Building a PHI/PII-Safe Logging Pipeline for Kubernetes
How I designed a 3-layer defense-in-depth architecture using Istio, Grafana Alloy, and Loki to achieve full HIPAA-compliant logging without losing developer visibility.
Technical deep-dives, architecture decisions, postmortems, and lessons from running real systems in production — written by the Devistio engineering team.
How I designed a 3-layer defense-in-depth architecture using Istio, Grafana Alloy, and Loki to achieve full HIPAA-compliant logging without losing developer visibility.
A walkthrough of eliminating all static AWS credentials from the pipeline using OIDC federated auth, STS AssumeRole, and 15-minute temporary credential lifecycles.
What happens when "just add an index" triggers a full production incident with 7 replicas lagging by 4 hours. A real postmortem with lessons and what changed after.
How I approached centralizing all outbound Kubernetes traffic through Istio Egress Gateway: investigation, PoC testing, production rollout, and the key decisions made along the way.
End-to-end walkthrough of building a secure telemetry ingestion platform using AWS PrivateLink, NLBs, Route53, and EKS: with zero public endpoints.
The silent security risk of aws-node relying on node IAM roles, how to investigate the complete credential flow, and a step-by-step guide to migrating to EKS Pod Identity.
We are converting our LinkedIn engineering write-ups into full technical posts. Follow Devistio on LinkedIn to get notified when they go live, or reach out directly.