Designing Security Policies for dotsecenv
A long weekend, a SUID dead end, and the simpler design that shipped.
Read →4 articles
A long weekend, a SUID dead end, and the simpler design that shipped.
Read →Why plaintext .env files are a prime target for supply-chain attacks, and how dotsecenv keeps developer secrets encrypted at rest with GPG.
Read →Issuing and renewing Let’s Encrypt SSL/TLS certificates with the DNS-01 challenge in Go, for services that cannot expose HTTP, using Cloudflare DNS and certmagic.
Read →Authenticate to Google Cloud from GitHub Actions without long-lived service account keys, using OIDC and Workload Identity Federation, in five steps.
Read →