
Kubernetes
Istio Service Mesh Architecture – Part1
What a mesh actually solves and when you don’t need one.

What a mesh actually solves and when you don’t need one.

one Policy engine behind every API request written once, tested like code, logged with a reason

Parts 1 and 2 built increasingly good answers to the same question: how do you get an IPsec tunnel out

Part 1 ended at a wall. The StrongSwan sidecar is a fine answer for one or two tunnels, but every

Sooner or later a cluster has to talk to something that isn’t in the cluster — a billing system behind

This is the security hardening playbook for multi-tenant Kubernetes platforms. Not a checklist from a compliance slide deck. These are