Publications
eBPF Threat Model
A comprehensive threat model for eBPF-based security solutions.
Hacking Kubernetes
The definitive guide to Kubernetes offensive and defensive security.
NIST SP 800-233
Security guide to service mesh proxy models for cloud-native applications.
Envoy Gateway Threat Model
A comprehensive threat model for the Envoy Gateway.
ArgoCD End User Hardening Guide
A guide to hardening ArgoCD for end users.
Flux D1 Reference GitOps Architecture
A hardened reference architecture for GitOps with Flux CD.
FINOS AI Readiness Governance Framework
AI governance framework for financial services.
FINOS AI Security Reference Architecture
AI security reference architecture for financial services.
Hardening Git for GitOps
How to secure Git workflows for GitOps.
Flatcar Threat Model (CNCF)
A project graduation threat model with the TAG Security community.
Kubernetes for Security Operations Centres
Community collaboration with JP Morgan Cyberops.
Kubernetes Threat Model for Financial Services User Group
Financial services-specific threat model for Kubernetes.
CIS Benchmarks for Google Kubernetes Engine
Center for Internet Security hardening guide for GKE.