🔒 Security & Privacy

Kubernetes 1.35: Taming Wild Kubeconfig Executables with AllowLists

Your kubeconfig might be running mystery code on your machine. Kubernetes 1.35 slams the door with exec plugin allowLists—simple, beta-ready security that feels like a bouncer for your credentials.

Kubernetes logo with a padlock securing a kubeconfig file and exec plugin icons

⚡ Key Takeaways

  • Kubernetes 1.35 adds beta credentialPluginPolicy and allowlist to kubeconfigs, curbing arbitrary exec risks. 𝕏
  • Set DenyAll to audit plugins, then whitelist paths or basenames for tight control. 𝕏
  • Future: checksums and signatures—turning plugins into trusted fortresses. 𝕏
Published by

Open Source Beat

Community-driven. Code-first.

Worth sharing?

Get the best Open Source stories of the week in your inbox — no noise, no spam.

Originally reported by Kubernetes Blog

Stay in the loop

The week's most important stories from Open Source Beat, delivered once a week.