An unmaintained identity component can remain invisible until a routine Kubernetes upgrade turns it into an incident.
Fabián Sellés Rosa, Platform Engineer and Runtime Tech Lead at Adevinta, explains how his team moved from KIAM to EKS Pod Identities without discarding the security boundaries and application interface that their internal platform depended on.
In this interview:
Why KIAM became urgent to replace after years of stable operation
How Crossplane, a custom controller, and KRO with ACK compared against the team's criteria
Why managed EKS Capabilities reduced toil but introduced observability and rollout trade-offs
How Kyverno preserved namespace-level authorization for IAM roles
Sponsor
This episode is sponsored by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits.
More info
Find all the links and info for this episode here: https://ku.bz/R_06hwnCn
Interested in sponsoring an episode? Learn more.
Information
- Show
- FrequencyUpdated weekly
- Published4 August 2026 at 10:00 UTC
- Length27 min
- Season9
- Episode2
- RatingClean
