Spotlight

Enforcing Signed Container Images in Kubernetes Using Cosign & Kyverno

Hansaka Biyon

This tutorial teaches how to enforce signed container images in Kubernetes using Cosign for signing, Harbor for storage, and Kyverno admission controller for verification, including custom CA trust configuration and CI/CD integration patterns.

More articles →

Tools and utilities

  • Kubeinvaders

    With k-inv, you can stress a Kubernetes cluster in a fun way and check its resilience by playing space invaders.

  • Kelos

    Kelos runs Claude Code, Codex, Gemini, and OpenCode as ephemeral Kubernetes pods, with CRDs for Tasks, Workspaces, AgentConfigs, and TaskSpawners that can auto-create PRs from GitHub issues, and chain tasks with dependsOn pipelines.

  • Prepackaged K3s Platform for Single-Node Kubernetes on VPS

    Kubee automates the setup of a K3s cluster on a single VPS and installs tightly integrated Helm charts (ArgoCD, Vault, Prometheus, etc.) with zero manual configuration.

  • Sealed Secrets Web

    Sealed Secrets Web is a tool that provides a web interface for managing and encrypting sensitive data in Kubernetes using the Sealed Secrets service by Bitnami.

  • ESP Kubernetes Reference Implementation

    ESP Kubernetes Reference Implementation runs compliance scanning in Kubernetes using ESP policies with pull-based agents that execute NIST, CIS, and STIG controls and produce CUI-free attestations forwarded to SIEM or cloud functions.

More projects →

Events starting soon

Discover more events onn Kube Events →

The Hidden Cost of Slow Autoscaling
The Hidden Cost of Slow Autoscaling

Forced platform migrations are usually treated as something to survive. At Scout24, a mandatory OS migration became an opportunity to rethink Kubernetes autoscaling, node provisioning, and infrastructure efficiency.

John Ford explains how Scout24 moved its EKS-based Infinity platform from a polling autoscaler and over-provisioned capacity to Karpenter and Bottlerocket. The result was faster node startup, a safer migration path, and about a 30% infrastructure reduction without major downtime.

In this interview:

  • Why two-minute node provisioning forced a 25% capacity buffer
  • How Karpenter made the Bottlerocket migration safer
  • What broke around EC2 metadata, AWS SDKs, and cgroups
  • How the new foundation enables Spot, ARM, and GPU workloads

Learn from production

More case studies →

Matching jobs

    • Data Engineer with System

    • Salary: $18K to $266.2K a year

    • Location: based in the office in New York, NY, USA

    • Tech stack: Kubernetes, AWS, Azure, GCP, Docker, Python, SQL, Airflow, Spark

    • DevOps Engineer with Absorb

    • Salary: $90 to $484K a year

    • Location: remote from

    • Tech stack: Kubernetes, AWS, Docker, C#, Powershell, Cloudformation, Bamboo, Prometheus, Sumo Logic

    • DevSecOps Engineer with David AI

    • Salary: $12.6K to $415.14K a year

    • Location: based in the office (and remote from home) in San Francisco, CA, USA

    • Tech stack: Kubernetes, AWS, Typescript, PostgreSQL, Terraform, Datadog, Grafana, Prometheus

    • Platform Engineer with David AI

    • Salary: $108K to $385K a year

    • Location: based in the office in San Francisco, CA, USA

    • Tech stack: Kubernetes, AWS, Typescript, PostgreSQL, Terraform, Datadog, Grafana, Prometheus

    • Platform Engineer with Normal Computing Corporation

    • Salary: $83.25K to $401.5K a year

    • Location: based in the office (and remote from home) in New York City, NY, USA

    • Tech stack: Kubernetes, Docker, Redis, Terraform

Discover more Kubernetes jobs on Kube Careers →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 187 issues and counting.

or subscribe via

Build something

More tutorials →

Call for Papers closing soon

  1. 2

    days

    DevSecOps Days Washington DC 2026

    The Call For Paper is open until 12 June 2026 at GMT-4. More info →
    • Location: Arlington, VA, USA

    • In-person conference organized by Carnegie Mellon University.

    • The conference starts on the 3 April 2026.

    • Apply here
  2. 2

    days

    fwd:cloudsec Europe 2026

    The Call For Paper is open until 12 June 2026 at GMT-4. More info →
    • Location: London, GB

    • In-person conference organized by Forward CloudSec.

    • The conference starts on the 8 September 2026.

    • Apply here
  3. 5

    days

    Update Conference Prague 2026

    The Call For Paper is open until 15 June 2026 at GMT-4. More info →
    • Location: Prague, CZ

    • In-person conference organized by Update Conference.

    • The conference starts on the 13 November 2026.

    • Apply here
  4. 5

    days

    Kubernetes Community Days San Francisco Bay Area 2026

    The Call For Paper is open until 15 June 2026 at GMT-4. More info →
    • Location: San Francisco, US

    • In-person conference organized by KCD SF Bay Area.

    • The conference starts on the 1 September 2026.

    • Apply here
  5. 5

    days

    Devopsdays Barcelona

    The Call For Paper is open until 15 June 2026 at GMT-4. More info →
    • Location: Barcelona, ES

    • In-person conference organized by Devopsdays.

    • The conference starts on the 13 November 2026.

    • Apply here
  6. 5

    days

    Devopsdays Portland

    The Call For Paper is open until 15 June 2026 at GMT-4. More info →
    • Location: Portland, OR, USA

    • In-person conference organized by Devopsdays.

    • The conference starts on the 8 September 2026.

    • Apply here
  7. 10

    days

    EuroBSDCon

    The Call For Paper is open until 20 June 2026 at GMT-4. More info →
    • Location: Brussels, BE

    • In-person conference organized by EuroBSDCon Foundation.

    • The conference starts on the 13 September 2026.

    • Apply here

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

More articles

Even more articles →