Blog

Notes on DevOps, Kubernetes, self-hosted infrastructure and consulting.
14 posts tagged guvenlik · clear filter
October 5, 2026
Publishing Packages Without Long-Lived Tokens: Trusted Publishing with OIDC on npm, PyPI and crates.io
A publish token sitting in a CI secret leaks, expires and is broader than it needs to be. Trusted publishing swaps it for the CI system's OIDC identity and a to...
ci-cd guvenlik sir-yonetimi
Read more →
October 3, 2026
Zero-Downtime Secret Rotation: Dual Keys, Alternating Users and the Consumers Left Behind
Rotation outages are caused by consumers, not by the value. Overlap windows, dual keys and alternating users, measuring the cutover, and the long-running proces...
sir-yonetimi guvenlik operasyon
Read more →
September 30, 2026
API Rate Limiting: Token Buckets, Choosing the Right Key and Distributed Counter Pitfalls
Why fixed windows let twice the limit through, why the IP address is a poor key, how INCR plus EXPIRE in Redis can block a client forever, and why you should an...
api-tasarimi backend guvenilirlik
Read more →
September 27, 2026
Custom Domains in SaaS: Ownership Verification, CNAME Targets and TLS Traps
Serving a SaaS from a customer's own domain is not a single CNAME record. Tenant routing, proof of ownership and certificate issuance are three separate problem...
saas multi-tenant guvenlik
Read more →
September 23, 2026
Automated TLS Certificates with ACME: Validation Method, Rate Limits and State You Must Keep
Choosing between HTTP-01, DNS-01 and TLS-ALPN-01, where Let's Encrypt rate limits will catch you, the state you actually need to back up, and pitfalls like spli...
guvenlik altyapi otomasyon
Read more →
September 19, 2026
Enforcing Policy in Kubernetes: OPA Gatekeeper vs. Kyverno, and When to Use Which
RBAC decides who can act, not whether the object they submit is actually valid. Admission-based policy engines close that gap. We compare OPA Gatekeeper, Kyvern...
kubernetes guvenlik otomasyon
Read more →
September 17, 2026
Trust the output, not the model: a last line of defense for automated content
When we built an automated content pipeline, the hard part was never writing the text but making sure it could never leak internal details. Here is why telling...
guvenlik otomasyon sizinti-onleme
Read more →
September 14, 2026
Webhook Design: Retries, Idempotency, and Signature Verification
Webhooks look simple until production traffic exposes three hard questions: delivery guarantees, duplicate events, and sender authenticity. This post covers ret...
saas api-tasarimi guvenlik
Read more →
September 12, 2026
When You Actually Need a Service Mesh, and When It's Just Complexity
A decision guide to the real differences between Istio, Linkerd, and Cilium, what actually justifies adopting a service mesh, and the concrete pitfalls that sho...
kubernetes mimari guvenlik
Read more →
September 11, 2026
What You Gain and Lose With an Immutable Operating System
A look at the three main approaches to read-only, image-based operating systems: what they actually buy you, and the costs that only show up after adoption.
linux altyapi guvenlik
Read more →
September 10, 2026
Identity and Authorization in SaaS: Single Sign-On, Roles, and Tenant Boundaries
In a multi-tenant SaaS product, authentication, role, and tenant boundary are three separate axes. How to pick an identity model, how to match tenants during OI...
saas guvenlik multi-tenant
Read more →
September 8, 2026
Cilium and eBPF: What Changes in Network Policy and Observability
Why iptables-based network policy runs into scaling walls in large clusters, how eBPF fixes that, and what Cilium's identity-based L7 policies and Hubble's side...
kubernetes guvenlik gozlemlenebilirlik
Read more →
September 3, 2026
Gateway API: What Changes After Ingress
Ingress has carried the same three or four fields for a decade, and everything else got bolted on through controller-specific annotations. Gateway API splits th...
kubernetes devops mimari
Read more →
September 1, 2026
Secret Management in Kubernetes: Which Approach Fits Where
Kubernetes' built-in Secret object is not encryption. Here is how to choose between Sealed Secrets, External Secrets Operator, SOPS, and Vault's injector based...
kubernetes sir-yonetimi guvenlik
Read more →