Apple Container 1.5.0: Native Kubernetes for SIGHUP Distribution

My first Apple Container Kubernetes and SIGHUP Distribution lab needed a deliberately narrow recovery path. container k8s create started the node but failed during preparation, so the lab helper applied two TCP MSS rules through legacy iptables and completed the kubeadm bootstrap itself. Apple Container 1.5.0 closes that story. It fixed the retained kernel failure at the source, so the cluster is created natively and the SIGHUP Distribution installs on top without any bootstrap workaround. The kernel backstory still matters, because the upgrade behavior that caused the failure is unchanged, and the remediation is the same explicit command. ...

October 1, 2026 · 6 min · 1095 words · Matteo Bisi

Who Owns NIS2 and DORA in a Platform Team

I keep seeing the same meeting. Someone from legal or risk drops a NIS2 control, a DORA article, or a “can we evidence this” request into the room. The Kubernetes platform team looks at security. Security looks at the platform team. A ticket lands on the security board, because that feels like the responsible place. Three sprints later the cluster has not changed, the evidence still does not exist, and everyone is slightly angry at the security lead. ...

September 10, 2026 · 11 min · 2151 words · Matteo Bisi

Kubernetes 1.37 Security: 3 Stable Advances, 3 Future Signals

Kubernetes 1.37, named Garhwal, was released on August 26, 2026. It contains 67 enhancements, with 16 reaching stable status. The security story is clear. Kubernetes 1.37 strengthens workload identity, trust distribution, and SELinux enforcement today. It also introduces early capabilities that point to better policy protection, safer writable storage, and more resilient recovery tomorrow. For customer decision-makers, the long feature list is not the point. The important question is whether the release helps organisations protect customer data and keep critical services trustworthy. These six features are the most useful answer. ...

September 4, 2026 · 7 min · 1286 words · Matteo Bisi

Kubernetes Audit Logs and HAProxy Logs for SOC Evidence

One of the most important topics my team has been following this year is designing and implementing a SOC service for cloud-native workloads at ReeVo. We started with the preventative layer. We designed and tuned a solid set of posture rules through our CNAPP solution, covering misconfigurations, risky privileges, and known bad patterns across our clusters. The platform also gives us runtime-security capabilities to identify suspicious behaviour as it occurs. That part is working well. ...

August 26, 2026 · 8 min · 1546 words · Matteo Bisi

Apple Container Kubernetes on macOS: A SIGHUP Distribution Lab

Apple Container 1.2.0 added an experimental Kubernetes plugin. It creates a local cluster from the kindest/node image, bootstraps upstream Kubernetes with kubeadm, configures kindnet, writes a kubeconfig, and leaves the node available to kubectl. The workflow does not require a separate desktop VM manager or Docker. I tested the feature on an Apple-silicon Mac with 32 GB of memory. It is useful for local Kubernetes development, but the experimental status matters. ...

August 16, 2026 · 9 min · 1836 words · Matteo Bisi

Shadow AI in CI/CD: Threat-Modelling Laptop to Kubernetes

Artificial intelligence is becoming part of daily software delivery, often before it becomes part of the organisation’s security architecture. This creates Shadow AI: AI tools, models, agents, extensions, or integrations used without formal approval, ownership, risk assessment, or monitoring. For executives, Shadow AI is not primarily a “developers using ChatGPT” issue. It is an enterprise-risk issue: ungoverned AI can gain access to source code, intellectual property, credentials, customer data, cloud environments, and deployment workflows. When AI systems are allowed to call tools or take actions, they must be treated as new non-human identities with access rights, not simply as productivity software. ...

July 27, 2026 · 13 min · 2597 words · Matteo Bisi

In 2026 I Am Still Asked Why You Need a Centralized Secrets Manager

It’s 2026 and I still get the same question from customers and colleagues: we already encrypt our secrets with git-crypt (or SOPS, or sealed-secrets), why do we need a full secrets manager on top of that? I hear it from platform teams that are otherwise mature, from developers who are genuinely trying to do the right thing, and from managers who see a centralized secrets manager as one more piece of infrastructure to buy, run, and justify. ...

July 17, 2026 · 9 min · 1824 words · Matteo Bisi

Back to Basics: TLS and PKI from the Ground Up

This is the third article in my “Back to Basics” series. The goal is simple: take something modern engineers interact with daily through abstractions, and explain what is actually happening underneath. In the first article, I hardened an SSH daemon and explained why the defaults are insecure. In the second, I showed that containers are ordinary Linux processes wrapped in namespaces and cgroups. This article applies the same approach to TLS: strip away the abstractions, read the raw structures, and understand what the tooling is doing on your behalf. ...

June 29, 2026 · 16 min · 3263 words · Matteo Bisi

In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog

It’s 2026 and I still receive questions from customers and colleagues about why they should adopt a hardened container image catalog, why it matters, and how to justify the investment internally. I hear it from security engineers, from architects, from technical leads at companies that are otherwise doing serious work on their security posture. The honest answer is short: European regulations like DORA and NIS2 require it, and from a purely technological standpoint it is the logical evolution of how we have always managed infrastructure. Both arguments stand independently. Together they leave no room for debate. ...

June 24, 2026 · 9 min · 1727 words · Matteo Bisi

Cloud Native Days Italy 2026: A Wrap-Up from Bologna

Bologna, May 18-19: The Fifth Edition Bologna, May 18-19, 2026. The fifth edition of Cloud Native Days Italy is behind us, and I’m still riding the wave of energy it left behind. Writing this post as one of the organizers feels different from a regular conference recap. Seeing something you worked on for months actually land — with real people in real rooms — is hard to describe briefly. If you want to read how the journey to this edition started, I covered it in an earlier post. ...

May 22, 2026 · 4 min · 761 words · Matteo Bisi