Thumbnail image

THE UNREASONABLE EFFECTIVENESS OF VEX IN NIXOS

Triggered by the flood of LLM-assisted vulnerability reports this year, we have heard a lot about the struggles that maintainers of popular (open-source) projects face to cope with them. Most projects have slowed down feature development to focus on vulnerability triage; others are still looking for ways to combat the flood itself.

Read more
Thumbnail image

KUBERNETES' DEFAULT COREDNS CONFIGURATION IS *INSECURE*

CoreDNS is the DNS server that powers most (all?) Kubernetes distributions, ever since it was made the default in v1.13 in December 2018.

Read more
Thumbnail image

COMPARISON OF GITHUB ACTION SCANNERS

GitHub Actions are a powerful way to automate your software development workflows, and manage them right in your repository. Even though they are becoming ever more popular, there is little movement to invest in tooling to make them more secure… at least until recently. In the last few weeks I have seen posts about zizmor and poutine. After a bit of digging I was also able to find octoscan, as well as a research project from Snyk called github-actions-scanner.

Read more
Thumbnail image

OPENPUBKEY SSH (OPKSSH) WITH KANIDM AS IDENTITY PROVIDER

Cloudflare has recently open-sourced the OPKSSH (OpenPubkey SSH) implementation, which they got as part of their acquisition of BastionZero last year.

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 6 - IDENTITY & ACCESS MANAGEMENT

A good Identity and Access Management (IAM) system is often overlooked in smaller environments and homelabs. Why is that?

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 5 - PERSISTENT STORAGE

Up until this point, we have only persisted data in K8s’ etcd database. Stateless workloads are nice, but at some point we want some of our data to survive a pod restart. In this part we will setup a basic NFS server to provide persistent storage and then make it available to our workloads using the NFS Subdirectory External Provisioner.

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 4 - CERT-MANAGER

Last time, we added ingress-nginx to our cluster so that external traffic can hit our services. In this post, we will secure that traffic using TLS.

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 3 - INGRESS

Last time, we added automated dependency updates to our cluster. In this post, we will get traffic into our cluster, by setting up an Ingress controller and a load balancer.

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 2 - AUTOMATED DEPENDENCY UPDATES

Last time, we set up Cilium and Flux to enable networking and GitOps for our Kubernetes cluster. In this post, we will add automated dependency updates to it.

Read more
Thumbnail image

KUBERNETES HOME LAB IN 2025: PART 1 - CNI & GITOPS

Last time, we left our Cluster in a semi-happy state: The nodes were up, the control plane was available, but we had no cluster network. Today, we will fix that, and a bit more.

Read more