Professional notes by Craig Johnston
long-form, short-form, working drafts · since 2008
long-form, short-form, working drafts · since 2008
VOL. XIX · MMXXVI
126 NOTES IN PRINT
126 NOTES IN PRINT
Tag: Security
CXXVI
Build Images Inside Your Cluster, Without the Docker Socket
Rootless container builds in CI with BuildKit, and where supply-chain guardrails belong
2026-07-19
CXXSelf-Hosted SSO with Keycloak
One login for every user-facing tool on the platform, instead of renting Okta or Auth0
2026-07-07
CIISecurity: Tool Poisoning, Prompt Injection, and the Trust Boundary
A server's words flow straight into the model's context. The anatomy of how that becomes an attack, and where the host has to stand to stop it
2026-06-04
LXXIXGoReleaser with Cosign Signing and Syft SBOM
Signed Builds and Supply Chain Security for Go Projects
2026-02-11
LXXVIIIAI on a Leash: Complete Go Project Configuration
AI on a Leash for Go
2026-02-09
LXXVIIRalph's Uncle
AI on a Leash
2026-02-06
LXVIApache NiFi: Securing Your Data Flows
Apache NiFi Part 2
2022-10-05
XXXKubernetes Team Access - RBAC for developers and QA
Role Based Access Control
2018-07-10
XXIVReverse Proxy in Golang
Retrofit security proxy to prevent XSS and code injection.
2018-06-15
XXICORS on Kubernetes Ingress Nginx
Painless CORS header configuration in Kubernetes
2018-05-28
XXJWT Microservice, Tokenize Remote APIs
Using txToken to create JWT Tokens from JSON POST data.
2018-05-27
XIXBasic Auth on Kubernetes Ingress
Basic Auth is supported by nearly every major web client, library, and utility.
2018-05-19
XVIIILet's Encrypt, Kubernetes
Automated, secure and free 443/https with signed x509 certificates for Ingress.
2018-05-18
XIIKubectl x509 Unable to Connect
Kubernetes remote access and TLS certs.
2018-05-10