Writing
Notes from the work
Mostly the things I had to figure out the hard way — pipeline security, Terraform at scale, and why the network is where platforms break. Published on Medium.
DevSecOps03
- Mar 2024· 2 minImplementing Security on Azure DevOps PipelinesWalking an Azure deployment architecture from its default state to a secured one — where the vulnerabilities actually are, and what a DevSecOps pipeline with SOC/SIEM integration changes.AzureDevSecOpsPipelines
- Feb 2023· 7 minDevSecOps: Implement Security Checks on GitLabWhy a CI/CD pipeline is one of the highest-value targets in your estate, and the practical checks to build into a GitLab pipeline from the outset rather than after the audit.DevSecOpsGitLabCI/CDAWS
- May 2022· 9 minDevSecOps: Implement Security on a CI/CD PipelineWhat a DevSecOps pipeline looks like end to end, mapped against CIS benchmarks — and why running several scanners beats trusting one.DevSecOpsKubernetesSecurityCI/CD
Infrastructure as code02
- Jun 2023· 3 minUnderstanding Terraform Variable Precedence OrderThe precedence rules that quietly cause the 'but I set that variable' bug, in the order Terraform actually evaluates them.TerraformAWSGCP
- Jun 2022· 16 minTerraform: Production-Grade IaC CodingFor people who know Terraform but haven't run it at scale. Module structure, loops and precedence, and the patterns that separate a working configuration from a maintainable one.TerraformIaCAWSGCP
Want this applied to your stack rather than read about?
Most of what's above started as a client problem. If one of them looks like yours, tell me about it.
Stockholm, Sweden (CET) · Comfortable overlap with European hours and US East Coast mornings