We realized when coordinating over a
recent issue that we don't have a list of folks running production Kubernetes clusters and who therefore have a legitimate need to hear about Kubernetes security issues before they are made public.
Until now, knowledge of such issues have been coordinated just between a few people, mostly Red Hat and Google employees, but we think that's no longer appropriate given the growing number of users managing their own installations of Kubernetes. Therefore, I have created the
kubernetes-security-announce group. Anyone may request to join, but we will try to curate this correctly--please give some justification as to why you need early knowledge of security flaws when asking to join.