IN THIS BLOG Overprivileged Kubernetes ServiceAccounts persist when broad RBAC, cloud IAM permissions, and long-lived credentials outlive their intended use. Reduce overprivileged access with least privileged RBAC, scoped cloud permissions, and short-lived certificates that eliminate static credentials. I spent two days last quarter tracking down why a developer could delete production secrets. The RBAC looked fine. The ClusterRoleBinding said edit, not cluster-admin. But someone had bound the default service account to cluster-admin permissions in a CI namespace three years ago, and that…
TL;DR: If your development, staging, and production API servers all trust the same OIDC issuer and audience, Kubernetes will accept the same cached kubectl token across all of them. You should use separate audiences in your API. One Company Login for Development, Staging, and Production A platform team manages three Kubernetes clusters: development, staging, and production. Each cluster has an API server, the Kubernetes component that receives kubectl requests.** The team connects all three API servers to the company login service, so Alice can sign in with her usual work account. Now Alice…
TL;DR: A production kubeconfig that contains a certificate or token is a production credential, and every copy then accesses the cluster with the same identity. You should use individual single sign-on (SSO) logins and short-lived credentials for your clusters. What the Kubeconfig Actually Controls Let's use a k3d cluster to parse the file. First, read the kubeconfig from disk: cat ~/.kube/config The file looks like this, with the encoded data shortened: apiVersion: v1 kind: Config current-context: k3d-lms-cluster clusters: - name: k3d-lms-cluster cluster: certificate-authority-data:…
Read this article to learn: Key differences between FIPS 140-2 and FIPS 140-3 The exact FIPS 140-2 to FIPS 140-3 transition dates, as described by NIST How to read a real CMVP certificate How FIPS 140-3 affects your infrastructure What is FIPS 140-3? FIPS 140-3 is the current standard for validating cryptographic modules, which are the specific hardware or software components that implement encryption and manage keys inside a defined boundary. FIPS 140-3 was approved on March 22, 2019, became effective on September 22, 2019, and supersedes FIPS 140-2, which dates back to 2001. Most FIPS 140-3…
AI agents run 24/7 with the same infrastructure access as your engineers. See how Teleport secures AI with cryptographic identity, audit, and trusted runtimes.
I taught the same AI workshop twice in one week, and half my material was already wrong by round two. Here's what that taught me about training on a moving target.
Learn how SSH, Kubernetes, database, and RDP create audit challenges for high-frequency and quant trading firms and how to unify audit trails across protocols.
Defense contractors pursuing CMMC Level 2 face persistent AC, IA, and AU findings. Coalfire outlines how Teleport addresses the enforcement and audit gaps assessors require.
Discover how Envoy + SDS and Teleport Workload Identity let off-cluster workloads securely call Istio services without distributing certificates.
Read at the source
Your visit, your choice.
Optional Google Analytics helps us understand visits. Microsoft Clarity records masked interactions to improve the site. Optional tools stay off unless you choose them. Privacy details.