<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Tolu Banji</title><description>Writing on cloud security, DevSecOps, and application security by Tolu Banji.</description><link>https://tolubanji.com/</link><item><title>Software Supply Chain Security on AWS: Keyless Signing, SBOMs, and SLSA Provenance</title><link>https://tolubanji.com/articles/aws-supply-chain-security/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-supply-chain-security/</guid><description>A GitHub Actions pipeline that builds a container image, gates it on fixable CVEs, signs it with Cosign keyless, attaches SLSA provenance, and refuses to call it deployable unless all of that verifies against the exact repo that built it.</description><pubDate>Wed, 01 Jul 2026 06:00:00 GMT</pubDate><category>cloud-security</category><category>aws</category><category>security-engineering</category><category>devsecops</category><category>AWS</category><category>ECR</category><category>Inspector</category><category>Cosign</category><category>Sigstore</category><category>SLSA</category><category>SBOM</category><category>Supply Chain Security</category><category>GitHub Actions</category><category>Container Security</category></item><item><title>Unified Threat Detection on AWS: Security Hub, GuardDuty, and Automated EC2 Isolation</title><link>https://tolubanji.com/articles/aws-unified-threat-detection/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-unified-threat-detection/</guid><description>How to wire Security Hub, GuardDuty Extended Threat Detection, and a Step Functions pipeline together so a HIGH finding automatically quarantines the affected EC2 instance within seconds.</description><pubDate>Wed, 17 Jun 2026 06:00:00 GMT</pubDate><category>cloud-security</category><category>aws</category><category>security-engineering</category><category>devsecops</category><category>AWS</category><category>Security Hub</category><category>GuardDuty</category><category>Step Functions</category><category>EventBridge</category><category>Lambda</category><category>EC2</category><category>Terraform</category><category>Incident Response</category><category>Cloud Security</category></item><item><title>Runtime Security on EKS: Tetragon eBPF Enforcement, Falco Detection, and GuardDuty</title><link>https://tolubanji.com/articles/aws-runtime-security-ebpf/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-runtime-security-ebpf/</guid><description>How to stack three runtime security layers on EKS so one kills processes in-kernel, one generates a queryable alert history, and one catches what the other two miss using AWS threat intelligence.</description><pubDate>Sun, 14 Jun 2026 16:00:00 GMT</pubDate><category>cloud-security</category><category>containers-orchestration</category><category>security-engineering</category><category>aws</category><category>EKS</category><category>Tetragon</category><category>eBPF</category><category>Falco</category><category>GuardDuty</category><category>Runtime Security</category><category>Kubernetes</category><category>AWS</category><category>Container Security</category><category>IRSA</category></item><item><title>Building an AWS Data Perimeter, Part 2: SCPs, RCPs, and Proving the Perimeter Holds</title><link>https://tolubanji.com/articles/aws-data-perimeter-part2/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-data-perimeter-part2/</guid><description>Attaching SCPs and RCPs to an AWS Organization, enforcing the new aws:VpceOrgID condition, and running denial tests against an external account with CloudTrail evidence.</description><pubDate>Mon, 01 Jun 2026 14:00:00 GMT</pubDate><category>cloud-security</category><category>aws</category><category>security-engineering</category><category>identity-access-management</category><category>AWS</category><category>Organizations</category><category>SCP</category><category>RCP</category><category>VPC Endpoint</category><category>S3</category><category>KMS</category><category>STS</category><category>Data Perimeter</category><category>CloudTrail</category><category>Cloud Security</category></item><item><title>Building an AWS Data Perimeter, Part 1: Design, Org Bootstrap, and Infrastructure</title><link>https://tolubanji.com/articles/aws-data-perimeter-part1/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-data-perimeter-part1/</guid><description>How to design a three-layer AWS data perimeter using SCPs, RCPs, and VPC endpoint policies, and build the substrate to validate it against an external account.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>cloud-security</category><category>aws</category><category>security-engineering</category><category>identity-access-management</category><category>AWS</category><category>Organizations</category><category>SCP</category><category>RCP</category><category>VPC Endpoint</category><category>S3</category><category>KMS</category><category>Data Perimeter</category><category>Cloud Security</category><category>CloudTrail</category></item><item><title>EKS Workload Identity: IRSA, OIDC Token Exchange, and When to Use Pod Identity</title><link>https://tolubanji.com/articles/eks-oidc-irsa-deep-dive/</link><guid isPermaLink="true">https://tolubanji.com/articles/eks-oidc-irsa-deep-dive/</guid><description>OIDC and IRSA for Amazon EKS: how to scope AWS access per workload without embedding credentials, and when Pod Identity is the better choice.</description><pubDate>Mon, 11 May 2026 10:30:00 GMT</pubDate><category>cloud-security</category><category>containers-orchestration</category><category>identity-access-management</category><category>aws</category><category>security-engineering</category><category>AWS</category><category>EKS</category><category>Kubernetes</category><category>OIDC</category><category>IRSA</category><category>Pod Identity</category><category>Security</category><category>IAM</category><category>DevSecOps</category><category>Container Security</category></item><item><title>IAM Basics I Keep Coming Back To</title><link>https://tolubanji.com/articles/aws-iam-foundations-users-roles-policies/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-iam-foundations-users-roles-policies/</guid><description>IAM identity types, policy evaluation logic, and the fundamentals that matter for AWS security work.</description><pubDate>Tue, 20 Jan 2026 11:44:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>aws</category><category>AWS</category><category>IAM</category><category>Security</category><category>Roles</category><category>Policies</category><category>Exam Prep</category></item><item><title>Building Resilience Through Chaos Engineering on AWS EKS</title><link>https://tolubanji.com/articles/chaos-engineering-eks/</link><guid isPermaLink="true">https://tolubanji.com/articles/chaos-engineering-eks/</guid><description>Chaos engineering practices using Chaos Mesh on Amazon EKS to build more resilient cloud-native applications</description><pubDate>Thu, 15 Jan 2026 10:30:00 GMT</pubDate><category>cloud-architecture</category><category>testing-quality</category><category>containers-orchestration</category><category>infrastructure-as-code-iac</category><category>AWS</category><category>EKS</category><category>Kubernetes</category><category>Chaos Engineering</category><category>DevOps</category><category>Resilience</category><category>Site Reliability</category><category>Cloud Native</category><category>Infrastructure</category></item><item><title>AWS Secrets Management</title><link>https://tolubanji.com/articles/aws-secrets-management-step-by-step-implementation/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-secrets-management-step-by-step-implementation/</guid><description>AWS secrets management solution with Infrastructure as Code, cost optimization, automated rotation, and monitoring</description><pubDate>Wed, 10 Dec 2025 09:45:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>aws</category><category>infrastructure-as-code-iac</category><category>secrets-management</category><category>AWS</category><category>DevSecOps</category><category>Security</category><category>Infrastructure</category><category>Terraform</category><category>Secrets Management</category></item><item><title>Inspector to SSM Vulnerability Patching Automation</title><link>https://tolubanji.com/articles/aws-vulnerability-patching-automation/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-vulnerability-patching-automation/</guid><description>That simple vulnerability patching pattern everyone shows? It doesn&apos;t work when you use it.</description><pubDate>Wed, 12 Nov 2025 10:15:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>aws</category><category>devsecops</category><category>AWS</category><category>Inspector</category><category>SSM</category><category>Automation</category><category>Vulnerability Management</category><category>EventBridge</category></item><item><title>AWS CLI Security Commands</title><link>https://tolubanji.com/articles/aws-cli-security-manual/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-cli-security-manual/</guid><description>I&apos;ve used these commands to catch everything from wide-open S3 buckets to overprivileged IAM roles. Here&apos;s your practical guide to AWS security auditing that comes in handy.</description><pubDate>Wed, 08 Oct 2025 14:30:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>aws</category><category>compliance-governance</category><category>AWS CLI</category><category>Cloud Security</category><category>DevSecOps</category><category>Security Audit</category><category>IAM</category></item><item><title>Multi-Tool Container Security Scanning with AWS Integration</title><link>https://tolubanji.com/articles/multi-tool-container-security-scanning/</link><guid isPermaLink="true">https://tolubanji.com/articles/multi-tool-container-security-scanning/</guid><description>Building a container security scanner using Trivy, Grype, and Snyk with AWS ECR and EKS deployment automation</description><pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate><category>cloud-security</category><category>containers-orchestration</category><category>security-engineering</category><category>devsecops</category><category>container-security</category><category>devsecops</category><category>aws</category><category>kubernetes</category><category>trivy</category><category>grype</category><category>snyk</category></item><item><title>Implementing and Securing OWASP Juice Shop with AWS WAF</title><link>https://tolubanji.com/articles/aws-waf-owasp-juice-shop-security/</link><guid isPermaLink="true">https://tolubanji.com/articles/aws-waf-owasp-juice-shop-security/</guid><description>AWS security engineering project implementing OWASP Juice Shop on ECS Fargate with AWS WAF protection, Terraform IaC, real-time Athena analytics, CI/CD security pipeline, and emergency response</description><pubDate>Fri, 05 Sep 2025 15:00:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>aws</category><category>infrastructure-as-code-iac</category><category>devsecops</category><category>security-automation</category><category>AWS</category><category>WAF</category><category>Security</category><category>OWASP</category><category>Terraform</category><category>DevSecOps</category><category>Infrastructure</category><category>CloudWatch</category><category>Athena</category><category>CI/CD</category></item><item><title>Secrets Management in Go Applications From Environment Variables to Vault</title><link>https://tolubanji.com/articles/secrets-management-in-go/</link><guid isPermaLink="true">https://tolubanji.com/articles/secrets-management-in-go/</guid><description>The irony is that Go makes building secure applications relatively straightforward, but its simplicity can be deceptive when it comes to secrets management.</description><pubDate>Thu, 14 Aug 2025 11:20:00 GMT</pubDate><category>secure-coding</category><category>security-engineering</category><category>Secrets Management</category><category>Secure-Coding</category><category>GO</category></item><item><title>Building an IaC Security Scanner in Go</title><link>https://tolubanji.com/articles/policyguard/</link><guid isPermaLink="true">https://tolubanji.com/articles/policyguard/</guid><description>As a security engineer who&apos;s implemented security controls across cloud environments, I&apos;ve always been curious about how policy engines work under the hood</description><pubDate>Wed, 09 Jul 2025 15:20:00 GMT</pubDate><category>infrastructure-as-code-iac</category><category>security-engineering</category><category>policy-as-code</category><category>Iac</category><category>terraform</category><category>OPA</category><category>GO</category></item><item><title>Monitoring Tells You It’s Broken; Observability Tells You Why</title><link>https://tolubanji.com/articles/observability-vs-monitoring/</link><guid isPermaLink="true">https://tolubanji.com/articles/observability-vs-monitoring/</guid><description>Most organizations think they have observability when they just have expensive monitoring. What is the difference and why it matters for both DevOps and security teams.</description><pubDate>Fri, 20 Sep 2024 19:45:00 GMT</pubDate><category>security-engineering</category><category>devsecops</category><category>Observability</category><category>Monitoring</category><category>DevOps</category><category>Security Operations</category><category>SRE</category></item><item><title>Are You Dyslexic? A Security Engineer&apos;s Late Discovery</title><link>https://tolubanji.com/articles/are-you-dyslexic/</link><guid isPermaLink="true">https://tolubanji.com/articles/are-you-dyslexic/</guid><description>I spent years thinking I was just &apos;not a good reader&apos; until a casual conversation led to a diagnosis that explained everything. Here&apos;s how dyslexia shapes my approach to learning and career in tech.</description><pubDate>Sat, 13 Jul 2024 16:45:00 GMT</pubDate><category>learning-career</category><category>Dyslexia</category><category>Learning</category><category>Career</category><category>Tech</category><category>Neurodiversity</category></item><item><title>When Containers Multiply Like Rabbits and You Need a System</title><link>https://tolubanji.com/articles/kubernetes-orchestrating-markdown/</link><guid isPermaLink="true">https://tolubanji.com/articles/kubernetes-orchestrating-markdown/</guid><description>We solved the &apos;works on my machine&apos; problem by packaging applications in containers. But success creates its own challenges. What happens when you&apos;re running not just one container, but hundreds? Or thousands?</description><pubDate>Tue, 20 Feb 2024 18:00:00 GMT</pubDate><category>containers-orchestration</category><category>Containerization</category><category>k8s</category><category>software development</category></item><item><title>Containers Changed Everything and I Wish I&apos;d Started Sooner</title><link>https://tolubanji.com/articles/containers-101-original-markdown/</link><guid isPermaLink="true">https://tolubanji.com/articles/containers-101-original-markdown/</guid><description>Remember when deploying software meant crossing your fingers and hoping it would work on the production server? When &apos;but it works on my machine&apos; was the most dreaded phrase in tech? Those days are fading fast, thanks to a technology that&apos;s quietly revolutionizing how we build and ship software: containers</description><pubDate>Thu, 15 Feb 2024 18:00:00 GMT</pubDate><category>container-security</category><category>containers-orchestration</category><category>Containerization</category><category>Container Engine</category><category>software development</category></item><item><title>How a Bank Fixed Their Security Nightmare With Defense in Depth</title><link>https://tolubanji.com/articles/case-studies-markdown/</link><guid isPermaLink="true">https://tolubanji.com/articles/case-studies-markdown/</guid><description>Let&apos;s takes you inside real organizations implementing Defense in Depth  strategies, revealing what works, what doesn&apos;t, and what you can apply to your own cloud journey</description><pubDate>Sat, 10 Feb 2024 16:00:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>Defense in depth</category><category>Cloud Security</category><category>AWS</category></item><item><title>Why One layered defense Never Works and What Does</title><link>https://tolubanji.com/articles/defense-in-depth-markdown/</link><guid isPermaLink="true">https://tolubanji.com/articles/defense-in-depth-markdown/</guid><description>The Defense in Depth is beautifully simple: never rely on just one defense. Instead, create multiple safeguards that work together. If one fails, others are ready to step in.</description><pubDate>Fri, 19 Jan 2024 16:00:00 GMT</pubDate><category>cloud-security</category><category>security-engineering</category><category>Defense in depth</category><category>Cloud Security</category><category>AWS</category></item><item><title>Separation of Concerns vs Least Privilege: Why They&apos;re Not the Same (and How to Use Both)</title><link>https://tolubanji.com/articles/separation-vs-least-privilege/</link><guid isPermaLink="true">https://tolubanji.com/articles/separation-vs-least-privilege/</guid><description>Two fundamental principles that sound similar but serve completely different purposes in cloud security. Here&apos;s why the distinction matters</description><pubDate>Fri, 14 Jul 2023 14:30:00 GMT</pubDate><category>security-engineering</category><category>cloud-security</category><category>AWS</category><category>IAM</category><category>Security Architecture</category><category>Best Practices</category></item></channel></rss>