<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>零信任 on 黄文卓 | DevOps Engineer</title>
    <link>https://socake.github.io/categories/%E9%9B%B6%E4%BF%A1%E4%BB%BB/</link>
    <description>Recent content in 零信任 on 黄文卓 | DevOps Engineer</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-CN</language>
    <managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor>
    <webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster>
    <copyright>© 2026 Wenzhuo Huang</copyright>
    <lastBuildDate>Fri, 07 Nov 2025 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/categories/%E9%9B%B6%E4%BF%A1%E4%BB%BB/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>用 WireGuard 构建多云 mesh VPN：从点对点到全网互联</title>
      <link>https://socake.github.io/posts/wireguard-mesh-vpn/</link>
      <pubDate>Fri, 07 Nov 2025 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/wireguard-mesh-vpn/</guid>
      <description>一份从实战出发的 WireGuard mesh VPN 笔记：讲清楚为什么不用 IPSec/OpenVPN、手写配置 vs Netmaker vs Tailscale 的选型对比、AWS 与阿里云跨云 mesh 的真实部署方案、MTU 与 NAT 穿透的踩坑，以及自动化密钥分发与监控方案。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/wireguard-mesh-vpn/featured.jpg" />
    </item>
    
    <item>
      <title>Cilium NetworkPolicy 与 L7 过滤生产落地实战</title>
      <link>https://socake.github.io/posts/cilium-network-policy-production/</link>
      <pubDate>Fri, 31 Oct 2025 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/cilium-network-policy-production/</guid>
      <description>一份基于 Cilium 1.16+ 的生产落地笔记：讲清楚 Kubernetes NetworkPolicy 的局限、CiliumNetworkPolicy 的扩展能力、L7 HTTP/Kafka/DNS 过滤的真实用法、Hubble 可观测性、策略开发方法论，以及多集群 ClusterMesh 场景下的策略治理。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/cilium-network-policy-production/featured.jpg" />
    </item>
    
    <item>
      <title>SPIFFE/SPIRE 工作负载身份实战：零信任网络的身份基石</title>
      <link>https://socake.github.io/posts/spiffe-spire-workload-identity/</link>
      <pubDate>Fri, 10 Oct 2025 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/spiffe-spire-workload-identity/</guid>
      <description>一份从生产部署出发的 SPIFFE/SPIRE 实战笔记：讲清楚 SVID、节点证明、工作负载证明、信任域联邦这些核心概念，用 Kubernetes + Istio + 非 K8s 工作负载的混合场景展示 SPIRE 如何统一身份，并分享升级、备份、Agent 崩溃等真实运维踩坑。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/spiffe-spire-workload-identity/featured.jpg" />
    </item>
    
  </channel>
</rss>
