Skip to main content

Eradicate long-lived tokens before they eradicate you

If you are still using classic GitHub PATs in your environments "just for pulling, read or packaging," you are not being pragmatic. You are accepting forever access as normal. That is a culture problem. Tooling only follows.

Your JetStream is fine. You just have two of them.

Publish returns ack. Consumer never sees the message. Restart a pod and a stuck queue suddenly drains. Realtime join works on one pod; another user never sees it. Websocket adapter events vanish depending on which replica you hit. Same cluster. Same Service DNS. Different JetStream stores. That is the smell.

AKS + Karpenter: kubectl logs returns 401 Unauthorized

kubectl get pods is fine. kubectl describe is fine. Then you hit kubectl logs on a pod that just landed on a Karpenter node and get 401 Unauthorized. Same cluster. Same context. Pods on the system pool still give you logs. That split is the smell.

Container Image SBOM Blind Spots: What Scanning Your Image Still Misses

Every container security program ends up doing the same three things: scan the image with Trivy in CI, sign it with cosign, put up a dashboard that counts CVEs. Then they call the problem "in progress."

That checklist is the easy 20% of the work. It makes a lot of noise but cuts very little risk.

Kubernetes Runtime Security: The Silence That Should Keep You Up at Night

On an engagement I worked alongside Olakojo testing a product. Between Ola is one of the best offensive security engineers in this space, and watching him work is a lesson in patience: he does not spray exploits and hope. He reads the app, finds the innocent looking path, and walks in through the front door everyone believed was secure.

Zero Trust Network Access vs VPN: The Art of the Rabona

A rabona is not the obvious pass. You wrap your leg behind the standing one, hit the ball at an awkward angle, and somehow the play opens up anyway. VPN vs Zero Trust feels like that at first, same pitch, different move entirely.

AWS Cloud Costs Nightmare, Cutting It To Elongate That Startup Runway

Cloud costs at early stage startups rarely spiral because of recklessness.

They spiral because the team was moving fast, the architecture made sense at the time, and nobody had the bandwidth to revisit it.

By the time the bill becomes a problem, the decisions are already baked in.

I have been on both sides of this, burning through it personally, and leading teams trying to unwind it before the runway ran out. Here is what has actually worked.