This is a personal blog about information security, GRC, the software development lifecycle, mentorship, community building, judgment calls that don't fit a checklist, and inconvenient truths whenever they cross a certain inconvenience threshold. Open-source security is a recurring focus -- project health, secure development in the commons, and related craft. I write through the path I actually walked: systems and networks administration, SRE, DevOps, software development, and cybersecurity. Some posts are hands-on -- how we design, build, and ship securely. Others are reflective notes on craft, mentoring, and teams under pressure, or notes from events I visit and talks I give. Sometimes I write to untangle something for myself until the problem has a clearer shape. Take what helps, leave the rest.
New pieces land below -- roughly weekly, with gaps when life is loud. Opinions are my own.