Safeguard
Tag

kubernetes

Safeguard articles tagged "kubernetes" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Cloud Security

The Kubernetes Token Nobody Asked For

Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.

Sep 18, 20265 min read
Infrastructure Security

Your Health and Metrics Endpoints Describe Your System to Anyone Who Asks

Nobody designed them. A framework, a platform team or a monitoring integration added them, they were configured once, and they are the endpoints that describe your architecture most accurately.

Sep 18, 20265 min read
DevSecOps

Your Deploy Kills Long-Running Jobs. Drain Instead.

SIGKILL after a ten second grace period destroys a twenty minute job and leaves its row marked RUNNING forever. Three drain strategies, the four ways they get undermined, and what to tell the user when one is lost anyway.

Sep 17, 20265 min read
Engineering

A Container Stuck on health: starting Is Probably a Crash Loop

Each restart resets the health check, so a crash loop and a slow boot look identical in the status column. The one command that tells them apart, and the merge conflict class that produces the most convincing version.

Sep 17, 20266 min read
Containers

Kubernetes Security News Today: What to Watch and How to Respond

Keeping up with Kubernetes security news today means more than reading headlines. Here's how to triage a fresh CVE, what IngressNightmare taught us, and where to look first.

Aug 2, 20266 min read
Container Security

A Practical Kubernetes Operator Security Checklist

Kubernetes operators run with broad cluster access. This checklist covers the controls that matter most in 2025, from RBAC scoping to image provenance.

Jul 26, 20264 min read
Vulnerability Analysis

Helm 2 Tiller's Default Unauthenticated gRPC Endpoint (CV...

CVE-2019-18658 shows how Helm 2's Tiller ran an unauthenticated gRPC endpoint by default, letting network-adjacent attackers seize cluster-admin control.

Jul 25, 20267 min read
Vulnerability Response

CVE-2025-31133 in runc: Patch Posture & SBOM Response

runc container-escape via /proc mount manipulation affects Docker, Kubernetes, and every CRI runtime. Defender playbook below.

Jul 23, 20267 min read
Containers

How to Build a Docker Image for Kubernetes Securely

You do not build Docker images inside Kubernetes the old way anymore. Here are the secure patterns for building images that k8s will run, from CI to in-cluster builders.

Jul 22, 20266 min read
Kubernetes Security

Best practices for securing Kubernetes ConfigMaps

ConfigMaps store plaintext in etcd with no size guardrail beyond 1 MiB — teams that drop credentials in them expose secrets to a far bigger RBAC audience.

Jul 13, 20266 min read
Containers

K8s Admission Controllers: Enforcing Policy at the Kubernetes API

A k8s admission controller intercepts every request to the API server and can validate or mutate it, making it the natural enforcement point for security policy.

Jul 12, 20266 min read
Container Security

Container-handling security fundamentals: immutability, signing, and privilege drops

Two runc CVEs, five years apart, both turned root-in-container into root-on-host — proof that container isolation needs backup, not blind trust.

Jul 11, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.