Ten Answers, One Canary: A Jev-Style Gate for Argo Rollouts
I put an LLM decision gate in front of Argo Rollouts and asked it the same question ten times per canary. The slow release got 'block' 7 of 8 times, then shipped anyway.
I put an LLM decision gate in front of Argo Rollouts and asked it the same question ten times per canary. The slow release got 'block' 7 of 8 times, then shipped anyway.
Pod logs named a human who never logged in. A signed, hash-chained audit trail replays the same crash and names the human, the agent and the task, and catches the insider who edits it.
One poisoned note, one bucket, five labs. mTLS, SPIFFE identity, delegated permits, a sandbox and a signed audit trail, each shown breaking before it holds.
A code-running agent tool inherits its pod's blast radius. NetworkPolicy, a dropped ServiceAccount token and gVisor shrink it — and a blast-radius report shows which layers actually hold.
A signed task proves who wrote it, not who allowed it. RFC 8693 permits with sub, act, scope and a 120s TTL, checked by OPA at the MCP gateway.
mTLS ends at the queue. SPIRE-issued identities and JWS-signed tasks stop forgery and tampering. A k3d lab shows what they still can't stop.
Autonomous agents on a bumpy network crash with no one to blame. mTLS paves the road, but it can't tell you who's driving. A k3d lab shows both.
ZTNA is what you get when you stop treating the network as the trust boundary and make every packet a policy decision against identity. A practitioner's map of the model, the vendors, and the DNS turn.
WireGuard won because it's boring — a short config, a fixed crypto suite, and a kernel module the size of a caffeine habit. Here's the practitioner's case for it in 2026.
VPNs extended the trust boundary over the public internet — and preserved the flaw at the heart of it. A practitioner's tour of OpenVPN, IPsec, split-DNS, and the DPI blocking era.
SSH replaced telnet in a few years and still runs everything three decades later. Here's why 'SSH is solved' is the most dangerous sentence in your runbook.
Why telnet, rsh, and finger made sense once — and why every modern remote-access control traces back to the moment the wire stopped being trusted.
Two major open-source model releases in one week signal a tipping point. Here's why I'm running capable agent models on my own hardware — and how you can too.
A practitioner's k3d lab for Cilium: install it next to your laptop, walk a CiliumNetworkPolicy progression from default-deny to L7 HTTP filtering, and read the drops in Hubble.
This post will show you how to secure your local development environment by using Bitwarden Secrets Manager with K3d.
A walkthrough of the Kubexperience workshop for developers, covering Kubernetes fundamentals, demos, and resources.