DEV Community

Gaberial Sofie profile picture

Gaberial Sofie

Security & IAM engineer. Keycloak, OAuth/OIDC, and pragmatic zero-trust — field notes from real deployments.

Joined Joined on  Personal website https://dorokhovich.com
One Realm for Every App and Tenant Was a Time Bomb: A Keycloak Realms Clients Roles Threat Model

One Realm for Every App and Tenant Was a Time Bomb: A Keycloak Realms Clients Roles Threat Model

Comments
7 min read
A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook

A Typosquatted Gem Almost Shipped, Caught by Luck: A Ruby Supply Chain Security Playbook

Comments
7 min read
Governance Risk Is Supply-Chain Risk: Auditing Every Dependency After the RubyGems Hostile Takeover

Governance Risk Is Supply-Chain Risk: Auditing Every Dependency After the RubyGems Hostile Takeover

Comments
7 min read
When One Keycloak Node Is a Single Point of Failure: A Keycloak Cluster Nginx Threat Model for Zero-Downtime Upgrades

When One Keycloak Node Is a Single Point of Failure: A Keycloak Cluster Nginx Threat Model for Zero-Downtime Upgrades

Comments 1
7 min read
Deleting Hand-Rolled Auth From a Next.js App: A Keycloak Nextjs Threat Model and NextAuth Cutover

Deleting Hand-Rolled Auth From a Next.js App: A Keycloak Nextjs Threat Model and NextAuth Cutover

Comments 1
7 min read
Collapsing 60 Trust Boundaries Into One: A Keycloak Identity Federation Threat Model and 90-Day Rollout

Collapsing 60 Trust Boundaries Into One: A Keycloak Identity Federation Threat Model and 90-Day Rollout

Comments
7 min read
Green Tests Aren't a Safe Supply Chain: A GitHub Actions Security Audit Gate That Blocks Vulnerable Deploys

Green Tests Aren't a Safe Supply Chain: A GitHub Actions Security Audit Gate That Blocks Vulnerable Deploys

Comments
6 min read
Adopting Keycloak Without a Bulk-Credential Migration: A Keycloak Custom Provider (SPI) Threat Model

Adopting Keycloak Without a Bulk-Credential Migration: A Keycloak Custom Provider (SPI) Threat Model

Comments
7 min read
Shrinking the Blast Radius of Our Identity Plane: Deploy Keycloak on AWS ECS Fargate with Terraform

Shrinking the Blast Radius of Our Identity Plane: Deploy Keycloak on AWS ECS Fargate with Terraform

Comments
8 min read
Attack Surface of Hand-Rolled Auth: Consolidating Keycloak FastAPI Role Based Access Control Across 40 Endpoints

Attack Surface of Hand-Rolled Auth: Consolidating Keycloak FastAPI Role Based Access Control Across 40 Endpoints

Comments
7 min read
When Your Resilience Vendor Is Your Single Point of Failure: A Multi-CDN Failover Threat Model After the November 2025 Cloudflare Outage

When Your Resilience Vendor Is Your Single Point of Failure: A Multi-CDN Failover Threat Model After the November 2025 Cloudflare Outage

1
Comments 1
7 min read
dev.to syndication + Reddit r/kubernetes (tool-comparison posts perform well as reference bookmarks)

dev.to syndication + Reddit r/kubernetes (tool-comparison posts perform well as reference bookmarks)

Comments
2 min read
Local Kubernetes Dev — Part 3: Tooling overview — who does what

Local Kubernetes Dev — Part 3: Tooling overview — who does what

1
Comments
1 min read
loading...