# Five copies of a kubeconfig, one name in the audit log

Canonical: https://brew.new/templates/goteleport/five-copies-of-a-kubeconfig-one-name-in-the-audit-log

Brand: goteleport.com
Category: general

![Preview of Five copies of a kubeconfig, one name in the audit log](https://cdn.brew.new/email-preview-88a1b1753c4a5b97-tracking_r57zzjt4ar23qwp6eatjrvvm198fsxrz-1791321668020.png)

## Email content

Teleport

New in Identity

Teleport — The AI Infrastructure Identity Company

Identity Summit: Mountain View and New York

More than 100 infrastructure and security leaders joined us at the Computer History Museum in Mountain View on September 24 and the Lotte Palace in New York on September 30. Ev Kontsevoy opened both with the argument that controls written for a static org chart cannot govern AI agents. Teleport product and marketing leaders laid out the move from Zero Trust to Agent Trust and gave a first look at Teleport Beams, which is the trusted runtime for agents launching November 9 (sign up for the waitlist). Speakers from Cisco, Duo SecurityDoorDash, Dialpad, VikingCloud, Veeam Software, Alteryx, CoreWeave, and THG Ingenuity shared how Teleport powers their solutions, accelerate AI safely while scaling to organizational demands.

Paris Summit is next, on November 5 at The Peninsula Paris.

Sign up to attend →

How to Eliminate Shared Production Kubeconfigs

By Daniele Polencic and Gulcan Topcu

A client certificate inside a kubeconfig supplies the username system:admin and the group system:masters, which bypasses RBAC, and Kubernetes keeps no list for revoking a single copy. Daniele Polencic, founder of LearnKube, where he teaches Kubernetes to engineers running it in production, works through the lab with co-author Gulcan Topcu. Deleting a CertificateSigningRequest leaves the signed certificate working, and recreating a ServiceAccount cuts off all of its tokens at once. You come away with a kubeconfig that holds login instructions instead of a credential, and a test showing one disabled SSO account losing access while a teammate keeps it.

Read the full post →

What PCI DSS 4.0 Requires for Infrastructure Identity and Access Evidence

By Eric Dixon

As a GRC and cybersecurity consultant preparing organizations for PCI DSS 4.0 assessments, Eric Dixon finds over-privileged RBAC more often than anything else, with access that outlives a role change close behind. He follows the evidence the way an assessor does, tying each access event to a person, the privileges in effect, and the review that followed. Dixon matches Requirements 7, 8, and 10 to the artifacts that satisfy them, from Kubernetes RBAC bindings to a single SIEM alert traced through ticket and resolution under 10.4.1.1. He closes with three traces to run on your own environment before the assessor arrives.

Read the full post →

Identity Security for AI

By Ben Arent

Fewer than 0.1% of employees are likely insider threats, and Teleport's Ben Arent argues that nearly all agents deserve that treatment by default. Delegation chains from user to agent to subagent blur who owns an action, and a two-approver rule means little when the same model fills both seats. Arent sets six identity security problems side by side for humans, service accounts, and agents. Then he walks through the trusted runtimes, LLM audit, and agentic classifiers in Teleport Identity Security for AI that answer them.

Read the full post →

Have questions or want to keep the conversation going? Join us in our Community Slack →

If you found this useful, pass it along to someone else who would, too.

Thanks for reading,

The Teleport Editorial Team

P.S. We'll be at these events over the next few weeks. Come find us.

Oct 14-15: DTX London, London

Oct 21-22: Platform Engineering & Developer Experience Summit, London

Oct 21-22: KCD UK, Edinburgh

Nov 4: Cloud Native London, London

Nov 5: Teleport Identity Summit, Paris

Nov 9-10: LeadDev Berlin, Berlin

Nov 9-12: KubeCon North America, Salt Lake City | Live session

Find us near you: https://goteleport.com/events/

Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612

If you no longer wish to receive these emails anymore, click on the following link:

UNSUBSCRIBE

TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY

[Open and remix this design](https://brew.new/templates/goteleport/five-copies-of-a-kubeconfig-one-name-in-the-audit-log)

[Browse email designs](https://brew.new/browse/templates)
