<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on DevOps &amp; Rock&#39;N&#39;Roll</title>
    <link>https://artazar.pages.dev/tags/security/</link>
    <description>Recent content in Security on DevOps &amp; Rock&#39;N&#39;Roll</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 19 Aug 2026 15:55:02 +0700</lastBuildDate>
    <atom:link href="https://artazar.pages.dev/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Letting Claude loose on an AWS account with Prowler</title>
      <link>https://artazar.pages.dev/blog/13-claude-prowler-security-scan/</link>
      <pubDate>Tue, 11 Aug 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/13-claude-prowler-security-scan/</guid>
      <description>&lt;p&gt;I had been meaning to run a proper security audit of one of our AWS accounts for months. The task kept losing to more urgent things, because it isn&amp;rsquo;t a single job — it&amp;rsquo;s install a scanner, work out its permissions, run it for an hour, then read several thousand findings and decide which twelve actually matter.&lt;/p&gt;&#xA;&lt;p&gt;So I gave the whole thing to Claude Code and watched. The interesting part wasn&amp;rsquo;t that it worked; it was where the effort actually went.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wrapping Kyverno policies into a chart you can actually tune</title>
      <link>https://artazar.pages.dev/blog/12-kyverno-policies-helm-chart/</link>
      <pubDate>Tue, 07 Jul 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/12-kyverno-policies-helm-chart/</guid>
      <description>&lt;p&gt;Kyverno&amp;rsquo;s policy library is excellent and you should read it. It is also a directory of static YAML files, which means adopting it looks like copying twenty ClusterPolicy manifests into your GitOps repo and then editing them by hand, per cluster, forever.&lt;/p&gt;&#xA;&lt;p&gt;That works until the second cluster. Dev wants &lt;code&gt;audit&lt;/code&gt; where prod wants &lt;code&gt;enforce&lt;/code&gt;. The infra cluster needs the CRI socket policy relaxed because your monitoring agent legitimately mounts it. A new namespace needs to be excluded from the Flux label requirement. Each of these is a one-line change to a file that&amp;rsquo;s now duplicated across three repositories, and none of them are visible from a single place.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IRSA to Pod Identity: notes from the migration</title>
      <link>https://artazar.pages.dev/blog/10-irsa-to-pod-identity/</link>
      <pubDate>Tue, 02 Jun 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/10-irsa-to-pod-identity/</guid>
      <description>&lt;p&gt;IRSA has been the way to give a Kubernetes pod an AWS identity since 2019, and it works. It also requires an OIDC provider per cluster, a trust policy per role that names a specific cluster&amp;rsquo;s OIDC issuer, and a mental model involving projected service account tokens that you re-derive from scratch every time something breaks.&lt;/p&gt;&#xA;&lt;p&gt;EKS Pod Identity does the same job with less machinery. I&amp;rsquo;ve now moved a few clusters over and it&amp;rsquo;s mostly good news, with a couple of edges worth knowing before you start.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EKS Access Entries: one ARN, one cluster, no sharing</title>
      <link>https://artazar.pages.dev/blog/07-eks-access-entries/</link>
      <pubDate>Tue, 21 Apr 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/07-eks-access-entries/</guid>
      <description>&lt;p&gt;EKS Access Entries replaced the &lt;code&gt;aws-auth&lt;/code&gt; ConfigMap and made cluster authorization a proper AWS API object instead of a YAML blob that you edited with trembling hands, hoping you wouldn&amp;rsquo;t lock yourself out. It&amp;rsquo;s a genuine improvement. But moving auth into the API surface also moves it into Terraform state, and that&amp;rsquo;s where it gets interesting.&lt;/p&gt;&#xA;&lt;p&gt;The error that sent me down this road:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error: creating EKS Access Entry (test-spain-001:arn:aws:iam::123456789012:role/PlatformAdmin):&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ResourceInUseException: The specified access entry resource is already in use&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;on this cluster.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;My first reaction was the wrong one: &lt;em&gt;are access entries global? Did creating one for cluster A break cluster B?&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet another Vault story</title>
      <link>https://artazar.pages.dev/blog/03-vault-my-experience/</link>
      <pubDate>Fri, 06 Oct 2023 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/03-vault-my-experience/</guid>
      <description>&lt;p&gt;One can find a million blog posts about various aspects of using Hashicorp Vault, this solution has truly received massive adoption. So now you don&amp;rsquo;t even question what you&amp;rsquo;re going to use as secrets storage, but the matter is more of &amp;ldquo;how&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;Being a complete and inveterate gitops&amp;rsquo;er, one of my primary objectives is to store as much as I can in Git and to deploy that into Kubernetes. This brought me to the BanzaiCloud Bank Vaults solution bundle that allows you to achieve exactly this. It provides the ability to configure Vault as a Custom Resource and store all its primary settings on a repository. This is not very far from the official Helm chart deployment with their values, but BanzaiCloud give you a bit more:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
