More than a year ago, I needed a private dns zone in Azure to test End to end TLS/SSL Offloading
Continue readingCategory: Azure
ThinkPHP Remote Code Execution Vulnerability and why we need to employ WAF at the edge gateways
I had no idea what this ThinkPHP is about until I Googled it but I knew someone is trying to
Continue readingAn Architect’s Journey to Kubernetes in AWS (EKS)
This would be my second post since I joined Fannie Mae and like many other companies Fannie Mae is big
Continue readingScoring SSL Lab A+ Rating at Azure Application Gateway
The basic tenets of data security (confidentiality and integrity)- data must be protected while in motion and at storage (rest).
Continue readingUpgrade Azure Kubernetes Cluster without downtime
Few weeks earlier I received an email from Microsoft asking me to upgrade my Kubernetes cluster running in Azure. “If
Continue readingAzure DevOps Build Pipeline- use keys and secrets from Key Vault
In Cybersecurity, Defense in Depth (DID) approach should be followed when available. DID is a concept in which multiple layers
Continue readingBuild your own Artificial Intelligence (AI) and Machine Learning (ML) to block robots at Application Gateway
You can always buy 3rd party services to provide web application firewall (WAF) like capability as you can focus on
Continue readingRead NSG Flow Logs from Azure Storage Account (How-To)
What’s your strategy on cloud network logging and monitoring? Where do you keep vpc/vnet flow logs? How long do you
Continue readingRevisit: End to end TLS with Azure Application Gateway and Kubernetes Ingress
If you work in Risk and Security organization and your applications or micro-services process PCI or GDPR data, your important
Continue readingAzure Key Vault- Safeguard Signing/Encryption Keys, Secrets and Certificates
Secret vault is where you hide your secrets like digital signing keys, encryption/decryption keys, api keys, client certificates and other
Continue reading