The Secure Way
Nodes and clusters, the secure way
Talos Linux, Kubernetes API hardening, service account tokens, RBAC and the cloud underneath.
14 guides
- Cloud firewalls by tag, the secure wayDigitalOcean cloud firewalls follow tags, so one missing or misspelled tag leaves a Droplet with no firewall at all. Design tag-based rules and audit coverage.
- Disk encryption on Talos with LUKS2 and TPM, the secure wayTalos encrypts STATE and EPHEMERAL with LUKS2, but a TPM key without SecureBoot, a static key on STATE, or a patch on a used disk protects little. Do it right.
- etcd on cloud VMs, the secure wayetcd on cloud VMs: mTLS for clients and peers on the private network only, timings that survive slow cloud disks, a dedicated volume, and snapshots encrypted.
- Kubernetes and Talos API access over a tailnet, the secure wayTake the Kubernetes API and the Talos API off the internet: join Talos nodes to a tailnet, firewall 6443 and 50000 to it, and let tailnet grants decide who connects.
- Kubernetes audit policy, the secure wayA Kubernetes audit policy that records who did what without copying Secrets and tokens into the log: rule order, levels per resource, and a Talos patch.
- Pod Security Admission levels in practice, the secure wayPod Security Admission accepts a bad Deployment and silently blocks its pods. Pin versions, pair enforce with warn and audit, avoid exemptions, pass restricted.
- RBAC least privilege with resourceNames, the secure wayRBAC resourceNames can limit a role to one Secret, but not for create, deletecollection or plain list. Scope reads and patches by name; police create by policy.
- Self-managed Pulumi state, the secure waySelf-managed Pulumi state keeps every non-secret value in plain text, in history and backups too. Mark secrets, use a real key provider, and lock down the bucket.
- ServiceAccount token hardening, the secure wayEvery pod gets an API token by default, and the API server quietly makes it valid for a year. Turn off automount, use short projected tokens, drop legacy ones.
- Talos Linux hardening, the secure wayTalos ships a hardened kernel, but its host firewall defaults to accept and admin credentials never expire. Close apid, scope talosconfig, and verify it.
- Talos machine configs in git with age, the secure wayTalos machine configs hold your cluster CA keys. Commit only patches and a sops+age encrypted secrets bundle, regenerate configs on demand, and block plaintext.
- Talos on DigitalOcean without losing kernel hardening, the secure wayOn DigitalOcean, Talos boots with GRUB and takes its kernel command line from the installer image. Keep KSPP args, and keep your machine config out of user data.
- Talos upgrades that keep your hardening, the secure wayA Talos upgrade can drop your extensions and kernel args, and it never adds the new security defaults. Pin the installer, snapshot the node, then diff it.
- VPC segmentation for untrusted CI, the secure wayCI runners execute code from pull requests and dependencies. Give them their own VPC, deny egress to your networks, block the metadata service, and prove it.
T Academy
Every guide here is taught hands-on in H2-CSPE Secure Platform Engineering: a real host in your browser, and every objective checked on the machine.
Start free