security
In-depth articles from the OrchesTerra engineering team.
Kubernetes
Validate, mutate, and generate with Kyverno without turning every deploy into a 403 — policy types, failure actions, exceptions, and a starter set for platform clusters.
2026-09-07 · 4 min read
CI/CD
Wire GitHub’s OIDC token to AWS, GCP, or Azure so Terraform CI can plan and apply without storing static access keys in repository secrets.
2026-08-25 · 4 min read
Kubernetes
A practical ESO setup: ClusterSecretStore, ExternalSecret refresh, IRSA/Workload Identity, and the failure modes that look like “the app has empty env vars.”
2026-08-22 · 4 min read
Kubernetes
A platform-team checklist to keep clusters cost-efficient and security-hardened: quotas, least privilege, network restrictions, and rightsizing.
2026-06-20 · 2 min read