Infrastructure security posts

  • Infrastructure security

ECS on EC2: Covering Gaps in IMDS Hardening

  • icon Oct 02, 2025
  • icon 10 minutes read
  • icon 1945
Introduction # AWS ECS is a widely-adopted service across industries. To illustrate the scale and ubiquity of this service, over 2.4 billion Amazon Elastic Container Service tasks are launched every week (source) and over 65% of all new AWS …
Read more
  • Infrastructure security
  • Tooling

Introducing Replik8s, a Modern Security Tool for Kubernetes

  • icon Sep 22, 2025
  • icon 3 minutes read
  • icon 524
Introduction # Security tools are often designed to highlight specific issues by consuming APIs and applying predefined logic. Each tool implements its own data structures, storage formats, and evaluation logic. While effective in narrow contexts, …
Read more
  • Infrastructure security

Remediating AWS IMDSv1

  • icon Aug 11, 2021
  • icon 15 minutes read
  • icon 3036
2024-12-17 Updated to include Declarative Policies Compute resources in AWS (for example, EC2 instances, ECS tasks/services, etc.) get access to AWS credentials, such as temporary instance role credentials, via the Instance Metadata Service (IMDS). …
Read more
  • Infrastructure security

Gripes with Google Groups

  • icon May 29, 2018
  • icon 4 minutes read
  • icon 820
If you’re like me, you think of Google Groups as the Usenet client turned mailing list manager. If you’re a GCP (Google Cloud Platform) user or maybe one of a handful of SAML (Security Assertion Markup Language) users you probably know …
Read more