Latest news, trends, and upcoming events for Kubernetes security, policy and governance, automation, platform engineering, and much more.
View in browser
Screenshot 2023-03-28 at 5.42.16 PM

The Kubernetes Governance Platform

 

 

The State of Kubernetes Policy and Governance

 

January, 2024

    enterprise@2x (1)-Mar-09-2023-11-06-39-5904-AM

    Hello, from all of us at Nirmata!

     

    This new year, we bring you our exclusive January newsletter with the latest insights, news, and updates on Kubernetes, cloud-native security, compliance and governance from across the industry. From Kubernetes security, compliance, Policy as Code, to pipelines and supply chain security, we cover it all. Please feel free to reach-out to us to share your feedback or say hello!

     

    Also, we are thrilled to announce that we've given our website a fresh new look and added some exciting features to enhance your experience! Head over to our New Website to explore the changes and see what's been added and improved! 

    Preventing “Sys:All” vulnerability by using Kyverno policy

     

    A critical vulnerability was discovered in Google Kubernetes Engine (GKE) that could allow attackers to take control of a Kubernetes cluster. The vulnerability is called “Sys:All” and is caused by a misunderstanding of the “system:authenticated” group.To protect your clusters, you can use the Kyverno policy that restricts the use of the groups necessary to exploit “Sys:All.” Read more. 

    Recent Blogs

    • In this blog post, Jim Bugwadia explained how policy-based resource management can be complementary to GitOps, what benefits it provides, and how to use Kyverno to mutate and generate rules with popular GitOps tools like Flux and ArgoCD. Read more here.

    • The success of Nirmata's migration to ARM processors reinforces the importance of staying abreast of advancements in technology. We invite you to embrace this paradigm shift and unlock the potential benefits it may bring to your infrastructure. More details. 
    • Using nctl to enforce security in CI/CD pipelines.
    Screenshot 2023-11-29 at 11.39.32 AM

    Download Free ebook

    Unveiling our latest Policy-as-code ebook on Kubernetes. Dive deep into the nuances of Kubernetes policy governance, and discover best practices for managing policies effectively. Download here. 

    Recent Events

    • Charles-Edouard Breteche, Staff Engineer at Nirmata and also a maintainer for Kyverno discussed How to automate Kubernetes security with policy-as-code. 
    • JimBugwadia talked about Kubernetes-native policy management with Kyverno, no-code policy with Kyverno, and signing and verifying container images with Sigstore Cosign and Kyverno. 
    • An interesting discussion between Selvi Radhakrishna Cherian, Co-host of the Founder's podcast, and Jim Bugwadia, CEO and Co-founder of Nirmata, on the Future of cloud security and go-to-market strategies! 

    Recent Videos

    • Delve into the fascinating realm of Kyverno security rules, and explore the crucial role these rules play in safeguarding your systems and applications.
    • By leveraging #kyverno, organizations can benefit from improved #kubernetes management, enhanced #security, and simplified policy enforcement, ultimately leading to more efficient and compliant Kubernetes environments. Watch the video here. 
    • In this tutorial, Anais Urlichs explains how to combine three amazing security tools: #Trivy, #Cosign and #Kyverno.

    Upcoming Events

    • Nirmata- Office Hours for Kyverno
      An interactive session and livestream hosted by the team at Nirmata, the creators of Kyverno, where we discuss all things Kubernetes policy and governance! Office hours occur on the second Thursday of every month at 10 am EST / 7 am PST. Join the Google group here to receive a calendar invite with meeting details. Episode 8 of the series demonstrated the new VAPs generation. Watch all the videos here.

    • Cloud Native Live: Kyveno 1.12 and beyond!
      The Kyverno project provides tools for cloud native policy and governance. In this session, Kyverno maintainers Shuting and Mariam will discuss new features in the 1.12 release, as well as the roadmap for upcoming releases. RSVP here.
    Screenshot 2023-11-21 at 5.48.19 PM

    From the Kyverno Community

    
    

    Kyverno Blogs

    • Deep dive with Thomas Segura and learn What long-lived service account tokens are, their uses, the risks they pose, and how they can be exploited. 
    • Explore the DryRun capability of ProjectSveltos with Eleni Grosdouli, and learn how to Use #Kyverno policies in the process.
    • Great blog by Chip Zoller where he explains how organizations can use two best-in-class tools, Kubecost for cost visibility and monitoring, and Kyverno for policy-as-code, to realize some massive savings.
    
    

    Community Engagement

    • 4.8k stars for Kyverno
    • Over 2.74 Billion image pulls for Kyverno
    • Growth in Kyverno adoption
    • Latest Kyverno adopters
    • New version of Kyverno Chainsaw
    • Kyverno debuts at 32 in the Top 100 security List

    We love hearing from you!

    Are you already using Kyverno or planning to use Kyverno for security, governance and compliance of your Kubernetes environments? Are you looking to solve complex problems such as multi-tenancy, software supply chain security or developer self-service?  Contact us to learn how we can help.

    LinkedIn
    X
    Github download-4

    Nirmata Inc., 6203 San Ignacio Avenue Suite 110, San Jose, CA 95119, United States

    Unsubscribe Manage preferences