Trivy scans images, Kyverno validates deployments, but what watches over what happens once the containers are running? Falco, the CNCF project, monitors syscalls in real time and alerts as soon as abnormal behavior is detected.
The intro article covered the why of OpenTofu. This one covers the how in production: state encryption with several key providers, key rotation, migrating an existing state, and the multi-environment patterns that hold up at scale.
Securing a production Kubernetes cluster isn't just a networking question. Vulnerability scanning, admission policies, least privilege: a hands-on review with Trivy and Kyverno.