Spotlight

Detecting vulnerabilities in public Helm charts

Nigel Douglas

This article shows how to scan Helm charts for insecure RBAC, secret leaks, and malicious templates using tools like Trivy, GitHub Search, and OPA.

More articles →

Tools and utilities

  • Gefyra: local app development

    Gefyra runs local code in any Kubernetes cluster without the build and push cycle.

  • Cluster API Incus: Kubernetes LXC provider

    This Cluster API provider lets you create and manage Kubernetes clusters running on Incus virtual machines using declarative Kubernetes-style configurations.

  • Benchmark Suite for Gateway API Implementations

    This tool provides a comprehensive test suite to evaluate real-world behavior (latency, scale, route propagation, traffic) of Kubernetes Gateway API implementations, beyond basic conformance.

  • Guardon: Real-time Kubernetes Policy Enforcement

    Guardon is a Kubernetes admission controller that enforces security and compliance policies in real-time before resources are created in your cluster.

  • Valkey cluster operator

    Valkey Operator is a Kubernetes operator that automates deployment and lifecycle management of Valkey clusters and instances with features like automated installation and configuration management.

More projects →

Events starting soon

Discover more events onn Kube Events →

Kubernetes is not just for Black Friday
Kubernetes is not just for Black Friday

You self-host services at home, but upgrades break things, rollbacks require SSH-ing in to kill containers manually, and there's no safety net if your hardware fails.

Thibault Martin, Director of Program Development at the Matrix Foundation, walked this exact path — from Docker Compose to Podman with Ansible to Kubernetes on a single server — and explains why each transition happened and what it solved.

In this interview:

  • Why Ansible's declarative promise fell short with the Podman collection, forcing sequential imperative steps instead of desired-state definitions
  • How community Helm charts replace the need to write and maintain every manifest yourself
  • Why GitOps isn't just a deployment workflow — it's a disaster recovery strategy when your infrastructure lives in your living room
  • How k3s removes the barrier to entry by bundling opinionated defaults so you can skip choosing CNI plugins and storage providers

Kubernetes doesn't have to be enterprise-scale — with the right distribution and community tooling, it can be a practical, low-overhead choice for anyone who cares about their data.

Learn from production

More case studies →

Matching jobs

    • DevOps Engineer with Intelliforce-IT Solutions Group

    • Salary: $166K to $213K a year

    • Location: based in the office in MD, USA

    • Tech stack: Kubernetes, AWS, ArgoCD, Docker, Python, Shell, Terraform, Gitlab, Ansible

    • AP Accountant / Bookkeeper with Cast AI

    • Salary: €28.98K to €41.8K a year

    • Location: remote from

    • Tech stack: Kubernetes, Python, SQL, Javascript, Java

    • CSM Team Lead - USA with Workwize

    • Salary: $86K to $130K a year

    • Location: remote from

    • Tech stack: Kubernetes

    • Data Engineer with Brainlabs

    • Salary: $88.2K to $302.5K a year

    • Location: fully remote

    • Tech stack: Kubernetes, GCP, AWS, Azure, Docker, Python, SQL, Javascript, Java, Snowflake

    • DevOps Engineer with Arine

    • Salary: $120K to $150K a year

    • Location: based in the office in San Francisco, CA, USA

    • Tech stack: Kubernetes, AWS, Docker, Shell, Python, DynamoDB, Terraform, Cloudformation, GitHub Actions, Jenkins

Discover more Kubernetes jobs on Kube Careers →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 170 issues and counting.

or subscribe via

Build something

More tutorials →

Call for Papers closing soon

  1. 3

    days

    OW2Con

    The Call For Paper is open until 14 February 2026 at GMT-5. More info →
    • Location: Paris-Châtillon, France

    • In-person conference organized by OW2.

    • The conference starts on the 2 June 2026.

    • Apply here
  2. 4

    days

    CfgMgmtCamp 2026 Ghent

    The Call For Paper is open until 15 February 2026 at GMT-5. More info →
    • Location: Ghent, BE

    • In-person conference organized by CfgMgmtCamp.

    • The conference starts on the 4 February 2026.

    • Apply here
  3. 4

    days

    Berlin Buzzwords

    The Call For Paper is open until 15 February 2026 at GMT-5. More info →
    • Location: Berlin, DE

    • In-person conference organized by Plain Schwarz UG.

    • The conference starts on the 9 June 2026.

    • Apply here
  4. 4

    days

    foss-north 2026

    The Call For Paper is open until 15 February 2026 at GMT-5. More info →
    • Location: Göteborg, SE

    • In-person conference organized by Free Open Source Software North Conferences.

    • The conference starts on the 28 April 2026.

    • Apply here
  5. 5

    days

    Site Reliability Engineering 2026

    The Call For Paper is open until 16 February 2026 at GMT-5. More info →
    • This is a virtual event

    • Online conference organized by Conf42.

    • The conference starts on the 19 March 2026.

    • Apply here
  6. 6

    days

    Kubernetes Community Days Toronto Canada 2026

    The Call For Paper is open until 17 February 2026 at GMT-5. More info →
    • Location: Toronto, CA

    • In-person conference organized by KCD Toronto.

    • The conference starts on the 13 May 2026.

    • Apply here
  7. 11

    days

    PlatformCON

    The Call For Paper is open until 22 February 2026 at GMT-5. More info →
    • This is a virtual event

    • Online conference organized by Platform Engineering.

    • The conference starts on the 26 June 2026.

    • Apply here

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

More articles

Even more articles →