Kubernetes

4essays ·All tags

Agent Safety24 min read

When Your Incident Response Requires an AI Model, You've Already Lost

Hugging Face tried to use commercial frontier models to reconstruct a security incident and got blocked by safety filters. The problem isn't the safety filters. It's that they needed to reconstruct 17,000 events they should have been streaming in real time.

  • Incident Response
  • Security
  • Agents
  • Telemetry
  • Kubernetes
  • Ebpf
Agent Safety24 min read

Scoped Credentials: The Least-Privilege Agent

Admin tokens for troubleshooting turn a minor compromise into a takeover. Map agent tasks to tight JWT scopes, Kubernetes identities, and ATR claims enforced at every tool call.

  • Secrets
  • Agents
  • Trust Boundaries
  • Security
  • Kubernetes
Agent Safety22 min read

Supply Chain Verification: Signing Images and Artifacts

Unsigned pulls make every downstream control irrelevant. Require Cosign/Kyverno provenance before anything runs — digest-pin images, verify signatures at admission, and treat ClawHub skills with the same zero-trust discipline.

  • Supply Chain
  • Kubernetes
  • Docker
  • Security
  • Agents
Architecture22 min read

Why Every Release You've Ever Published Can Be Silently Changed

A practical guide to permanent, verifiable, machine-readable software releases using Arweave, Radicle, IPFS, and a manifest format your CI pipeline and your agents can reason about.

  • Supply Chain
  • Agents
  • Security
  • Ipfs
  • Arweave
  • Kubernetes
  • Docker