Live Average

  •  Home
  •  About
  •  Blog
  •  Projects
  •  Posts
  •  Categories
  •  Contact
  • Share
  • Search
  • Menu
  •  Home

  •  About

  •  Blog

  •  Projects

  •  Posts

  •  Categories

  •  Contact

Recent Posts

Secure Internal Applications with Layered Access Controls on Envoy Gateway

March 25, 2026

RBAC Audit Compliance for Kubernetes: Practical Enforcement and Verification

March 24, 2026

Falco in Production: Tuning, Integration, and Operational Realities

March 23, 2026

Surviving Vendor Pitches at Kubecon: a Platform Engineer's Playbook

March 22, 2026

Kubernetes Authorizer Alwaysdeny Behavior Explained and Fixed

March 21, 2026
View more posts

Secure Internal Applications with Layered Access Controls on Envoy Gateway

Use IP allowlisting for a basic perimeter, combine with OIDC for identity verification.

March 25, 2026 JR

3 minute read

Use IP allowlisting for a basic perimeter, combine with OIDC for identity verification, and consider zero trust overlays like OpenZiti for scalable security.

  • Continue Reading
    • Kubernetes
    • Security
    • DevSecOps

    Share this post

  • Twitter

  • Google+

  • Facebook

  • Reddit

  • LinkedIn

  • StumbleUpon

  • Pinterest

  • Email

RBAC Audit Compliance for Kubernetes: Practical Enforcement and Verification

Implement RBAC audits by enforcing policies with Kyverno, validating access controls.

March 24, 2026 JR

2 minute read

Implement RBAC audits by enforcing policies with Kyverno, validating access controls, and maintaining audit trails to meet compliance requirements.

  • Continue Reading
    • Kubernetes
    • Security
    • DevSecOps

    Share this post

  • Twitter

  • Google+

  • Facebook

  • Reddit

  • LinkedIn

  • StumbleUpon

  • Pinterest

  • Email

Falco in Production: Tuning, Integration, and Operational Realities

Falco detects runtime threats in Kubernetes but requires deliberate tuning and alerting integration to avoid drowning in noise.

March 23, 2026 JR

2 minute read

Falco detects runtime threats in Kubernetes but requires deliberate tuning and alerting integration to avoid drowning in noise.

  • Continue Reading
    • Kubernetes
    • Security
    • DevSecOps

    Share this post

  • Twitter

  • Google+

  • Facebook

  • Reddit

  • LinkedIn

  • StumbleUpon

  • Pinterest

  • Email

Surviving Vendor Pitches at Kubecon: a Platform Engineer's Playbook

A practical guide for platform engineers to manage vendor pitches efficiently at KubeCon.

March 22, 2026 JR

2 minute read

A practical guide for platform engineers to manage vendor pitches efficiently at KubeCon.

  • Continue Reading
    • Kubernetes
    • Security
    • DevSecOps

    Share this post

  • Twitter

  • Google+

  • Facebook

  • Reddit

  • LinkedIn

  • StumbleUpon

  • Pinterest

  • Email

Kubernetes Authorizer Alwaysdeny Behavior Explained and Fixed

The AlwaysDeny authorizer mode in Kubernetes does not deny requests as expected due to its design to return NoOpinion.

March 21, 2026 JR

2 minute read

The AlwaysDeny authorizer mode in Kubernetes does not deny requests as expected due to its design to return NoOpinion, requiring configuration adjustments.

  • Continue Reading
    • Kubernetes
    • Security
    • DevSecOps

    Share this post

  • Twitter

  • Google+

  • Facebook

  • Reddit

  • LinkedIn

  • StumbleUpon

  • Pinterest

  • Email

Hugo Future Imperfect

OpenShift & Kubernetes Mechanic

Preventative maintenance, routine care, and repairs for Kubernetes & OpenShift clusters

Recent Posts

Secure Internal Applications with Layered Access Controls on Envoy Gateway

March 25, 2026

RBAC Audit Compliance for Kubernetes: Practical Enforcement and Verification

March 24, 2026

Falco in Production: Tuning, Integration, and Operational Realities

March 23, 2026

Surviving Vendor Pitches at Kubecon: a Platform Engineer's Playbook

March 22, 2026

Kubernetes Authorizer Alwaysdeny Behavior Explained and Fixed

March 21, 2026
View more posts

Categories

devsecops 41

kubernetes 41

security 41

news 16

coding 14

infrastructure-management 12

infrastructure 11

k8s 5

living 4

nagios 3

openshift 3

check_mk 1

features 1

hugo 1

motorycles 1

powershell 1

About

I’m a Red Hatter working as a Solutions Architect, formerly a Senior Cloud Success Architect, with a focus on and passion for OpenShift and Ansible. Previous life? Cloud Advanced Technology Lead & Big Data Engineer for Lockheed Martin Space, IT/IS Data Center Manager for Lockheed Martin IS&GS, and Senior Infrastructure Designer/Administrator for the City of Gainesville & City of Alachua.

Learn More

© 2026 Live Average . Powered by Hugo