Habr•October 8, 2026•🇷🇺Translated from Russian

Tools Alone Won't Suffice: Building Systemic Kubernetes Security Across Hundreds of Clusters at Alfa-Bank

Alfa-Bank has operated Kubernetes clusters for more than ten years and reports that over 53 percent of Russian companies now use vanilla Kubernetes, yet security outcomes remain poor. According to the Red Hat “State of Kubernetes Security 2024” report, 46 percent of organizations suffered financial losses due to insufficient Kubernetes security, and nine out of ten experienced at least one container or Kubernetes-related incident.

Alexander, lead of the K8S and cloud security department, argues that the root cause is not a lack of tools—more than 100 security products exist—but the absence of a systemic process framework. Before the bank adopted such a framework, requirements, incidents, and audits existed in isolation, and teams had no accurate inventory of clusters or their configurations.

Process Map Built Around the Threat Lifecycle

The bank groups its processes into a pipeline that follows the threat lifecycle: detect, prevent, verify, control, and respond. Every process begins with threat modeling that feeds into security requirements, which are then communicated to delivery teams, validated through reviews and audits, and supported by runtime monitoring and incident response. The resulting map closely resembles classic security operations workflows rather than Kubernetes-specific tooling checklists.

Responsibility for each step is defined using a RACI matrix that distinguishes Responsible, Accountable, Consulted, and Informed parties. This matrix is applied across domains because cluster security depends on node security, business workload security depends on the cluster, and vice versa.

Key Process Areas

  • Threat modeling draws on commercial feeds, public research, and internal intelligence; the security team owns the model and maps scenarios to requirements.
  • Requirements are translated into architecture patterns for single-tenant and multi-tenant clusters, plus scripts, playbooks, and audit policies developed jointly with DevOps teams.
  • Project expertise is coordinated by AppSec Business Partners who route relevant projects to the Kubernetes security team for validation against patterns and specifications.
  • Audits combine automated and manual detection of misconfigurations, contextual validation with delivery teams, remediation tracking against SLAs, and two-stage inventory covering both clusters and their internal objects.
  • Risk assessment serves as the final control when technical mitigation is impossible; the Kubernetes team contributes mitigation descriptions and risk scenarios.
  • Platform operations run on four dedicated clusters managed entirely by the security team.
  • SOC integration supplies log-collection policies, detection signatures, and playbooks while the SOC team leads primary incident response.

Competency Model and Staffing

Four roles cover the required breadth of skills: Architect (sets foundational decisions), Analyst/Engineer (implements and operates processes), Auditor (drives the full audit lifecycle and tooling), and Platform DevOps Engineer (maintains observability and platform stability). With more than 500 clusters ranging from six to over 300 nodes, the bank determined that these four specialized positions are the minimum needed to sustain the system.

Related articles

Habr•Other

Luna Decisions Integration with n8n for Real Estate Listing Parsing: Workflow Architecture, Limitations and Open Questions

A detailed technical discussion explores the use of n8n workflows to monitor real estate advertisements by combining scheduled data collection, normalization, and comparison logic with potential AI-driven decision layers. The article examines the boundary between raw parsing and actionable decisions, highlighting how simple code-based event detection can be augmented by structured outputs from models such as OpenAI GPT-6 Luna Decisions. Key components include a Dispatcher node that identifies new listings, price drops, and removals, while storing state in Google Sheets and generating Telegram summaries. Limitations around data completeness, currency conversion, and false positives for sold status are analyzed in depth. The author proposes an experimental branch that routes validated price-change events to Luna Decisions API for typed scoring before any human notification. Overall the piece invites community feedback on whether a dedicated Decisions API provides measurable advantages over rule-based conditions or standard structured LLM outputs.

AntiMalware•Other

Bureau 1440 Unveils Satellite Internet Terminals Reaching 700 Mbps for Industrial and Rail Use

Bureau 1440 presented three satellite terminal models at the Digital Solutions forum in Russia. The 1440 ULTRA model supports data speeds up to 700 Mbps and is designed for remote industrial sites and infrastructure, operating both stationary and in motion. The company reduced the terminal's weight by 30 percent while maintaining 600 by 600 mm dimensions and adding IP67 dust and water protection. The 1440 ZEMLYA variant is already undergoing tests on Russian Railways trains, including Lastochka and Sapsan services, and is rated for operation at speeds up to 400 km/h. A compact 1440 MINI concept aims for around 100 Mbps in a 300 by 300 mm portable form factor intended for rescue teams and expeditions. All models are being developed alongside the company's low-orbit satellite constellation, with test connections already active on rail lines and in remote settlements. Sales have not yet begun, and the company will announce availability separately while noting that maximum speeds are not guaranteed in every environment.

AntiMalware•Other

GTA V Unofficial Browser Port Runs Locally via WebAssembly Using Leaked Rockstar Sources

Enthusiasts created an unofficial port of GTA V that executes the game directly in the browser through WebAssembly without any cloud streaming. The project compiled the original RAGE engine to wasm64 and built a compatibility layer translating DirectX 11 calls to WebGPU. Game assets were served over HTTP while JavaScript handled input and saves, and AudioWorklet managed audio. The port retained Euphoria physics and Scaleform interfaces but removed Bink video playback. Requirements ranged from 3 to 16 GB of RAM, supporting both story mode and free roam. The site was taken offline shortly after launch, first displaying a thank-you message and later redirecting to adult content. Analysis of the build confirmed debug symbols and developer file paths consistent with leaked Rockstar source code.

Habr•Other

PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios

A large organization's PKI infrastructure faced a critical bottleneck when a data center outage triggered simultaneous startup of tens of thousands of Kubernetes pods, each requiring mTLS certificates. The existing setup using ESAUS and Citadel routed all requests through external certificate authorities that could only sustain 50-70 RPS against an incoming burst of 100,000 requests. Average daily load of 10-11 RPS had masked the thundering herd risk during mass recovery. Scaling the CA 15x was rejected due to cost and the fundamental dependency on real-time signing. The team introduced pre-issuance of certificates stored in a dedicated Unified Secret Storage (ЕХС) layer that supports 14,000 RPS reads while the CA continues normal operation. This architectural separation of issuance and consumption reduced recovery time from nearly 24 minutes to seconds while shifting focus to secure secret lifecycle management including KRA key protection.