Advertisement · 728 × 90

Posts by Tremolo Security

Preview
Release 1.0.46-2026032001 · TremoloSecurity/OpenUnison bugs: non http(s) redirects don't get generated properly #1053 oidc auth - overlapping requests overwrites state and code verifier #1052 Tasks: 1.0.46 build #1048

OpenUnison 1.0.46 is now available! Small release to fix a couple of bugs. github.com/TremoloSecur...

3 weeks ago 2 1 0 0
Preview
Release 1.0.45-2026031201 · TremoloSecurity/OpenUnison Tasks: 1.0.45 build #1043 bugs: Kubernetes Watches - Increase to 10 minutes #1051 K8s Dynamic Config - failure to start a dynamicly loaded object leads to failed startup #1021 OpenIDConnect IdP ...

OpenUnison 1.0.45 has been released! The latest version now supports hot update of keys, so your identity providers can rotate keys automatically without restarts.

github.com/TremoloSecur...

1 month ago 1 0 0 1

We've sponsored this great podcast, and you should too!

2 months ago 2 1 0 0
Preview
Release v1.0.10 · TremoloSecurity/kube-oidc-proxy tasks: 1.0.10 build #74

We've updated kube-oidc-proxy. No new features, but have cut known CVEs for the code base to 0! Updated libraries and removed deprecated ones. Integrated into the OpenUnison helm charts. github.com/TremoloSecur...

2 months ago 2 1 0 0
Preview
OpenUnison 1.0.44 OpenUnison 1.0.44 adds native Headlamp support, expanded OpenID Connect features, a SCIM 2.0 gateway, and enhanced deployment security with hardened, automated TLS and streamlined namespace and…

This release brings native Headlamp integration, expanded OIDC capabilities, and a new SCIM 2.0 gateway.

If you care about Kubernetes identity done right, take a look 👇
www.tremolo.io/post/openuni...

2 months ago 1 0 0 1
Post image Post image Post image

We're going to have a @headlamp.dev plugin for OpenUnison that adds namespace limiting based on an API and a "who am i" page so you can see you ask kubernetes sees you. We're also going to add some other operational support tasks that are common too.

2 months ago 6 3 0 0

Just finished rewriting Openunison 's Traefik support. Moving forward, Traefik will likely be my go-to Ingress controller. Gateway API support added too but with lack of consistent re-encryption support and no standard for sticky sessions I don't recommend it yet.

2 months ago 2 1 0 0
Advertisement
Preview
a man in an orange shirt is standing with his hands on his hips and says `` who 's awesome ? you are '' . ALT: a man in an orange shirt is standing with his hands on his hips and says `` who 's awesome ? you are '' .

This is an appreciation post for people who provide detailed GitHub issues.

3 months ago 7 1 0 0
Preview
Short Lived Tokens With Vault Without The Static ServiceAccount Learn how to securely authenticate Kubernetes workloads with HashiCorp Vault using short-lived tokens instead of static ServiceAccount credentials. This post explains why long-lived ServiceAccount…

Authenticate Kubernetes workloads to HashiCorp Vault using JWT/OIDC and short-lived tokens—no static ServiceAccount credentials.

#Kubernetes #Vault #OIDC #WorkloadIdentity
www.tremolo.io/post/short-l...

3 months ago 1 0 0 1

Um, no, um, but, I...think I hear my mom calling...

3 months ago 0 0 0 1

Hmmm....bit of nostalgia marketing....

3 months ago 1 1 0 1

It would be pretty cool if you, I dunno, tossed kube on their and then set it up to securely talk to cloud based systems without any static keys...

3 months ago 1 0 0 1
Post image

Rewrote the websockets layer to be simpler, now Head Lamp with impersonation is working great for logs and terminals! Next release will default to Head Lamp instead of the Kubernetes dashboard. Will also remove the need for a second chart.

4 months ago 1 1 0 0

It'll be OK Marc....

5 months ago 0 0 0 1
Preview
Chapter 16 Part II & Chapter 17 Part I : Building and deploying Applications on Istio YouTube video by Kubernetes: An Enterprise Guide

We deployed Istio...now what? Does it work? Can my app run? How do I know the mesh is running? Join us at noon EST to find out!

youtube.com/live/hMFX7EI...

6 months ago 1 1 0 0
Preview
OpenUnison 1.0.43 Feature summary for OpenUnison 1.0.43.

We've released OpenUnison 1.0.43! We've made building Security Token Services easier, simplified kubernetes logins with a new kubectl plugin, and made privileged access to Kubernetes a snap. Check out our new features with more blog posts coming soon!
www.tremolo.io/post/openuni...

6 months ago 1 0 0 1
Advertisement
Preview
Chapter 16: An Introduction to Istio It might be the start of spooky season, but your service mesh doesn't need to be scary! We're going to introduce you to Istio and the concepts of service mes...

Trick or treat, smell my skeet, give me a great service mesh. If you don't, I don't care, I'll pull out your token there! OK, know it doesn't all rhyme but let's learn how to deploy Istio!

6 months ago 1 1 0 0
Post image

Are you also at #kcddc? Come find me and say hi!

7 months ago 1 1 0 0
Preview
Chapter 15: Monitoring Clusters and Workloads Part II - OpenSearch YouTube video by Kubernetes: An Enterprise Guide

Your Pods, they're talking to you....can you hear them? We'll walk through how Kubernetes manages your logs using OpenSearch.
youtube.com/live/VeArPBy...

7 months ago 1 1 0 0
7 months ago 0 0 0 1

No, also, no one likes old pictures of them being posted on socials without their permission!!!!!

7 months ago 1 1 0 0

A customer did an accessibility review of OpenUnison's UI. Try hard to get it right, don't pretend to always do and was pretty happy at how well the report came back. Been in the weeds the last couple of days getting the few issues they found corrected.

7 months ago 4 1 0 0
Preview
Chapter 14: Backing Up Your Workloads - Part II YouTube video by Kubernetes: An Enterprise Guide

Backups and disaster recovery is so hot we couldn't keep it in just one live stream! We'll wrap up our chapter on backups today at noon EST!
youtube.com/live/ibE6I5_...

7 months ago 3 1 0 0
Post image

This was @tremolo.io first conference booth. Red Hat Summit 2015. We were talking about applications and OpenShift and almost everyone we talked to was asking about Satellite🤣🤣🤣. This was our official exit from "stealth".

8 months ago 2 1 0 0
Preview
Chapter 14: Backing Up Workloads YouTube video by Kubernetes: An Enterprise Guide

In a stream that's too hot for TV....the sexiest topic in all of enterprise infrastructure...BACKUPS!!!! Join us at noon for deep dive on our backups chapter with Velero!

youtube.com/live/yByl5Zm...

8 months ago 2 1 0 0
Advertisement
Preview
Securely Calling AWS APIs From Kubernetes Securely interact with AWS APIs from your Kubernetes clusters by generating short lived tokens. Explore how you can use Kubernetes' TokenRequest API, SPIRE, or OpenUnison's Security Token Service to…

For TBT, how can you use your Kubernetes ServiceAccount tokens to access AWS services? www.tremolo.io/post/securel...

10 months ago 1 1 0 0
Picture of the cover of Kubernetes: An Enterprise Guide, 3rd ed

Picture of the cover of Kubernetes: An Enterprise Guide, 3rd ed

Packt is giving Kubernetes: An Enterprise Guide, 3rd Ed away for $38US. Get the paperback, you get the PDF for free. Kube, auth, networking, monitoring, vCluster, Vault, Istio, Pulumi, and more!
a.co/d/7dwcw20

10 months ago 3 1 0 0
Preview
Chapter 9: Building Multitenant Clusters with vClusters - Part III YouTube video by Kubernetes: An Enterprise Guide

One more vCluster lab! We're wrapping up the chapter building a self service portal for vCluster deployment, integrating our vClusters with Vault for secrets management and our enterprise authentication. Hope to see you there! youtube.com/live/udRnQWd...

11 months ago 1 1 0 1
Preview
From the kubernetes community on Reddit Explore this post and more from the kubernetes community

If you're using OpenUnison, we're looking for help testing out our new kubectl authentication plugin! Any feedback would be greatly appreciated! www.reddit.com/r/kubernetes...

11 months ago 1 1 0 0
Preview
Chapter 9: Building Multitenant Clusters with vClusters - Part I YouTube video by Kubernetes: An Enterprise Guide

🚨In thirty minutes let's talk vClusters!🚨 youtube.com/live/QDOU1Jd...

1 year ago 4 1 0 0