tutorial Kubernetes
The archive / 07 published
Writing
Field notes on software systems, security boundaries, and the details that explain how things work.
Start here
Selected paths
tutorial Application security
The Blend of Developer Tools into Security Assessments
essay Application security
Long-lived JWT - Abuse and Mitigation
The complete index
All posts 07
Quick Guide on Kubernetes Admission Controllers
A visual guide to Kubernetes admission controllers and where they sit in the API request path.
Guide to Informers, Custom Controller
How Kubernetes informers and custom controllers watch resources and reconcile desired state.
Long-lived JWT - Abuse and Mitigation
Why long-lived access tokens increase exposure and how expiration, revocation, and rotation change the tradeoffs.
The Blend of Developer Tools into Security Assessments
Using browser developer tools to investigate postMessage, heap snapshots, Lighthouse findings, and network resources during web security assessments.
CSV Formula Injection
Tracing how spreadsheet formulas can be injected through exported CSV data.
Authorization Checks Made Easy
A practical workflow for testing authorization boundaries with browser containers and proxy tools.
Finding Gems in JavaScript using Dumpster Diver
Finding secrets and overlooked details in JavaScript files with Dumpster Diver.