<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sachin Chaurasiya — DevOps, DevSecOps &amp; Cloud Security</title><description>Practical engineering notes on building, securing, deploying and operating production infrastructure: Kubernetes, CI/CD, IaC, supply chain security and observability.</description><link>https://sachinchaurasiya.com</link><language>en</language><managingEditor>hello@sachinchaurasiya.com (Sachin Chaurasiya)</managingEditor><item><title>Argo CD ApplicationSets for Multi-Environment Delivery</title><link>https://sachinchaurasiya.com/blog/argocd-applicationsets-multi-environment-delivery</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/argocd-applicationsets-multi-environment-delivery</guid><description>Replace hand-copied Argo CD Applications with an ApplicationSet driven by per-environment config files: the Git file generator, templatePatch for automated versus manual sync, AppProject boundaries and deletion policy.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>argocd</category><category>gitops</category><category>kubernetes</category><category>kustomize</category><category>ci-cd</category><category>deployment</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Attestations and Provenance: Binding the SBOM to the Image</title><link>https://sachinchaurasiya.com/blog/attestations-and-provenance-with-cosign</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/attestations-and-provenance-with-cosign</guid><description>Turn the SBOM from part 2 into a Cosign attestation bound to the image digest, verify it and read the predicate back, list what hangs off an image with cosign tree, and see what SLSA build provenance adds.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>cosign</category><category>sbom</category><category>supply-chain</category><category>provenance</category><category>devsecops</category><category>sigstore</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Cloud Identity and Least Privilege: Humans, Workloads and CI</title><link>https://sachinchaurasiya.com/blog/cloud-identity-and-least-privilege</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/cloud-identity-and-least-privilege</guid><description>Human and workload identities and the credentials that carry them: why static keys are dangerous, how a bound short-lived token differs from a legacy one, how CI assumes a role without a key, and how to scope each one.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>iam</category><category>least-privilege</category><category>rbac</category><category>kubernetes</category><category>terraform</category><category>cloud-security</category><category>checkov</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Cloud Network Security Boundaries: Exposure, Tiers and Default Deny</title><link>https://sachinchaurasiya.com/blog/cloud-network-security-boundaries</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/cloud-network-security-boundaries</guid><description>Deciding what a cloud workload exposes: public and private subnets, security groups that reference each other instead of address ranges, egress control, TLS and DNS, proven with connection tests on a three-tier layout.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>network-security</category><category>cloud-security</category><category>terraform</category><category>docker</category><category>tls</category><category>checkov</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Debugging Kubernetes Workloads: A Repeatable Process on Real Failures</title><link>https://sachinchaurasiya.com/blog/debugging-kubernetes-workloads</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/debugging-kubernetes-workloads</guid><description>A troubleshooting sequence (get, describe, logs, events, exec, port-forward) applied to four broken workloads: a crashing container, a missing image, a missing ConfigMap and an empty Service. Real events, real fixes.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubectl</category><category>debugging</category><category>troubleshooting</category><category>devops</category><category>production-engineering</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Generate an SBOM with Syft and Read What It Tells You</title><link>https://sachinchaurasiya.com/blog/generate-an-sbom-with-syft</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/generate-an-sbom-with-syft</guid><description>Run Syft from its container against a small Node.js image, read the CycloneDX output package by package, see where each one came from, learn what an SBOM does not prove, and store it next to the artifact.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>sbom</category><category>syft</category><category>supply-chain</category><category>container-security</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Health, Resources and Reliability</title><link>https://sachinchaurasiya.com/blog/kubernetes-health-resources-and-reliability</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-health-resources-and-reliability</guid><description>What readiness, liveness and startup probes do (with a failing one of each), how requests decide scheduling and limits decide OOMKilled and throttling, what the cgroup counters show, and how termination grace works.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubectl</category><category>probes</category><category>resources</category><category>devops</category><category>production-engineering</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Observability with Prometheus, Grafana and Loki</title><link>https://sachinchaurasiya.com/blog/kubernetes-observability-prometheus-grafana-loki</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-observability-prometheus-grafana-loki</guid><description>kube-prometheus-stack, Loki in single-binary mode and Alloy on a kind cluster; the PromQL and LogQL that answer operational questions; low-cardinality log labels; a real OOM restart loop diagnosed end to end.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Observability</category><category>observability</category><category>prometheus</category><category>grafana</category><category>loki</category><category>kubernetes</category><category>alerting</category><category>production-engineering</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Scaling, Rollouts and Recovery</title><link>https://sachinchaurasiya.com/blog/kubernetes-scaling-rollouts-and-recovery</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-scaling-rollouts-and-recovery</guid><description>Manual scaling, rolling updates and rollback as an operator sees them, and a HorizontalPodAutoscaler on kind with metrics-server: real utilisation figures, a 2-to-6 scale-up under load, and the scale-down window.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubectl</category><category>autoscaling</category><category>rollback</category><category>deployment</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Services, Networking and DNS: Following One Request</title><link>https://sachinchaurasiya.com/blog/kubernetes-services-networking-and-dns</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-services-networking-and-dns</guid><description>How a request finds a pod: cluster DNS, the Service ClusterIP, the EndpointSlice the selector fills, port versus targetPort, headless Services and Ingress in outline; each inspected on a kind cluster, mistakes included.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubectl</category><category>services</category><category>networking</category><category>dns</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Workloads and Controllers: Choosing and Reading Them</title><link>https://sachinchaurasiya.com/blog/kubernetes-workloads-and-controllers</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-workloads-and-controllers</guid><description>Deployments, StatefulSets, DaemonSets, Jobs and CronJobs on a real three-node cluster: what kubectl reports, what happens when you delete a pod of each kind, why a DaemonSet skips the control plane, and which to use.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubectl</category><category>deployments</category><category>statefulsets</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Logging, Audit and Security Visibility: Who Did What, From Where</title><link>https://sachinchaurasiya.com/blog/logging-audit-and-security-visibility</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/logging-audit-and-security-visibility</guid><description>Application, infrastructure and audit logs and what each answers; Kubernetes API audit logging enabled on a real cluster, tuned from lease noise to the events that matter, and read for denied and privileged requests.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>observability</category><category>audit-logging</category><category>kubernetes</category><category>logging</category><category>prometheus</category><category>cloud-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Platform Engineering Foundations: Defining the Platform Contract</title><link>https://sachinchaurasiya.com/blog/platform-engineering-foundations-the-platform-contract</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/platform-engineering-foundations-the-platform-contract</guid><description>The operating model behind the CI templates, ApplicationSets, Kyverno guardrails and observability stack on this site: what a team hands over, what the platform returns, where the golden path ends and enforcement begins.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevOps</category><category>devops</category><category>gitops</category><category>ci-cd</category><category>kubernetes</category><category>production-engineering</category><category>argocd</category><category>kyverno</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Platform Guardrails with Kyverno and GitOps</title><link>https://sachinchaurasiya.com/blog/platform-guardrails-with-kyverno-and-gitops</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/platform-guardrails-with-kyverno-and-gitops</guid><description>Kyverno as a platform guardrail system: baseline and production policy layers keyed on namespace labels, delivered by Argo CD from one repository, rolled out audit-first, with scoped expiring exceptions.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevOps</category><category>kyverno</category><category>argocd</category><category>gitops</category><category>kubernetes</category><category>policy-as-code</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Production Cloud Hardening: A Checklist That Connects the Controls</title><link>https://sachinchaurasiya.com/blog/production-cloud-hardening-checklist</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/production-cloud-hardening-checklist</guid><description>The hardening checklist for a cloud-hosted production workload, built from parts 1 to 4 and the existing edge, container and Kubernetes articles: each control with the command that proves it and the gap it covers.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>cloud-security</category><category>hardening</category><category>tls</category><category>security-headers</category><category>cloudflare</category><category>kubernetes</category><category>backups</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Reusable GitLab CI Templates and Components: A Golden Delivery Path</title><link>https://sachinchaurasiya.com/blog/reusable-gitlab-ci-templates-and-components</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/reusable-gitlab-ci-templates-and-components</guid><description>One platform-owned GitLab CI template instead of a pipeline per repository: spec:inputs with validation, a consumer that includes it by project and tag, extension points, versioning, and what a consumer can override.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>gitlab-ci</category><category>ci-cd</category><category>devops</category><category>trivy</category><category>gitleaks</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Scan Images and SBOMs with Grype: From 183 Findings to 3</title><link>https://sachinchaurasiya.com/blog/scan-images-and-sboms-with-grype</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/scan-images-and-sboms-with-grype</guid><description>Grype against the SBOM from part 2: 183 matches read by severity, ecosystem and fix state; two Dockerfile changes that take it to 3; exit-code behaviour for CI; and how to triage what remains.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>grype</category><category>sbom</category><category>sca</category><category>supply-chain</category><category>container-security</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Secrets and Configuration Security: Images, Kubernetes, Vault and Rotation</title><link>https://sachinchaurasiya.com/blog/secrets-and-configuration-security</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/secrets-and-configuration-security</guid><description>The secrets lifecycle for a cloud workload: credentials recovered from image history and deleted layers, a build that leaves nothing behind, Secrets in etcd before and after encryption at rest, rotation, and Vault TTLs.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>secrets-management</category><category>vault</category><category>kubernetes</category><category>docker</category><category>trivy</category><category>gitleaks</category><category>cloud-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Sign and Verify Container Images with Cosign</title><link>https://sachinchaurasiya.com/blog/sign-and-verify-container-images-with-cosign</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/sign-and-verify-container-images-with-cosign</guid><description>Cosign with a key pair against a local registry: why the digest is the identity; signing and verifying; a moved tag failing verification while the digest passes; keyless signing as configuration; where the check goes.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>cosign</category><category>supply-chain</category><category>container-security</category><category>devsecops</category><category>sigstore</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Understanding the Software Supply Chain</title><link>https://sachinchaurasiya.com/blog/understanding-the-software-supply-chain</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/understanding-the-software-supply-chain</guid><description>The delivery chain from source through dependencies, build, artifact, image, registry and deployment; where each link can be compromised; and the control for each, from lockfiles and SBOMs to signing by digest.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>supply-chain</category><category>sbom</category><category>cosign</category><category>devsecops</category><category>container-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Building Reliable Pipelines: Pinning, Caching, Artifacts and Failure Handling</title><link>https://sachinchaurasiya.com/blog/building-reliable-cicd-pipelines</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/building-reliable-cicd-pipelines</guid><description>Make a pipeline produce the same result every time and fail usefully: pinned images and lockfiles, a cache keyed on the lockfile, artifacts versus caches, needs, retries and timeouts, and build kept apart from deploy.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>ci-cd</category><category>gitlab-ci</category><category>artifacts</category><category>reproducible-builds</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>CI/CD Fundamentals: How a Pipeline Actually Runs</title><link>https://sachinchaurasiya.com/blog/cicd-fundamentals-how-a-pipeline-runs</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/cicd-fundamentals-how-a-pipeline-runs</guid><description>What a delivery pipeline does between a push and a deployment: stages and jobs, runners, checkout, build, test, artifacts, environments and promotion, with a GitLab CI pipeline you can execute locally and watch fail.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>ci-cd</category><category>gitlab-ci</category><category>artifacts</category><category>deployment</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Deployment Strategies: Rolling, Blue/Green and Canary on Kubernetes</title><link>https://sachinchaurasiya.com/blog/deployment-strategies-rolling-blue-green-canary</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/deployment-strategies-rolling-blue-green-canary</guid><description>Rolling updates, blue/green switches and canary releases built from plain Deployments and Services on a kind cluster, with the health checks, gates and promotion steps that decide when each one is right.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>deployment</category><category>kubernetes</category><category>ci-cd</category><category>canary</category><category>blue-green</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>IaC Security in CI/CD: Gates, Exceptions and Baselines</title><link>https://sachinchaurasiya.com/blog/iac-security-in-cicd</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/iac-security-in-cicd</guid><description>Put Checkov in front of terraform plan: a GitLab CI job on every merge request, a baseline so only new findings fail, a pass/fail policy by check ID, exceptions with reasons, reports in the MR, and branch protection.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>Infrastructure as Code</category><category>checkov</category><category>terraform</category><category>gitlab-ci</category><category>iac</category><category>infrastructure-as-code</category><category>policy-as-code</category><category>ci-cd</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Rollback and Recovery: Versioned Artifacts, Rollout Undo and the Database Problem</title><link>https://sachinchaurasiya.com/blog/rollback-and-recovery-for-deployments</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/rollback-and-recovery-for-deployments</guid><description>Make rollback a deploy, not a rebuild: immutable artifacts and image digests, a failed rollout detected with rollout status and conditions, kubectl rollout undo on a real failure, and migrations planned separately.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>rollback</category><category>kubernetes</category><category>ci-cd</category><category>deployment</category><category>artifacts</category><category>devops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Scan Infrastructure as Code with Checkov</title><link>https://sachinchaurasiya.com/blog/scan-terraform-with-checkov</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/scan-terraform-with-checkov</guid><description>Run Checkov against Terraform with a public database, an open security group and an unprotected bucket; read the 22 findings and why they matter; fix them; then record the rest as documented skips.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>Infrastructure as Code</category><category>checkov</category><category>terraform</category><category>iac</category><category>infrastructure-as-code</category><category>policy-as-code</category><category>aws</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Secure Terraform Foundations: Pinning, State, Secrets and Review</title><link>https://sachinchaurasiya.com/blog/secure-terraform-foundations</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/secure-terraform-foundations</guid><description>The security foundations of a Terraform repository: pinned versions with a committed lock file, remote state with locking and access control, secrets kept out of source, least-privilege plan and apply roles.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>Infrastructure as Code</category><category>terraform</category><category>iac</category><category>infrastructure-as-code</category><category>secrets-management</category><category>aws</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Building Minimal Container Images with Multi-Stage Builds</title><link>https://sachinchaurasiya.com/blog/building-minimal-container-images-with-multi-stage-builds</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/building-minimal-container-images-with-multi-stage-builds</guid><description>Build the same Go service as a single-stage image and as a multi-stage image on a distroless base, then compare size, package count, scanner findings and the user it runs as.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>Docker</category><category>docker</category><category>container-security</category><category>trivy</category><category>go</category><category>supply-chain</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>A GitLab CI/CD Security Pipeline That Developers Do Not Route Around</title><link>https://sachinchaurasiya.com/blog/gitlab-ci-devsecops-pipeline</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/gitlab-ci-devsecops-pipeline</guid><description>The GitLab pipeline that gated this site while it ran CI: frozen installs, parallel quality gates, Trivy with SAST and secret detection, artifact verification, and one deployment owner behind protected main.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>gitlab-ci</category><category>ci-cd</category><category>devsecops</category><category>trivy</category><category>semgrep</category><category>gitleaks</category><category>cloudflare</category><category>supply-chain</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>GitOps Deployment with Argo CD</title><link>https://sachinchaurasiya.com/blog/gitops-deployment-with-argo-cd</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/gitops-deployment-with-argo-cd</guid><description>Install Argo CD, model applications and projects, enable automated sync with pruning and self-heal, and lock the control plane down so Git really is the only way to change the cluster.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>argocd</category><category>gitops</category><category>kubernetes</category><category>helm</category><category>ci-cd</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Hardening a Static Site on Cloudflare: TLS, Headers and a Hash-Based CSP</title><link>https://sachinchaurasiya.com/blog/hardening-a-static-site-on-cloudflare</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/hardening-a-static-site-on-cloudflare</guid><description>The security configuration behind this site: a per-page Content Security Policy with script hashes and no unsafe-inline, hardening headers served from Workers static assets, and the zone settings that back them up.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Cloud Security</category><category>cloudflare</category><category>tls</category><category>csp</category><category>security-headers</category><category>astro</category><category>edge-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Lab: Enforce Pod Security with Pod Security Admission and Kyverno</title><link>https://sachinchaurasiya.com/labs/enforce-pod-security-with-psa-and-kyverno</link><guid isPermaLink="true">https://sachinchaurasiya.com/labs/enforce-pod-security-with-psa-and-kyverno</guid><description>On a kind cluster, turn on the restricted Pod Security profile for a namespace, watch it reject a default pod, then add a Kyverno ValidatingPolicy in Audit mode, read the PolicyReport, and switch it to Deny.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>Labs</category><category>kubernetes</category><category>kyverno</category><category>kubernetes-security</category><category>admission-control</category><category>pod-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kyverno Policies for Kubernetes Security: Validate, Mutate, Generate</title><link>https://sachinchaurasiya.com/blog/kyverno-policies-for-kubernetes-security</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kyverno-policies-for-kubernetes-security</guid><description>Install Kyverno 1.19, write CEL-based ValidatingPolicy, MutatingPolicy and GeneratingPolicy resources for non-root pods, image tags, allowed registries and default-deny networking, and roll them out audit-first.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kyverno</category><category>kubernetes</category><category>kubernetes-security</category><category>admission-control</category><category>policy-as-code</category><category>network-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Lab: Generate an SBOM with Syft and Scan It with Grype</title><link>https://sachinchaurasiya.com/labs/generate-an-sbom-with-syft-and-scan-it-with-grype</link><guid isPermaLink="true">https://sachinchaurasiya.com/labs/generate-an-sbom-with-syft-and-scan-it-with-grype</guid><description>Produce CycloneDX and SPDX bills of materials for a container image without a Docker socket, scan the SBOM with Grype, gate on fixable findings only, and see why the SBOM is worth keeping after the release.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Labs</category><category>sbom</category><category>syft</category><category>grype</category><category>supply-chain</category><category>container-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Lab: Least-Privilege Kubernetes RBAC for a Deployer Service Account</title><link>https://sachinchaurasiya.com/labs/least-privilege-kubernetes-rbac-for-a-deployer</link><guid isPermaLink="true">https://sachinchaurasiya.com/labs/least-privilege-kubernetes-rbac-for-a-deployer</guid><description>Create a service account that can roll out Deployments in one namespace and nothing else, prove the boundary with impersonation and a real short-lived token, and audit the cluster for wildcard roles and anonymous access.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Labs</category><category>kubernetes</category><category>rbac</category><category>kubernetes-security</category><category>least-privilege</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Kubernetes Security Checklist for Production Clusters</title><link>https://sachinchaurasiya.com/blog/kubernetes-security-checklist</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/kubernetes-security-checklist</guid><description>A layered checklist — control plane, workloads, network, secrets, supply chain and runtime — with the manifests and commands to verify each control rather than just tick it.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>kubernetes</category><category>kubernetes-security</category><category>rbac</category><category>kyverno</category><category>falco</category><category>network-security</category><category>secrets-management</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Lab: Scan Git Repositories with Gitleaks</title><link>https://sachinchaurasiya.com/labs/scan-git-repositories-with-gitleaks</link><guid isPermaLink="true">https://sachinchaurasiya.com/labs/scan-git-repositories-with-gitleaks</guid><description>Seed a repository with realistic fake secrets, catch them with Gitleaks in history and working-tree modes, ignore a confirmed false positive by fingerprint, and block the next one at commit time.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>Labs</category><category>gitleaks</category><category>secrets-management</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Secrets Detection with Gitleaks</title><link>https://sachinchaurasiya.com/blog/secrets-detection-with-gitleaks</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/secrets-detection-with-gitleaks</guid><description>Stop credentials from reaching Git: run Gitleaks in pre-commit hooks and CI, tune rules and allowlists, handle findings without leaking them further, and decide when history rewriting is worth it.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>gitleaks</category><category>secrets-management</category><category>gitlab-ci</category><category>supply-chain</category><category>devsecops</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Lab: Secure Docker Images with Trivy</title><link>https://sachinchaurasiya.com/labs/secure-docker-images-with-trivy</link><guid isPermaLink="true">https://sachinchaurasiya.com/labs/secure-docker-images-with-trivy</guid><description>Build a deliberately weak image, scan it with Trivy, and rebuild it until the gate for fixable HIGH and CRITICAL findings passes: current base, non-root user, patched packages, no pip in the runtime image.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Labs</category><category>trivy</category><category>docker</category><category>container-security</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Container Image Scanning with Trivy</title><link>https://sachinchaurasiya.com/blog/container-image-scanning-with-trivy</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/container-image-scanning-with-trivy</guid><description>How Trivy finds OS and application vulnerabilities, secrets and misconfigurations in container images, how to make the results actionable, and how to wire it into CI without slowing builds down.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>Security Tools</category><category>trivy</category><category>docker</category><category>container-security</category><category>sca</category><category>sbom</category><category>gitlab-ci</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item><item><title>Building a Secure CI/CD Pipeline with Jenkins</title><link>https://sachinchaurasiya.com/blog/building-a-secure-cicd-pipeline-with-jenkins</link><guid isPermaLink="true">https://sachinchaurasiya.com/blog/building-a-secure-cicd-pipeline-with-jenkins</guid><description>A declarative Jenkins pipeline with secrets scanning, SAST, image scanning and least-privilege credential handling — and the agent, plugin and Docker decisions that keep it that way.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>jenkins</category><category>ci-cd</category><category>devsecops</category><category>trivy</category><category>gitleaks</category><category>semgrep</category><category>docker</category><author>hello@sachinchaurasiya.com (Sachin Chaurasiya)</author></item></channel></rss>