<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Isolation on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/isolation/</link>
    <description>Recent content in Isolation on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 16 May 2025 09:30:03 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/isolation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Securing Kubernetes 1.33 Pods: The Impact of User Namespace Isolation</title>
      <link>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</link>
      <pubDate>Fri, 16 May 2025 09:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</guid>
      <description>Kubernetes 1.33 enables user namespace isolation by default for pods, greatly enhancing security by mapping container root users to unprivileged host UIDs. This post explores the feature’s security benefits including process isolation and lateral movement prevention, infrastructure requirements like Linux kernel 6.3 and compatible container runtimes, and how to enable user namespaces in your pod specifications. Learn why this advancement is crucial for securing Kubernetes workloads in modern environments.</description>
    </item>
  </channel>
</rss>
