Topic

Cloud Security

Cloud-native security spent a decade producing findings and comparatively little time producing enforcement. Scanners generate thousands of CVEs against images nobody can patch, policy engines run in audit mode indefinitely, and the control that would actually have stopped the last incident — verifying that a running artifact is the one your pipeline built — is still unimplemented in most clusters.

The focus here is on controls that change what can execute, not controls that describe what already did. Sigstore and keyless signing wired into admission control, including the rollout sequence that avoids taking production down on day one. eBPF-based runtime monitoring: what it genuinely sees at the syscall boundary, what it costs in CPU, and where the vendor demos are misleading. Service mesh security, evaluated honestly against its latency and operational overhead rather than its feature matrix. The recurring argument is that a control you cannot afford to enforce is not a control.

Articles in Cloud Security

3 published

Other topics

Kubernetes FinOps Platform Engineering AI Infrastructure