Agentic DevOps Security: Old IAM Failures at New Speed
Agentic DevOps security concerns aren't new — they're old IAM failures (least privilege, step-up auth, JIT) agents now exercise at machine speed.
Read moreWriting on cloud security, DevSecOps practices, compliance, and building security into the infrastructure delivery pipeline.
Agentic DevOps security concerns aren't new — they're old IAM failures (least privilege, step-up auth, JIT) agents now exercise at machine speed.
Read moreAI agents with direct write access to production reintroduce the risks we eliminated with IaC — state drift, broken audit trails, and silent mutations.
Read moreStatic scanners miss whether a built image behaves like the runtime you intend to ship. dgoss turns images into testable runtime contracts for CI/CD.
Read moreServerless compute reduces PCI-DSS scope by eliminating infrastructure layers that require patching and monitoring. Compliance becomes configuration.
Read moreWhy idempotent or fully reproducible Dockerfiles are frequently promoted but often misplaced objectives compared to immutable artifacts and regular CI rebuilds.
Read more