<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: zaronkedl</title><link>https://news.ycombinator.com/user?id=zaronkedl</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 01 May 2026 18:41:41 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=zaronkedl" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by zaronkedl in "Show HN: Kloak, A secret manager that keeps K8s workload away from secrets"]]></title><description><![CDATA[
<p>That's right, OP is the main maintainer and the idea he has is that nothing should change in the application.  The application believe it has the secret, but the secret is injected on the wire AND only for the intended destination.<p>Please have a look at the demo if you can ; there is a webhook that abstract changing the secret resource name for you.  You just "annotate" the secret resource and kloak admission controller will rewrite secrets of your deployment resource for you after that.  This means the app never actually see the secret (accidental or not).</p>
]]></description><pubDate>Sun, 26 Apr 2026 10:48:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909215</link><dc:creator>zaronkedl</dc:creator><comments>https://news.ycombinator.com/item?id=47909215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909215</guid></item><item><title><![CDATA[New comment by zaronkedl in "Show HN: Kloak, A secret manager that keeps K8s workload away from secrets"]]></title><description><![CDATA[
<p>Yes, we have host and ip filtering in place that can be used to ensure the secret is sent only for the destination we expect.<p>It's not perfect though, see
Host Filtering |
<a href="https://getkloak.io/docs/guides/host-filtering.html" rel="nofollow">https://getkloak.io/docs/guides/host-filtering.html</a></p>
]]></description><pubDate>Sun, 26 Apr 2026 10:39:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909156</link><dc:creator>zaronkedl</dc:creator><comments>https://news.ycombinator.com/item?id=47909156</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909156</guid></item></channel></rss>