<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>容器安全 on 黄文卓 | DevOps Engineer</title>
    <link>https://socake.github.io/tags/%E5%AE%B9%E5%99%A8%E5%AE%89%E5%85%A8/</link>
    <description>Recent content in 容器安全 on 黄文卓 | DevOps Engineer</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-CN</language>
    <managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor>
    <webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster>
    <copyright>© 2026 Wenzhuo Huang</copyright>
    <lastBuildDate>Wed, 18 Mar 2026 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E5%AE%B9%E5%99%A8%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>容器镜像构建优化：BuildKit、多阶段构建与供应链安全</title>
      <link>https://socake.github.io/posts/container-image-build-optimization/</link>
      <pubDate>Wed, 18 Mar 2026 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/container-image-build-optimization/</guid>
      <description>深入剖析容器镜像构建优化的每个环节：BuildKit 并行构建与 Secrets 注入、Go/Python/Node.js 多阶段 Dockerfile 模板、&amp;ndash;mount=type=cache 与远程缓存、Distroless vs Alpine 选型、dive 分析层内容，以及完整的供应链安全闭环（syft SBOM + Cosign 签名 + K8s 准入控制验签）。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/container-image-build-optimization/featured.jpg" />
    </item>
    
    <item>
      <title>Pod Security Standards 生产落地：从 PSP 到 PSA 的迁移实战</title>
      <link>https://socake.github.io/posts/kubernetes-pod-security-standards/</link>
      <pubDate>Fri, 21 Nov 2025 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/kubernetes-pod-security-standards/</guid>
      <description>一份从 PSP 迁移到 Pod Security Standards 的实战笔记：对比 Baseline 与 Restricted 两套 profile 的实际约束、Pod Security Admission 的三种 mode、如何一次性迁移 200+ 命名空间、和 Kyverno/OPA 互补使用的最佳实践，以及遗留业务 securityContext 改造的典型模式。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/kubernetes-pod-security-standards/featured.jpg" />
    </item>
    
    <item>
      <title>Falco 运行时安全实战：从规则开发到生产级调优</title>
      <link>https://socake.github.io/posts/falco-runtime-security-deep/</link>
      <pubDate>Fri, 03 Oct 2025 09:30:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/falco-runtime-security-deep/</guid>
      <description>一份来自生产环境的 Falco 实战笔记：从 eBPF 驱动选型、规则开发方法论、误报治理，到与 Falcosidekick、Loki、SIEM 的告警联动，覆盖 0.40/0.41/0.42 三个版本的关键变更与真实踩坑案例。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/falco-runtime-security-deep/featured.jpg" />
    </item>
    
    <item>
      <title>DevSecOps 安全左移实践：从代码到生产的全链路安全</title>
      <link>https://socake.github.io/posts/devsecops-practice/</link>
      <pubDate>Wed, 20 Aug 2025 10:30:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/devsecops-practice/</guid>
      <description>安全不是最后一道关卡，而是嵌入每个研发环节的连续过程。本文从代码静态分析、依赖漏洞扫描、镜像安全、K8s 运行时防护到供应链签名，逐层拆解 DevSecOps 的完整实施路径，并给出一个可落地的流水线设计。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/devsecops-practice/featured.jpg" />
    </item>
    
  </channel>
</rss>
