Build Provenance and Deployment Gate Operations
Supply-chain security is not complete when an attestation exists. It matters when provenance becomes part of deployment policy.
AI DevOps Korea
Aidevops.kr covers LLMOps, RAG, agents, observability, evaluation, and cost-performance optimization for production AI services.
Tag Archive
This tag currently appears in 5 posts. Following adjacent tags and category signals usually makes the topic easier to understand from multiple angles.
Expand The Topic
Supply-chain security is not complete when an attestation exists. It matters when provenance becomes part of deployment policy.
The shift toward user namespaces being enabled by default is more than a small Kubernetes option change. It signals stronger container isolation expectations.
The rise of zero trust was not just a new security slogan. It reflected a deeper collapse of old assumptions about networks, trust, and where work happens.
A practical introduction to SBOMs, provenance, attestations, and release verification for teams hardening modern delivery pipelines.
This article organizes the core security baseline for running Linux servers safely in production, covering SSH hardening, least privilege, patching, firewalls, audit logs, and operating procedures in a checklist-oriented way.