Container Runtime Hardening: Rootless, Read-Only, and Fewer Capabilities
Scanning tells you what is inside the image. These four settings decide what it can do once it is running — and what breaks when you turn them on.
blog
30 articles on building and operating reliable systems.
Showing 30 of 30 articles
Scanning tells you what is inside the image. These four settings decide what it can do once it is running — and what breaks when you turn them on.
Tags move underneath you and nobody tells you. Pinning digests, gating on real CVEs, emitting an SBOM, and signing what my pipeline actually built.
An access key sitting in CI secrets has no expiry and no owner. Replacing it with OIDC federation means the pipeline authenticates per run instead of carrying a permanent password.
Out of the box a cluster lets almost anything run as root with a mounted token and an open network. Three labels, one role cleanup, and a default-deny policy fix most of it.
A scanner that blocks on every historic finding gets bypassed within a week. Baselines, severity floors, and the split between fast PR checks and slow nightly ones.
AI code review, agentic CI, generated tests — I tried the lot. Here's what survived a year of real repositories, and what quietly got turned off.
Kernel-level metrics, traces, and network policy with no agents in your pods — how eBPF quietly moved from research project to default infrastructure.
The Terraform fork that became a Linux Foundation project, state encryption built in, and how to decide between tofu and terraform without starting a religion war.
Golden paths, internal developer portals, and the honest question of whether your team needs a platform at all — what platform engineering actually buys you.
WASM at the edge, Wasm plugins in proxies and databases, and whether containers should be looking over their shoulder — where WebAssembly actually earns its keep in 2026.
Trunk-based development with flags instead of release branches — how we ship code continuously but expose features only when we're ready.
set -euo pipefail, quoting like you mean it, and other bash habits that turn fragile one-liners into scripts you can trust when it matters.
The .env file I committed once, how I cleaned it up, and the boring habits that keep API keys out of git history for good.
Logs Insights queries, metric filters, and alarms that matter — finding root cause from CloudWatch alone, the way you have to when SSH is not an option.
Automated backups, point-in-time recovery, snapshots versus replicas — and why you should restore a database on purpose before you need to by accident.
Burstable instances, credit balances, and CloudWatch graphs — how to pick an EC2 size you won't regret, and how to shrink one you already regret.
Standard, IA, Glacier tiers, lifecycle rules, and the retrieval fees that ruin your day — how I stopped overpaying for object storage.
A botched inline policy, an expired access key, and an empty permission set — the IAM story every cloud engineer seems to live through once.
Subnets, gateways, route tables, security groups — the AWS networking basics I wish someone had drawn on a whiteboard for me the first time.
Stop shipping pipelines held together with duct tape. A practical playbook for CI/CD that teams trust on day one — and still trust six months later.
Bridge networks, port publishing, and why localhost lies to you inside a container — the mental model that made container networking stop being magic.
Recreate, rolling, blue-green, canary. How to pick the right Kubernetes deployment strategy — and what can go wrong with each one.
Blameless timelines, action items that ship, and the meeting structure that turns outages into engineering instead of finger-pointing.
Aliases, TTLs, health checks, and failover routing — the DNS mechanics behind every domain cutover, including the ones you'll do at midnight.
Multi-stage builds, distroless bases, and layer hygiene. A practical guide to shrinking Docker images the right way.
How to structure Terraform for multiple environments without copy-pasting modules or stepping on production state.
Dashboards are how you OBSERVE, not what you're building. Design observability around golden signals, SLOs, and concrete questions.
Git is the source of truth. Argo CD syncs reality to git. A field-tested setup — repos, apps, sync waves, and the gotchas.
Effective Linux hardening isn't a security checklist that makes the machine unusable. It's SSH config, patching, least privilege, and logging.
Right-sizing, lifecycle, and reserved coverage. Cloud cost cuts don't come from dashboards — they come from three decisions made weekly.