A kubelet image credential provider for Alibaba Cloud Container Registry(ACR)
github.com/mozillazg/ku...
@mozillazg.bsky.social
https://github.com/mozillazg
A kubelet image credential provider for Alibaba Cloud Container Registry(ACR)
github.com/mozillazg/ku...
If you are a volunteer maintainer of an open source project, you owe nobody a "responsible disclosure" policy. If enterprises and foundations want you to have one, tell them they can pay you.
17.10.2025 16:50 β π 1 π 1 π¬ 0 π 0what happens if u cut 4 wires out of an ethernet cable & then plug it into yr PC
09.10.2025 14:04 β π 294 π 44 π¬ 16 π 4Our State of Cloud Security 2025 study is out!
www.datadoghq.com/state-of-clo...
β’ On AWS, 40% of organizations leverage data perimeters
β’ 11% of Google Cloud GKE and 23% of Google Cloud VMs are overprivileged
β’ On Azure, 1.3% of storage containers are public, 58% proactively block public access
Calling all Kubernetes security interested folk. We're planning the next version of the OWASP Kubernetes Top 10, and have a survey to solicit ideas and feedback here docs.google.com/forms/d/e/1F... . Shouldn't take more than a couple of minutes to fill out and all feedback's welcome!
06.10.2025 13:10 β π 6 π 7 π¬ 0 π 0If you're new to the Unix or Linux command line, I just want you to know:
Me and all my colleagues with years of experience
Still get confused between `ln -s` and `ln` daily.
Screenshot of the eBPF workshop program, showing Session 3 ("Time for Better and Safer Programming") and the beginning of Session 4 ("Profiling meets Machine Learning and Privacy").
The list of papers accepted at the 3rd #eBPF workshop has been published! conferences.sigcomm.org/sigcomm/2025...
11.08.2025 15:32 β π 4 π 3 π¬ 0 π 0Please please please please do not follow this advice. Sealed secrets are a terrible idea. Git is designed to be easily branchesd and not tracked. Secrets management is about tracking secrets and easy rotation. Encrypting data in git isn't more secure then keeping your secrets in etcd.
16.08.2025 18:24 β π 5 π 1 π¬ 1 π 0Ok, I have a rant I have to let go of.
If you generate a change to an open-source project fully with AI, didn't read, review, understand, and questioned it, then at least have the decency to say this on the PR description.
You're stealing people's time by making them review it for you.
MCP Server for Kubernetes Audit Logs
github.com/mozillazg/ku...
Next eBPF acquisition in the books, this time for security
www.cyera.com/de/press-rel...
Screenshot of the top of the list, showing the interactive selectors and the three eBPF papers published at NSDI'25.
With NSDI'25 coming to an end today, I've updated the list of #eBPF papers to include the three papers published at USENIX NSDI this year! pchaigno.github.io/bpf/2025/01/...
30.04.2025 15:01 β π 2 π 2 π¬ 0 π 0table of contents for tmp.0ut volume 4
Would you look at that, it's tmp.0ut Volume 4! Happy Friday, hope you enjoy this latest issue!
tmpout.sh/4/
I've added talk recordings to my list of eBPF papers, when available. That's 33 videos of ~20min discussing various aspects and use cases of #eBPF!
pchaigno.github.io/bpf/2025/01/...
ptcpdump v0.32.1 is released!
1. fix(backend): enable process filtering for the cgroup-skb backend
2. Use BPF ringbuf instead of perfbuf when kernel support is available
3. improve detection of backported tcx/ringbuf support in older kernels
github.com/mozillazg/pt...
The next blog in our #Kubernetes #Security fundamentals series is out now. This time we're taking a look at the world of network security!
securitylabs.datadoghq.com/articles/kub...
ptcpdump v0.32.0 is released!
* Add support for capturing traffic based on user ID
* Enrich capture output with user information
* Support for displaying thread ID and name in cgroup-skb output
github.com/mozillazg/pt...
First blog post of the new year and this is one I've been meaning to write up for a while which is some details on #Kubernetes API Server proxy feature and how it might be possible to use some known weaknesses in it to escalate your privileges in a cluster.
raesene.github.io/blog/2025/01...
The next in my #Kubernetes #Security fundamentals video series is up now.
This time I'm looking at how service account authentication works in Kubernetes, with some hopefully interesting details on how bound service account tokens work.
youtu.be/jTswj4CS4IA?...
I've made an interactive list of #eBPF research papers. Only papers from the top academic conferences, including lots of papers on eBPF verification, kernel offloads, security analysis, etc.
pchaigno.github.io/bpf/2025/01/...
I plan to keep the list up-to-date.
Exploring Workload Identity Federation for GKE
mozillazg.com/2025/01/secu...
happy new year!π₯ππ₯³ππ
01.01.2025 01:26 β π 1 π 0 π¬ 0 π 0ptcpdump v0.31.0 is released!
github.com/mozillazg/pt...
writing about the terminal is so funny because it's like "redirects are so useful! hooray!"
"okay and also `cmd file.txt > file.txt` will permanently delete the contents of `file.txt`β
lots of cool useful tools with the occasional horrifying fact that you just need to keep seared into your memory
dockerc: container image to single executable compiler
github.com/NilsIrl/dock...
My re:Invent talk is up! www.youtube.com/watch?v=yuXF...
04.12.2024 18:13 β π 12 π 2 π¬ 0 π 0Stratus Red Team v2.20.0 is now available, with great contributions from @flekyy90.bsky.social allowing you to reproduce AWS TTPs seen in the wild!
β Use GetFederationToken to generate temporary credentials
β Use SendSerialConsoleSSHPublicKey to pivot to EC2 instances
github.com/DataDog/stra...
We're now officially on Bluesky!
Expect:
β New articles on Security Labs about cloud, container and application security
β OSS projects for cloud security practioners
β Conference talks at community conferences
See also our starter pack bsky.app/starter-pack... with our authors and researchers!