<!-- Blog directory -->
/var/log/blog
A mid-project look at the detection pipeline, negative fixtures, circuit breaker, S3 policy ambiguity, and the gap between documented events and real AWS behavior.
read_log2026-07-08Starting PontoAntiCrack in dry-runThe design for an AWS detection and response system that plans first, preserves evidence, limits its own authority, and starts without changing resources.
read_log2026-07-01KateClusters is finished, including the test that attacks FalcoThe final KateClusters results across control-plane hardening, RBAC, Pod Security, NetworkPolicy, runtime detection, and four controlled attack scenarios.
read_log2026-06-17KateClusters in the middle: default-deny means DNS tooA practical update from the hardening phase, covering the CIS baseline, audit policy, encrypted Secrets, Calico, RBAC, Falco, and a cluster that briefly lost DNS.
read_log2026-06-03Starting KateClusters from a clean Debian VMWhy I chose kubeadm for the Kubernetes part of TrustStack, what the single-node lab can prove, and why the first benchmark must happen before hardening.
read_log2026-05-27AwLZ is complete: what changed after building a real AWS landing zoneA retrospective on completing the six AwLZ Terraform stacks, validating the guardrails and log archive, and handing the next part of TrustStack to KateClusters.
read_log2026-05-06AwLZ halfway through: when the guardrails guard against meA mid-build report on AwLZ, including Terraform state, multi-account logging, delegated security services, and SCPs that blocked their own deployment path.
read_log2026-04-22Starting AwLZ: building the AWS foundation before the security demosThe first TrustStack build log, covering the scope, account structure, Terraform bootstrap, and failure modes I want AwLZ to address.
read_log2026-04-15TrustStack: why I am building a cloud security lab as one connected systemThe reasoning behind TrustStack, the four projects inside it, and my decision to learn by building, breaking, and verifying the controls myself.
read_log2026-03-31making a payment plan systemhow I made a FullStack banking/payment plan managment and creation application
read_log2026-03-25pontosv: Hardening a Home Server Like It's Production (Because It Is)Ten weeks of mystery outages, three stacked root causes, and the security doctrine that came out of running a real production workload on hardware I own.
read_log2026-03-21Publishing a National Journal With Zero Open PortsHow Revista BRASILCON runs on hardware I own, serves readers worldwide, and exposes not a single inbound port to the internet.
read_log2026-03-15My Hyundai security nightmareA case study from my work automating Hyundai's new-hire onboarding flow. Some implementation details are generalized to respect confidentiality.
read_log2026-02-14The LaG of Feb 1, 2026the Lates and Greatest of the first month (and week) of 2026
read_log2026-02-13my_second_postthe biggest hurdles, and how i got over them
read_log2026-02-12my_first_postwhy i decided to start this blog, and how
read_log