
Tetragon on Kubernetes: in-kernel runtime enforcement
A Tetragon Kubernetes tutorial: installation, TracingPolicy design, monitor mode, and the difference between detecting a runtime event and blocking it in-kernel.

A Tetragon Kubernetes tutorial: installation, TracingPolicy design, monitor mode, and the difference between detecting a runtime event and blocking it in-kernel.

A practical PodSecurityPolicy replacement guide: roll out Pod Security Admission in stages, pin policy versions, and avoid the traps that break workloads.

A practical Renovate Kubernetes guide: keep Helm charts, Argo CD manifests, image tags, OpenTofu providers, and GitHub Actions current without the PR flood.

Automatically update RDS credentials and application config on EC2 instances.

How to auto update security groups with Cloudflare IPs using AWS Lambda

Learn how to protect your ALB with AWS WAF and CloudFront.

Zero trust architecture in Kubernetes, from implementation and policy to observability.

Use External Secrets Operator to sync AWS Secrets Manager values into Kubernetes with IRSA, sane refresh policies, and less secret material in git.