pontope.infopontope.blog
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240

<!-- Blog directory -->

/var/log/blog

2026-07-22PontoAntiCrack halfway through: 167 tests and no permission to remediate

A mid-project look at the detection pipeline, negative fixtures, circuit breaker, S3 policy ambiguity, and the gap between documented events and real AWS behavior.

read_log
2026-07-08Starting PontoAntiCrack in dry-run

The design for an AWS detection and response system that plans first, preserves evidence, limits its own authority, and starts without changing resources.

read_log
2026-07-01KateClusters is finished, including the test that attacks Falco

The final KateClusters results across control-plane hardening, RBAC, Pod Security, NetworkPolicy, runtime detection, and four controlled attack scenarios.

read_log
2026-06-17KateClusters in the middle: default-deny means DNS too

A practical update from the hardening phase, covering the CIS baseline, audit policy, encrypted Secrets, Calico, RBAC, Falco, and a cluster that briefly lost DNS.

read_log
2026-06-03Starting KateClusters from a clean Debian VM

Why I chose kubeadm for the Kubernetes part of TrustStack, what the single-node lab can prove, and why the first benchmark must happen before hardening.

read_log
2026-05-27AwLZ is complete: what changed after building a real AWS landing zone

A retrospective on completing the six AwLZ Terraform stacks, validating the guardrails and log archive, and handing the next part of TrustStack to KateClusters.

read_log
2026-05-06AwLZ halfway through: when the guardrails guard against me

A mid-build report on AwLZ, including Terraform state, multi-account logging, delegated security services, and SCPs that blocked their own deployment path.

read_log
2026-04-22Starting AwLZ: building the AWS foundation before the security demos

The first TrustStack build log, covering the scope, account structure, Terraform bootstrap, and failure modes I want AwLZ to address.

read_log
2026-04-15TrustStack: why I am building a cloud security lab as one connected system

The reasoning behind TrustStack, the four projects inside it, and my decision to learn by building, breaking, and verifying the controls myself.

read_log
2026-03-31making a payment plan system

how I made a FullStack banking/payment plan managment and creation application

read_log
2026-03-25pontosv: Hardening a Home Server Like It's Production (Because It Is)

Ten weeks of mystery outages, three stacked root causes, and the security doctrine that came out of running a real production workload on hardware I own.

read_log
2026-03-21Publishing a National Journal With Zero Open Ports

How Revista BRASILCON runs on hardware I own, serves readers worldwide, and exposes not a single inbound port to the internet.

read_log
2026-03-15My Hyundai security nightmare

A case study from my work automating Hyundai's new-hire onboarding flow. Some implementation details are generalized to respect confidentiality.

read_log
2026-02-14The LaG of Feb 1, 2026

the Lates and Greatest of the first month (and week) of 2026

read_log
2026-02-13my_second_post

the biggest hurdles, and how i got over them

read_log
2026-02-12my_first_post

why i decided to start this blog, and how

read_log