-
August 11, 2026
Letting Claude loose on an AWS account with Prowler
Running Prowler across an AWS account with an agent, a read-only role, and a bastion — then triaging 1,684 findings.
8-minute read
·
AwsSecurityProwlerAiAutomation
-
July 7, 2026
Wrapping Kyverno policies into a chart you can actually tune
Turning a pile of static ClusterPolicy manifests into a Helm chart with three tiers of configurability.
9-minute read
·
KyvernoHelmKubernetesSecurityGitops
-
June 2, 2026
IRSA to Pod Identity: notes from the migration
Migration notes, the annotation that becomes a lie, and the host port 80 conflict that took down ingress.
7-minute read
·
AwsEksIamKubernetesSecurity
-
April 21, 2026
EKS Access Entries: one ARN, one cluster, no sharing
Access entries are scoped per cluster, not shared. Three ways to collide with one, and how to dedupe in Terraform.
4-minute read
·
AwsEksTerraformIamSecurity
-
October 6, 2023
Yet another Vault story
Running Hashicorp Vault the GitOps way with Bank-Vaults: secret injection, probes, and Raft snapshots.
4-minute read
·
VaultSecurityKubernetesGitops