Containers · 8 min
Hardening container images without slowing your pipeline
Distroless bases, digest pins, and a scan policy that fails the build only when the finding is reachable — not when the CVE feed is loud.
Read →Writing
Long-form pieces on the controls, pipelines, and data paths I actually implement. Newest first.
Containers · 8 min
Distroless bases, digest pins, and a scan policy that fails the build only when the finding is reachable — not when the CVE feed is loud.
Read →DSPM / DLP · 11 min
Classification without inventory is a dashboard. Map stores, identities, and egress paths first — then the DLP rule has somewhere to live.
Read →DevOps · 9 min
OPA and Kyverno only work when the exception path is a pull request with an expiry. Otherwise you have a wiki with YAML.
Read →Cloud Security · 10 min
The resource policy you did not draw is the one the attacker walks. Graph who can assume whom, then cut the edges that surprise you.
Read →DevOps · 7 min
Pre-commit, the git host, and runtime detection are three different jobs. Mixing them is how every finding becomes a medium.
Read →DSPM / DLP · 12 min
Object storage PUT, kubectl cp, and a mis-aimed Fluent Bit are how regulated data leaves. Browser CASB never saw them.
Read →