Spotlight

Securing Your Internal Tools: Implementing Identity-Aware Proxy (IAP) for GKE Resources with CDKTF

Ogonna Nnamani

This tutorial walks you through setting up Google Cloud IAP for Kubernetes services, using CDKTF (TypeScript) to configure OAuth, BackendConfig, and service annotations so your internal tools are protected behind identity checks.

More articles →

Tools and utilities

  • PodCertificateSigner: certificate controller

    PodCertificateSigner lets your Kubernetes cluster automatically issue TLS certificates for pods by handling PodCertificateRequest resources with a custom signer controller.

  • cert-manager Management via MCP

    cert-manager-mcp-server provides cert-manager resource management through Model Context Protocol (MCP), letting AI assistants like Claude inspect certificates, issuers, and certificate requests directly in Kubernetes clusters.

  • Crowdsec: security solution

    Crowdsec is a security engine that detects malicious behavior from logs and community-shared intelligence, allowing you to block bad IPs and share threat data across your fleet.

  • Kexa: Cloud Compliance

    This tool enables you to scan and enforce compliance across multi-cloud infrastructure with customizable YAML rules, alerts and integrations.

  • Dingus: bug identification

    This code tool helps you gather logs, metrics and code changes, then uses AI-powered root-cause analysis to surface what broke in production and suggest immediate fixes.

More projects →

Events starting soon

Discover more events onn Kube Events →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 150 issues and counting.

or subscribe via

Learn from production

More case studies →

Matching jobs

    • DevSecOps Engineer with Built Technologies

    • Salary: $120K to $185K a year

    • Location: fully remote

    • Tech stack: Kubernetes, AWS, Python, Javascript, Typescript, Go, SQL, C++, C#, Snowflake

    • Machine Learning Engineer with Grafana Labs

    • Salary: CA$186.37K to CA$223.64K a year

    • Location: remote from Canada

    • Tech stack: Kubernetes, AWS, GCP, Azure, Docker, Python, Javascript, Typescript, Go, Rust

    • Platform Engineer with Geotab

    • Salary: $38.56K to $330K a year

    • Location: fully remote

    • Tech stack: Kubernetes, GCP, OpenShift, ArgoCD, Docker, Java, Python, Shell, Go, Terraform

    • Platform Engineer with National Information Solutions Cooperative (NISC)

    • Salary: $24.75K to $484K a year

    • Location: based in the office (and remote from home) in Cedar Rapids, IA; Lake Saint Louis, MO; Mandan, ND, USA

    • Tech stack: Kubernetes, AWS, Docker, SQL, Python, Java, Typescript, Cassandra, Spark, Terraform

    • Software Engineer with Forter

    • Salary: $67.5K to $660K a year

    • Location: based in the office (and remote from home) in NYC, NY, USA

    • Tech stack: Kubernetes, AWS, GCP, Azure, Docker, Python, Java, Kotlin, Rust, Go

Discover more Kubernetes jobs on Kube Careers →

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

Build something

More tutorials →

More articles

Even more articles →