Every article
Kubernetes RBAC: the foundations, and the pitfalls that survive an audit
Every one of these pitfalls is published on kubernetes.io. What is missing is the ordering — and the path that leads from a vSphere Namespace straight to cluster-admin.
Network policies and Cilium: building a defensible default-deny
The NetworkPolicy API ships with Kubernetes; enforcing it is the CNI's job. What Cilium adds, what stays standard, and how to reach default-deny by watching real flows before blocking any.
Supply chain security: Sigstore, SBOM, admission control
Kubernetes verifies no image signature on its own. Signing with Sigstore, inventorying with an SBOM, refusing at admission — and what each of those verbs actually covers.
Runtime security: Falco and Tetragon, and how to actually choose
Falco and Tetragon both collect through eBPF. What separates them lies elsewhere: event scope, rule model, and above all what each one can actually prevent.




