The k3s Home Lab, Part 4: Ephemeral GitHub Actions Runners with ARC
Connecting GitHub Actions, ARC, a private Gitea registry, and Flux into a scale-to-zero delivery pipeline for a journaling application.
Read postBlog
Long-form technical writing on cybersecurity architecture, cloud security, infrastructure, automation, and the messy parts of operating controls in the real world.
Connecting GitHub Actions, ARC, a private Gitea registry, and Flux into a scale-to-zero delivery pipeline for a journaling application.
Read postMoving from a working Kubernetes cluster to a reproducible one: bootstrapping Flux, structuring reconciliation, handling secrets, and learning to treat Git as the control plane.
Read postA practical migration story about translating containers into Kubernetes workloads without confusing orchestration with resilience.
Read postWhy I chose k3s, how the control plane, networking, ingress, storage, and Proxmox failure domains fit together, and what I would design first next time.
Read postBuilding the original Docker and Traefik deployment around automatic discovery while reducing the risk of mounting the Docker daemon socket directly.
Read postAgentic AI governance becomes real when Purview, Power Platform, Entra ID, SIEM monitoring, and data governance are wired into enforceable identity, DLP, and behavioral controls.
Read postMicrosoft's Copilot stack makes agent building accessible, but enterprise governance has to balance citizen development with identity, lifecycle, data, connector, and oversight controls.
Read postAgentic AI needs more than policy language. This post introduces MAESTRO for threat modeling and the Agentic Trust Framework for zero trust controls, autonomy gates, and enterprise-ready guardrails.
Read postA practical Palo Alto Networks policy guide on moving from brittle URL-only rules toward App-ID, SSL decryption, security profile groups, application groups, and least-privilege enforcement.
Read postEnterprise NAC is less a product installation than a multi-domain engineering program. This post walks through visibility, enforcement, 802.1X, exceptions, segmentation, operations, and where Forescout and FortiNAC each fit.
Read post