Setting Up Kubernetes RBAC: The Roles and RoleBindings That Actually Enforce Least Privilege

Setting Up Kubernetes RBAC: The Roles and RoleBindings That Actually Enforce Least Privilege

By KP  |  TZoneLabs  |  DevOps & Cloud Engineering A Role scoped to one namespace, bound to one service account, with verbs limited to exactly what that workload does, is what turns Kubernetes RBAC into an actual security boundary instead of a checkbox. Most clusters we’ve audited get this half right: the Role exists, but … Read more

A Namespace Relabel Silently Broke a NetworkPolicy Selector, and Cross-Namespace Traffic Started Timing Out

A Namespace Relabel Silently Broke a NetworkPolicy Selector, and Cross-Namespace Traffic Started Timing Out

By KP  |  TZoneLabs  |  DevOps & Cloud Engineering A payments-team service started timing out on calls to a shared internal API, intermittently, with nothing in either side’s logs pointing at why. No connection refused, no TLS error, no 5xx. Just a hang until the client’s own timeout gave up. The pods were healthy, the … Read more

We Leaked a Production Database Password Into Build Logs for Three Weeks Because One CI Variable Wasn’t Marked Masked

We Leaked a Production Database Password Into Build Logs for Three Weeks Because One CI Variable Wasn’t Marked Masked

By KP  |  TZoneLabs  |  DevOps & Cloud Engineering For three weeks, our staging database password was sitting in plain text in every CI job log a specific pipeline produced. Anyone with read access to the project, which included a few external contractors, could open a job log and copy it out. Nobody stole it, … Read more

Kubernetes RBAC Setup: A Practical Guide (No More Guessing Permissions)

Kubernetes RBAC Setup: A Practical Guide (No More Guessing Permissions)

By KP  |  TZoneLabs  |  DevOps & Cloud Engineering The fastest way to grant a pod too much power in Kubernetes is kubectl create clusterrolebinding temp –clusterrole=cluster-admin –serviceaccount=default:default. It works immediately, which is exactly the problem. Nobody circles back to fix it, and six months later a compromised pod can read every secret in the … Read more