I Built the Cloud Audit SIEM I Kept Wishing Existed
CAIB turns AWS, GCP, Azure, and Cloudflare audit logs into one self-hosted, testable detection system—and records the trade-offs instead of hiding them.
Read the field noteArchitecture notes, failure reports, security trade-offs, and exact fixes from a home rack operated by a SecOps engineer who should know better.
CAIB turns AWS, GCP, Azure, and Cloudflare audit logs into one self-hosted, testable detection system—and records the trade-offs instead of hiding them.
Read the field noteA production site passed its build, origin, route, header, and preview checks—then looked broken on mobile because immutable CDN caching preserved the previous stylesheet.
Read the field noteA curated inventory of the services behind 76 running containers—what each group does, why it exists, and which pieces are temporary.
Read the field noteThe design choices behind a two-host Docker home lab: leaving Kubernetes, centralizing ingress, separating state, treating sockets as root, and applying before committing.
Read the field noteThe compute, DNS, ingress, database, storage, monitoring, and backup design—without publishing addresses or turning the site into reconnaissance.
See how it fits togetherA green container is an alibi, not evidence. Verify application behavior and committed data.
Docker sockets, automation tokens, and friendly dashboards all deserve the same suspicion.
The useful lesson is usually the decision that looked reasonable five minutes before the incident.