Author: nim
[AWS/EKS] Unlocking Simplicity and Security of Amazon EKS Pod Identity.
Amazon EKS Pod Identity is a new feature introduced by Amazon EKS that simplifies the process for cluster administrators to configure Kubernetes applications to obtain AWS IAM permissions. This enhancement allows permissions to be configured more easily and with fewer steps, directly through the EKS console, APIs, and CLI. Links This feature is particularly important…
Read More “[AWS/EKS] Unlocking Simplicity and Security of Amazon EKS Pod Identity.” »
[Gitleaks/njsscan/semgrep] Secure Your code by CAST and SAST tools
Look into CAST tool Ở đây mình sẽ dụng Docker để run gitleaks Bạn sẽ cần replace: ${path_to_host_folder_to_scan} đây là folder chứa code của bạn.Và tiếp theo là phần [COMMAND]: Và bên dưới là phần chúng ta scan, mình sử dụng command detect. nếu bạn muốn output hiện thị chi tiết hơn thêm –verbose Để…
Read More “[Gitleaks/njsscan/semgrep] Secure Your code by CAST and SAST tools” »
[K8S] How to distribute pod all over node on K8S
The affinity spec, particularly the podAntiAffinity section in Kubernetes, is used to control how pods are scheduled relative to each other What is Pod Anti-Affinity? Pod Anti-Affinity is a Kubernetes scheduling feature that prevents pods with specific labels from being placed on the same node or a set of nodes. It’s used to increase application…
Read More “[K8S] How to distribute pod all over node on K8S” »
[Golang] The declarations are very helpful in Golang
[Security Group/Terraform] Look into some exciting in Security Group Terraform
Hôm nay mình gặp khá nhiều lỗi trong khi cố gắng add thêm 1 rule trong Sec Group của AWS bằng terraform. Đầu tiên mình đã có sẵn 1 SecGroup template đã được sử dụng trước đó. Bạn có thể thấy là mình đang có 1 rule inbound vào port 9094 cho phép subnet được…
Read More “[Security Group/Terraform] Look into some exciting in Security Group Terraform” »
[Synthetic Test] Create a Status Page for your product easily.
Mình chắc hẳn các bạn đã sử dụng các dịch vụ như là github, aws, …Và khi bạn vào hay sử dụng dịch vụ bạn thấy lag lag,Bạn lên google và gõ các từ khóa như là github status Bạn cũng đang muốn làm 1 status page như github. 1) Uptime-Kuma 1.1) Install Uptime-Kuma on…
Read More “[Synthetic Test] Create a Status Page for your product easily.” »
[AWS] Optimizing Image Storage in Amazon ECR: Understanding Layer Reuse and Immutability.
When you push an image to ECR, it is stored as a series of layers that represent the image contents. Each layer contains filesystem changes, metadata, etc. When you push a second image to ECR, even if it has different metadata, like the tag name, ECR checks the layer contents and reuses any identical layers….
[Golang/Swagger] Apply Swagger to describe the information API on Golang
Sau khi chúng ta thực hiện code xong 1 api thì chúng ta cần note lên 1 swagger để các teams khác integrate sẽ dễ dàng hơn Với echo framework thì chúng ta sẽ sử dụng echo-swagger Bạn sẽ cần chạy các command dưới đây, cùng vị trí với file main.go tiếp đến bạn chạy…
Read More “[Golang/Swagger] Apply Swagger to describe the information API on Golang” »
[Oauth2-Proxy] Oauth2-Proxy encounters issue with Cognito
Hiện tại thì Oauth2-Proxy incounter issue with Cognito.https://github.com/oauth2-proxy/oauth2-proxy/pull/2265 oauth2-proxy encodes the redirect-URL as part of the state parameter to the authorization endpoint. AWS doesn’t give a full documentation on valid characters, but it hints that URL-encoding data will not work and advice to do a base64 encoding instead. https://docs.aws.amazon.com/cognito/latest/developerguide/authorization-endpoint.html This patch will do a base64-encoding…
Read More “[Oauth2-Proxy] Oauth2-Proxy encounters issue with Cognito” »