OpenUnison 1.0.45 has been released! The latest version now supports hot update of keys, so your identity providers can rotate keys automatically without restarts.
github.com/TremoloSecur...
OpenUnison 1.0.45 has been released! The latest version now supports hot update of keys, so your identity providers can rotate keys automatically without restarts.
github.com/TremoloSecur...
We've sponsored this great podcast, and you should too!
We've updated kube-oidc-proxy. No new features, but have cut known CVEs for the code base to 0! Updated libraries and removed deprecated ones. Integrated into the OpenUnison helm charts. github.com/TremoloSecur...
This release brings native Headlamp integration, expanded OIDC capabilities, and a new SCIM 2.0 gateway.
If you care about Kubernetes identity done right, take a look π
www.tremolo.io/post/openuni...
We're going to have a @headlamp.dev plugin for OpenUnison that adds namespace limiting based on an API and a "who am i" page so you can see you ask kubernetes sees you. We're also going to add some other operational support tasks that are common too.
Just finished rewriting Openunison 's Traefik support. Moving forward, Traefik will likely be my go-to Ingress controller. Gateway API support added too but with lack of consistent re-encryption support and no standard for sticky sessions I don't recommend it yet.
This is an appreciation post for people who provide detailed GitHub issues.
Authenticate Kubernetes workloads to HashiCorp Vault using JWT/OIDC and short-lived tokensβno static ServiceAccount credentials.
#Kubernetes #Vault #OIDC #WorkloadIdentity
www.tremolo.io/post/short-l...
Um, no, um, but, I...think I hear my mom calling...
Hmmm....bit of nostalgia marketing....
It would be pretty cool if you, I dunno, tossed kube on their and then set it up to securely talk to cloud based systems without any static keys...
Rewrote the websockets layer to be simpler, now Head Lamp with impersonation is working great for logs and terminals! Next release will default to Head Lamp instead of the Kubernetes dashboard. Will also remove the need for a second chart.
It'll be OK Marc....
We deployed Istio...now what? Does it work? Can my app run? How do I know the mesh is running? Join us at noon EST to find out!
youtube.com/live/hMFX7EI...
We've released OpenUnison 1.0.43! We've made building Security Token Services easier, simplified kubernetes logins with a new kubectl plugin, and made privileged access to Kubernetes a snap. Check out our new features with more blog posts coming soon!
www.tremolo.io/post/openuni...
Trick or treat, smell my skeet, give me a great service mesh. If you don't, I don't care, I'll pull out your token there! OK, know it doesn't all rhyme but let's learn how to deploy Istio!
Are you also at #kcddc? Come find me and say hi!
Your Pods, they're talking to you....can you hear them? We'll walk through how Kubernetes manages your logs using OpenSearch.
youtube.com/live/VeArPBy...
No, also, no one likes old pictures of them being posted on socials without their permission!!!!!
A customer did an accessibility review of OpenUnison's UI. Try hard to get it right, don't pretend to always do and was pretty happy at how well the report came back. Been in the weeds the last couple of days getting the few issues they found corrected.
Backups and disaster recovery is so hot we couldn't keep it in just one live stream! We'll wrap up our chapter on backups today at noon EST!
youtube.com/live/ibE6I5_...
This was @tremolo.io first conference booth. Red Hat Summit 2015. We were talking about applications and OpenShift and almost everyone we talked to was asking about Satelliteπ€£π€£π€£. This was our official exit from "stealth".
In a stream that's too hot for TV....the sexiest topic in all of enterprise infrastructure...BACKUPS!!!! Join us at noon for deep dive on our backups chapter with Velero!
youtube.com/live/yByl5Zm...
For TBT, how can you use your Kubernetes ServiceAccount tokens to access AWS services? www.tremolo.io/post/securel...
Picture of the cover of Kubernetes: An Enterprise Guide, 3rd ed
Packt is giving Kubernetes: An Enterprise Guide, 3rd Ed away for $38US. Get the paperback, you get the PDF for free. Kube, auth, networking, monitoring, vCluster, Vault, Istio, Pulumi, and more!
a.co/d/7dwcw20
One more vCluster lab! We're wrapping up the chapter building a self service portal for vCluster deployment, integrating our vClusters with Vault for secrets management and our enterprise authentication. Hope to see you there! youtube.com/live/udRnQWd...
If you're using OpenUnison, we're looking for help testing out our new kubectl authentication plugin! Any feedback would be greatly appreciated! www.reddit.com/r/kubernetes...
π¨In thirty minutes let's talk vClusters!π¨ youtube.com/live/QDOU1Jd...