Tag: Kubernetes
All the articles with the tag "Kubernetes".
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Blockchain#Hoodi#Validator
Hoodi Validator Use Cases and Data Flows
How Hoodi execution, consensus, validation, signing, and observability components exchange data in a Kubernetes-based validator platform.
3 min read - #Vault#Kubernetes#Hoodi
cert-manager and Vault: Roles, Scope, and Collaboration
How cert-manager, Vault, Kubernetes, and AWS KMS work together to protect Vault transport, workload identity, and validator secrets.
15 min read - #Vault#Identity Management#Kubernetes
Identity Management Using Vault
How Vault, Kubernetes, AWS, and GitHub divide responsibility for workload, operator, and release identities.
7 min read - #Kubernetes#EKS#Hoodi
Kubernetes Namespace Design for a Hoodi Validator
A security-focused guide to designing Kubernetes namespace boundaries for a Hoodi validator architecture.
6 min read - #Vault#Kubernetes#EKS
Vault Architecture on Kubernetes
A practical guide to Vault architecture, workload identity, secret delivery, PKI, and operations on Kubernetes.
8 min read - #Vault#Ethereum#Hoodi
Vault Secret Management for Hoodi Validator
How Vault Agent delivers validator secrets for Engine API authentication, TLS, signing, and slashing protection.
8 min read - #AWS#ECR#EKS
Private ECR Delivery Architecture for Private EKS
A defense-in-depth design for delivering approved private ECR artifacts to private EKS workloads.
Updated:15 min read - #AWS#EKS#Kubernetes
EKS Security Controls Implemented in the Cluster Design
A technical overview of EKS security controls implemented across the cluster design.
8 min read - #Ethereum#Hoodi#AWS
Private EKS Security Design Review
A confidentiality-focused security design review of a private EKS environment.
10 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Local Accounts Check to Prowler
How Prowler identifies AKS clusters that still allow local Kubernetes accounts to bypass Microsoft Entra ID authentication.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Monitor Check to Prowler
How Prowler identifies AKS clusters without Azure Monitor managed Prometheus metrics enabled.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Defender Check to Prowler
How Prowler identifies AKS clusters without Microsoft Defender for Containers security monitoring enabled.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Auto-Upgrade Check to Prowler
How Prowler identifies AKS clusters without an automatic Kubernetes upgrade channel and helps prevent version drift.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the EKS SaaS baseline, and why tenant deletion is a control-plane workflow, not a single DynamoDB delete.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (9) - CI/CD Verification
Gating EKS SaaS deployments on requirement IDs, from rendering Helm and Kustomize manifests to running tenant-boundary tests across Cognito pools.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (8) - Evidence and Review
Why an EKS SaaS requirement is a criterion rather than proof, and how the plugin ties NetworkPolicy, IRSA, and tenant-context requirements to evidence-based status.
2 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (7) - Refresh and Lifecycle
Refreshing the EKS SaaS security contract as ingress, cluster topology, and IAM bindings change, without losing prior approvals, evidence, or requirement history.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (6) - Authoring, Validation, and Publication
Writing atomic, verifiable EKS SaaS requirements for tenant identity, network isolation, IRSA, and the provisioning pipeline, validated by code before publication.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (5) - Responsibility and Prioritization
Splitting EKS SaaS work across AWS, the platform team, product teams, and the SaaS operator, and why IRSA and shared controllers need more than one owner.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (4) - Blast Radius
Calculating blast radius across the AWS EKS SaaS reference architecture, from a contained siloed order table to a provisioning pipeline that can reach the whole account.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (3) - Threat Analysis
A ten-threat model across the AWS EKS SaaS reference architecture's shared control plane, tenant namespaces, ingress routing, and IAM Roles for Service Accounts.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (2) - CIA Impact and Baseline
Calculating CIA impact for the AWS EKS SaaS reference architecture, where pooled and siloed DynamoDB models and a shared control plane both feed the result.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's EKS SaaS reference architecture, where namespace-per-tenant isolation and a shared control plane change what counts as a boundary.
6 min read - #Security Design#Security Requirements#Plugin
Security Requirements Plugin - Kubernetes Analysis Added
Turning Kubernetes manifests into a security graph so RBAC, NetworkPolicy, service mesh, and cloud IAM relationships feed blast-radius and requirements analysis.
9 min read