» Tag
zero-trust
7 postsDesigning Conditional Access policies for AI agent identities
How to apply Conditional Access to AI agent identities in Microsoft Entra: autonomous agents, approval-based targeting, and safe staged rollout guidance.
AI Sandboxing: The Real Risk Lives in Infrastructure, Not the Model
As autonomous AI agents gain access to tools, credentials, and infrastructure, security focus is shifting from model behavior to runtime isolation and sandboxing.
Remote Attestation: Proving Server Integrity with TPMs
Remote attestation uses TPMs to cryptographically prove a host's boot integrity, helping infrastructure detect and reject compromised machines automatically.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comZero-Trust Workload Identity in Kubernetes: SPIFFE, SPIRE, Cilium
Why IP-based network policies fail in Kubernetes, and how SPIFFE, SPIRE, and Cilium enable cryptographic workload identity and enforced mutual TLS.
Kars: A Kubernetes-Native Zero-Trust Runtime for AI Agents
Kars runs each AI agent in an isolated Kubernetes sandbox, routing every external call through a Rust-based zero-trust broker with no agent-held credentials.
Building a Zero-Trust Network Perimeter for S3 with Terraform
Even if IAM keys leak, attackers stay locked out. Learn how VPC Endpoints and S3 bucket policies enforce a zero-trust network perimeter in Terraform.
Cloudflare routes public traffic to private apps securely
Cloudflare's new Application Services for Private Origins brings WAF, bot management and caching to private origins without exposing public IPs.