# agilicus.com > AI-optimized mirror of agilicus.com containing 50 pages totalling 35,464 words of clean markdown content, structured data, and semantic HTML. Original source: https://agilicus.com/. Last updated: 2026-06-10T01:40:41.088Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [site-root.html](/content/site-root.html) (1 words) ## Articles & Blog Posts - [Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea](/content/defence-in-depth-zero-trust-is-a-critical-layer-not-a-panacea.html): "Defence in Depth" strategy, explaining why zero trust is a critical layer in protecting critical infrastructure. From the medieval castle analogy to the "lizard brain" risks of AI-amplified human engineering, learn why layered security and strong authentication are more important than ever in 2026. (1,276 words) - [Assessing Your Industrial Cyber Security Posture](/content/assessing-your-industrial-cyber-security-posture/index.html): The convergence of operational technology and information technology demands a pragmatic approach. Discover our five-dimensional scorecard to evaluate and improve your industrial cyber security posture. (856 words) - [DoS’ing the cloud with logs](/content/dosing-the-cloud-with-logs/index.html): Could cloud logging be the next NTP amplification attack for a DDoS? A small input produces a larger output, the ingredients are there... (693 words) - [NERC CIP Compliance for Small Independent Power Producers: A Pragmatic Approach](/content/nerc-cip-compliance-for-small-independent-power-producers-a-pragmatic-approach.html): With the April 1, 2026 enforcement date for NERC CIP-003-9 past, small Independent Power Producers (IPPs) face unique regulatory pressures. This post explores a pragmatic approach to securing low-impact assets, replacing legacy VPNs with a zero trust architecture that automates vendor access controls and simplifies audit evidence retention. (783 words) - [Securing the Flow: GAO Highlights Persistent Cyber Threats to Water and Wastewater Systems](/content/securing-the-flow-gao-highlights-persistent-cyber-threats-to-water-and-wastewater-systems.html): A recent Government Accountability Office report reveals that nearly 170,000 water systems are increasingly vulnerable to sophisticated cyberattacks. Because the air gap is dead, traditional virtual private networks no longer provide adequate protection. Agilicus AnyX secures critical infrastructure by implementing Zero Trust Architecture, replacing perimeter-based defences with precise, identity-based access and mandatory Multi-Factor Authentication. (890 words) - [A Pragmatic Blueprint for Industrial Cyber Security](/content/a-pragmatic-blueprint-for-industrial-cyber-security.html): A strong cyber security posture is built on orthogonal defences. Review the five key dimensions of our best practices program and take the assessment to measure your resilience. (804 words) - [The naked cloud: elasticsearch is stretch but doesn’t cover security](/content/the-naked-cloud-elasticsearch-is-stretch-but-doesnt-cover-security.html): Wide open elasticsearch on the Internet. Its common. The user usually believes since they use private IP (NAT) they are protected. Wrong. (520 words) - [Water utility cybersecurity: The nearly £1 million lesson from South Staffordshire Water](/content/water-utility-cybersecurity-the-nearly-1-million-lesson-from-south-staffordshire-water.html): The £963,900 ICO fine against South Staffordshire Water highlights the fatal flaw in perimeter-based security. Learn how Agilicus Zero Trust architecture addresses identity failures and the 'legacy headache' in critical infrastructure. (994 words) - [Safely secure secrets: a sops plugin for kustomize](/content/safely-secure-secrets-a-sops-plugin-for-kustomize/index.html): Secrets get committed to git, forgotten, and then resurrected by the wrong people later. Don't let this happen to you, use sops. And be declarative, use kustomize. And do it with this cool new library I wrote. (570 words) - [What a wicked NAT we weave: detangling the cloud](/content/what-a-wicked-nat-we-weave-detangling-the-cloud/index.html): Cloud. It achieves its elastic nature using Load Balancers and Proxies. The sad side affect of these is they remove the source IP. Let's try to bring it back. (467 words) - [The Epitome of Absolute Trust: Why Legacy Virtual Private Networks Are a Liability](/content/the-epitome-of-absolute-trust-why-legacy-virtual-private-networks-are-a-liability.html): Legacy virtual private networks are a liability, acting as an ethernet cable into your deep infrastructure. With active exploitation of obsolete protocols on the rise, organisations must abandon absolute trust. Discover why modernising access through an Identity-Aware Proxy is the only pragmatic defence against perimeter zero-day vulnerabilities. (607 words) - [Cyber Security Is Physical Safety: Lessons From a Thermal Runaway](/content/cyber-security-is-physical-safety-lessons-from-a-thermal-runaway.html): A report on a recent B.C. EV charger fire reveals the danger of relying on software for physical safety. Learn why hardware interlocks and zero trust are non-negotiable for remote maintenance. (789 words) - [Zero Trust Audit Logging: Reliable Meets Simple](/content/zero-trust-audit/index.html): Big investments in SIEM become big headaches due to correlating IP and NAT. Skip that with crypto-secure audit with Zero Trust via JWT. (313 words) - [When your security tools cost more than the thing they protect](/content/when-your-security-tools-cost-more-than-the-thing-they-protect.html): The (memory) cost of all the security proxies can be higher than the thing they protect. Let's look at Istio. (577 words) - [Kooking Kontainers With Kubernetes: A Recipe for Dual-Stack Deliciousness](/content/kooking-kontainers-with-kubernetes-a-recipe-for-dual-stack-deliciousness.html): Kubernetes technically doesn't support dual-stack (ipv4 and ipv6 simultaneously). What if you want to run some CI job in there that requires a localhost ::1 to bind to? Read on! (481 words) - [Helm, Kubernetes, and the immutable configMap… a design pattern](/content/helm-kubernetes-and-the-immutable-configmap-a-design-pattern.html): Add the sha-hash of a configmap contents to its name as a design pattern and simplify your Deployment restarts, knowing they always have the right value and don't die on error. (473 words) - [Completely Complex Cloud Cluster Capacity Crisis: Cool as a Cucumber in Kubernetes](/content/completely-complex-cloud-cluster-capacity-crisis-cool-as-a-cucumber-in-kubernetes.html): Keeping your cool during an upgrade is important. Let the scheduler do its work, you'll reconverge to happiness. (620 words) - [Docker Hub Hack: Secure Your Supply Chain](/content/docker-hub-hack-secure-your-supply-chain/index.html): Docker hub loses account info, deploy tokens for github + bitbucket. Supply chain security chaos should ensue. Or are we now too blase? Its not me, right? (459 words) - [The desktop crypto curveball: test your encryption](/content/desktop-test-encryption-curveball/index.html): Encryption. Its good, if its working,. You should test your encryption, on the desktop, on the server, once in a while. Curveball recently came out, test it!. (369 words) - [I Fixed My Malware Injection Issue With Content-Security-Protection](/content/stop-injected-malware-on-your-sit/index.html): My personal site had a permissive content-security-policy. This allowed malicious adware injectors to grafitti it up. I fixed mine, fix yours today. (362 words) - [Snooping on your Kubernetes nodes containers without ssh’ing to it: dink](/content/snooping-on-your-kubernetes-nodes-containers-without-sshing-to-it-dink.html): Want to see what 'docker' is doing on a Kubernetes node (logs, ps, images), or re-pull an image? Don't want to ssh there? dink! (329 words) - [Declarative GitFlow: restrict kustomize to master branch](/content/declarative-gitflow-restrict-kustomize-to-master-branch.html): Prevent accidents from happening on un-merged feature branches with GitFlow and kustomize. (329 words) - [Multiple Kubernetes contexts and your multi-coloured prompt](/content/multiple-kubernetes-contexts-and-your-multi-coloured-prompt.html): You are working with multiple clouds. But, you keep changing context and then accidentally applying something. Ooops. If only this could be simpler.Drop these two bits in your .bashrc. Now you can simply say 'context foo' and be in that context with a little bit of colour in your prompt to remind you. (269 words) - [Moving into a new (cloud) neighbourhood? Check its reputation!](/content/moving-into-a-new-cloud-neighbourhood-check-its-reputation.html): Your shiny new cloud instances might be tarnished by the reputation of the last tenant. Use Shodan to check, and Greynoise to see if its above the norm. And above all, don't panic! (334 words) - [The Firewall Emperor Has No Clothes](/content/firewall-emperor-has-no-clothes/index.html): The Firewall Emperor, long the king of security, has no clothes. Micro segmentation is just more firewalls. You want Zero Trust Network Access. (312 words) - [Kustomizing Kustomize: Releasing Our Tools](/content/kustomize-plugin-examples/index.html): Declarative. It becomes a way of life. We have chosen kustomize to safely build our inventory of YAML, including Istio and Cert-Manager. But, it has proven (332 words) - [Agilicus Story: Cloud Native Computing Foundation Stories](/content/agilicus-story-cloud-native-computing-foundation-stories.html): Agilicus presents its architecture, philosophy, strategy at CNCF Eastern Canada Stories Meetup (281 words) - [Security and the Cloud: The need for high bandwidth entropy](/content/security-and-the-cloud-the-need-for-high-bandwidth-entropy.html): Randomness is needed for seeding encryption, particularly at session start. In an orchestrated cloud environment, we use a lot of it, but have no user to provide. What to do? (483 words) - [Simplify Security: Split Identity and Authorisation with Zero Trust](/content/simplify-security-zero-trust-split/index.html): Zero Trust. The key principle is, we split identity and authorisation apart. We move from a perimeter-based trust (e.g. VPN + firewall) to a user + asset-based model. (356 words) - [Keep your cloud clean: HSTS preload](/content/keep-your-cloud-clean-hsts-preload/index.html): HSTS exists to secure your site, to enforce your HTTPS-only policy. Why not use it and put yourself on the preload list? (372 words) - [My team works outside, why can’t their Kronos Timesheet?](/content/outside-team-inside-kronos-zero-trust-solution/index.html): Access your on-premise Kronos from any user, from any device, from any network. Increased security, increased simplicity. Zero Trust Networking. (408 words) - [Covert Exfiltration, Cloud Native](/content/covert-exfiltration-cloud-native/index.html): Your virtual-private-cloud private IP setup still has access to key API's such as storage and messaging. Have you considered exfiltration through these? (333 words) - [Cloud Security Blasphemy: Secrets in git](/content/cloud-security-blasphemy-secrets-in-git/index.html): Ever wondered why so many breaches happen due to secrets being checked in to source control? Want to make it easy to commit them to git, and be secure at the same time? Read On! (270 words) - [Keep your certificates young and fresh](/content/keep-your-certificates-young-and-fresh/index.html): TLS certificates, unlike wine, do not get better with age. Refresh them before they hit the end of their lifecycle. (235 words) - [Today’s post brought to you by the letter ‘k’: quickly re-pull an image in kubernetes](/content/todays-post-brought-to-you-by-the-letter-k-quickly-re-pull-an-image-in-kubernetes.html): Have you ever had a Pod in a Deployment that you wish would just pull the latest container image to see what's up? Want to run the equivalent of `touch`? Read on! (271 words) - [Learn. Do. Teach.](/content/blog/index.html): Do. Learn. Teach. Posts by Agilicus. (11,463 words) - [Strong Identity and Authentication: Avoid Named User License Costs With Federation](/content/strong-identity-and-authentication-avoid-named-user-license-costs-with-federation.html): Implement a srong, simple, secure authentication system, including support for 2-factor authentication, without triggering named-user license costs. (400 words) - [Laughably Loquacious Logging](/content/laughably-loquacious-logging/index.html): Cloud logging. How much space does a typical keep-alive take if you log it? You would be shocked that 1 byte of log could be 32+ KiB of output space. Watch the entropy! (1,792 words) - [‘first’ and ‘only’ are four-letter words in cloud. How to do something ‘once’ and ‘first’ in a Kubernetes Deployment](/content/first-and-only-are-four-letter-words-in-cloud-how-to-do-something-once-and-first-in-a-kubernetes-deployment.html): Cloud Native implies a continuum. A declarative world that has no special event that occurs when it is started or finished. Non cloud-native applications often have 'start' or 'upgrade' tasks that need performing. Things that need to be done 'one' or 'first' or at some lifecycle stage. How can we integrate these two worlds? (779 words) - [How phishing negates your firewall](/content/how-phishing-negates-your-firewall/index.html): Your corporate firewall. That invulnerable bastion that lets you fearlessly run less-than-secure internal tools like a CRM, a Finance portal. But, is it really invulnerable? Or is it a paper wall at best? We look at how Cross-Site-Scripting vulnerabilities, known session ID cookies or access tokens can allow content from the world to pierce it as if it were not there. We do this using the weakest link: you. (508 words) - [Secure Exposed Access: Zero-Trust Legacy Online With High Security and No Work](/content/secure-exposed-access-blog/index.html): Somewhere in your basement lurks a challenge. A web application that people need, but you don't trust. Maybe its your timesheet or vacation planner. Maybe its (489 words) - [Security of the upstream code, and, the importance of the egress firewall](/content/security-of-the-upstream-code-and-the-importance-of-the-egress-firewall.html): Bad code can come in through our own import statements and software process. Do you run an egress firewall to protect the world from yourself? (304 words) - [Two-Factor Herd Immunity: Mozilla 2-factor authentication](/content/two-factor-herd-immunity/index.html): Mozilla makes multi-factor authentication mandatory for authors. Herd Immunity suggests if we get a few more, we are all protected. (440 words) - [Remove SMS from your 2-factor authentication](/content/remove-sms-from-your-2-factor-authentication/index.html): SMS (text) has no place in your 2-factor authentication world. Remove it now and rely on a physical device (e.g. YubiKey) or TOTP (e.g. Authenticator app). (397 words) - [404 Not Found](/content/apps-need-2-factor-auth/index.html) (4 words) - [The Agilicus Philosophy: Continuous Learn. Do. Teach.](/content/agilicus-agile-philosophy/index.html): The Agilicus Philosophy: The world we work in changes. Our requirements change. By continuously learning and adapting, we survive and thrive. (235 words) - [Ding Dong: The VPN is dead. Split Identity and Authorisation to Simplify Security](/content/ding-dong-the-vpn-is-dead/index.html): A philosophy that allows you to reduce cost, increase security, and increase user engagement and satisfaction. All 3 at once. Sounds crazy? (349 words) - [You want me to sign in with what now?](/content/you-want-me-to-sign-in-with-what/index.html): "Sign in with...". What does it mean? Why should I use it? What am I giving up? There must be a catch, right? (247 words) - [Your VPN Hates Your Video Conferencing. Here’s Why](/content/your-vpn-hates-your-video-conferencing-heres-why/index.html): Got VPN? Got perfect video conferencing with everyone all the time? If yes, well, this video is not for you. For the rest, read and view! (239 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives