Spotlight
Michael Pechner
This tutorial shows how to let cert-manager issue Let's Encrypt certificates for services outside the cluster, using DNS-01 validation and AWS Secrets Manager as the delivery path to an OpenVPN server.
Nerav Doshi
This article explains how to design a production-grade MCP server for platform teams, with governance, backend clients, tool definitions and auth as four separate layers, plus the RBAC and deployment work needed before it touches a real cluster.
Aviral Agarwal
This article follows a secret from an external store into a pod through the Secrets Store CSI Driver, explaining the registrar, the SecretProviderClass and the provider plugin. It also covers syncing back into a native Kubernetes Secret for env vars.
Luka Klaric
This tutorial builds a Docker image with a secret, then shows how it still sits in an earlier image layer after you delete it, and pulls it back out with docker history, jq and tar.
Tools and utilities
Kogaro continuously validates Kubernetes config with 60+ checks across reference, resource, security, image, and network domains, catching silent failures before they impact production.
Kubesafe is a tool that prevents accidental execution of dangerous commands on the wrong Kubernetes cluster by providing a safety net for cluster management.
NineVigil is a Kubernetes operator that runs AI agents inside gVisor sandboxes, closes their network egress with Cilium and keeps a tamper-evident audit record of every run.
AegisBPF is an eBPF agent that actually blocks unwanted file and network access at the Linux kernel level, instead of only alerting you after something already happened.
Multikube is a reverse proxy that sits in front of several Kubernetes API servers, terminating TLS and handling authentication and authorization centrally so kubectl talks to one endpoint.
Events starting soon
October 1, 2026
Location: Philadelphia, PA, USA
This event requires an entrance fee
Use DOD26KUBEEVENTS to get $30 off
October 1, 2026
This is a virtual event
This is a free event.
October 1, 2026
This is a virtual event
This is a free event.
October 1, 2026
Location: Frankfurt am Main, DE
This is a free event.
October 1, 2026
This is a virtual event
This is a free event.
October 1, 2026
Location: St. Louis, MO, USA
This event requires an entrance fee
Learn from production
Ron Matsliah
This case study shows how a team ran ServiceNow's MID Server on EKS as a StatefulSet and faked the EC2 metadata service so the agent would accept IRSA credentials.
Deepakravi
This case study shows how to stabilize Harbor on VMware VKS by expanding storage, upgrading the Supervisor Service, and configuring Trivy scanning to receive vulnerability results.
Gleb Wam
This case study explains how a privileged Kubernetes pod with host access can lead to container escape, control plane disruption, service account theft, and cloud resource takeover.
Alex
This case study explains how a Kubernetes secrets audit exposed weak secret handling and forced a move toward safer secret management.
It covers encoded secrets, RBAC, encryption, external secret stores, and audit-ready controls.
Matching jobs
DevOps Engineer with Valarian Technologies Limited
Salary: US$72K to US$324.5K a year
Location: based in the office (and remote from home) in London, GB
Tech stack: Kubernetes, On-premise, Helm, ArgoCD, Flux, Go, Python, Rust, Terraform, Tekton
Infrastructure Architect with North Point Technology
Salary: $95.67K to $253K a year
Location: based in the office in Chantilly, VA, USA
Tech stack: Kubernetes, OpenShift, Java, Python
Machine Learning Engineer with Valarian Technologies Limited
Salary: US$112.5K to US$330K a year
Location: based in the office (and remote from home) in London, GB
Tech stack: Kubernetes, Python
Platform Engineer with New Relic
Salary: $126K to $158K a year
Location: based in the office in Portland, OR, USA
Tech stack: Kubernetes, Helm, ArgoCD, Flux, Go
Platform Engineer with Valarian Technologies Limited
Salary: US$66.6K to US$303.6K a year
Location: based in the office in London, GB
Tech stack: Kubernetes, Bare-metal, GCP, On-premise, Helm, Kustomize, Flux, Docker, Go, Javascript
Build something
Raajkumar Tutika
This tutorial walks through wiring cert-manager and Let's Encrypt into the Istio ingress gateway on GKE, so your HTTPS certificates just renew themselves.
LearnKube
This tutorial shows how two in-cluster services can authenticate each other with Service Account tokens and the TokenReview API, then makes it safer with audience-bound projected tokens.
Parag Shahade
This tutorial shows how to build a simple bot-detection system from Nginx logs and use GCP controls to investigate and slow suspicious traffic.
Pixel Robots.
This tutorial shows how to install Microsoft's managed cert-manager extension on an AKS cluster and use it with Gateway API to issue and auto-renew Let's Encrypt certificates.
More articles
Francesco Vitullo
This article asks what a container can block on its own when a dependency turns malicious, and tests nono, a capability-based sandbox that limits file and network access at runtime.
Dwayne McDaniel
This article explains what an attacker can really do with leaked Kubernetes credentials, from kubeconfigs to service account tokens, and how to check the blast radius and shut it down.
Nisha P
This article walks through making a container image safe before it ever reaches the cloud, using multi-stage builds, a distroless base and Trivy scans to cut the CVE count down.
prajakta
This article walks through building a Kubernetes admission webhook in Go from scratch, including the TLS trust setup and the bootstrapping deadlock nobody warns you about.