<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Duy Mach Tien — blog</title><description>DevOps engineer working on bare-metal Kubernetes, SLSA L3 signed supply chains, GitOps with Argo CD, and AWS delivery with centralised secrets and logging.</description><link>https://kythuat.vn</link><language>en</language><atom:link href="https://kythuat.vn/rss.xml" rel="self" type="application/rss+xml"/><item><title>Security that matches your traffic</title><link>https://kythuat.vn/blog/security-that-matches-your-traffic</link><guid isPermaLink="true">https://kythuat.vn/blog/security-that-matches-your-traffic</guid><description>Tutorials put WAF, Origin Shield and Shield Advanced in front of sites that get four thousand visits a month. This works out, with verified August 2026 prices, the traffic level at which each layer starts paying for itself — and shows that for a portfolio the honest answer is a hosted zone and nothing else.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>aws</category><category>cloudfront</category><category>s3</category><category>cost</category><category>security</category></item><item><title>The interview question about SSH keys</title><link>https://kythuat.vn/blog/the-interview-question-about-ssh-keys</link><guid isPermaLink="true">https://kythuat.vn/blog/the-interview-question-about-ssh-keys</guid><description>&quot;You have a lot of hosts — how do you manage SSH keys?&quot; is really a question about where authorisation state lives. Working the answer from authorized_keys through Vault SSH certificates to Session Manager, and admitting which layer actually solves the problem.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>ssh</category><category>vault</category><category>aws</category><category>security</category><category>operations</category></item><item><title>It is probably not DNS</title><link>https://kythuat.vn/blog/it-is-probably-not-dns</link><guid isPermaLink="true">https://kythuat.vn/blog/it-is-probably-not-dns</guid><description>&quot;It&apos;s always DNS&quot; is a punchline that became a diagnostic strategy. Six unrelated faults — ephemeral ports, conntrack, MTU, egress policy, CPU throttling, kube-proxy rule scaling — produce a symptom indistinguishable from a DNS failure, and each has one observation that rules it out.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate><category>kubernetes</category><category>networking</category><category>dns</category><category>debugging</category><category>observability</category></item><item><title>Your allowlist is where the misses come from</title><link>https://kythuat.vn/blog/your-allowlist-is-where-the-misses-come-from</link><guid isPermaLink="true">https://kythuat.vn/blog/your-allowlist-is-where-the-misses-come-from</guid><description>Auditing three of my own repositories for credentials before publishing them. The regex found the easy half; the exclusions I added to quiet the noise are what hid the rest.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>security</category><category>secrets</category><category>audit</category><category>git</category><category>methodology</category></item><item><title>Security scanning on GitLab CE, where none of the security features exist</title><link>https://kythuat.vn/blog/security-scanning-on-gitlab-ce</link><guid isPermaLink="true">https://kythuat.vn/blog/security-scanning-on-gitlab-ce</guid><description>The built-in scanning templates are an Ultimate feature. Building the same coverage from Trivy, Gitleaks and Semgrep — and finding the one security-shaped report a Community Edition merge request will actually render.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>gitlab</category><category>ci-cd</category><category>trivy</category><category>semgrep</category><category>security</category></item><item><title>A Secret in a GitOps repo is a Secret in production</title><link>https://kythuat.vn/blog/a-secret-in-a-gitops-repo-is-a-secret-in-production</link><guid isPermaLink="true">https://kythuat.vn/blog/a-secret-in-a-gitops-repo-is-a-secret-in-production</guid><description>Pulling hardcoded credentials out of Argo CD-synced manifests, and finding the connection string that made the whole exercise pointless — plus why a working default credential is worse than no default at all.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>kubernetes</category><category>gitops</category><category>argo-cd</category><category>secrets</category><category>security</category></item><item><title>The CSP was in Terraform, the script was in Astro, and nothing checked</title><link>https://kythuat.vn/blog/the-csp-and-the-build-did-not-agree</link><guid isPermaLink="true">https://kythuat.vn/blog/the-csp-and-the-build-did-not-agree</guid><description>A postmortem on a bug that could not fail locally — the security header lived in one repository layer and the markup that violated it in another, and only production applied both.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><category>postmortem</category><category>csp</category><category>astro</category><category>terraform</category><category>cloudfront</category></item><item><title>Serving a static site from S3 without making the bucket public</title><link>https://kythuat.vn/blog/private-s3-origin-with-cloudfront-oac</link><guid isPermaLink="true">https://kythuat.vn/blog/private-s3-origin-with-cloudfront-oac</guid><description>Origin Access Control, a CloudFront Function for clean URLs, and why a private origin returns 403 instead of 404.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>aws</category><category>cloudfront</category><category>s3</category><category>terraform</category></item><item><title>Signing container images is the easy half</title><link>https://kythuat.vn/blog/signing-images-is-the-easy-half</link><guid isPermaLink="true">https://kythuat.vn/blog/signing-images-is-the-easy-half</guid><description>Cosign takes an afternoon. Making the cluster refuse an unsigned image is where supply-chain work actually starts.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>kubernetes</category><category>kyverno</category><category>cosign</category><category>slsa</category></item><item><title>I built a Count-Min Sketch and the hash map won</title><link>https://kythuat.vn/blog/i-built-a-sketch-and-the-hash-map-won</link><guid isPermaLink="true">https://kythuat.vn/blog/i-built-a-sketch-and-the-hash-map-won</guid><description>A streaming algorithm with a beautiful error bound, benchmarked against the boring alternative on the workload it was actually for — and what the two benchmarks disagreeing taught me about reading my own numbers.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate><category>algorithms</category><category>streaming</category><category>benchmarks</category><category>cpp</category><category>detection</category></item><item><title>The kernel knows everything except who you are</title><link>https://kythuat.vn/blog/the-kernel-knows-everything-except-who-you-are</link><guid isPermaLink="true">https://kythuat.vn/blog/the-kernel-knows-everything-except-who-you-are</guid><description>Building an eBPF collector that catches every outgoing TCP connection from a pod — and discovering that the hard part is not the kprobe, it is turning a cgroup id back into a pod name without asking the API server.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate><category>ebpf</category><category>kubernetes</category><category>co-re</category><category>libbpf</category><category>observability</category></item></channel></rss>