<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Minoko Labs</title><link>https://minoko.life/tags/security/</link><description>Recent content in Security on Minoko Labs</description><generator>Hugo -- 0.154.0</generator><language>en-us</language><lastBuildDate>Fri, 09 Jan 2026 10:00:00 +0000</lastBuildDate><atom:link href="https://minoko.life/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Fixing CVE-2025-12183 in Gradle When the Dependency Changed Ownership</title><link>https://minoko.life/posts/gradle-capability-resolution-cve-fix/</link><pubDate>Fri, 09 Jan 2026 10:00:00 +0000</pubDate><guid>https://minoko.life/posts/gradle-capability-resolution-cve-fix/</guid><description>Using Gradle capability resolution to fix a CVE when the vulnerable library was forked to a new Maven coordinate and direct upgrade is not possible.</description></item><item><title>Adding NetworkPolicies for Defense-in-Depth with Linkerd</title><link>https://minoko.life/posts/networkpolicy-defense-in-depth/</link><pubDate>Sat, 03 Jan 2026 23:49:47 +0000</pubDate><guid>https://minoko.life/posts/networkpolicy-defense-in-depth/</guid><description>Implementing Kubernetes NetworkPolicies alongside Linkerd mTLS to restrict pod-to-pod communication in critical namespaces.</description></item><item><title>OPNsense IDS Monitoring with Suricata, Loki, and Grafana</title><link>https://minoko.life/posts/opnsense-ids-monitoring-with-loki/</link><pubDate>Thu, 01 Jan 2026 23:30:00 +0000</pubDate><guid>https://minoko.life/posts/opnsense-ids-monitoring-with-loki/</guid><description>Forward OPNsense Suricata IDS alerts to Loki via syslog and visualize intrusion detection events in Grafana alongside firewall logs.</description></item><item><title>Automatic Certificate Rotation with cert-manager and Linkerd</title><link>https://minoko.life/posts/cert-manager-linkerd-rotation/</link><pubDate>Thu, 01 Jan 2026 12:00:00 +0000</pubDate><guid>https://minoko.life/posts/cert-manager-linkerd-rotation/</guid><description>Automate Linkerd identity issuer certificate rotation using cert-manager, with a CronJob to sync secret formats and Prometheus alerts for expiry warnings.</description></item><item><title>Preventing Your Dual-Homed Linux Box from Bridging Networks</title><link>https://minoko.life/posts/dual-homed-network-isolation-article/</link><pubDate>Tue, 30 Dec 2025 10:00:00 +0000</pubDate><guid>https://minoko.life/posts/dual-homed-network-isolation-article/</guid><description>Prevent a dual-homed Linux workstation from bridging networks using firewalld zones and FORWARD rules, with exceptions for Kubernetes pod networking.</description></item></channel></rss>