
Hari 47: DefectDojo API — 7 Scans, 16 Findings Centralized
Upload 7 scanner reports (Trivy, Semgrep, Checkov) ke DefectDojo via import-scan API. 15 tests imported, 46 findings centralized. upload-scans.sh script + conditional CI job. ZAP needs XML format.

Hari 46: DefectDojo — Vuln Management Dashboard
DefectDojo via Docker Compose — no clone 358MB repo, standalone compose file, 7 containers, port 8088. Single pane of glass untuk semua scan findings. Fase 4 dimulai!

Hari 45: Fase 3 Complete — K8s & Runtime Security
15 hari, 6 defense layers, 12 lessons. Fase 3 K8s & Runtime Security selesai! Kubesec 0→12, Checkov 20→0, Falco 29 rules, 6 alerts fired. Defense in depth proven. Retrospective complete.

Hari 44: AI Threat Modeling — 3 Attack Paths
AI (glm-5.2) analyzes K8s cluster config and identifies 3 attack paths: container escape (CVSS 9.8), lateral movement (CVSS 7.5), secret exfiltration (CVSS 8.6). Defense in depth validated — every attack path has multiple mitigations from Day 31-43.

Hari 43: External Secrets — AWS to K8s Sync
External Secrets Operator sync JWT_SECRET dari AWS Secrets Manager ke K8s Secret. Secret Reference Pattern: git cuma referensi, nilai di AWS. ESO SecretSynced dalam 20s. GitHub Push Protection block Checkov report yang contain AWS keys.

Hari 42: Webhook Alerting — Falco to Python Receiver
n8n Docker pull timed out → pivot ke Python webhook receiver. Falcosidekick webhook output enabled. End-to-end: attack → Falco → Falcosidekick → webhook → IF routing CRITICAL to Slack path. 3 alerts received.
Page 4 of 13 • 76 articles