FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Kubernetes v1.35: Restricting executables invoked by kubeconfigs via exec plugin allowList added to kuberc
NewsDevOps

Kubernetes v1.35: Restricting executables invoked by kubeconfigs via exec plugin allowList added to kuberc

via Kubernetes Blog1mo ago

Did you know that kubectl can run arbitrary executables, including shell scripts, with the full privileges of the invoking user, and without your knowledge? Whenever you download or auto-generate a kubeconfig , the users[n].exec.command field can specify an executable to fetch credentials on your behalf. Don't get me wrong, this is an incredible feature that allows you to authenticate to the cluster with external identity providers. Nevertheless, you probably see the problem: Do you know exactly what executables your kubeconfig is running on your system? Do you trust the pipeline that generated your kubeconfig ? If there has been a supply-chain attack on the code that generates the kubeconfig, or if the generating pipeline has been compromised, an attacker might well be doing unsavory things to your machine by tricking your kubeconfig into running arbitrary code. To give the user more control over what gets run on their system, SIG-Auth and SIG-CLI added the credential plugin policy an

Continue reading on Kubernetes Blog

Opens in a new tab

Read Full Article
1 views

Related Articles

I switched to a solid-state portable battery for a week - now lithium-ion feels outdated
News

I switched to a solid-state portable battery for a week - now lithium-ion feels outdated

ZDNet • 9m ago

8-Bit Music Theory: How They Made The Great Sea Feel C U R S E D
News

8-Bit Music Theory: How They Made The Great Sea Feel C U R S E D

Dev.to • 2h ago

Smart Ward Assistant
News

Smart Ward Assistant

Medium Programming • 2h ago

News

I Built a SaaS App on a Broken Phone with Zero Budget - Here’s What Happened

Medium Programming • 2h ago

The Developer Took Revenge on the Manager — But Not the Way You’d Expect
News

The Developer Took Revenge on the Manager — But Not the Way You’d Expect

Medium Programming • 2h ago

Discover More Articles