Secure Docker and Kubernetes

From supply chain to runtime: build safer images, lock down clusters, instrument logging & audit trails, and stay ahead of emerging threats.

As seen at:DevOps DozenDevOps.comWeAreDevelopers

Three Books, One Mission

Learn container security through a comprehensive guide, a dark fantasy novel, and a comic book — pick your style.

Black Forest Shadow book cover
Black Forest Shadow book cover — back cover

Black Forest Shadow

A dark fantasy novel set in 1865 — learn container security through an immersive narrative.

Prefer a different store? Your choice will be remembered.

Learn More

Buy directly

Docker and Kubernetes Security book cover
Docker and Kubernetes Security book cover — back cover

Docker and Kubernetes Security

The comprehensive guide — supply chain to runtime, with TL;DRs, exercises, and CI/CD integration.

Prefer a different store? Your choice will be remembered.

Learn More
Black Forest Commandos: Asgard Mission comic book cover
Black Forest Commandos: Asgard Mission comic book cover — back cover

Black Forest Commandos

The comic book origin story — ten commandos securing Asgard against CVE monsters through an epic visual narrative.

Latest from the Blog

View all →
The Poisoned Macchiato: Signing Java SBOMs with Cosign

August 1, 2026 · 15 min read

The Poisoned Macchiato: Signing Java SBOMs with Cosign

A café, a suspicious espresso, and a lesson in supply chain trust. Learn how to generate BuildKit SBOM attestations for Java images and re-attest them with Cosign as OCI referrers.

Black Forest Commandos: Asgard Mission DIY v1.5.2

June 23, 2026 · 15 min read

Black Forest Commandos: Asgard Mission DIY v1.5.2

Hands-on workshop materials for the 10 Black Forest Commandos in Asgard v1.5.2. Covering secure initialization, SBOM generation via Scout, Attestations, Hardened Images, VEX exemptions, Docker Bake, Cosign signing, and Zero-Day defense.

Beyond SLSA: How to Stop Zero-Click CI/CD Worms with the IX Hexbreaker Aegis Framework

June 16, 2026 · 11 min read

Beyond SLSA: How to Stop Zero-Click CI/CD Worms with the IX Hexbreaker Aegis Framework

The security perimeter of modern software development has officially collapsed. This article introduces the IX Hexbreaker Aegis Framework, a 9-step active defense architecture designed to sanitize the local developer environment, lock down agentic AI, and stop autonomous worms dead in their tracks.

Stay in the Loop

New books, workshop dates, and security deep-dives — straight to your inbox.

No spam. Unsubscribe anytime.