/Blog

Jul 2026

Application Security Testing on EKS: SAST, DAST, and a Runtime Agent Blocking the Same Exploit

Trivy, OWASP ZAP, OpenRASP, and Amazon Inspector layered on an EKS pipeline, verified by a live SQL injection blocked twice: once by ZAP at scan time and once inside the running JVM.

Jul 2026

Software Supply Chain Security on AWS: Keyless Signing, SBOMs, and SLSA Provenance

A GitHub Actions pipeline that builds a container image, signs it with Cosign keyless, attaches SLSA provenance, and only marks it deployable if the signature and provenance verify against the exact repo that built it.

Jun 2026

Unified Threat Detection on AWS: Security Hub, GuardDuty, and Automated EC2 Isolation

Security Hub, GuardDuty Extended Threat Detection, and Step Functions wired so a HIGH finding auto-quarantines the affected EC2 instance in under a minute, with a one-command rollback.

Jun 2026

Runtime Security on EKS: Tetragon eBPF Enforcement, Falco Detection, and GuardDuty

Tetragon eBPF, Falco, and GuardDuty Runtime Monitoring stacked on EKS. Tetragon kills violating processes in-kernel, Falco keeps a queryable alert history, and GuardDuty catches attacks that dodge path-based blocking by running renamed binaries.

Jun 2026

Building an AWS Data Perimeter, Part 2: SCPs, RCPs, and Proving the Perimeter Holds

Attaching SCPs, RCPs, and the new aws:VpceOrgID VPC-endpoint condition to an AWS Organization, then proving the perimeter by denying an external account's requests and reading it back from CloudTrail.

May 2026

Building an AWS Data Perimeter, Part 1: Design, Org Bootstrap, and Infrastructure

Designing an AWS data perimeter from SCPs, RCPs, and VPC endpoint policies, and building the org, VPC, and encrypted S3 substrate needed to validate it end-to-end.

May 2026

EKS Workload Identity: IRSA, OIDC Token Exchange, and When to Use Pod Identity

OIDC and IRSA for EKS: scoping AWS access per workload without embedding credentials, plus when Pod Identity is the better trade-off.

Jan 2026

IAM Basics I Keep Coming Back To

IAM identity types, policy evaluation logic, and the fundamentals that matter for AWS security work.

Jan 2026

Building Resilience Through Chaos Engineering on AWS EKS

Chaos engineering practices using Chaos Mesh on Amazon EKS to build more resilient cloud-native applications

Dec 2025 (1)
Nov 2025 (1)
Oct 2025 (1)
Sep 2025 (2)
Aug 2025 (1)
Jul 2025 (1)
Sep 2024 (1)
Jul 2024 (1)
Feb 2024 (3)
Jan 2024 (1)
Archive (1)