Security · HIPAA

Building a PHI/PII-Safe Logging Pipeline for Kubernetes

How I designed a 3-layer defense-in-depth architecture using Istio, Grafana Alloy, and Loki to achieve full HIPAA-compliant logging without losing developer visibility.

COMING SOONDRAFTING
Security · IAM

Zero-Trust CI/CD: Replacing Long-Lived Keys with OIDC

A walkthrough of eliminating all static AWS credentials from the pipeline using OIDC federated auth, STS AssumeRole, and 15-minute temporary credential lifecycles.

COMING SOONDRAFTING
Postmortem · Database

1 Query. 45M Rows. 4 Hours of Chaos.

What happens when "just add an index" triggers a full production incident with 7 replicas lagging by 4 hours. A real postmortem with lessons and what changed after.

COMING SOONDRAFTING
Networking · Istio

Centralized Egress with Istio: Investigation Before Implementation

How I approached centralizing all outbound Kubernetes traffic through Istio Egress Gateway: investigation, PoC testing, production rollout, and the key decisions made along the way.

COMING SOONDRAFTING
Observability · AWS

Multi-Account Observability with PrivateLink: Architecture Deep-Dive

End-to-end walkthrough of building a secure telemetry ingestion platform using AWS PrivateLink, NLBs, Route53, and EKS: with zero public endpoints.

COMING SOONDRAFTING
Kubernetes · Security

Why VPC CNI Running on Node IAM Roles Is a Security Problem

The silent security risk of aws-node relying on node IAM roles, how to investigate the complete credential flow, and a step-by-step guide to migrating to EKS Pod Identity.

COMING SOONDRAFTING
Blog posts dropping soon.

We are converting our LinkedIn engineering write-ups into full technical posts. Follow Devistio on LinkedIn to get notified when they go live, or reach out directly.

Follow Devistio on LinkedIn Get in Touch