Spotlight

Detecting vulnerabilities in public Helm charts

Nigel Douglas

This article shows how to scan Helm charts for insecure RBAC, secret leaks, and malicious templates using tools like Trivy, GitHub Search, and OPA.

More articles →

Tools and utilities

  • Guardon: Real-time Kubernetes Policy Enforcement

    Guardon is a Kubernetes admission controller that enforces security and compliance policies in real-time before resources are created in your cluster.

  • Synapse: reverse proxy

    Synapse is a high-performance reverse proxy and firewall built with Rust, using XDP-based packet filtering for ultra-low latency protection at kernel level.

  • kubectl-rexec: exec audit

    kubectl-rexec is a kubectl plugin that provides full audit logging for kubectl exec sessions, addressing the security gap where standard exec commands leave no trace of what happens inside containers.

  • Kaniop: Kubernetes Operator for Kanidm

    Kaniop is a Kubernetes operator written in Rust for managing Kanidm identity management clusters, providing declarative identity management through GitOps workflows.

  • Dockadvisor: Lightweight Dockerfile Linter with Quality Scoring

    Dockadvisor is a lightweight Dockerfile linter built in Go that validates your Dockerfiles with over 60 rules covering syntax, security, and best practices.

More projects →

Events starting soon

Discover more events onn Kube Events →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 150 issues and counting.

or subscribe via

Learn from production

More case studies →

Matching jobs

    • DevOps Engineer with Relativity Space

    • Salary: $140K to $178K a year

    • Location: based in the office in Long Beach, CA, USA

    • Tech stack: Kubernetes, GCP, On-premise, Helm, Go, Python, Shell, SQL, Javascript, Java

    • DevSecOps Engineer with Raft Company Website

    • Salary: $140K to $165K a year

    • Location: based in the office in Colorado Springs, CO, USA

    • Tech stack: Kubernetes, AWS, Helm, Docker, Java, Python, Go, Terraform, Gitlab, Ansible

    • DevSecOps Engineer with Red Cell Partners

    • Salary: $175K to $215K a year

    • Location: fully remote

    • Tech stack: Kubernetes, AWS, Python, Go, Shell, DynamoDB, Terraform, Cloudformation, CDK, Pulumi

    • Engineering Manager with Robinhood

    • Salary: $180K to $270K a year

    • Location: based in the office in Bellevue, WA, USA

    • Tech stack: Kubernetes, AWS, Python, SQL, Go, Java, Javascript, Typescript, C#

    • Head Of Engineering with Relativity Space

    • Salary: $263K to $337K a year

    • Location: remote from

    • Tech stack: Kubernetes, AWS, GCP, Docker, SQL, Python, Javascript, Java, C++, C#

Discover more Kubernetes jobs on Kube Careers →

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

Build something

More tutorials →

More articles

Even more articles →