Kubernetes 1.35: Taming Wild Kubeconfig Executables with AllowLists
Your kubeconfig might be running mystery code on your machine. Kubernetes 1.35 slams the door with exec plugin allowLists—simple, beta-ready security that feels like a bouncer for your credentials.
theAIcatchupApr 07, 20263 min read
⚡ Key Takeaways
Kubernetes 1.35 adds beta credentialPluginPolicy and allowlist to kubeconfigs, curbing arbitrary exec risks.𝕏
Set DenyAll to audit plugins, then whitelist paths or basenames for tight control.𝕏
Future: checksums and signatures—turning plugins into trusted fortresses.𝕏
The 60-Second TL;DR
Kubernetes 1.35 adds beta credentialPluginPolicy and allowlist to kubeconfigs, curbing arbitrary exec risks.
Set DenyAll to audit plugins, then whitelist paths or basenames for tight control.
Future: checksums and signatures—turning plugins into trusted fortresses.