Distroless: How to Build Slim, Secure Containers
Distroless images contain only your app and its runtime, no shell, no package manager, no attack surface. Here's how to build them.
All the articles with the tag "security".
Distroless images contain only your app and its runtime, no shell, no package manager, no attack surface. Here's how to build them.
Certificate pinning and HPKP explained: what they are, why HPKP destroyed itself, and modern alternatives like CAA records and Certificate Transparency.
Stop leaking secrets, dependencies, and OS garbage into git. Here are the .gitignore patterns that save you from disaster.
HashiCorp Vault vs Infisical compared: secrets management for DevOps teams, Docker Compose setup, SDK examples, and when the added complexity is worth it.
FOSS licenses explained for developers and self-hosters: MIT vs GPL vs AGPL vs Apache 2.0, copyleft vs permissive, and what recent license changes mean for you.
Mutual TLS (mTLS) explained for mortals: how both sides authenticate, setting up step-ca for internal PKI, generating client certs, and configuring nginx with mTLS.
Hide your SSH port from scanners with port knocking. It's not a replacement for security, but it's a valid defense-in-depth tactic.
You turned the VPN on and half your traffic still leaves over the normal route. How VPN routing works, reading the routing table, and forcing all traffic.
Kernel live patching applies CVE fixes to a running kernel with no reboot, using kpatch or Canonical Livepatch. Setup for Ubuntu and RHEL, plus what it can't fix.
Your DNS queries go out in plain text, so your ISP logs every site you visit. This covers how DoH, DoT, and DoQ fix that, and how to self-host with AdGuard Home.
You don't need a GUI to see network packets. Learn tcpdump filters, flags, and pcap capture to debug servers from the command line, no Wireshark needed.
AppArmor vs SELinux: what mandatory access control actually does, writing AppArmor profiles with aa-genprof, SELinux labels and audit2allow, and when to use each.