Configuring MCP servers correctly — the parts that bite
The two-part declaration people get half right, why an API key is not an MCP credential, and where secrets should live so a prompt injection cannot read them.

Every post tagged Security — practitioner notes from running Kubernetes, OpenShift and DevOps tooling in production for clients across the EU and the Gulf.
4 posts
The two-part declaration people get half right, why an API key is not an MCP credential, and where secrets should live so a prompt injection cannot read them.
Locking a namespace to default-deny and adding traffic back safely, why DNS breaks first, and the selector mistake that silently allows far more than intended.
How OpenShift SCCs assign arbitrary UIDs, why that breaks images built for root, how to read the admission error, and how to fix it without granting anyuid.
Curriculum weightings for the Certified Kubernetes Security Specialist, the prerequisite rule that is more ambiguous than people assume, and how to prepare.