L’Auvergnat Breton 🧜‍♂️ is a user on mastodon.papey.fr. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

That's the part of the containers way I just can't accept:

github.com/kubernetes/ingress/

1. Your ingress controller is a Google managed nginx image you have no guarantee on.
2. It downloads and run a binary from Github.

No hashs, no signatures; Google, GitHub, tini's owner and anyone pwning them could get a root shell in your setup and MITM everything without anyone noticing for some time.