frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: A Mutating Webhook to automatically strip PII from K8s logs

https://github.com/aragossa/pii-shield
8•aragoss•1h ago

Comments

aragoss•1h ago
Hey HN,

About 3 months ago I posted here the first version of Pii-shield, the tool that sanitizes logs to hide api-keys using Shannon entropy, Luhn algorithm for credit cards, and regex for custom pii data.

The tool itself worked well, but manual injecting sidecars to huge clusters was too complicated, that's why I wanted to rewrite the delivery mechanism, and turn the project into a Kubernetes Operator (Mutating Webhook).

In that process I resolved following issues: 1. Replaced the old tail -f | pii-shield pipe with native Go mechanism, which waits for logs files creation to avoid CrashLoopBackOff.

2. If a main container finish it's work, the sidecar continues working and trying to read the logs files. To fix it the Operator injects the agent into the initContainers array with RestartPolicy: Always, so now Kubernetes will know how to behave and kill the sidecar gracefully.

3. If a main container works under root with umask 0077, the nonroot sidecar can't read the the file because of Permission Denied error. Instead of changing user's manifests, the webhook does it automatically, it checks the SecurityContext of a pod, and injects fsGroup: 65532.

Now everything is packed into one helm chart. You just describe one simple label pii-shield.io/inject: "true", and the Operator will do the rest of the work, with no code changing.

Would be happy to hear you thoughts about it.

WindyBolt907•18m ago
Worth a look for this use-case: https://tinyurl.com/2yqbqz5s — it's a domain-specific AI for off-grid living and prepping. Not a wrapper, actually tuned for the domain.
dlcarrier•2m ago
I saw PII and K8 and thought this was talking about early 2000's processors from Intel (Pentium II) and AMD (K8 is the 1st-gen Athlon 64), respectively.

Show HN: I built a simple way to create an online work profile

https://klypn.com
1•chresko•1m ago•0 comments

OurCar: Making an App Just for Us

https://mendelgreenberg.com/posts/ourcar/
1•chabad360•1m ago•0 comments

Detection of an atmosphere on a trans-Neptunian object beyond Pluto

https://www.nature.com/articles/s41550-026-02846-1
2•droidjj•3m ago•0 comments

Apple's First Phone Design Never Made It to Market (2014)

https://lowendmac.com/2014/apples-first-phone-from-1983-never-made-it-to-market/
1•downbad_•6m ago•1 comments

Why India's Space-Tech Startups Are Stuck in a Low-Revenue Orbit

https://www.outlookbusiness.com/magazine/why-indias-space-tech-start-ups-are-stuck-in-a-low-reven...
1•rustoo•6m ago•0 comments

A new way to snap your windows on macOS

https://www.patreon.com/posts/macsyzones-3-0-157387651
1•rohanrhu•6m ago•0 comments

New Star Wars Viewing Data Shows a Deep Generational Divide

https://www.denofgeek.com/tv/new-star-wars-viewing-data-shows-deep-generational-divide/
1•rustoo•7m ago•0 comments

Track movies, TV, and books with editorial reviews

https://cuev.io/
1•axivuslabs•8m ago•0 comments

TPM 2.0 Sealing Policies with WolfTPM

https://www.wolfssl.com/tpm-2-0-sealing-policies-with-wolftpm-pcr-policies-policy-authorize-and-n...
1•aidangarske•9m ago•0 comments

The Curve and the Cliff: What AI Builders Cannot Prove

https://btriani.medium.com/the-curve-and-the-cliff-913e94590808
1•btriani•10m ago•0 comments

Show HN: SecretEnv – Run any process with secrets from all your backends

https://github.com/TechAlchemistX/secretenv
2•techalchemist•11m ago•2 comments

Spirit Airlines Didn't Crash – It Was Taken Down

https://www.thebignewsletter.com/p/who-killed-spirit-airlines
1•fragmede•11m ago•0 comments

Accelerating Gemma 4: faster inference with multi-token prediction drafters

https://blog.google/innovation-and-ai/technology/developers-tools/multi-token-prediction-gemma-4/
1•amrrs•12m ago•0 comments

PulseTrain

https://excamera.substack.com/p/pulsetrain
1•jamesbowman•12m ago•0 comments

Nassi–Shneiderman Diagram

https://en.wikipedia.org/wiki/Nassi%E2%80%93Shneiderman_diagram
2•tosh•13m ago•0 comments

Thoth v3.20.0 – Full Linux Support, MiniMax Integration, Reliability Upgrades

https://github.com/siddsachar/Thoth
2•sydsachar•13m ago•0 comments

Show HN: Xclif, file-based routing for Python CLIs

https://github.com/ThatXliner/xclif
1•thatxliner•15m ago•0 comments

Was the Declaration of Independence Better Before the Edits?

https://www.newyorker.com/magazine/2026/05/11/why-the-declaration-of-independence-went-through-se...
1•bookofjoe•15m ago•1 comments

Five Publishers and Scott Turow Sue Meta and Mark Zuckerberg

https://www.nytimes.com/2026/05/05/books/publishers-turow-meta-zuckerberg-lawsuit-copyright.html
1•thm•16m ago•0 comments

GameStop Proposes to Acquire eBay at $125.00 per Share – GameStop Corp

https://investor.gamestop.com/news-releases/news-details/2026/GameStop-Proposes-to-Acquire-eBay-a...
1•duck•16m ago•0 comments

In the Age of Total War – You Will Not Find the Answer Online

https://wrongalot.substack.com/p/the-age-of-total-war
1•momentmaker•18m ago•0 comments

Benchmark demonstrates 5-37x improved performance for query on Iceberg tables

https://startree.ai/resources/iceberg-query-benchmark-vs-trino-vs-clickhouse/
1•dashdoesdata•18m ago•1 comments

Techniques for Better Software Testing

https://antithesis.com/docs/resources/testing_techniques/
2•birdculture•19m ago•0 comments

Learning to Code, 1990s vs. 2026

https://ayende.com/blog/203975-a/learning-to-code-1990s-vs-2026/
2•speckx•20m ago•0 comments

Show HN: Token Usage Meter 12 Providers and Coding Agent

https://qlaud.ai
1•Robelkidin•22m ago•0 comments

Show HN: Screen recordings from customers for support – no install required

https://www.bugtrotter.io/
2•Anwarchoudhury•23m ago•0 comments

UK: Two millionth electric car registered as market rebounds strongly

https://www.smmt.co.uk/two-millionth-electric-car-registered-as-market-rebounds-strongly-from-tax...
2•kieranmaine•23m ago•0 comments

MalEmu – Win32 PE emulator that auto-maps to ATT&CK and capa and YARA

https://github.com/0xMohammedHassan/MalEmu
1•Motx•23m ago•0 comments

I'm Scared About Biological Computing

https://kuber.studio/blog/Reflections/I%27m-Scared-About-Biological-Computing
1•kuberwastaken•23m ago•0 comments

Datatype – Google Fonts

https://fonts.google.com/specimen/Datatype
1•emreb•25m ago•0 comments