Hashicorp Vault -  Secret Engines - #2
24:13
Пікірлер
@schoolbook1
@schoolbook1 4 күн бұрын
In CKS perspective this channel is one among the best so far. Am learning a lot on this channel. Bless you brother for this content.
@learnwithgvr
@learnwithgvr 4 күн бұрын
Thank you Bro
@JoseCastro-ql1yl
@JoseCastro-ql1yl 8 күн бұрын
Awesome
@learnwithgvr
@learnwithgvr 8 күн бұрын
Thanks for watching and keep learning
@manjushashi3851
@manjushashi3851 Ай бұрын
Hi, How to map the policy Vault to the AWS IAM role?
@learnwithgvr
@learnwithgvr Ай бұрын
In my channel there is video on Auto unseal using AWS KMS.... Check this video if it helps... if not let me know I will help you
@jaybotha5155
@jaybotha5155 Ай бұрын
Thank you very much for this video it helped alot.
@learnwithgvr
@learnwithgvr Ай бұрын
Glad to hear that it's helpful. Keep learning and subscribe and like
@Daveooooooooooo0
@Daveooooooooooo0 Ай бұрын
I didnt know pdb is not respected when pc is 0❤
@meetalideshmukh6889
@meetalideshmukh6889 Ай бұрын
Thanks alot.
@learnwithgvr
@learnwithgvr Ай бұрын
Thanks for watching Meetali, pls subscribe
@meetalideshmukh6889
@meetalideshmukh6889 Ай бұрын
@@learnwithgvr this series is far far better than the paid training I am receiving these days from office.
@VasyChristmas
@VasyChristmas Ай бұрын
Thank you kindly for your presentation. We are just implementing vault for storing and delivering secrets. This video is very useful.
@learnwithgvr
@learnwithgvr Ай бұрын
Glad to hear that video is useful
@manjushashi3851
@manjushashi3851 Ай бұрын
Hi Bro, let me know the process of vault access from IAM Role. Can you please help me
@learnwithgvr
@learnwithgvr Ай бұрын
There is documentation on vault IAM auth role, please go through and let me know if you have any questions support.hashicorp.com/hc/en-us/articles/19951252634387-How-to-Set-up-AWS-Auth-Method-Cross-Account-Access-with-Vault
@manjushashi3851
@manjushashi3851 Ай бұрын
@@learnwithgvr thanks for the reply bro. I will get back to you if I get stuck anywhere
@learnwithgvr
@learnwithgvr Ай бұрын
Sure
@pk-mh2cx
@pk-mh2cx Ай бұрын
Are you deciding how to install Kubebench during the exam or do they tell you?
@learnwithgvr
@learnwithgvr Ай бұрын
It's already installed, you just need to use it
@PRAVEENKUMAR-kg6rx
@PRAVEENKUMAR-kg6rx 2 ай бұрын
Mind blowing tutorial 😊😊😊 I learned about kms . Thank you
@learnwithgvr
@learnwithgvr 2 ай бұрын
Thanks a lot, keep learning
@ashishwakchaure1476
@ashishwakchaure1476 2 ай бұрын
Thanks GVR , very informative and presented very well , Please will you also make videos on topics like Cilium , eBPF?
@learnwithgvr
@learnwithgvr 2 ай бұрын
Sure will make detailed video on eBPF
@TheEmperorXavier
@TheEmperorXavier 2 ай бұрын
This is a very good breakdown of Vault. Thank you
@learnwithgvr
@learnwithgvr 2 ай бұрын
Thanks 👍
@vinayayinapurapu
@vinayayinapurapu 2 ай бұрын
is this still applicable? According to latest changes this PSP has been replaced / updated with Pod Security Admissions.
@learnwithgvr
@learnwithgvr 2 ай бұрын
In this Playlist Pod Security Admission is available
@vinayayinapurapu
@vinayayinapurapu 2 ай бұрын
you CKS series is like webseries. Its addicting. Also do you plan to update series on latest changes? Starting tomorrow there is a change in exam pattern.
@learnwithgvr
@learnwithgvr 2 ай бұрын
Not many changes ..but will do
@Veera945
@Veera945 2 ай бұрын
Very much useful video, Brother i need some information on how can we setup opa policy for creating a minimum of two pods <how to restrict if the user is creating with single pod>
@learnwithgvr
@learnwithgvr 2 ай бұрын
Yes possible, you need to setup on every deployment, should have min 2 pods. see below yaml. hope this helps ---------------------------------- apiVersion: gatekeeper.sh/v1beta1 kind: ConstraintTemplate metadata: name: minimum-pods spec: crd: name: minimumpods namespace: gatekeeper-system targets: - target: deployment parameters: - name: minPods type: integer ---------------------------------- apiVersion: gatekeeper.sh/v1beta1 kind: Constraint metadata: name: enforce-minimum-pods spec: template: name: minimum-pods parameters: - name: minPods value: 2
@sandeepmalviya100
@sandeepmalviya100 2 ай бұрын
Excellent video. Thank you
@learnwithgvr
@learnwithgvr 2 ай бұрын
Thank you Sandeep
@vinayayinapurapu
@vinayayinapurapu 2 ай бұрын
how to clean up the OPA CRD Constraint template to get back cluster to initial state? Just want to get cluster at original state without OPA gatekeeper and constraints.
@learnwithgvr
@learnwithgvr 2 ай бұрын
first find all using k api-resources, then is remove all Constraints, ConstraintTemplates
@vinaydeep557
@vinaydeep557 2 ай бұрын
Is OPA documentation allowed during exam?
@learnwithgvr
@learnwithgvr 2 ай бұрын
Not allowed bro...see here list of sites allowed during exam docs.linuxfoundation.org/tc-docs/certification/certification-resources-allowed#certified-kubernetes-administrator-cka-and-certified-kubernetes-application-developer-ckad-and-certified-kubernetes-security-specialist-cks
@pattanayakbabu559
@pattanayakbabu559 2 ай бұрын
Very helpful and informative session. Keep on posting this kind of session.
@learnwithgvr
@learnwithgvr 2 ай бұрын
Thank you
@prashanthrebel4875
@prashanthrebel4875 2 ай бұрын
Do we have kube-bench for rke cluster ?
@learnwithgvr
@learnwithgvr 2 ай бұрын
Sorry seen latem pls refer kubebench GitHub repo or use yaml file installation to scan
@TheNomadclub
@TheNomadclub 3 ай бұрын
great job brother ! such a gem
@learnwithgvr
@learnwithgvr 3 ай бұрын
Thanks Bro
@brontelobo
@brontelobo 3 ай бұрын
Very nice demo. Thank you!
@vitusyu9583
@vitusyu9583 3 ай бұрын
Also, could i know what terminal software you use? is it iterm2, or warp?
@learnwithgvr
@learnwithgvr 3 ай бұрын
it's iterm2
@vitusyu9583
@vitusyu9583 3 ай бұрын
One question: is it possible to apply a psp to the default service account? since i think it may be more important for a pod is run under the default sa if no specific service account is specified.
@learnwithgvr
@learnwithgvr 3 ай бұрын
Yes, we can apply and it's highly recommended for enhanced security By applying PSS to the default service account, you can significantly improve the security posture of your Kubernetes cluster and protect your applications and data from unauthorized access and potential vulnerabilities
@Vocal236
@Vocal236 3 ай бұрын
Its 💎. Thanks alot
@learnwithgvr
@learnwithgvr 3 ай бұрын
Thanks Bro
@vinayayinapurapu
@vinayayinapurapu 3 ай бұрын
is this still a valid series for CKS in 2024? i am planning to give next month.
@learnwithgvr
@learnwithgvr 3 ай бұрын
CKS new curriculum is applicable from Sept 12 onwards...so better plan before that. If not no issue there is slight change
@designer_X
@designer_X 3 ай бұрын
Are you need a Thumbnail designer ?
@learnwithgvr
@learnwithgvr 3 ай бұрын
Share your email
@ShradhaRathod-u1o
@ShradhaRathod-u1o 3 ай бұрын
what if I have ten nodes then the job will create the pod in any node, and it will provide information about that node only right? what about the rest nodes?
@learnwithgvr
@learnwithgvr 3 ай бұрын
Yes. While installing Kubebench on every node can provide granular insights into the security posture of each individual node, it's not always necessary or practical Pros: it provides detailed security assesment of everynode, Can detect, identify and resolve security issues of the Nodes Cons: kube bench will consumer resources Managing and monitoring of kube bench is time consuming Collecting security data from every node can generate a large volume of information that may be difficult to analyze If it is a small cluster, it's a feasible to have a cube bench in the nodes If your organization requires security assessment completely on all the nodes then go for it Deploy Kubebench on a dedicated node or a management cluster to scan all nodes periodically is the better approach Hope this helps. Thanks for asking this question
@diegonayalazo
@diegonayalazo 3 ай бұрын
Thanks
@learnwithgvr
@learnwithgvr 3 ай бұрын
Cheers
@prashantbathula5448
@prashantbathula5448 3 ай бұрын
Awesome detailed explanation
@learnwithgvr
@learnwithgvr 3 ай бұрын
Thank you
@rajeshraj-bx2zb
@rajeshraj-bx2zb 3 ай бұрын
Sir please do the additional topics added for cks kubernetes - newchanges from sep12
@rajeshraj-bx2zb
@rajeshraj-bx2zb 3 ай бұрын
Sir please do the additional topics added for cks kubernetes - newchanges from sep12 .
@learnwithgvr
@learnwithgvr 3 ай бұрын
thanks for suggestion. sure will do.
@rajeshrajesh-zn8vm
@rajeshrajesh-zn8vm 3 ай бұрын
Please do cks new topics which are going to be added from sep12 for upcoming cks exam.
@learnwithgvr
@learnwithgvr 3 ай бұрын
thanks for your input. sure will do soon
@MaryC33333
@MaryC33333 3 ай бұрын
Excellent video, thanks for the info!
@learnwithgvr
@learnwithgvr 3 ай бұрын
Thank you
@RaviPrakash-ix9dd
@RaviPrakash-ix9dd 4 ай бұрын
sir you give best explanation, thank you for uploading 🙏 please uploading interview questions for aws
@learnwithgvr
@learnwithgvr 4 ай бұрын
Thank you Ravi Prakash. sure will try to creat videos on AWS interview questions
@debidattagouda9374
@debidattagouda9374 4 ай бұрын
u are a great teacher.
@learnwithgvr
@learnwithgvr 4 ай бұрын
Thank you
@vaishakh-aws
@vaishakh-aws 4 ай бұрын
Excellent explanation with all your expertise, Dear GVR. I'm sure this content of yours will stay at the top among all for many more years. Thank you for making it easy to understand.
@learnwithgvr
@learnwithgvr 4 ай бұрын
My pleasure, keep learning
@romanigorevich5021
@romanigorevich5021 4 ай бұрын
Thanks for your video; it's useful. One piece of advice: It looks like you have a good microphone but no pop filter, or it's positioned incorrectly. There are intense plosive sounds. When you try to fix it, your sound will be much better than now!
@learnwithgvr
@learnwithgvr 4 ай бұрын
thanks for suggestion, cheers
@MOHAMMEDAHMEDMUDASSIR
@MOHAMMEDAHMEDMUDASSIR 4 ай бұрын
IS THIS THE COMPLETE TRAINING PLAYLIST ON KUBERNETES SECURITY ?
@learnwithgvr
@learnwithgvr 4 ай бұрын
yes pls check my playlists in the channel
@sureshscribnar
@sureshscribnar 5 ай бұрын
greate videos. Thanks for the content. I like the way your terminal shows color? How did you configure it this way? Is it any plugin or any other terminal?
@learnwithgvr
@learnwithgvr 5 ай бұрын
Thanks bro for the feedback. It's iTerm2 terminal for Mac. Applied autosuggestion, syntax highlight and kubecolor on top it for kubectl colours
@ElCanalDeJoshOfficial
@ElCanalDeJoshOfficial 5 ай бұрын
You should do an additional video to explain what has changed for the CKS. This content is amazing!
@learnwithgvr
@learnwithgvr 5 ай бұрын
Great suggestion!, will do soon, thank you
@charlesuneze
@charlesuneze 6 ай бұрын
Nice video. What's the name of your mic?
@learnwithgvr
@learnwithgvr 6 ай бұрын
Thanks, it's Audio-Technica ATR2100x-USB Cardioid Dynamic USB XLR Microphone
@charlesuneze
@charlesuneze 6 ай бұрын
@@learnwithgvr Thank you
@jalandharbehera99
@jalandharbehera99 6 ай бұрын
❤❤
@learnwithgvr
@learnwithgvr 4 ай бұрын
thank you
@sebastianilopezgma
@sebastianilopezgma 6 ай бұрын
Thxs! good video!
@learnwithgvr
@learnwithgvr 4 ай бұрын
thank you
@henikamoun3826
@henikamoun3826 6 ай бұрын
hello thank u but can u tell me why with the new user it only show the default namespace not all of them somoene can help ?
@learnwithgvr
@learnwithgvr 4 ай бұрын
if do not specify it will consider defult namespace. if you want any specific namespace you can update your kubeconfig desired context namespace
@santoshs3441
@santoshs3441 6 ай бұрын
excellent explanation
@learnwithgvr
@learnwithgvr 4 ай бұрын
thanks a lot
@vijaynarayanan2836
@vijaynarayanan2836 6 ай бұрын
Nice video and informative. Please reduce filler words. Repetitively using basically word. Sometimes it’s kind of annoying
@learnwithgvr
@learnwithgvr 6 ай бұрын
Thanks for the feedback, it was first video and listen 1.5x speed for better reach