pontope.infopontope.blog

<!-- Blog directory -->

/var/log/blog

2026-09-02TrustStack finished with a failed deployment

The final TrustStack retrospective, from AWS governance and runtime attacks to signed images, Kyverno enforcement, and the value of proving the denied path.

read_log
2026-08-26ProvenancePipeline is finished: the unsigned image never became a pod

The final supply-chain test connecting signed builds to Kyverno admission, including the allowed image, the denied image, and the limits of the trust model.

read_log
2026-08-19ProvenancePipeline halfway through: the pipeline is green, the project is not done

A mid-build report on SBOMs, vulnerability scanning, Cosign keyless signing, Rekor, SLSA provenance, and the admission-control work still missing.

read_log
2026-08-12Starting ProvenancePipeline: a container tag is not an identity

The plan for proving where a container image came from, what it contains, and whether Kubernetes should allow it to run.

read_log
2026-08-05PontoAntiCrack is finished: from documentation fixtures to real AWS events

How PontoAntiCrack moved through dry-run, real event capture, bounded remediation, circuit-breaker testing, and its handoff to ProvenancePipeline.

read_log
2026-07-22PontoAntiCrack halfway through: 167 tests and no permission to remediate

A mid-project look at the detection pipeline, negative fixtures, circuit breaker, S3 policy ambiguity, and the gap between documented events and real AWS behavior.

read_log
2026-07-08Starting PontoAntiCrack in dry-run

The design for an AWS detection and response system that plans first, preserves evidence, limits its own authority, and starts without changing resources.

read_log
2026-07-01KateClusters is finished, including the test that attacks Falco

The final KateClusters results across control-plane hardening, RBAC, Pod Security, NetworkPolicy, runtime detection, and four controlled attack scenarios.

read_log
2026-06-17KateClusters in the middle: default-deny means DNS too

A practical update from the hardening phase, covering the CIS baseline, audit policy, encrypted Secrets, Calico, RBAC, Falco, and a cluster that briefly lost DNS.

read_log
2026-06-03Starting KateClusters from a clean Debian VM

Why I chose kubeadm for the Kubernetes part of TrustStack, what the single-node lab can prove, and why the first benchmark must happen before hardening.

read_log
2026-05-27AwLZ is complete: what changed after building a real AWS landing zone

A retrospective on completing the six AwLZ Terraform stacks, validating the guardrails and log archive, and handing the next part of TrustStack to KateClusters.

read_log
2026-05-06AwLZ halfway through: when the guardrails guard against me

A mid-build report on AwLZ, including Terraform state, multi-account logging, delegated security services, and SCPs that blocked their own deployment path.

read_log
2026-04-22Starting AwLZ: building the AWS foundation before the security demos

The first TrustStack build log, covering the scope, account structure, Terraform bootstrap, and failure modes I want AwLZ to address.

read_log
2026-04-15TrustStack: why I am building a cloud security lab as one connected system

The reasoning behind TrustStack, the four projects inside it, and my decision to learn by building, breaking, and verifying the controls myself.

read_log
2026-03-31making a payment plan system

how I made a FullStack banking/payment plan managment and creation application

read_log
2026-03-25pontosv: Hardening a Home Server Like It's Production (Because It Is)

Ten weeks of mystery outages, three stacked root causes, and the security doctrine that came out of running a real production workload on hardware I own.

read_log
2026-03-21Publishing a National Journal With Zero Open Ports

How Revista BRASILCON runs on hardware I own, serves readers worldwide, and exposes not a single inbound port to the internet.

read_log
2026-03-15My Hyundai security nightmare

A case study from my work automating Hyundai's new-hire onboarding flow. Some implementation details are generalized to respect confidentiality.

read_log
2026-02-14The LaG of Feb 1, 2026

the Lates and Greatest of the first month (and week) of 2026

read_log
2026-02-13my_second_post

the biggest hurdles, and how i got over them

read_log
2026-02-12my_first_post

why i decided to start this blog, and how

read_log