Picture this: your kubeconfig quietly firing off a shady script on your machine. Kubernetes 1.35 slams the door with an exec plugin allowlist, handing you god-mode control over credential plugins.
DevTools FeedApr 03, 20263 min read11 views
⚡ Key Takeaways
Kubernetes 1.35 adds exec plugin allowList to kubeconfig, blocking rogue executables by default.𝕏
Set policy to DenyAll first to audit plugins, then whitelist trusted ones by path or name.𝕏
Future: checksums and signatures will make this unbreakable against supply-chain attacks.𝕏
The 60-Second TL;DR
Kubernetes 1.35 adds exec plugin allowList to kubeconfig, blocking rogue executables by default.
Set policy to DenyAll first to audit plugins, then whitelist trusted ones by path or name.
Future: checksums and signatures will make this unbreakable against supply-chain attacks.