From KIAM to EKS Pod Identities, with Fabián Sellés Rosa

An unmaintained identity component can remain invisible until a routine Kubernetes upgrade turns it into an incident.

Fabián Sellés Rosa, Platform Engineer and Runtime Tech Lead at Adevinta, explains how his team moved from KIAM to EKS Pod Identities without discarding the security boundaries and application interface that their internal platform depended on.

In this interview:

  • Why KIAM became urgent to replace after years of stable operation

  • How Crossplane, a custom controller, and KRO with ACK compared against the team's criteria

  • Why managed EKS Capabilities reduced toil but introduced observability and rollout trade-offs

  • How Kyverno preserved namespace-level authorization for IAM roles

Sponsor

This episode is sponsored by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits.

More info

  • Find all the links and info for this episode here: https://ku.bz/R_06hwnCn

  • Interested in sponsoring an episode? Learn more.