The Secure Way

Hardening guides, the secure way

We know why you're here. The docs said it would just work. Pull up a chair.

Step-by-step guides to setting up infrastructure securely: post-quantum TLS, WAFs, DNSSEC, service meshes, Kubernetes, secrets, identity, supply chain, detection and Linux hosts. Each guide shows the secure configuration, what the official docs leave out, how to prove it works, and the mistakes people make.

150 guides in 13 categories

Start herePost-quantum TLS at NIST level 5ML-KEM-1024, the standard name for Kyber-1024: what it is, how it compares to X25519MLKEM768, and how to prove what a server negotiates.

Post-quantum and TLS

Edge and WAF

DNS and DNSSEC

Service mesh

Kubernetes networking with Cilium

Nodes and clusters

Sandboxing untrusted code

Secrets and PKI

Identity and access

Build and supply chain

Runtime detection and observability

Linux hosts