Posts about #devops
4 posts
Lightweight Web Auditing vs. OWASP ZAP: Choosing the Right Security Workflow
OWASP ZAP is powerful but heavy — complex setup, minutes per scan, massive false positives. Here's when to use ZAP, when to use lightweight scanners, and how to build a layered security workflow.
How to Monitor Website Uptime: A Practical Guide
Set up website uptime monitoring that actually works — from basic health checks to multi-location verification, alerting, and response-time tracking.
The 5-minute pre-deploy security checklist (for anyone shipping fast)
You're about to push to production. You have five minutes. Here's the exact checklist — free scan, headers, exposed files, secrets, deps, redirects, cookies — that catches the majority of real-world breaks before your users do.
How a silent TypeError drained our cloud credits and what we learned
A Python string-vs-datetime mismatch caused orphan droplets to bill for 3 days. Full postmortem with root cause, compounding bugs, and the fix.