This tutorial shows how to build a hub-style multi-cluster cert-manager control plane where a central hub cluster manages certificate issuance and distribution across multiple spoke clusters using cert-manager and trust-manager
➜ https://t.co/kmZg5qxFUm
This week on the Learn Kubernetes Weekly:
🔥 Qwen 3.5 27B on GKE with B200 GPUs
🤖 AI-Powered IT Helpdesk
⚙️ Ansible AWX on Kubernetes
🛡️ Kubermatic SecureGuard
🔐 Secrets Management
⭐️ StormForge
Read it now: https://t.co/DY5DsXjkns
This tutorial teaches Kubernetes security testing from an offensive perspective, covering:
- pod compromise detection,
- service account token exploitation,
- RBAC privilege escalation,
- and tools like kubeletctl and peirates
➜ https://t.co/IbueaAw1Yx
Siclaw is an open source AI SRE platform for read-only infrastructure diagnostics, root cause analysis, team workflows, Kubernetes access, and MCP-based investigation without changing live systems directly
➤ https://t.co/h3AqpYjKBt
This article explains how to build a highly available GKE architecture using Multi-Cluster Services and Multi-Cluster Gateway
It covers subnet naming requirement for cross-regional internal ALBs, cluster setup via Fleet, demo app with request routing
➜ https://t.co/0IEn3tHCZv
This case study shows how Unitary built Osmia, an open-source orchestration layer on EKS to run autonomous AI coding agents safely at scale using pod isolation, Karpenter, IRSA-based secrets, and real-time trajectory scoring
➤ https://t.co/5RpUQaPTWd
PII-Shield is a sidecar that sanitizes logs before they leave the pod by detecting secrets and personal data, preserving JSON structure, and supporting Helm based deployment.
➤ https://t.co/0rpFGaCaQz
This tutorial shows how to run Cloudflare Tunnels as a DaemonSet to expose services with zero open inbound ports, using liveness probes, Kubernetes Secrets, and GitOps with ArgoCD
➜ https://t.co/t5ITZF2SO1
This article explains how one team evaluated Crossplane and KRO to replace KIAM with EKS Pod Identities, balancing flexibility, maturity, and operational overhead after outages
➤ https://t.co/lCMx9r8mEZ
This article reviews Kubermatic SecureGuard (KubeSG), a Kubernetes-native open source secrets manager built on OpenBao and the External Secrets Operator that automates secret rotation and delivery without app rewrites or proprietary SDKs
➜ https://t.co/kdyBW2kTgB
KubeUser is a Kubernetes native operator that manages users, certificates, RBAC, and kubeconfigs declaratively for small teams that want simple cluster access without a full IAM or OIDC stack
➤ https://t.co/Vzf5evuYhb
This article shows how to sign every container image using Cosign keyless signing in GitHub Actions and enforce signatures at pod admission with Kyverno, using the chalk/debug npm attack as the real-world motivation
➜ https://t.co/BR33fzfyim
This week on the Learn Kubernetes Weekly:
🔥 Fix That Saved 600 Hours
🔐 Why Kubernetes Has No Login
⚙️ Durable Workflows Beyond Vercel
🧩 Missing Operator Layers
🚨 KServe Production Failures and Fixes
⭐️ Qodo
Read it now: https://t.co/TCDVq5qwAG
This article explains Kubernetes secrets management from an SRE angle by comparing:
- Sealed Secrets,
- External Secrets Operator,
- and Vault-based approaches with examples
➜ https://t.co/kw5rv4FhFU
🗣️ Alessandro Pomponio, Research Software Engineer @ IBM Research, explains selecting CNCF tools like ArgoCD, Kyverno, and Kueue for their GitOps platform, emphasizing ease of use for researchers
Watch the full episode: https://t.co/mU3auSfm5x
This tutorial shows how to set up TLS-terminated ingress on EKS Auto Mode using ACM and an ALB, skipping the traditional AWS Load Balancer Controller installation and OIDC setup
➜ https://t.co/7z1wIJcDsK
🚀 New: User and workload identities in Kubernetes.
Learn how the API server authenticates users and pods, how service account tokens work, why projected tokens matter, and how Kubernetes identities can federate with AWS IAM.
https://t.co/cif1PVlSHy