DEV Community

Gaberial Sofie profile picture

Gaberial Sofie

Security & IAM engineer. Keycloak, OAuth/OIDC, and pragmatic zero-trust — field notes from real deployments.

Joined Joined on  Personal website https://dorokhovich.com
Your Ingress does nothing until you have an Ingress controller (and 3 more local-k8s networking traps)

Your Ingress does nothing until you have an Ingress controller (and 3 more local-k8s networking traps)

Comments
2 min read
Local Kubernetes Dev — Part 11: Networking — reaching your service and Ingress

Local Kubernetes Dev — Part 11: Networking — reaching your service and Ingress

Comments
1 min read
Running Postgres, Redis and RabbitMQ inside your local k3d cluster (with the 2025 Bitnami trap)

Running Postgres, Redis and RabbitMQ inside your local k3d cluster (with the 2025 Bitnami trap)

Comments
2 min read
Local Kubernetes Dev — Part 9: Dependencies — databases, queues, caches

Local Kubernetes Dev — Part 9: Dependencies — databases, queues, caches

Comments
1 min read
One Realm for Every App and Tenant Was a Time Bomb: A Keycloak Realms Clients Roles Threat Model

One Realm for Every App and Tenant Was a Time Bomb: A Keycloak Realms Clients Roles Threat Model

Comments
7 min read
A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook

A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook

Comments
7 min read
Governance Risk Is Supply-Chain Risk: Auditing Every Dependency After the RubyGems Hostile Takeover

Governance Risk Is Supply-Chain Risk: Auditing Every Dependency After the RubyGems Hostile Takeover

Comments
7 min read
When One Keycloak Node Is a Single Point of Failure: A Keycloak Cluster Nginx Threat Model for Zero-Downtime Upgrades

When One Keycloak Node Is a Single Point of Failure: A Keycloak Cluster Nginx Threat Model for Zero-Downtime Upgrades

Comments 1
7 min read
Deleting Hand-Rolled Auth From a Next.js App: A Keycloak Nextjs Threat Model and NextAuth Cutover

Deleting Hand-Rolled Auth From a Next.js App: A Keycloak Nextjs Threat Model and NextAuth Cutover

Comments 1
7 min read
Collapsing 60 Trust Boundaries Into One: A Keycloak Identity Federation Threat Model and 90-Day Rollout

Collapsing 60 Trust Boundaries Into One: A Keycloak Identity Federation Threat Model and 90-Day Rollout

Comments
7 min read
Green Tests Aren't a Safe Supply Chain: A GitHub Actions Security Audit Gate That Blocks Vulnerable Deploys

Green Tests Aren't a Safe Supply Chain: A GitHub Actions Security Audit Gate That Blocks Vulnerable Deploys

Comments
6 min read
Adopting Keycloak Without a Bulk-Credential Migration: A Keycloak Custom Provider (SPI) Threat Model

Adopting Keycloak Without a Bulk-Credential Migration: A Keycloak Custom Provider (SPI) Threat Model

Comments
7 min read
Shrinking the Blast Radius of Our Identity Plane: Deploy Keycloak on AWS ECS Fargate with Terraform

Shrinking the Blast Radius of Our Identity Plane: Deploy Keycloak on AWS ECS Fargate with Terraform

Comments
8 min read
Attack Surface of Hand-Rolled Auth: Consolidating Keycloak FastAPI Role Based Access Control Across 40 Endpoints

Attack Surface of Hand-Rolled Auth: Consolidating Keycloak FastAPI Role Based Access Control Across 40 Endpoints

Comments
7 min read
When Your Resilience Vendor Is Your Single Point of Failure: A Multi-CDN Failover Threat Model After the November 2025 Cloudflare Outage

When Your Resilience Vendor Is Your Single Point of Failure: A Multi-CDN Failover Threat Model After the November 2025 Cloudflare Outage

1
Comments 1
7 min read
k3d, kind, Helm, Kustomize, Tilt, Skaffold, k9s: a one-screen map of who does what

k3d, kind, Helm, Kustomize, Tilt, Skaffold, k9s: a one-screen map of who does what

Comments
2 min read
Local Kubernetes Dev — Part 3: Tooling overview — who does what

Local Kubernetes Dev — Part 3: Tooling overview — who does what

1
Comments
1 min read
loading...