This is the hub page for the DevSecOps writing on rivassec.com. The posts below share one throughline: security controls only matter if they hold up under real operational pressure - the day a role is assumed at scale, the moment an alert fires against your own tooling, or the 208th day of uptime.
Identity and Access
- IAM Blast Radius Is an Architecture Problem, Not a Policy Problem
- IAM Roles That Fail Loud: Small Defaults, Big Difference
Cryptography and Transport
Operating Under Pressure
- The 208.5-Day Kernel Bug: Uptime, Overflow, and Risk
- Taming the OOM Killer: Process Priorities on Linux
- Bandit-Clean Pwnagotchi Plugins: How subprocess Goes From Risk to Routine