<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>容器安全 on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/%E5%AE%B9%E5%99%A8%E5%AE%89%E5%85%A8/</link><description>Recent content in 容器安全 on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Wed, 18 Mar 2026 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E5%AE%B9%E5%99%A8%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml"/><item><title>容器镜像构建优化：BuildKit、多阶段构建与供应链安全</title><link>https://socake.github.io/posts/container-image-build-optimization/</link><pubDate>Wed, 18 Mar 2026 10:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/container-image-build-optimization/</guid><description>深入剖析容器镜像构建优化的每个环节：BuildKit 并行构建与 Secrets 注入、Go/Python/Node.js 多阶段 Dockerfile 模板、&amp;ndash;mount=type=cache 与远程缓存、Distroless vs Alpine 选型、dive 分析层内容，以及完整的供应链安全闭环（syft SBOM + Cosign 签名 + K8s 准入控制验签）。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/container-image-build-optimization/featured.jpg"/></item><item><title>Pod Security Standards 生产落地：从 PSP 到 PSA 的迁移实战</title><link>https://socake.github.io/posts/kubernetes-pod-security-standards/</link><pubDate>Fri, 21 Nov 2025 10:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/kubernetes-pod-security-standards/</guid><description>一份从 PSP 迁移到 Pod Security Standards 的实战笔记：对比 Baseline 与 Restricted 两套 profile 的实际约束、Pod Security Admission 的三种 mode、如何一次性迁移 200+ 命名空间、和 Kyverno/OPA 互补使用的最佳实践，以及遗留业务 securityContext 改造的典型模式。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/kubernetes-pod-security-standards/featured.jpg"/></item><item><title>Falco 运行时安全实战：从规则开发到生产级调优</title><link>https://socake.github.io/posts/falco-runtime-security-deep/</link><pubDate>Fri, 03 Oct 2025 09:30:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/falco-runtime-security-deep/</guid><description>一份来自生产环境的 Falco 实战笔记：从 eBPF 驱动选型、规则开发方法论、误报治理，到与 Falcosidekick、Loki、SIEM 的告警联动，覆盖 0.40/0.41/0.42 三个版本的关键变更与真实踩坑案例。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/falco-runtime-security-deep/featured.jpg"/></item><item><title>DevSecOps 安全左移实践：从代码到生产的全链路安全</title><link>https://socake.github.io/posts/devsecops-practice/</link><pubDate>Wed, 20 Aug 2025 10:30:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/devsecops-practice/</guid><description>安全不是最后一道关卡，而是嵌入每个研发环节的连续过程。本文从代码静态分析、依赖漏洞扫描、镜像安全、K8s 运行时防护到供应链签名，逐层拆解 DevSecOps 的完整实施路径，并给出一个可落地的流水线设计。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/devsecops-practice/featured.jpg"/></item></channel></rss>