Posts
All the articles I've posted.
-
SLSA Level 2: what build provenance is and why it isn't SBOM
SLSA Level 2 in practice: how build provenance differs from an SBOM, why L2 is a realistic target, how the GitLab Runner itself generates a non-forgeable attestation, and how to verify it with glab/cosign and at admission.
-
The Intervals.icu MCP server in Claude, behind Pomerium
How we connected the Intervals.icu MCP server to Claude and locked it behind Pomerium auth. Plus: how to build a dedicated Claude project and turn it into a personal coach with instructions.
-
Keyless image signing: Sigstore and cosign in CI
Keyless container image signing with Sigstore: cosign, Fulcio and Rekor sign artifacts against your CI's OIDC identity with no long-lived keys. We walk the flow, the pitfalls, and a minimal GitLab CI pipeline with admission-time verification.
-
Self-hosted Matrix + Element: a messenger that's actually yours
Why a self-hosted Matrix server with the Element client is more private and freer than Telegram, WhatsApp or Signal — federation, data ownership, E2EE and bridges, plus a minimal Synapse + Element Docker deploy.