DevOps & Infrastructure

Dow DevOps

Building, breaking, and building again.

Latest Articles

Fresh insights on DevOps, infrastructure, and modern engineering

Kyverno apiCall SSRF: Policy Engines Need Egress Boundaries Too

Kyverno apiCall SSRF: Policy Engines Need Egress Boundaries Too

Kyverno's apiCall feature is exactly the kind of capability platform teams end up wanting after the first wave of policy adoption. Static admission checks are useful, but real clusters are full of context. A namespace may need to be compared against an inventory system. A deployment may need

10 min read
Admission Webhooks Are Control Plane Dependencies, Not Just Add-ons

Admission Webhooks Are Control Plane Dependencies, Not Just Add-ons

A moderate Kubernetes ecosystem CVE does not always deserve a full incident response. It does often deserve a design review. CVE-2026-44247, published through the GitHub advisory database for Volcano, is a good example. Volcano is a Kubernetes-native batch scheduling system. The advisory says its webhook server did not enforce a

8 min read
Policy Engine Face-off: Azure Policy vs. Kyverno for AKS Governance

Policy Engine Face-off: Azure Policy vs. Kyverno for AKS Governance

Last month, while implementing governance controls for a client's AKS environment, I discovered something that Azure's documentation glosses over: Azure Policy for Kubernetes, despite its seamless integration, cannot automatically generate resources based on policy violations.

15 min read
Azure CNI with Cilium: Beyond the Basics - Unlocking Enterprise eBPF Security

Azure CNI with Cilium: Beyond the Basics - Unlocking Enterprise eBPF Security

When Microsoft announced Azure CNI powered by Cilium, the community celebrated the arrival of eBPF networking to AKS. However, enterprise security teams are noticing a critical gap: Azure's managed offering lacks the advanced features that make Cilium the choice for zero-trust architectures.

11 min read

Showing 1 - 21 of 21 posts