OPA & Rego: Policy as Code Beyond Kubernetes
OPA and Rego aren't just Kubernetes gatekeepers. Block :latest tags in CI, enforce Terraform resource tags, and filter HTTP APIs.
All the articles with the tag "security".
OPA and Rego aren't just Kubernetes gatekeepers. Block :latest tags in CI, enforce Terraform resource tags, and filter HTTP APIs.
Lock down your Vaultwarden with Authelia forward auth, two-factor authentication at the proxy layer before a single byte reaches your password vault.
Stop typing LUKS passphrases on every headless reboot. Tang + Clevis = NBDE: disks unlock automatically on your trusted network, stay sealed everywhere else.
Protocol mimicry only wins the hiding fight. Learn why relay cascades, domestic hosting, and disposable infrastructure make blocking your traffic expensive.
REALITY does not disguise your traffic as a real TLS handshake, it serves an actual one. How that works, a working config, and the honest limits of the trick.
iptables is in soft retirement. Here's why the nft shim isn't a long-term plan and what direct nftables syntax actually buys you.
Encryption hides content, not shape. Here's why state-level censors don't read your VPN traffic, they recognize it, and what actually still works in 2026.
Use age + age-plugin-yubikey to encrypt files with a key that literally cannot leave your hardware token. No GPG drama required.
Pangolin gives you Cloudflare Tunnel-style access to home services via a $5 VPS, WireGuard mesh, and zero vendor lock-in.
Keyless signed git commits with Sigstore and Gitsign, no GPG key rot, no passphrase prompts. OIDC-backed ephemeral certs that just work.
Sealed Secrets vs External Secrets Operator: which Kubernetes secret manager fits your GitOps workflow best, home lab cluster or production multi-tenant setup?
Renovate vs Dependabot for self-hosted teams: config depth, ecosystem coverage, self-host paths, and which bot wins for Forgejo/GitLab shops.