#DevSecOps
A set of research notes and deep dives focused on correctness, security, and operational evidence.
Best starting points
Multi-Region Design: Failover That You Can Actually Test
Threat-model-first analysis (June 2022): Multi-Region Design: Failover That You Can Actually Test.
Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security
Threat-model-first analysis (May 2022): Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security.
Post-Quantum Readiness at the Edge: Constraints and Migration
Engineering notebook entry (December 2021): Post-Quantum Readiness at the Edge: Constraints and Migration.
Anomaly Detection: What 'Baseline' Means in Industrial Systems
Threat-model-first analysis (November 2021): Anomaly Detection: What 'Baseline' Means in Industrial Systems.
Safety-Critical vs Security-Critical: Integrating Two Worlds
Correctness-focused deep dive (August 2021): Safety-Critical vs Security-Critical: Integrating Two Worlds.
Roadmap
- Start with assumptions and invariants
- Enumerate failure modes and attack surfaces
- Define what to monitor and how to roll back