Skip to Content
All memories

DevSecOps & Resilience Engineering

Browse series · RSS · Atom

Start here: first entry.

  1. Supply Chain Security: SLSA, SBOM, and Build Provenance

    January 1, 2022 · 3 min

    Spec-driven research note (January 2022): Supply Chain Security: SLSA, SBOM, and Build Provenance.

  2. Reproducible CI/CD: Determinism as Defense

    February 1, 2022 · 3 min

    Engineering notebook entry (February 2022): Reproducible CI/CD: Determinism as Defense.

  3. Secrets Hygiene: Rotation, Scoping, and Runtime Delivery

    March 1, 2022 · 3 min

    Adversarial-first deep dive (March 2022): Secrets Hygiene: Rotation, Scoping, and Runtime Delivery.

  4. Runtime Security: eBPF, Policy, and Drift Detection

    April 1, 2022 · 3 min

    Adversarial-first deep dive (April 2022): Runtime Security: eBPF, Policy, and Drift Detection.

  5. Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security

    May 1, 2022 · 4 min

    Threat-model-first analysis (May 2022): Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security.

  6. Multi-Region Design: Failover That You Can Actually Test

    June 1, 2022 · 4 min

    Threat-model-first analysis (June 2022): Multi-Region Design: Failover That You Can Actually Test.

  7. Rate Limiting & Load Shedding: Protecting Reliability SLOs

    July 1, 2022 · 3 min

    Engineering notebook entry (July 2022): Rate Limiting & Load Shedding: Protecting Reliability SLOs.

  8. Observability at Scale: Traces, Cardinality, and Cost

    August 1, 2022 · 3 min

    Spec-driven research note (August 2022): Observability at Scale: Traces, Cardinality, and Cost.

  9. Backup/Restore as a Protocol: RPO/RTO with Adversaries

    September 1, 2022 · 3 min

    Adversarial-first deep dive (September 2022): Backup/Restore as a Protocol: RPO/RTO with Adversaries.

  10. Secure Configuration: Policy-as-Code and Guardrails

    October 1, 2022 · 3 min

    Spec-driven research note (October 2022): Secure Configuration: Policy-as-Code and Guardrails.

  11. Rust/Go Secure Coding Patterns: The Bugs That Still Happen

    November 1, 2022 · 3 min

    Adversarial-first deep dive (November 2022): Rust/Go Secure Coding Patterns: The Bugs That Still Happen.

  12. Red Teaming Infrastructure: Turning Attacks into Regression Tests

    December 1, 2022 · 3 min

    Threat-model-first analysis (December 2022): Red Teaming Infrastructure: Turning Attacks into Regression Tests.