Security architecture journal
Notes from the boundary between systems and risk.
Practical observations on network security, identity, infrastructure hardening and the architectural decisions that tend to become incidents six months later.
Recent notes
Architecture before products
Technical notes about real infrastructure patterns: what they protect, where they fail and what should be verified before deployment.
Trust boundaries are more important than network diagrams
A diagram can show every firewall and VLAN while still hiding the assumptions that actually define the security model. A practical method for identifying where trust really changes.
Reverse proxy hardening beyond TLS
TLS is only the entrance. Request handling, origin exposure, timeouts and logging often determine whether the design remains defensible.
Identity is not a replacement for segmentation
Identity-aware access improves control, but it does not eliminate the need for network boundaries, limited blast radius and explicit service exposure.
Security architecture is applied skepticism.
Every design begins with assumptions. The useful part starts when those assumptions are written down and tested.