<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blog on t0ul</title><link>https://t0ul.com/blog/</link><description>Recent content in Blog on t0ul</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 12 Feb 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://t0ul.com/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>GittyUp! From Linode+Dev Hackathon</title><link>https://t0ul.com/blog/gittyup-from-linode-dev-hackathon/</link><pubDate>Sun, 12 Feb 2023 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/gittyup-from-linode-dev-hackathon/</guid><description>&lt;p&gt;I recently built a project for a hackathon and figured I&amp;rsquo;d share it here for those interested in managing their GitHub.com repository security.&lt;/p&gt;
&lt;h2 id="gitty-up"&gt;Gitty Up&lt;/h2&gt;
&lt;p&gt;Gitty Up Sec.&lt;/p&gt;
&lt;p&gt;It’s a web app where a user can create an account and add an admin GitHub.com token so that they can run their GitHub org against security best practices;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;secret scanning&lt;/li&gt;
&lt;li&gt;static code analysis&lt;/li&gt;
&lt;li&gt;dependency scanning&lt;/li&gt;
&lt;li&gt;branch protections&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For each repo present in the Org. with a single report is generated.&lt;/p&gt;</description></item><item><title>How I got my CISSP</title><link>https://t0ul.com/blog/how-i-got-my-cissp/</link><pubDate>Wed, 25 Jan 2023 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-i-got-my-cissp/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;The Certified Information Systems Security Professional or CISSP is known for its rigorous exam and challenging requirement of needing at least 5 years of experience working in security-related roles.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m happy to say I was able to pass on the first attempt and would like to share my experience and study path with others interested in the CISSP.&lt;/p&gt;
&lt;h2 id="i-career-background"&gt;I. Career Background&lt;/h2&gt;
&lt;p&gt;DevSecOps engineer for 4 1/2 years building security features for a platform in AWS cloud with Python, Go, and Kubernetes which obtained the ISO 27001 &amp;amp; ISO 27002 type I and Type II. During that time, I also received the AWS security specialty certification. Then moved to a whole security infrastructure security analyst job for about 5 months before attempting the CISSP Exam.&lt;/p&gt;</description></item><item><title>Introducing Automate the Boring Stuff with GO</title><link>https://t0ul.com/blog/introducing-automate-the-boring-stuff-with-go/</link><pubDate>Fri, 04 Nov 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/introducing-automate-the-boring-stuff-with-go/</guid><description>&lt;p&gt;The beginner-friendly guide to programming with GO/GoLang. No prior experience is required!&lt;/p&gt;
&lt;h2 id="welcome-to-the-free-e-book-for-beginner-coders-interested-in-go"&gt;Welcome to the Free E-book for Beginner Coders Interested in GO&lt;/h2&gt;
&lt;p&gt;If you&amp;rsquo;re new to GO and a Beginner in programming then there are not really books or learning resources for you. Most GO related books expect you to have some programming experience and involve complex topics such as Web Application building.&lt;/p&gt;</description></item><item><title>Ultimate GoLang Beginner's Cheat Sheet</title><link>https://t0ul.com/blog/ultimate-golang-beginners-cheat-sheet/</link><pubDate>Fri, 28 Oct 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/ultimate-golang-beginners-cheat-sheet/</guid><description>&lt;p&gt;A handy reference guide for GoLang&lt;/p&gt;
&lt;p&gt;When I first learned GoLang 5 years ago, I remember constantly looking up its syntax and things like printing, which was much different than Python 3&amp;rsquo;s way of doing things.&lt;/p&gt;
&lt;p&gt;So, I&amp;rsquo;ve put together the things I looked up the most during my first few months with GoLang in a handy cheat sheet.&lt;/p&gt;
&lt;p&gt;But don&amp;rsquo;t worry, I&amp;rsquo;ll provide it in text for those who like blog posts.&lt;/p&gt;</description></item><item><title>InfraHamBurglar: a CyberSecurity News Bot built with AWS Lambda, GoLang, and Twitter API v2</title><link>https://t0ul.com/blog/infrahamburglar-cybersecurity-news-bot/</link><pubDate>Wed, 19 Oct 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/infrahamburglar-cybersecurity-news-bot/</guid><description>&lt;p&gt;InfraHamBurglar a Twitter Bot for sharing CyberSecurity News&lt;/p&gt;
&lt;p&gt;Today I am introducing the InfraHamBurglar Twitter Bot, which is reporting on the latest &amp;ldquo;Robble, Robble&amp;rdquo; worldwide.&lt;/p&gt;
&lt;p&gt;As someone who works in cybersecurity, I thought it would be funny to have a Twitter bot named the &amp;ldquo;InfraHamBurglar&amp;rdquo; as a pun on an Infrastructure Burglar that is going Ham. Where Infrastructure loosely means Servers and Databases that exist in the cloud.&lt;/p&gt;</description></item><item><title>DevSecOps Engineer Resume</title><link>https://t0ul.com/blog/devsecops-engineer-resume/</link><pubDate>Mon, 10 Oct 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/devsecops-engineer-resume/</guid><description>&lt;p&gt;In this post, I provide my DevSecOps Engineer Resume as an example, and the tool I wield to make it competitive when applying to jobs.&lt;/p&gt;
&lt;h2 id="current-devsecops-engineer-resume"&gt;Current DevSecOps Engineer Resume&lt;/h2&gt;
&lt;p&gt;I use a plain text-style resume when applying online to jobs because of the Applicant Tracking System (ATS), which is a piece of software that scans most people&amp;rsquo;s resumes whenever they apply online.&lt;/p&gt;</description></item><item><title>How I used Machine Learning with GoLang to get More Followers on TikTok</title><link>https://t0ul.com/blog/how-i-used-machine-learning/</link><pubDate>Tue, 04 Oct 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-i-used-machine-learning/</guid><description>&lt;p&gt;In this post, I will show how to use machine learning with GoLang to build a model to predict what makes a video follow-worthy on my TikTok based on my posts so far.&lt;/p&gt;
&lt;p&gt;The data set was created by going through my videos and manually inputting data into a google sheet. For whatever reason, TikTok doesn&amp;rsquo;t have an easily accessible API, and paid products are expensive.&lt;/p&gt;</description></item><item><title>GoLang, Svelte, and Wails 2.0: Cross Platform Desktops just got even easier</title><link>https://t0ul.com/blog/golang-svelte/</link><pubDate>Tue, 27 Sep 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/golang-svelte/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;In the past building, a desktop app required you to learn a completely different tech stack. However, if you&amp;rsquo;re a GoLang enthusiast, then you&amp;rsquo;re in luck. In the many frameworks written, there&amp;rsquo;s Wails v2. Which has been designed to let users stick with GoLang and their JavaScript (JS) framework choice to build a fully cross-platform desktop application.&lt;/p&gt;
&lt;p&gt;Wails works similarly to Electron if you&amp;rsquo;re familiar with it. If not, here&amp;rsquo;s the gist: you can build a desktop app without learning anything other than JS, HTML, and CSS.&lt;/p&gt;</description></item><item><title>Most Popular GoLang Frameworks</title><link>https://t0ul.com/blog/most-popular-golang-frameworks/</link><pubDate>Wed, 21 Sep 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/most-popular-golang-frameworks/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;A framework is typically an opinionated way of building something that a dev or group of devs have built and shared with the world. Web Dev frameworks are by far the most popular.&lt;/p&gt;
&lt;p&gt;A web dev framework is one that provides templates and design patterns for building Web Applications like Google, Yahoo, FaceBook, InstaGram, Twitter, and so on. Some of the most popular web dev ones of all time are Ruby on Rails and Python&amp;rsquo;s Django, but what if you&amp;rsquo;re a GoLang programmer?&lt;/p&gt;</description></item><item><title>DevOps Engineer Resume</title><link>https://t0ul.com/blog/devops-engineer-resume/</link><pubDate>Sun, 18 Sep 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/devops-engineer-resume/</guid><description>&lt;p&gt;In this post, I provide my DevOps Engineer Resume as an example, and the tool I wield to make it competitive when applying to jobs.&lt;/p&gt;
&lt;p&gt;DevOps is a challenging field to get into and as a consequence, it is even more challenging finding DevOps Engineers in most folk&amp;rsquo;s immediate network.&lt;/p&gt;
&lt;p&gt;In fact, I had never met a DevOps Engineer until my internship in college.&lt;/p&gt;</description></item><item><title>How to use GoLang, Hugo, and Lambda for a Single Page Application</title><link>https://t0ul.com/blog/golang-hugo-lambda-spa/</link><pubDate>Thu, 15 Sep 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/golang-hugo-lambda-spa/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;In this post, I&amp;rsquo;ll show how I built the website Free Resume Scanner with Hugo and AWS Serverless. The architecture of the app is similar to most Single Page Web applications. But instead of using React.js, or whatever the trendy Javascript framework is at the moment. We&amp;rsquo;ll use Hugo as our front end. I personally chose this setup with blogging in mind because blogging is one of the best ways to boost a website&amp;rsquo;s search engine optimization (SEO) to get web traffic aka users.I hope that you use this as a starting point in your dev adventures and even more so consider building small open source tools as well.&lt;/p&gt;</description></item><item><title>Make your Static Netlify Pop with a Newsletter feature</title><link>https://t0ul.com/blog/make-your-static-netlify-site-pop-with-a-newsletter/</link><pubDate>Sat, 03 Sep 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/make-your-static-netlify-site-pop-with-a-newsletter/</guid><description>&lt;p&gt;In this post, I&amp;rsquo;ll show exactly how to create a newsletter for your site and enable users to sign up via a popup as they read the article.&lt;/p&gt;
&lt;h2 id="what-were-creating"&gt;What we&amp;rsquo;re creating&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;ll show how to create a popup form that will enable users to sign-up for the Newsletter. It&amp;rsquo;ll activate once the visitor to the site has read a certain amount of the post. In this case, it&amp;rsquo;ll be the Tech Newsletter, but the code will work for any newsletter.&lt;/p&gt;</description></item><item><title>How to Recover After Seeing Your Start-Up Idea Get Beat</title><link>https://t0ul.com/blog/how-to-recover-after-seeing-your-start-up-idea-get-beat/</link><pubDate>Tue, 19 May 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-recover-after-seeing-your-start-up-idea-get-beat/</guid><description>&lt;h1 id="how-to-recover-after-seeing-your-start-up-idea-get-beat"&gt;How to Recover After Seeing Your Start-Up Idea Get Beat&lt;/h1&gt;
&lt;h3 id="intro"&gt;Intro&lt;/h3&gt;
&lt;p&gt;Hi, I may or may not have spent the last two months creating
&lt;a href="https://tradernooks.com"&gt;TraderNooks&lt;/a&gt;- An Animal Crossings New Horizons trading platform where users build a wishlist and can find others who have items on their wishlist with the click of a button.&lt;/p&gt;
&lt;p&gt;Then, after finding users that owns their items they can select to make an offer. The offer is composed of what the user is offering to trade and their preferred means of contact.&lt;/p&gt;</description></item><item><title>How to beat Animal Crossing New Horizons</title><link>https://t0ul.com/blog/how-to-beat-animal-crossing-new-horizons/</link><pubDate>Thu, 02 Apr 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-beat-animal-crossing-new-horizons/</guid><description>&lt;h2 id="beginning"&gt;Beginning&lt;/h2&gt;
&lt;p&gt;In the beginning, you awake in a tent without anything to your name, or so you think until you talk to Tom Nook, who will politely inform you that you owe him 5000 Nook Miles.&lt;/p&gt;
&lt;p&gt;To pay him, you&amp;rsquo;ll have to do specific tasks to earn Nook Miles.&lt;/p&gt;
&lt;p&gt;Also, he&amp;rsquo;ll mention to bring him any unique creatures you find to him because he has a &amp;lsquo;friend&amp;rsquo;.&lt;/p&gt;</description></item><item><title>No-Code Review for Website and Web Application building</title><link>https://t0ul.com/blog/no-code-review-for-website-and-web-application-building/</link><pubDate>Thu, 02 Apr 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/no-code-review-for-website-and-web-application-building/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;No code is a recent movement of technology designed to allow those who do not know how to program build web applications, websites, and even mobile apps.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nocode.tech"&gt;nocode.tech&lt;/a&gt; is a website that has an assortment of no-code offerings, describing where each tool is used in the process of developing a web app, website, or mobile app. It from this site that I found &lt;a href="https://carrd.co"&gt;Carrd.co&lt;/a&gt; for building a website.&lt;/p&gt;</description></item><item><title>Dependency injection with GOlang</title><link>https://t0ul.com/blog/dependency-injection-with-golang/</link><pubDate>Sun, 29 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/dependency-injection-with-golang/</guid><description>&lt;h1 id="intro"&gt;Intro&lt;/h1&gt;
&lt;p&gt;Dependency injection is a form of testing that emphasizes testing of the expected behavior of the functions. Whereas, mocking or faking is concerned with testing the implementation of the code. Because it has the assumption that the thing being mocked accurately reflects the &lt;strong&gt;real-world&lt;/strong&gt; use of the thing being mocked.&lt;/p&gt;
&lt;p&gt;However, no matter how close a mock gets the the actual thing it is suppose to represent it will never be that thing. Yet, mocking isn&amp;rsquo;t evil and is a valid means of making progress when stuck on writing tests, and having some tests is better than having 0 tests.&lt;/p&gt;</description></item><item><title>Top 10 tips for Animal Crossing New Horizons</title><link>https://t0ul.com/blog/top-10-tips-for-animal-crossing-new-horizons/</link><pubDate>Sun, 29 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/top-10-tips-for-animal-crossing-new-horizons/</guid><description>&lt;h1 id="intro"&gt;Intro&lt;/h1&gt;
&lt;p&gt;I joined the Animal Crossing New Horizons wave, and as a new player, here are things I wish I would have known during my first 40+ hours of play.&lt;/p&gt;
&lt;h2 id="1-do-not-sell-wood-stones-and-iron"&gt;1.) Do not Sell Wood, Stones, and Iron&lt;/h2&gt;
&lt;p&gt;I made the mistake of selling everything that I could early on in the game to pay of the &lt;strong&gt;loan&lt;/strong&gt; but ended up wasting nook miles just to go to islands to get wood, stones, and iron.&lt;/p&gt;</description></item><item><title>How to Give Feedback on Pull Requests</title><link>https://t0ul.com/blog/how-to-give-feedback-on-pull-requests/</link><pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-give-feedback-on-pull-requests/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;I have a lot of pull requests during my first year of software engineering, and most of them have been for code and documentation. I have learned from feedback from other team members (or lack of response) what works and what does not. So here is how I go about providing feedback.&lt;/p&gt;
&lt;h2 id="how-to-give-feedback-on-prs-related-to-code-changes"&gt;How to give feedback on PR&amp;rsquo;s related to code changes&lt;/h2&gt;
&lt;p&gt;In general analyzing code changes are easier because one easy way to see if the proposed changes should get the +1 or not is if the system does not break.&lt;/p&gt;</description></item><item><title>How I use Test-Driven Development</title><link>https://t0ul.com/blog/how-i-use-test-driven-development/</link><pubDate>Sun, 15 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-i-use-test-driven-development/</guid><description>&lt;h2 id="how-does-test-driven-development-impact-the-software-i-create"&gt;How does Test-Driven Development Impact the Software I create?&lt;/h2&gt;
&lt;p&gt;I remember starting as an entry-level software engineer and hearing senior engineers on my team get into heated debates about Test-Driven Development (TDD).&lt;/p&gt;
&lt;p&gt;At the time, I was against it because it seemed like extra work. All I wanted was to finish &lt;strong&gt;feature&lt;/strong&gt; of the week.&lt;/p&gt;
&lt;p&gt;However, it all changed after my first feature went into production and caused me and other engineers hours of headaches.&lt;/p&gt;</description></item><item><title>What I learned from working in the industry for one year</title><link>https://t0ul.com/blog/junior-software-engineer-tips/</link><pubDate>Wed, 11 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/junior-software-engineer-tips/</guid><description>&lt;h3 id="introduction"&gt;Introduction&lt;/h3&gt;
&lt;p&gt;I&amp;rsquo;ve learned to do the following as a junior software engineer during my first year in industry.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;TL;DR&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Write a design document&lt;/li&gt;
&lt;li&gt;Document as much as possible&lt;/li&gt;
&lt;li&gt;Test-Driven Development but not 100% test coverage&lt;/li&gt;
&lt;li&gt;Log as much as possible&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="1-i-learned-to-start-with-a-design-document"&gt;1.) I learned to start with a design document&lt;/h3&gt;
&lt;p&gt;A design document is a way of showing viewers of your software what the intended behavior is. I like to use &lt;a href="https://draw.io"&gt;Draw.io&lt;/a&gt; an open-source online piece of software that allows you to save the drawing to your local machine. So, what I like to do is layout the program&amp;rsquo;s intended logic is with all the possible decision paths, which has helped to find edge cases and write tests.&lt;/p&gt;</description></item><item><title>Why I think Everyone should learn at least one programming language in the U.S.</title><link>https://t0ul.com/blog/why-everyone-should-learn-one-programming-language/</link><pubDate>Wed, 11 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/why-everyone-should-learn-one-programming-language/</guid><description>&lt;h3 id="intro"&gt;Intro&lt;/h3&gt;
&lt;p&gt;The economy has transitioned from industrial to the information age, from physical to digital. Yet, the public education system has not caught up with this shift and is still equipping graduates with an Industrial Age skillset. A skillset that does not enable participation in the Information Age Economy.&lt;/p&gt;
&lt;h2 id="comparison-of-skillsets"&gt;Comparison of Skillsets&lt;/h2&gt;
&lt;p&gt;Before going further, here is a basic comparison of skillsets to keep in mind when thinking about public k-12.&lt;/p&gt;</description></item><item><title>How I became a software engineer</title><link>https://t0ul.com/blog/how-i-became-a-software-engineer/</link><pubDate>Fri, 06 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-i-became-a-software-engineer/</guid><description>&lt;h2 id="high-school"&gt;High School&lt;/h2&gt;
&lt;p&gt;I went to school, where the graduating class was only 200 people, and there were not any programming classes. Neither one of my parents were STEM majors; both were blue-collar workers with zero interest in modern technology.&lt;/p&gt;
&lt;p&gt;Because of my parent&amp;rsquo;s lack of interest in technology, our household did not have a computer until 7th grade, and it was only for homework assignments (MS Word).&lt;/p&gt;</description></item><item><title>How to Use Anchore Inline Docker Image Scan</title><link>https://t0ul.com/blog/how-to-use-anchore-inline-docker-image-scan/</link><pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-anchore-inline-docker-image-scan/</guid><description>&lt;h3 id="introduction"&gt;Introduction&lt;/h3&gt;
&lt;p&gt;Anchore is a tool that scans Docker images for common vulnerabilities and not so common vulnerabilities if you purchase the paid version. However, the free version is useful and should still be used on your team to avoid common vulnerabilities.&lt;/p&gt;
&lt;p&gt;Thankfully, the Anchore team is kind enough to have created an entire shell script to both install the Anchore Database locally and run the Anchore CLI all in one line.&lt;/p&gt;</description></item><item><title>How to use PiNg to Debug Networking Problems</title><link>https://t0ul.com/blog/how-to-use-ping-to-debug-networking-problems/</link><pubDate>Sun, 01 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-ping-to-debug-networking-problems/</guid><description>&lt;h2 id="cant-visit-any-webpages-from-your-browser"&gt;Can&amp;rsquo;t visit any webpages from your browser?&lt;/h2&gt;
&lt;p&gt;You&amp;rsquo;re at home and notice that the internet seems to be out whenever you try to connect to a website on your laptop.&lt;/p&gt;
&lt;p&gt;You have already tried turning the wifi router on and off again already, but with no luck.&lt;/p&gt;
&lt;p&gt;Now it is time to check other possible causes.&lt;/p&gt;
&lt;h3 id="potential-causes"&gt;Potential Causes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Local network connection&lt;/li&gt;
&lt;li&gt;Internet Service Provider (ISP)&lt;/li&gt;
&lt;li&gt;Local router&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-to-do"&gt;What to do?&lt;/h2&gt;
&lt;p&gt;Open a terminal or command prompt if you&amp;rsquo;re on windows and use PiNg to check if &lt;strong&gt;any&lt;/strong&gt; website is reachable, &lt;code&gt;www.google.com&lt;/code&gt; is a common choice.&lt;/p&gt;</description></item><item><title>How to use Kubebench to Add Security to a Kops Provisioned Kubernetes Cluster</title><link>https://t0ul.com/blog/how-to-use-kubebench-to-add-security-to-a-kops-provisioned-kubernetes-cluster/</link><pubDate>Mon, 17 Jun 2019 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-kubebench-to-add-security-to-a-kops-provisioned-kubernetes-cluster/</guid><description>&lt;p&gt;Kops is a popular opensource tool that makes it easier to provision and deploy Kubernetes clusters in Cloud Service Providers.&lt;/p&gt;
&lt;p&gt;However, the default provisioning may not adhere to the best practices as outlined by Kube-bench for Security, and kops probably cannot achieve a one-size-fits-all security solution as each user&amp;rsquo;s use of kops may vary.&lt;/p&gt;
&lt;p&gt;Yet, one should be aware of what default security choices kops makes on behalf of the user, which are generally well, thanks, kops team!&lt;/p&gt;</description></item><item><title>How to use Regex expressions when working with AWS WAF CloudFormation template</title><link>https://t0ul.com/blog/how-to-use-regex-expressions-when-working-with-aws-waf-cloudformation-template/</link><pubDate>Wed, 01 May 2019 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-regex-expressions-when-working-with-aws-waf-cloudformation-template/</guid><description>&lt;p&gt;AWS announced support for using Regex Expressions for their WAF CloudFormation Templates. However, a quick prayer to the lord of IT – Google – reveals that no one has figured it out from a solely CloudFormation solution.&lt;/p&gt;
&lt;p&gt;This post tells you what can (and cannot) be done through editing the CloudFormation WAF template, which I discussed earlier in:&lt;/p&gt;
&lt;p&gt;How to Add OWASP 10 to a Load Balancer for a Kubernetes Cluster and EC2 Instances&lt;/p&gt;</description></item><item><title>How to use Docker Bench Security for Container and Host Hardening</title><link>https://t0ul.com/blog/how-to-use-docker-bench-for-security/</link><pubDate>Wed, 17 Apr 2019 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-docker-bench-for-security/</guid><description>&lt;p&gt;Docker is the rage now in the field of containerization and, as a consequence, is a target for attack.&lt;/p&gt;
&lt;p&gt;Although Docker does have some security benefits out of the box upon installation enabled via the default settings, they may not be enough to prevent attacks. This article will focus on using &lt;a href="https://github.com/Docker/Docker-bench-security"&gt;Docker Bench for Security&lt;/a&gt; to aid in tweaking the settings of Docker in line with the standard best practices of using Docker.&lt;/p&gt;</description></item></channel></rss>