Blogs and News

Find valuable insights, knowledge, and inspiration for your business in our selected articles. Explore practical tips from our team of experts and fuel your company’s growth.
Filter:
Featured Image

Validating Zero Trust: Network Policy Testing with Flux CD and Netassert

GitOps revolutionised how we deliver applications, enabling faster deployments and managing infrastructure with targeted declarative precision. However, this precision doesn’t extend to securing dynamic environments and remains incredibly difficult. Consider a historical three-tier application architecture: a frontend web service, backend API, and data store. The engineer’s accountability ended when the application code was pushed to version control, and automation carried it to production (that developers may not be permitted to access).

By Giovanni Baggio
security networking kubernetes ci-cd blue-team flux-cd gitops zero-trust
Featured Image

The End of Safe Software? No, It's Not.

In the wake of Anthropic’s announcement of Mythos and Project Glasswing, and with the still-emerging blast radius of Aqua Security’s Trivy compromise, many security professionals are predicting the end of safe software. We do not agree. Instead, they simply highlight and reinforce: Security standards are rising, and proactivity breeds assurance Security basics are more important than ever Open source is resilient The Attack Chains that Matter What does this mythical LLM and an open source project’s compromise have to do with each other?

By John Kjell
security open-source supply-chain generative-ai
Featured Image

Defusing CanisterWorm: How Bun and Deno Secure the JavaScript Supply Chain

TeamPCP’s CanisterWorm is exploiting npm’s postinstall hooks. Learn how modern JavaScript runtimes like Bun and Deno neutralise this threat by default.

By Fabian Kammel
supply-chain security open-source threat-modeling
Featured Image

How LLMs Are Ending The Attacker-Defender Stalemate (And What to Do About It)

Frontier Large Language Models (LLMs) are reshaping how software is built, attacked, and secured. Their impact is most visible in code generation and vulnerability discovery, where they reduce the time and expertise required to produce outputs that previously demanded specialist knowledge. As organisations rush to adopt AI tools into development and operations, a practical question arises: in a world where AI can autonomously write exploits and generate patches, what is the role of human-driven security?

By Sam Holmes & James Callaghan
security generative-ai red-team governance assurance blue-team
Featured Image

The Vercel Breach: When Roblox Cheats, AI Tools, and Poor Secrets Management Collide

The recent breach at Vercel is a textbook example of how modern supply-chain compromises unfold, starting with a Roblox cheat script.

By Aiman Alsari
openbao supply-chain ai-security secrets-management
Featured Image

ControlPlane Enterprise for OpenBao - Meet the Team

Meet the team behind the new ControlPlane Enterprise for OpenBao

By Rob Kenefeck
openbao security secrets-management open-source infrastructure
Featured Image

sandbox-probe: Putting AI sandboxing to the test

Announcing ControlPlane’s sandbox-probe: testing the limits of AI Agent Sandboxes

By Alberto Rodriguez & Jack Kelly
generative-ai containers pentesting security
Featured Image

Why We Are Throwing Our Weight Behind OpenBao

We are expanding our open source commitment to include OpenBao. Here is why we believe in true digital sovereignty, meeting market demand, and providing sustainable support for the maintainers of critical security projects.

By Andrew Martin
security governance cloud open-source
Featured Image

ControlPlane Launches Enterprise Support For OpenBao To Strengthen Secrets Security

Announcing the launch of a new offering designed to help organizations securely adopt and operate the OpenBao secrets management platform.

By Pam Oldfield
assurance cloud compliance identity infrastructure openbao platform-engineering supply-chain zero-trust
Featured Image

Out on the GenAI Wild West: Part II - The Long Arm of the Law

As AI agents execute workflows and access sensitive systems, organizations must shift from model safety to architectural controls, continuous testing, and framework-aligned governance.

By Torin van den Bulk
security generative-ai compliance governance
Featured Image

Check Point and ControlPlane Partner to Help Enterprises Securely Scale AI and Accelerate Agentic Innovation

The partnership delivers a comprehensive, regulator-ready security framework to enable organizations to move confidently from AI experimentation to production deployment.

By Pam Oldfield
ai-security cloud compliance generative-ai governance security
Featured Image

Open Source Security Risks: Countering the Threat

Open source supply chain attacks are on the rise. What can businesses do to protect themselves?

By Pam Oldfield
generative-ai cloud compliance governance security
Featured Image

FluxCon Atlanta Was Just the Start

Reflecting on eight years of Flux deployment, two years of Enterprise and a watershed moment.

By Andrew Martin
gitops security flux-cd ci-cd kubernetes
Featured Image

Making TDD Work for You, Part 2: crossing TDD's tribal lines

Second and final part of a series about how to make TDD work for you.

By Houssem El Fekih
devops automation delivery containers
Featured Image

Out on the GenAI Wild West: Part I - Red Team Redemption

Multi-turn agentic adversarial testing uncovers vulnerabilities in foundational models, highlighting the need for adaptive defenses, model-specific strategies, and continuous evaluation to secure GenAI

By Torin van den Bulk
security generative-ai pentesting
Featured Image

Penetration Testing and Purple Teaming: Essential for Financial Services Security

The financial services sector is increasingly targeted by cybercriminals, with cyberattacks leading to significant financial losses and reputational damage. Penetration testing and purple teaming are two security testing methodologies essential in enhancing cybersecurity posture and readiness. In this article, we will explore the importance of penetration testing and purple teaming in protecting financial services institutions against ever-evolving threats. The Impact of Cybercrime on Financial Services Financial institutions are enticing targets for cybercriminals due to the potential for direct financial gain and access to vast amounts of valuable data.

By Gabriela Georgieva
security pentesting purple-team blue-team
Featured Image

Trust Issues: Navigating Open Source and Software Supply Chain Risk

A two-part journey through the lens of large banks, regulated industries, and security consultancies

By Francesco Beltramini
security supply-chain compliance governance open-source
Featured Image

The Quantum Leap: Navigating PQC Adoption in Today's Digital Infrastructure

Key insights on PQC adoption in today’s digital infrastructure

By Fabian Kammel
security infrastructure compliance kubernetes open-source
Featured Image

DevSecOps is the New DevOps

A look at transforming to DevSecOps from a technical and cultural perspective, including a deeper look some supply-chain considerations.

By Eugene Davis
security devops supply-chain ci-cd containers
Featured Image

Making TDD Work for You, Part 1: When to Invest and Essential Practices

First part of a series about how to make TDD work for you.

By Houssem El Fekih
devops automation delivery containers
Featured Image

Improve your OPA policies user-based with Gatekeeper

For Open Policy Agent (OPA), most of the policies that are written are based on Kubernetes resources. For example, the deployment of Pods should be avoided with the tag latest. But sometimes it is necessary to write more fine-grained OPA policies based on Kubernetes users, groups or service accounts. Let me give you an example so that the code and explanations can be better understood. Example of a use case Imagine you have a Jenkins job that creates Namespaces for tenants.

By Jose A. Berchez - ControlPlane
kubernetes security compliance containers identity
Featured Image

Beyond Compliance: Strategic Cyber Resilience in Financial Services Under the EU’s CRA

The EU’s Cyber Resilience Act (CRA) isn’t just another regulatory hurdle; it’s a fundamental shift in how we approach digital security.

By Andrew Crawford
compliance security supply-chain threat-modeling infrastructure
Featured Image

Back to the Future: Next-Generation Cloud Native Security - A talk by Andrew Martin & Matt Jarvis

In this talk, Andrew Martin and Matt Jarvis explored the history of cloud-native computing, examined the current security landscape, and shared their predictions for the decade ahead.

By Niamh O'Loughlin
security kubernetes cloud threat-modeling supply-chain
Featured Image

Kubernetes and the UK

Kubernetes marked its 10th anniversary last year, and the CNCF commemorates a decade of remarkable success this year.

By Niamh O'Loughlin
kubernetes security containers cloud training
Featured Image

ControlPlane at KubeCon EU London ‘25 - Recap

A recap of ControlPlane’s activities at KubeCon EU in London

By Ashley Ward
kubernetes security training pentesting cloud
Featured Image

Flux D2 Reference Architecture – Gitless GitOps for Secure Multi-Tenancy

Introducing Gitless GitOps and the Flux Operator for secure, scalable multi-tenant Kubernetes environments.

By Niamh O'Loughlin
flux-cd gitops kubernetes infrastructure security
Featured Image

ControlPlane is Heading to KubeCon EU '25 London

ControlPlane’s events and CTF at KubeCon EU in London

By Niamh O'Loughlin
kubernetes security training containers cloud
Featured Image

Ephemeral Environments for GitLab Merge Requests with Flux Operator

Flux Operator creates ephemeral environments for GitLab MRs. Each MR gets an automatic, dedicated preview instance for faster validation and iteration.

By Francesco Beltramini, ControlPlane
flux-cd gitops ci-cd kubernetes devops
Featured Image

See it, Hack It, Sort It: How Open Source Software Protects Our AI Enablers

Protecting GPU resources in cloud infrastructure: threat modeling, attack vectors, and practical security measures using open source tools.

By Marcus Tenorio
security kubernetes generative-ai threat-modeling pentesting
Featured Image

What is Continuous Delivery & How Does It Work?

An exploration of what Continuous Delivery is, how it differs from related concepts, and how Flux can help.

By Jack Kelly
ci-cd flux-cd gitops kubernetes devops
Featured Image

Securing Kubernetes Clusters: Lessons and Best Practices from the Field

Key lessons from ControlPlane’s KubeCon EU 2023 talk, covering Kubernetes threat modelling, attack techniques, and essential security measures to protect clusters.

By ControlPlane
kubernetes security pentesting threat-modeling training
Featured Image

What is Flux CD

Flux is an open source tool used to keep Kubernetes clusters in sync with configuration artefacts, especially when that configuration needs to change regularly, like when you update your software or a dependent part of your system receives a patch. Flux has been built from the ground up to use native Kubernetes APIs and to integrate with the wider Kubernetes ecosystem tools like Prometheus. It supports multi-tenancy clusters and scales massively with support for syncing multiple Git Repositories or other sources of configuration artefacts.

By Rob Kenefeck
flux-cd gitops kubernetes ci-cd delivery
Featured Image

Celebrating a Year of Commitment to CNCF Flux: Sustainability, Innovation, and Growth

ControlPlane supported CNCF Flux over the past year by enabling ongoing development, innovation, and community engagement.

By ControlPlane
flux-cd gitops kubernetes infrastructure devops
Featured Image

Streamlining Application Delivery with Flux and the Generic Helm Chart Pattern

Based on the excellent technical article written by Flux Core Maintainer and fellow ControlPlaner Stefan Prodan.

By Francesco Beltramini
flux-cd gitops kubernetes platform-engineering delivery
Featured Image

What is GitOps

This is the first in a series of articles about Flux CD, and introduces the foundational knowledge of GitOps. GitOps is a term coined by Weaveworks in 2018. It has been referred to as the best thing since Infrastructure as Code, and has also been referred to as being versioned CI/CD on top of declarative infrastructure. Much like how DevOps broke down the silos between Developers and Operations/Infrastructure Teams, GitOps merges the concerns for application deployment with infrastructure deployment.

By Rob Kenefeck
gitops ci-cd kubernetes automation devops
Featured Image

Unlocking Delivery Success: Overcoming Framework Limitations in Regulated Environments

ControlPlane pioneers delivery success by blending Agile adaptability with Waterfall structure to overcome regulatory challenges and drive efficiency.

By ControlPlane Agile Team
devops compliance automation delivery
Featured Image

Automated Cloud Native Incident Response with Kubernetes and Service Mesh

ControlPlane is a proud member of and long-term contributor to the Fintech Open Source Foundation (FINOS), and almost a third of our firm’s consultants contribute to initiatives like the AI Readiness SIG, Common Cloud Controls, and Compliant Financial Infrastructure.

By Matt Turner & Francesco Beltramini
security kubernetes automation incident-response threat-modeling blue-team monitoring
Featured Image

Open Source in Finance Forum New York 2024 Recap

ControlPlane is a proud member of and long-term contributor to the Fintech Open Source Foundation (FINOS), and almost a third of our firm’s consultants contribute to initiatives like the AI Readiness SIG, Common Cloud Controls, and Compliant Financial Infrastructure.

By Francesco Beltramini
compliance cloud generative-ai security threat-modeling
Featured Image

The Path to Zero CVEs: Vanquishing Cyber Threats

Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.

By Andrew Martin and Michael Lieberman
security compliance supply-chain threat-modeling monitoring
Featured Image

Enterprise for Flux CD Now Available on AWS Marketplace

Our products and services are now available through our partnership with AWS

By ControlPlane
flux-cd gitops aws kubernetes platform-engineering
Featured Image

ControlPlane at KubeCon NA '24 Salt Lake City

ControlPlane’s events and CTF at KubeCon NA in Salt Lake City

By Niamh O'Loughlin
kubernetes security training containers pentesting
Featured Image

The Landscape Podcast: Flux with Core Maintainer Stefan Prodan

Stefan Prodan, core maintainer of Flux, discusses its role in automating Kubernetes with GitOps, enhancing security, and scaling infrastructure management

By Stefan Prodan
flux-cd gitops kubernetes devops platform-engineering
Featured Image

Introducing the Flux Operator - GitOps on Autopilot Mode

Stefan Prodan, core maintainer of the CNCF Flux project, introduces the Flux Operator.

By Stefan Prodan
flux-cd gitops kubernetes platform-engineering automation
Featured Image

ControlPlane Outreach: Exposing At-Risk Students to Careers in Tech

ControlPlane partnered with Spark! to empower at-risk students through workshops that introduced them to tech careers, continuous learning, and future possibilities.

By Maddie Clingan and Yannis Follias
compliance generative-ai kubernetes security training
Featured Image

Future Open Source LLM Killchains! A Talk by Vicente Herrera

In The Security Ai Summit 2024, Principal Consultant Vicente Herrera explores how advanced adversaries could exploit vulnerabilities in the open-source AI ecosystem, particularly in large language models (LLMs), by targeting MLOps infrastructure, with a focus on mitigation strategies to prevent such attacks.

By ControlPlane Team
generative-ai security supply-chain threat-modeling kubernetes
Featured Image

FINOS AI Readiness Open Sourced

ControlPlane’s pivotal role in the FINOS AI Governance Framework highlights our commitment to advancing AI readiness in financial services.

By ControlPlane
generative-ai compliance security governance threat-modeling
Featured Image

Smarter Than Your Average SBOM! A Talk by Matt Jarvis & Andrew Martin

In Kubernetes Community Day UK 2023 Snyk, Director Matt Jarvis and ControlPlane CEO Andrew Martin teamed up and deeply delved into the Software Bill of Materials (SBOMs) world

By ControlPlane Team
security supply-chain compliance kubernetes containers
Featured Image

FINOS AI Governance Framework

At the Secure AI Summit earlier this year, ControlPlane’s Torin van den Bulk delivered an eye-opening talk on the ‘Invisible infiltration of AI supply chains by adversarial actors’. This talk examines the importance of securing the data, models, and pipelines involved at each step of an AI supply chain.

By Torin van den Bulk
generative-ai security compliance threat-modeling supply-chain governance
Featured Image

ControlPlane at the Bleeding Edge: Ending the Pain of Periods

The ControlPlane Agile team is proudly taking steps toward breaking down awkwardness, stigma, and workplace barriers to menstrual health.

By ControlPlane Agile Team
training security infrastructure compliance
Featured Image

I'll Let Myself In: Kubernetes Privilege Escalation Tactics

ControlPlane’s talk at KubeCon Europe 2024 gave attendees an overview of Cloud-Native Penetration Test and privilege escalation tactics to make cloud native systems more secure

By Iain Smart
kubernetes security pentesting red-team training
Featured Image

The Impact of the Polyfill Supply Chain Attack

How the Polyfill supply chain attack highlights the issues with trust in open source software and what approaches can be taken to mitigate the risk.

By Kevin Ward
security supply-chain pentesting infrastructure compliance
Featured Image

Mastering the Cloud Native Wave: Security Resilience in Modern Systems

ControlPlane’s talk at InfoSec Europe 2024 gave attendees an overview of observations and techniques to make cloud native systems more resilient"

By Rob Kenefeck
security cloud kubernetes zero-trust
Featured Image

Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 2)

How malicious VSCode extensions can steal your credentials

By Fabian Kammel & Kevin Ward
security pentesting red-team supply-chain devops
Featured Image

Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 1)

Attack paths for remotely compromising Visual Studio Code

By Kevin Ward & Fabian Kammel
security pentesting red-team supply-chain devops
Featured Image

Open Source Dynamics in the Era of Licence Innovation

This blog post explores innovative business models for open source projects, focusing on enterprise support and subscription services, and discusses the balance between community contributions and sustainable growth.

By Andrew Martin
cloud generative-ai infrastructure security
Featured Image

How to create a Table Top Exercise for Cyber Incident Responders

OpenSSF and ControlPlane created, hosted and ran a tabletop exercise for Incident Responders in the format of a panellist discussion. Let’s have a look behind the scenes and uncover tips and tricks how a security team can carry out a similar exercise.

By Ian Barbour
security training pentesting threat-modeling supply-chain incident-response
Featured Image

Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native Ecosystem

James Callaghan, principal consultant at ControlPlane, and Constanze Roedig discuss open source cloud native threat intelligence at KubeCon + CloudNativeCon Europe 2024

By James Callaghan
security kubernetes threat-modeling pentesting infrastructure
Featured Image

Flux CD Architecture Overview

Stefan Prodan, core maintainer of the CNCF Flux project, provides a comprehensive overview of Flux CD architectures for multi-cluster continuous delivery

By Stefan Prodan
flux-cd gitops kubernetes ci-cd platform-engineering monitoring
Featured Image

Isovalent and ControlPlane's Joint Whitepaper

Engineers, product managers and consultants from both companies explore how Cilium can tackle the challenges of cloud native compliance

By Ollie Cuffley-Hur & Martyn Smith
compliance kubernetes networking security platform-engineering
Featured Image

The Lowdown on Locked Namespaces

Marco De Benedictis, senior consultant at ControlPlane, discusses how Kubernetes namespaces have grown from an optional feature to a security boundary at KubeCon + CloudNativeCon Europe 2024

By Marco De Benedictis
kubernetes security containers networking threat-modeling
Featured Image

Zero Trust Training Courses with the Linux Foundation

ControlPlane has authored two Zero Trust training courses for the Linux Foundation

By ControlPlane
zero-trust security training spiffe-spire identity
Featured Image

ControlPlane at KubeCon EU Paris ‘24 - Recap

A recap of ControlPlane’s activities at KubeCon EU in Paris

By Ashley Ward
kubernetes security flux-cd training gitops
Featured Image

The Envoy Gateway End User Threat Model, in collaboration with the Linux Foundation

ControlPlane has collaborated with the Linux Foundation to threat model Envoy Gateway and generate an End User guide

By ControlPlane
security threat-modeling kubernetes infrastructure networking
Featured Image

Flux CD: D1 Reference Architecture

ControlPlane’s commitment to supporting the Flux Project continues, providing a model and a guide for multi-cluster, multi-tenant environments

By Andrea Martino
flux-cd gitops kubernetes platform-engineering infrastructure
Featured Image

ControlPlane at KubeCon EU '24 Paris

ControlPlane’s talks and events schedule for KubeCon EU in Paris

By Niamh O'Loughlin
kubernetes security flux-cd training containers
Featured Image

Container Security Basics at Securi-Tay 2024

ControlPlane’s principal consultant, Iain Smart, talks about Container and Kubernetes Security at Abertay Hackers’ Securi-Tay 2024

By Iain Smart
security containers kubernetes pentesting training
Featured Image

NIST Special Publication 800-204D calls for GitOps approaches

Exploring how NIST’s latest publication underscores the necessity of integrating GitOps strategies in software supply chain security within DevSecOps CI/CD pipelines

By Andrew Martin
gitops security compliance ci-cd supply-chain
Featured Image

Bringing light to risks lurking in the black boxes of AI models

ControlPlane’s principal consultant, Vicente Herrera, talks about AI Security at OpenUK’s “State of Open Con 2024”

By Vicente Herrera
generative-ai security kubernetes pentesting threat-modeling
Featured Image

ControlPlane backs the CNCF Flux Project by Employing Maintainers

ControlPlane’s support for the CNCF Flux project ensures the sustainability and security of critical systems through open source maintenance and innovative enterprise solutions

By Andrew Martin
flux-cd gitops kubernetes security infrastructure
Featured Image

ControlPlane and Scott Logic Collaborate on Scottish Government Identity and Payments Systems

Collaborative efforts between ControlPlane and Scott Logic on the Scottish Government identity and payment systems: security architectures, platform integrations, and project assurance

By Andrew Martin
security compliance kubernetes infrastructure platform-engineering
Featured Image

Tangible Value with ControlPlane Enterprise for Flux CD

ControlPlane Enterprise elevates Flux CD with enhanced security, support, and compliance, catering to diverse needs in Kubernetes deployments

By ControlPlane
flux-cd gitops kubernetes security compliance
Featured Image

AI Software Development Lifecycle on Kubernetes

AI software’s evolution on Kubernetes: current methodologies, potential future developments, and inherent risks

By ControlPlane
generative-ai kubernetes security threat-modeling containers
Featured Image

ControlPlane at OpenSSF and Open Source Summit Japan, 2023

ControlPlane’s journey to Japan and an overview of some of the talks presented

By Jack Kelly
security supply-chain kubernetes training infrastructure
Featured Image

Navigating Cloud Security and Automation with Eficode

Talking to Eficode about Cloud Native Security Challenges

By Andrew Martin
security cloud automation devops kubernetes
Featured Image

Play the 2023 CNCF CTF Scenarios with the Revamped Simulator

The public release of the 2023 CNCF CTF Scenarios is here! In this blog post, we’ll walk you through the revamped simulator and how to get started with the challenges.

By Kevin Ward
security kubernetes pentesting containers training
Featured Image

Cloud Native and Kubernetes Security Predictions 2024

A look into the tumultuous waters of cloud and Kubernetes security in 2024

By Andrew Martin
security kubernetes cloud generative-ai supply-chain
Featured Image

Andrew Martin on "Nerding Out With Viktor" — Security, Penetration Testing, and Threat Modelling

The inaugral “Nerding Out With Viktor” podcast with ControlPlane CEO, Andrew Martin

By Niamh O'Loughlin
security pentesting threat-modeling kubernetes red-team
Featured Image

Unveiling the Future of CI/CD Security: A Deep Dive into Advanced Practices

The “Advanced CI/CD Security” workshop we ran at DevOpsCon 2023 in Munich provided a deep dive into the latest practices shaping the future of cloud security

By Fabian Kammel
security ci-cd devops kubernetes training
Featured Image

Conference Recap: ControlPlane at KubeCon NA '23 Chicago

Reflecting upon our experience at KubeCon North America 2023

By Jasmine Andine
Featured Image

ControlPlane at KubeCon NA '23 Chicago

Where to find ControlPlane talks and events at KubeCon North America 2023 in Chicago

By Jasmine Andine
kubernetes security training pentesting containers
Featured Image

Take Zero Trust to the Next Level with Confidential Virtual Machines

SPIFFE and confidential computing are two security projects that minimize the level of implicit trust a user needs to place into a computing system. We will show how to combine these approaches to minimize the trust we need to place in public cloud services

By Fabian Kammel
spiffe-spire security aws zero-trust identity cloud
Featured Image

The National Cybersecurity Strategy Implementation Plan

The first annual iteration of the National Cybersecurity Strategy Implementation Plan has been released, detailing how the US government plans to achieve the goals previously outlined in 2021’s National Cybersecurity Strategy

By Andrew Martin
security compliance supply-chain threat-modeling infrastructure
Featured Image

Dark Matter Cloud Anonymous: Andrew Martin and Amanda Brock discuss open source and OpenUK's report

The event took questions from an audience of industry veterans and discussed open source security, developer understanding of Kubernetes, FinOps for cloud, and more

By Emma Ballantyne
security kubernetes cloud infrastructure compliance
Featured Image

Charting Zero Trust and High Assurance: ControlPlane’s Takeaways from the NIST Multi-Cloud and OSCAL Conferences

ControlPlane’s Experience at the 4th Annual OSCAL and Multi-Cloud Conferences Sponsored by NIST

By Torin van den Bulk
compliance zero-trust security cloud training
Featured Image

Conference Recap: ControlPlane at KubeCon EU '23

ControlPlane talk & event write-ups from KubeCon EU in Amsterdam

By Ollie Cuffley-Hur
kubernetes security training spiffe-spire threat-modeling
Featured Image

Threat Modelling Zero Trust at KubeCon EU 2023 Amsterdam

ControlPlane show you how to threat model Zero Trust architectures at KubeCon Europe 2023 in Amsterdam

By James Callaghan
security threat-modeling zero-trust kubernetes identity
Featured Image

KubeCon EU '23: Open Source Releases

ControlPlane open sources security and threat model knowledge

By Andrew Martin
security kubernetes threat-modeling infrastructure training
Featured Image

Netassert v2: Network Security Testing

How to write, test, and secure your network configurations

By Prithak Sharma
security networking kubernetes containers infrastructure
Featured Image

Collie: A toolkit for securing cloud controller provisioned infrastructure

Demonstrating compliance and securing infrastructure provisioned by Kubernetes Cloud Infrastructure Controllers

By Rowan Baker & Henry Mortimer
security compliance kubernetes cloud infrastructure
Featured Image

ControlPlane at DevSecCon UK Meet-up

ControlPlane at DevSecCon UK Meet-up

By Joe Collins
security kubernetes cloud infrastructure networking
Featured Image

ControlPlane at KubeCon EU 2023 Amsterdam

Where to find ControlPlane talks and events at KubeCon Europe 2023 in Amsterdam

By Ollie Cuffley-Hur
kubernetes security training pentesting containers
Featured Image

Intro to the CloudNative SecurityCon CTF

Capture-the-Flag platform demo with The New Stack 🔐🏴‍☠️

By ControlPlane
security kubernetes containers pentesting training
Featured Image

The Most Excellent Learnings of CloudNative SecurityCon 2023

The Cloud Native security community is vibrant and strong 🌩🎉

By ControlPlane
security kubernetes training cloud threat-modeling
Featured Image

The Inaugural CloudNative SecurityCon, North America, and Security Zero Day

Cloud Native security bursts onto the conference circuit 🌩🎉

By ControlPlane
security kubernetes training pentesting containers
Featured Image

SPIFFE: The Keystone Species of Cloud Native Security

Short-lived cryptographic identities are the basis upon which secure communication and access control are built 🗟🙊

By ControlPlane
spiffe-spire security identity zero-trust kubernetes
Featured Image

Cloud Native and Kubernetes Security Predictions 2023

A speculative look into the perils and opportunities that 2023 holds 🕵️🔎

By Andrew Martin
kubernetes security cloud supply-chain generative-ai
Featured Image

KCD UK 2022

Kubernetes Community Days 2022 at CodeNode, London ☸

By Jaymie Thomas
kubernetes security networking containers training
Featured Image

ControlPlane Accelerates International Expansion

ControlPlane expands into North America and APAC with two key executive hires 📈

By Andrew Martin
security kubernetes cloud infrastructure
Featured Image

KubeCon NA 2022 - Techstrong TV interview

Andrew Martin joins Mitch Ashley of Techstrong TV for a chat about ControlPlane, Hacking Kubernetes, and avoiding configuration gotchas 📺

By Jaymie Thomas
kubernetes security containers training
Featured Image

An evening of network security

An evening of network security by Tailscale and ControlPlane 🔐

By Jaymie Thomas
security networking kubernetes training
Featured Image

ControlPlane at KubeCon NA 2022 Detroit

Where to find ControlPlane talks and events at KubeCon North America 2022, Detroit ☸

By Jaymie Thomas
kubernetes security training pentesting containers
Featured Image

The Future of Open Source Technology in Financial Services

ControlPlane’s New York City event with FINOS 🏙

By Jaymie Thomas
security compliance cloud kubernetes containers
Featured Image

What's New - Kubernetes 1.25 Security Features

Overview of new security features in Kubernetes v1.25 ⚸🔐

By James Cleverley-Prance
kubernetes security containers identity infrastructure
Featured Image

VEXing challenges - ControlPlane at the Open Source Summit Europe 2022, Dublin

ControlPlane and OpenUK information at the Open Source Summit Europe 2022 in Dublin 🔐

By Jaymie Thomas
security supply-chain kubernetes training
Featured Image

OpenUK Reports on the State of Open: The UK in 2022

ControlPlane contributes to the definitive open source report for the UK

By Andrew Martin
security infrastructure supply-chain compliance training
Featured Image

Walking the talks - ControlPlane at KubeCon Europe 2022

ControlPlane talks at KubeCon EU, 2022 ☸

By Jaymie Thomas
kubernetes security training threat-modeling pentesting
Featured Image

Shift Left: Where Cloud Native Computing Security Is Going (The New Stack)

DevSecOps leaders on the direction of CloudNative Security

By ControlPlane
security cloud devops kubernetes gitops
Featured Image

Hacking Kubernetes Book Released

A threat-based guide to Kubernetes security 📖

By Andrew Martin
kubernetes security pentesting threat-modeling containers
Featured Image

Securing the Kubernetes Supply Chain: Software Factory Reference Architecture

Sophisticated mechanisms and best practices to enhance defenses against supply chain threats in Kubernetes

By Andrew Martin
kubernetes security supply-chain ci-cd containers
Featured Image

Hardening Git for GitOps

ControlPlane whitepaper on securing GitOps workflows at source ✍

By Andrew Martin
gitops security flux-cd ci-cd kubernetes
Featured Image

CNCF Cloud Native Security Whitepaper

ControlPlane collaborates with authors in sig-security 📜

By Andrew Martin
security kubernetes cloud threat-modeling compliance
Featured Image

Hands-on Kubernetes Security

Learning Kubernetes the Secure Way 💻

By Pi Unnerup
kubernetes security training pentesting containers
Featured Image

Kubernetes Predictions 2019

5 predictions and 5 wishes for Kubernetes in the year ahead 🕵️🔎

By Andrew Martin
kubernetes security cloud containers infrastructure
Featured Image

ControlPlane Sponsors PhD of in-toto Author Santiago Torres

ControlPlane, the open source and cloud native security company, sponsors the PhD work of in-toto author Santiago Torres, furthering the advancement of software supply chain security.

By Andrew Martin
security supply-chain infrastructure training
Featured Image

11 Ways (Not) to Get Hacked

An overview of essential security features for Kubernetes, and a glance to the future 👨‍🚀

By Andrew Martin
kubernetes security containers infrastructure incident-response