Tremolo Security's Avatar

Tremolo Security

@tremolo.io

Creators of OpenUnison, the easiest way to add authentication and Namespace as a Service to any Kubernetes cluster. Follow this account for updates! Docs - https://openunison.github.io/

45
Followers
7
Following
34
Posts
15.08.2024
Joined
Posts Following

Latest posts by Tremolo Security @tremolo.io

Preview
Release 1.0.45-2026031201 Β· TremoloSecurity/OpenUnison Tasks: 1.0.45 build #1043 bugs: Kubernetes Watches - Increase to 10 minutes #1051 K8s Dynamic Config - failure to start a dynamicly loaded object leads to failed startup #1021 OpenIDConnect IdP ...

OpenUnison 1.0.45 has been released! The latest version now supports hot update of keys, so your identity providers can rotate keys automatically without restarts.

github.com/TremoloSecur...

12.03.2026 17:06 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

We've sponsored this great podcast, and you should too!

18.02.2026 19:45 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Release v1.0.10 Β· TremoloSecurity/kube-oidc-proxy tasks: 1.0.10 build #74

We've updated kube-oidc-proxy. No new features, but have cut known CVEs for the code base to 0! Updated libraries and removed deprecated ones. Integrated into the OpenUnison helm charts. github.com/TremoloSecur...

12.02.2026 15:24 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
OpenUnison 1.0.44 OpenUnison 1.0.44 adds native Headlamp support, expanded OpenID Connect features, a SCIM 2.0 gateway, and enhanced deployment security with hardened, automated TLS and streamlined namespace and…

This release brings native Headlamp integration, expanded OIDC capabilities, and a new SCIM 2.0 gateway.

If you care about Kubernetes identity done right, take a look πŸ‘‡
www.tremolo.io/post/openuni...

28.01.2026 15:24 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image Post image Post image

We're going to have a @headlamp.dev plugin for OpenUnison that adds namespace limiting based on an API and a "who am i" page so you can see you ask kubernetes sees you. We're also going to add some other operational support tasks that are common too.

24.01.2026 15:20 πŸ‘ 6 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Just finished rewriting Openunison 's Traefik support. Moving forward, Traefik will likely be my go-to Ingress controller. Gateway API support added too but with lack of consistent re-encryption support and no standard for sticky sessions I don't recommend it yet.

22.01.2026 20:14 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
a man in an orange shirt is standing with his hands on his hips and says `` who 's awesome ? you are '' . ALT: a man in an orange shirt is standing with his hands on his hips and says `` who 's awesome ? you are '' .

This is an appreciation post for people who provide detailed GitHub issues.

14.01.2026 13:38 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Short Lived Tokens With Vault Without The Static ServiceAccount Learn how to securely authenticate Kubernetes workloads with HashiCorp Vault using short-lived tokens instead of static ServiceAccount credentials. This post explains why long-lived ServiceAccount…

Authenticate Kubernetes workloads to HashiCorp Vault using JWT/OIDC and short-lived tokensβ€”no static ServiceAccount credentials.

#Kubernetes #Vault #OIDC #WorkloadIdentity
www.tremolo.io/post/short-l...

13.01.2026 15:24 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Um, no, um, but, I...think I hear my mom calling...

30.12.2025 21:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Hmmm....bit of nostalgia marketing....

30.12.2025 21:02 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1

It would be pretty cool if you, I dunno, tossed kube on their and then set it up to securely talk to cloud based systems without any static keys...

22.12.2025 16:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Rewrote the websockets layer to be simpler, now Head Lamp with impersonation is working great for logs and terminals! Next release will default to Head Lamp instead of the Kubernetes dashboard. Will also remove the need for a second chart.

09.12.2025 03:52 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

It'll be OK Marc....

16.11.2025 15:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
Chapter 16 Part II & Chapter 17 Part I : Building and deploying Applications on Istio YouTube video by Kubernetes: An Enterprise Guide

We deployed Istio...now what? Does it work? Can my app run? How do I know the mesh is running? Join us at noon EST to find out!

youtube.com/live/hMFX7EI...

08.10.2025 14:33 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
OpenUnison 1.0.43 Feature summary for OpenUnison 1.0.43.

We've released OpenUnison 1.0.43! We've made building Security Token Services easier, simplified kubernetes logins with a new kubectl plugin, and made privileged access to Kubernetes a snap. Check out our new features with more blog posts coming soon!
www.tremolo.io/post/openuni...

01.10.2025 09:24 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
Chapter 16: An Introduction to Istio It might be the start of spooky season, but your service mesh doesn't need to be scary! We're going to introduce you to Istio and the concepts of service mes...

Trick or treat, smell my skeet, give me a great service mesh. If you don't, I don't care, I'll pull out your token there! OK, know it doesn't all rhyme but let's learn how to deploy Istio!

30.09.2025 16:16 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Are you also at #kcddc? Come find me and say hi!

16.09.2025 13:51 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Chapter 15: Monitoring Clusters and Workloads Part II - OpenSearch YouTube video by Kubernetes: An Enterprise Guide

Your Pods, they're talking to you....can you hear them? We'll walk through how Kubernetes manages your logs using OpenSearch.
youtube.com/live/VeArPBy...

10.09.2025 13:40 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
04.09.2025 12:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

No, also, no one likes old pictures of them being posted on socials without their permission!!!!!

24.08.2025 15:05 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

A customer did an accessibility review of OpenUnison's UI. Try hard to get it right, don't pretend to always do and was pretty happy at how well the report came back. Been in the weeds the last couple of days getting the few issues they found corrected.

22.08.2025 19:06 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Chapter 14: Backing Up Your Workloads - Part II YouTube video by Kubernetes: An Enterprise Guide

Backups and disaster recovery is so hot we couldn't keep it in just one live stream! We'll wrap up our chapter on backups today at noon EST!
youtube.com/live/ibE6I5_...

20.08.2025 13:29 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

This was @tremolo.io first conference booth. Red Hat Summit 2015. We were talking about applications and OpenShift and almost everyone we talked to was asking about Satellite🀣🀣🀣. This was our official exit from "stealth".

15.08.2025 17:41 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Chapter 14: Backing Up Workloads YouTube video by Kubernetes: An Enterprise Guide

In a stream that's too hot for TV....the sexiest topic in all of enterprise infrastructure...BACKUPS!!!! Join us at noon for deep dive on our backups chapter with Velero!

youtube.com/live/yByl5Zm...

06.08.2025 14:39 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Securely Calling AWS APIs From Kubernetes Securely interact with AWS APIs from your Kubernetes clusters by generating short lived tokens. Explore how you can use Kubernetes' TokenRequest API, SPIRE, or OpenUnison's Security Token Service to…

For TBT, how can you use your Kubernetes ServiceAccount tokens to access AWS services? www.tremolo.io/post/securel...

12.06.2025 15:31 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Picture of the cover of Kubernetes: An Enterprise Guide, 3rd ed

Picture of the cover of Kubernetes: An Enterprise Guide, 3rd ed

Packt is giving Kubernetes: An Enterprise Guide, 3rd Ed away for $38US. Get the paperback, you get the PDF for free. Kube, auth, networking, monitoring, vCluster, Vault, Istio, Pulumi, and more!
a.co/d/7dwcw20

29.05.2025 00:56 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Chapter 9: Building Multitenant Clusters with vClusters - Part III YouTube video by Kubernetes: An Enterprise Guide

One more vCluster lab! We're wrapping up the chapter building a self service portal for vCluster deployment, integrating our vClusters with Vault for secrets management and our enterprise authentication. Hope to see you there! youtube.com/live/udRnQWd...

28.04.2025 15:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1
Preview
From the kubernetes community on Reddit Explore this post and more from the kubernetes community

If you're using OpenUnison, we're looking for help testing out our new kubectl authentication plugin! Any feedback would be greatly appreciated! www.reddit.com/r/kubernetes...

21.04.2025 13:50 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Chapter 9: Building Multitenant Clusters with vClusters - Part I YouTube video by Kubernetes: An Enterprise Guide

🚨In thirty minutes let's talk vClusters!🚨 youtube.com/live/QDOU1Jd...

09.04.2025 15:33 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
09.04.2025 10:24 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0