Skip to content

Open a connection

What are you building?

Give us the short version. We’ll read it, think about it, and get back to you like humans do.

Now booking early engagements

Workshops, adoption & support

Hands-on sessions for engineering and platform teams — from OIDC fundamentals to zero-trust workload identity in Kubernetes. And once your team is sold on a tool, we'll help you actually roll it out and support it, so adopting open source doesn't become its own headache.

Half-day or full-dayRemote or on-siteSmall groups, hands-on labs

Session topics

Pick a starting point — we'll tailor it to your stack.

Cloud-Native Security Fundamentals

Threat models for Kubernetes and cloud platforms — what actually changes versus traditional infra, and where teams get bitten first.

OIDC & Workload Identity

Move your services and CI/CD pipelines from static, long-lived secrets to short-lived, cryptographically verifiable identity.

Zero Trust in Practice

Design patterns for verifying every request on its own merits, instead of trusting anything inside the network perimeter.

Kubernetes Hardening

RBAC that actually restricts, admission control, and supply-chain security for teams running production clusters.

GitOps & Modern CI/CD

Get hands-on with Argo CD, Flux, Tekton, and Prow — build progressive delivery and CI/CD pipelines that fit how Kubernetes actually works.

Adoption & support

Adopting open source shouldn't feel like a science project.

A new tool is easy in a demo and hard in production. We help you go from proof-of-concept to a real rollout — installation, configuration, migrating off legacy tooling, building custom Kubernetes operators and controllers when off-the-shelf tooling doesn't quite fit, and getting your team comfortable operating it day to day. Once it's live, we stay on for ongoing support, so a broken upgrade or a confusing GitHub issue thread doesn't become your problem alone.

In practice that spans everything from OS and runtime hardening to cloud infrastructure managed declaratively through Kubernetes to automating CVE remediation so upgrades show up as pull requests instead of a "dependency debt" sprint that keeps getting pushed to next quarter. See below for concrete examples of what that looks like today.

Tools we work with

GitOps

Argo CDFlux

CI/CD

TektonProwJenkins X

Policy & admission

OPA / GatekeeperKyverno

Secrets & identity

Vaultcert-managerSPIFFE / SPIRE

Service mesh

IstioLinkerd

Supply chain

Sigstore / CosignTrivyRenovate

Cloud infra via Kubernetes

AWS ACKConfig Connector (KCC)

Node & runtime security

BottlerocketgVisor

Custom operators & controllers

KubebuilderOperator SDKcontroller-runtime

Not on the list? If it's part of the cloud-native or DevOps/platform toolchain, ask us — this is a starting point, not the limit.

What a session looks like

A typical half-day, OIDC-focused session.

Every session is scoped to your team, but here's a real shape for a half-day workshop on workload identity — mostly hands-on, minimal slides.

  1. 09:00

    Kickoff & threat model for your stack

  2. 10:30

    Hands-on lab: issuing & verifying OIDC tokens

  3. 13:00

    Zero trust patterns — live Q&A

  4. 15:00

    Wrap-up, resources & next steps

How it works

Three steps, no procurement headache.

01

Tell us about your stack

A short call about what you run, your team’s level, and what "good" looks like for you.

02

We tailor the session

No generic deck — labs and examples built around your actual infrastructure and threat model.

03

Hands-on session

Remote or on-site, with your team at the keyboard, not just watching slides go by.