Containers · 8 min
Hardening container images without slowing your pipeline
Distroless bases, digest pins, and a scan policy that fails the build only when the finding is reachable — not when the CVE feed is loud.
Read →Cloud Security / DevOps / Data Protection
I’m a security architect writing long-form, implementation-level articles on DevOps, containers, and DSPM/DLP. No noise — just the ideas that actually ship.
$ scan --scope cluster --fail-on highscanning 42 workloads · 6 namespaces✓ image digest pinned 38/42! privileged containers 2✗ secrets in env 1$ kubectl get ns --show-labelsNAME STATUS AGEprod Active 412dbuild Active 89d$ dlp policy diff --from main+ block exfil via object store~ classify unstructured at restposture score 72 → 81
Containers · 8 min
Distroless bases, digest pins, and a scan policy that fails the build only when the finding is reachable — not when the CVE feed is loud.
Read →DSPM / DLP · 11 min
Classification without inventory is a dashboard. Map stores, identities, and egress paths first — then the DLP rule has somewhere to live.
Read →DevOps · 9 min
OPA and Kyverno only work when the exception path is a pull request with an expiry. Otherwise you have a wiki with YAML.
Read →Pipelines, policy as code, and the controls that survive a real release train.
Image hardening, runtime isolation, and Kubernetes posture that does not stall delivery.
Finding shadow data, classifying it, and stopping exfil without breaking the business.
Identity, blast radius, and the control planes that actually decide who can take the data.
Twelve years across cloud, containers, and data protection. I write up the designs that survived contact with production — and the ones that did not.