Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@cncf.ioOct 7, 2026, 9:10 PM

Handling $180B+ in annual payments while staying compliant with strict regulations isn't easy.

Join us next Wednesday, Oct 14 for a #CloudNative Live fireside chat with Razorpay and Nirmata on using #Kyverno for continuous, automated security policies in production. 🛠️️
https://bit.ly/3VAdjwC

@cncf.ioOct 3, 2026, 9:32 AM

In August, we introduced two new Phippy friends: Ky, the #Kyverno Great Pyrenees keeping clusters on the golden path, and Falkey the #Falco, catching runtime anomalies. 🐾

Get to know them before grabbing their exclusive swag at KubeCon + CloudNativeCon in November: https://bit.ly/4ieF8DS

@darryl-ruggles.cloudOct 1, 2026, 5:30 AM

https://lckhd.eu/1RPsl7

#Kubernetes #Kyverno

Security in Kubernetes clusters is not really understood well. By default, anyone with kubectl access can ship a pod that runs as root, pulls :latest, or ignores resource limits. These deploy fine and (in many cases), nobody notices or understands, and

@stackflag.bsky.socialSep 26, 2026, 9:40 PM

CVE-2026-100706 - kyverno
Kyverno versions earlier than 1.19.1 do not correctly check specially encoded URLs in its policy calls. This mistake lets a user in one namespace create resources, such as webhooks or policy…

Too many irrelevant or confusing CVEs? Use stackflag.com

#kyverno #CVE #infosec

@awscmblogposts.bsky.socialSep 11, 2026, 9:34 AM

✍️ New blog post by Mohamed Radwan

Stop Paying for Availability You Don’t Actually Have

#aws #kubernetes #devops #kyverno

@umbra-codex.bsky.socialSep 7, 2026, 12:00 PM

Kyverno CVE-2026-84200: overlapping PolicyExceptions let the LEAST restrictive one win. Name a Pod `*ingress*` and your hostPath ban stops applying. Fixed in v1.13.0. Audit overlaps if you can't upgrade. Exception logic is control logic.

#Kubernetes #DevSecOps #Kyverno

Dark neon infographic comparing two states of Kyverno policy exceptions. The left column, in red, is headed "Overlapping exceptions" and lists: Two exceptions, one policy, two exceptions, the looser one wins; Name your pick, a pod named to match a wildcard slips past the ban; Policy goes soft, the hostPath ban the team relied on stops applying. The right column, in teal, is headed "Audit overlaps" and lists: One exception, one exception per policy and rule, never two; Upgrade now, upgrade to the fixed release and recheck your rules; Test the hole, name a pod to match a wildcard and confirm it blocks. Between the columns sits a cracked shield emblem above the label Kyverno and the line "Least restrictive wins: when two exceptions overlap, the looser one wins the bypass", with an arrow labeled "Audit and fix" pointing from left to right. The footer reads "Policy exceptions are control logic. Do you audit your policy exceptions, or just the policy?"