The DevOpsBeast Blog

Production engineering notes.

Field notes on Kubernetes, GPUs, Linux, and the rest of the production stack, from engineers who run real infrastructure.

Security··10 min read

Signed Is Not Safe: What an Artifact Signature Actually Proves

SolarWinds was signed. Correctly, by the vendor's own certificate, on an artifact the vendor genuinely produced. Every verification a customer could perform would have passed. Signing answers a much narrower question than most teams assume, and knowing which question changes what you build.

Read post