kubernetes
Safeguard articles tagged "kubernetes" — guides, analysis, and best practices for software supply chain and application security.
144 articles
GCP Binary Authorization Enforcement Runbook 2026
A practical 2026 runbook for enforcing GCP Binary Authorization in production, including attestation pipelines, break-glass procedures, and rollout sequencing.
What a Cloud Native Security Platform Actually Does
A cloud native security platform unifies posture, workload, and supply chain controls for containerized apps. Here is what the category covers and how to tell the marketing from the substance.
Container Security and Gartner: Reading the CNAPP Market Guide
When people search for container security Gartner coverage, they usually mean the CNAPP Market Guide. Here is what Gartner's framing says about securing containers.
Zarf Air-Gap Deployment: A 2026 Walkthrough
How Zarf 0.45 packages and deploys Kubernetes workloads into disconnected environments, where the design works well, and the operational realities to plan for.
Open Source Container Security: A Practical Guide
You can build a solid container security stack entirely from open source tools — here's which ones cover which layer, and where the gaps show up at scale.
Container Hardening Guide 2025: From Base Image to Production
A practical guide to hardening container images and deployments. Covers base image selection, build-time security, runtime protections, and Kubernetes-specific controls.
Kubernetes Ingress TLS: Setup, Certificates, and Common Mistakes
How Ingress TLS works in Kubernetes: terminating HTTPS at the ingress, wiring TLS secrets, automating certificates with cert-manager, and the mistakes that break it.
What a Container Security Platform Should Actually Do
A container security platform has to cover images, registries, and running workloads. Here is what real coverage looks like and how to evaluate one.
Rolling Out Zero-CVE Base Images Org-Wide
A pragmatic playbook for migrating an entire engineering organisation onto zero-CVE base images, covering pilot selection, registry mirroring, drift control, and the hard people-side of the rollout.
Sigstore Policy Controller v0.15: TUF Delegation and Admission Posture
Policy Controller v0.15 ships sigstore-go's delegation-aware TUF client, a monthly cadence, and tighter integration with cosign 3.x. We benchmarked admission on a 400-node cluster.
Container Supply Chain Defence: Build To Run
An end-to-end view of container supply chain controls from source through registry to runtime, covering signing, attestation, admission policy, and runtime drift, with concrete checkpoints at each stage.
cAdvisor: Container Resource Monitoring, Explained
cAdvisor gives you per-container CPU, memory, network, and filesystem metrics out of the box — here's what it actually measures, how it fits with Prometheus and Kubernetes, and where its limits show up.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.