SRE

3 Articles
Kyverno apiCall SSRF: Policy Engines Need Egress Boundaries Too
10 min read

Kyverno apiCall SSRF: Policy Engines Need Egress Boundaries Too

Kyverno's apiCall feature is exactly the kind of capability platform teams end up wanting after the first wave of policy adoption. Static admission checks are useful, but real clusters are full of context. A namespace may need to be compared against an inventory system. A deployment may need

Read →
Admission Webhooks Are Control Plane Dependencies, Not Just Add-ons
8 min read

Admission Webhooks Are Control Plane Dependencies, Not Just Add-ons

A moderate Kubernetes ecosystem CVE does not always deserve a full incident response. It does often deserve a design review. CVE-2026-44247, published through the GitHub advisory database for Volcano, is a good example. Volcano is a Kubernetes-native batch scheduling system. The advisory says its webhook server did not enforce a

Read →

Showing 1 - 3 of 3 posts