This week's articles
Exploring Firecracker MicroVMs for Multi-Tenant Dagger CI/CD Pipelines
#ci/cd, #defend
Experimenting with the feasibility of running Dagger CI/CD pipelines isolated from each other using Firecracker microVMs to provide a strong security model in a multi-tenant scenario. When a customer runs a pipeline, their containers are executed in an isolated environment.
Warden: Real Time Anomaly Detection at Pinterest
#defend, #monitor
Pinterest Engineering has developed a real-time anomaly detection system called Warden, which uses machine learning to identify unusual activity and potential security threats on their platform.
How to choose the right API Gateway auth method
#aws, #build, #iam
API Gateway supports quite a few authentication and authorization methods, plus, you can always authenticate users inside your endpoint. So, the big question is, how do you choose the right one for your API?
Understanding networking in Kubernetes
#explain, #kubernetes
An in-depth analysis of Kubernetes networking, including container-to-container, pod-to-pod, pod-to-service, ingress, and egress communication.
|
|
Tools
macaron
Macaron is a supply chain security analysis tool from Oracle Labs that checks conformance to SLSA framework. You can also refer to the companion blog post.
devenv
Fast, Declarative, Reproducible, and Composable Developer Environments.
aws-imds-packet-analyzer
A tool that traces TCP interactions with the EC2 Instance Metadata Service (IMDS), assisting in identifying the processes making IMDSv1 calls on a host.
|
|
Sponsor
Ready to reduce the need for countless spreadsheets and endless email threads β while saving up to 85% of compliance costs? Vanta is your trust management platform for continuously monitoring your controls, reporting on security posture, and streamlining audit readiness. Maintain centralized visibility into your security status and automate up to 90% of the work for SOC 2, ISO 27001, GDPR, HIPAA, and more. Take a tour of Vantaβs platform to see how it works
|
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! π If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|