2025 13:15 β€” πŸ‘ 19    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Release v0.32.0 Β· mozillazg/ptcpdump Changelog f5c4d69 feat(filter): Add support for capturing traffic based on user ID (#233) 924c6fa chore(deps): update github.com/cilium/ebpf to v0.17.1 (#232) 3f1dab8 chore(output): Remove group I...

ptcpdump v0.32.0 is released!
* Add support for capturing traffic based on user ID
* Enrich capture output with user information
* Support for displaying thread ID and name in cgroup-skb output
github.com/mozillazg/pt...

19.01.2025 15:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Exploring the Kubernetes API Server Proxy

First blog post of the new year and this is one I've been meaning to write up for a while which is some details on #Kubernetes API Server proxy feature and how it might be possible to use some known weaknesses in it to escalate your privileges in a cluster.

raesene.github.io/blog/2025/01...

18.01.2025 12:54 β€” πŸ‘ 24    πŸ” 14    πŸ’¬ 0    πŸ“Œ 0
Kubernetes Security Fundamentals: Authentication - Part 3
YouTube video by Datadog Kubernetes Security Fundamentals: Authentication - Part 3

The next in my #Kubernetes #Security fundamentals video series is up now.

This time I'm looking at how service account authentication works in Kubernetes, with some hopefully interesting details on how bound service account tokens work.

youtu.be/jTswj4CS4IA?...

14.01.2025 17:38 β€” πŸ‘ 35    πŸ” 9    πŸ’¬ 0    πŸ“Œ 1
Preview
eBPF Research Papers When I started reading on BPF there weren’t many academic papers to describe how it worked, how it didn’t, or how it is used. There are many blog posts and informal articles out there, but it’s harder...

I've made an interactive list of #eBPF research papers. Only papers from the top academic conferences, including lots of papers on eBPF verification, kernel offloads, security analysis, etc.
pchaigno.github.io/bpf/2025/01/...
I plan to keep the list up-to-date.

07.01.2025 16:30 β€” πŸ‘ 18    πŸ” 13    πŸ’¬ 1    πŸ“Œ 1
Preview
Exploring Workload Identity Federation in GKE In this article, we will briefly explore a feature called "Workload Identity Federation for GKE" that was recently announced by GKE in their official blog. Features Overview Workload Identity Federati...

Exploring Workload Identity Federation for GKE
mozillazg.com/2025/01/secu...

10.01.2025 01:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

happy new year!πŸ’₯πŸŽ‡πŸ₯³πŸŽ‰πŸŽŠ

01.01.2025 01:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v0.31.0 Β· mozillazg/ptcpdump Changelog b4870fe feat: support filter by container-id prefix matching 12 or more characters (#218) e3fa2ee feat(platform): Add support for OpenWrt 24.10 on x86-64 architecture (#214) a353f78 chor...

ptcpdump v0.31.0 is released!
github.com/mozillazg/pt...

22.12.2024 05:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

writing about the terminal is so funny because it's like "redirects are so useful! hooray!"

"okay and also `cmd file.txt > file.txt` will permanently delete the contents of `file.txt`”

lots of cool useful tools with the occasional horrifying fact that you just need to keep seared into your memory

13.12.2024 21:31 β€” πŸ‘ 289    πŸ” 25    πŸ’¬ 19    πŸ“Œ 4
Preview
Release v0.30.0 Β· mozillazg/ptcpdump Changelog 7d71bb8 chore(bpf): Optimize BPF attachment by skipping netdev hooks when not using TC backend (#209) 0308649 feat(capture): Add --backend=cgroup-skb support for cgroup-based packet capt...

github.com/mozillazg/pt...

08.12.2024 07:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
pcapng: support read and write Enhanced Packet Block (EPB) options by mozillazg Β· Pull Request #58 Β· gopacket/gopacket

github.com/gopacket/gop...

08.12.2024 03:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
GitHub - NilsIrl/dockerc: container image to single executable compiler container image to single executable compiler. Contribute to NilsIrl/dockerc development by creating an account on GitHub.

dockerc: container image to single executable compiler
github.com/NilsIrl/dock...

05.12.2024 13:28 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
AWS re:Invent 2024 - Securing Kubernetes workloads in Amazon EKS (KUB315)
YouTube video by AWS Events AWS re:Invent 2024 - Securing Kubernetes workloads in Amazon EKS (KUB315)

My re:Invent talk is up! www.youtube.com/watch?v=yuXF...

04.12.2024 18:13 β€” πŸ‘ 12    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image

Stratus Red Team v2.20.0 is now available, with great contributions from @flekyy90.bsky.social allowing you to reproduce AWS TTPs seen in the wild!

βž” Use GetFederationToken to generate temporary credentials

βž” Use SendSerialConsoleSSHPublicKey to pivot to EC2 instances

github.com/DataDog/stra...

04.12.2024 16:20 β€” πŸ‘ 14    πŸ” 9    πŸ’¬ 1    πŸ“Œ 2

We're now officially on Bluesky!

Expect:

βž” New articles on Security Labs about cloud, container and application security
βž” OSS projects for cloud security practioners
βž” Conference talks at community conferences

See also our starter pack bsky.app/starter-pack... with our authors and researchers!

03.12.2024 14:30 β€” πŸ‘ 20    πŸ” 9    πŸ’¬ 2    πŸ“Œ 2

@mozillazg is following 20 prominent accounts