<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Devsecops on Hi, I&#39;m Muhammad Amal</title>
    <link>https://muhammadamal.my.id/tags/devsecops/</link>
    <description>Recent content in Devsecops on Hi, I&#39;m Muhammad Amal</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 08 Sep 2025 09:00:00 +0700</lastBuildDate>
    <atom:link href="https://muhammadamal.my.id/tags/devsecops/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DevSecOps in AI ML Pipelines, A Comprehensive Tutorial</title>
      <link>https://muhammadamal.my.id/blog/devsecops-ai-ml-pipelines-comprehensive-tutorial/</link>
      <pubDate>Mon, 08 Sep 2025 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/devsecops-ai-ml-pipelines-comprehensive-tutorial/</guid>
      <description>How to wire real security gates into ML pipelines without grinding training to a halt, with code and policies that actually work.</description>
    </item>
    <item>
      <title>Pod Security Standards in 2023, Migrating Off PSPs Without Breaking Everything</title>
      <link>https://muhammadamal.my.id/blog/pod-security-standards-migration/</link>
      <pubDate>Thu, 28 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/pod-security-standards-migration/</guid>
      <description>Migrating from PodSecurityPolicy to Pod Security Standards on Kubernetes 1.28 — namespace labels, audit-mode rollout, and the workloads guaranteed to break.</description>
    </item>
    <item>
      <title>Vault 1.14 Dynamic Secrets in Kubernetes, Past the Sidecar Demo</title>
      <link>https://muhammadamal.my.id/blog/vault-dynamic-secrets-kubernetes/</link>
      <pubDate>Thu, 14 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/vault-dynamic-secrets-kubernetes/</guid>
      <description>Running Vault 1.14 dynamic database secrets in Kubernetes 1.28 — injector vs CSI, lease renewal, and the failure modes that bite under load.</description>
    </item>
    <item>
      <title>Wiring Trivy 0.45 Into a CI Pipeline That Actually Blocks Bad Builds</title>
      <link>https://muhammadamal.my.id/blog/trivy-container-scanning-pipeline/</link>
      <pubDate>Mon, 04 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/trivy-container-scanning-pipeline/</guid>
      <description>Trivy 0.45 in CI: severity gating, ignore policies, DB caching, and the gotchas that bite teams shipping containers daily.</description>
    </item>
  </channel>
</rss>
