Discover and read the best of Twitter Threads about #eks

Most recents (4)

Mounting a #Kubernetes service account to a pod with permissions to deploy other pods implies that if your app has RCE, a threat actor will be able to infect other Services in the cluster (yes, even if you use strict PSPs) #KubernetesSecurity #k8s #aks #gke #eks
#DevSecOps
🧵 👇
Background:
▪︎ A Service in #k8s is an object that balances HTTP requests between pods belonging to that Service
▪︎ A Service identifies its pods through a set of labels (e.g. "fancy-app: prod", "db: users", etc)
▪︎ A pod with a label associated with a Service will become part of that Service automatically

Attack scenario:
1. A pod is mounting a service account with permissions to deploy other pods
2. A container in the pod is running a vulnerable app, providing RCE to an attacker
Read 6 tweets
New launch! Starting today, @awscloud #AppRunner services can communicate with private endpoints hosted in your VPCs. Simply create a VPC connector by specifying subnet(s) and security group(s) to control egress access from your service to your VPC. /1
aws.amazon.com/blogs/aws/new-…
If you are not already familiar with AWS #AppRunner, here is a mini thread with useful links to get started. It is easy to get a secure, auto-scaled, highly-available web app running within a few minutes: /2
#AppRunner is built on #ECS #Fargate. VPC connectors are a new, simple, secure and scalable option for your containers to privately access your VPCs in Fargate, exposed in #AppRunner. /3
aws.amazon.com/fargate/
Read 13 tweets
Bırakın $ırıngaları da Avrupa'da en fazla kenevir ekili alan niçin ve nasıl Fransa'da ona bakalım..
Keneviri de Fransa'yı da anlatılmadığı gibi anlayalım.
#oxygen #oksijen #PCR #maske #testkiti #ECS #EKS
#Anandamide #hempoil #cannabisindustry #cannabisculture #CannabisCommunity
1- Bugün İstanbul Lisesi olarak kullanılan Düyun-u Umumiye Binası'nın ana kapısı. Düyun-u Umumiye (Düyun-u Umumiye-i Osmaniye Varidat-ı Muhassasa İdaresi), 1881-1923 yılları arasında Osmanlı İmparatorluğu'nun iç ve dış borçlarını denetleyen kurumdur.
2- Navarin Bozgunu, Osmanlı ve Mısır donanmalarıyla, birlikte hareket eden Britanyalı, Fransız ve Rus donanmaları arasında; 20 Ekim 1827 tarihinde geçmiş olan bir deniz muharebesidir. Bu muharebe Osmanlı tarihinde , Navarin Baskını veya Navarin Faciası adlarıyla da geçer.
Read 22 tweets
Today during the #reInvent keynote, we have announced Amazon #EKS on #Fargate. So proud of my team! AWS customers can now run both native #ECS tasks as well as #Kubernetes pods on Fargate. In this thread, I'll try to explain our reasoning behind some major design decisions. 1/n
For #EKS on #Fargate, we wanted to give customers a native k8s experience. You can use your existing tooling to run pods on Fargate. Fargate operates at the task (ECS) and pod (K8S) level, so any higher level abstraction (deployments, replicasets, etc.) built on top works. 2/n
When designing #EKS on #Fargate, instead of building a one-off integration with Kubernetes, we've asked ourselves "What additional capabilities does Fargate need in order to become a service on which other multi-tenant serverless containers offerings can be built?". 3/n
Read 14 tweets

Related hashtags

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!