What this is, and who it is for
Security here is enforced by the platform rather than by review, on a zero-trust basis where no workload is trusted by default: Kyverno and OPA Gatekeeper block non-compliant workloads at admission, Trivy scanning and SBOM generation run in the pipeline, container images are signed with Cosign to protect the supply chain, secrets are encrypted with SOPS and Age so they can live safely in Git, and CrowdSec provides collaborative intrusion detection across every ingress point. It is for teams that need to answer what is running, who shipped it, and whether it is permitted.
Start a conversationHarden cloud systems with collaborative CrowdSec intrusion detection, automated Kyverno admission controllers, and encrypted secrets via SOPS & Age.
Based in Casablanca (GMT+1): overlapping working hours with European teams and a morning overlap with North America.
Cybersecurity & DevSecOps
Capabilities
CrowdSec collaborative intrusion defense
Kyverno policy admission controllers
SOPS + Age GitOps secret encryption
Linux kernel hardening & WireGuard mesh
Delivered architecture
Multi-Node CrowdSec Hub-and-Spoke Cluster
Credential
IBM / Security
Application Security for Developers and DevOps Professionals
Questions, answered
Technical questions, answered directly.
What is CrowdSec and how is it deployed here?
CrowdSec is a collaborative intrusion detection engine. In this architecture a centralised Local API hub runs in an isolated Proxmox LXC container and orchestrates multi-node edge bouncers over mTLS, so a signal seen at one ingress is enforced at every ingress.
How fast is threat remediation?
Real-time across all ingress points in under 100ms, with zero false-positive blockages.
What does policy as code mean in practice?
Admission policies written as Kubernetes manifests — Kyverno rules or OPA Gatekeeper constraints that block root containers and unsigned images — so a workload that violates policy cannot start, and the rule itself is versioned and reviewed like code.
How are secrets and the supply chain handled?
Secrets are encrypted with SOPS and Age so encrypted values can be committed to Git and decrypted only in-cluster. SBOMs are generated in the pipeline and container images are signed with Cosign so deployment can verify provenance.
Is there a credential behind this practice?
Yes. Application Security for Developers and DevOps Professionals, issued by IBM, credential ID WFUQWCQQRJGL, verifiable through the public Coursera link on this page.
Cybersecurity & DevSecOps