<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>UNRESOLVED</title>
    <link>https://unresolved.dev</link>
    <description>Writing about infrastructure, security, and the engineering assumptions underneath the systems we build.</description>
    <language>en</language>
    <atom:link href="https://unresolved.dev/rss.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Multi-Layered Hardening for Kubernetes: Why Each Layer Has to Be Tested on Its Own Terms</title>
      <link>https://unresolved.dev/articles/multi-layered-hardening-for-kubernetes</link>
      <guid>https://unresolved.dev/articles/multi-layered-hardening-for-kubernetes</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>A hardened Kubernetes cluster is not the sum of six checklists completed once. It is six layers that each need to be tested on their own terms, because none of them defends the others.</description>
      <category>Kubernetes Security</category>
    </item>
    <item>
      <title>Observability Isn&apos;t the Same Thing as Logging</title>
      <link>https://unresolved.dev/articles/observability-isnt-the-same-thing-as-logging</link>
      <guid>https://unresolved.dev/articles/observability-isnt-the-same-thing-as-logging</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>Logging tells you what a system said about itself. Observability is being able to ask a question you didn&apos;t anticipate and still get an answer.</description>
      <category>Observability</category>
    </item>
    <item>
      <title>The Security Control That Worked Too Well</title>
      <link>https://unresolved.dev/articles/the-security-control-that-worked-too-well</link>
      <guid>https://unresolved.dev/articles/the-security-control-that-worked-too-well</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>Effectiveness and accountability are not the same property. A control can have both, or either, or neither, and the failure mode of &apos;either&apos; is easy to miss.</description>
      <category>Kubernetes Security</category>
    </item>
    <item>
      <title>Cloud Firewall Logs Everything, Except What It Drops</title>
      <link>https://unresolved.dev/articles/cloud-firewall-logs-everything-except-what-it-drops</link>
      <guid>https://unresolved.dev/articles/cloud-firewall-logs-everything-except-what-it-drops</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
      <description>Closing out ten months of testing Alibaba Cloud with the same question the series opened on: a control that stops something is not automatically a control that tells you about it.</description>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>When Prevention Isn&apos;t Detection</title>
      <link>https://unresolved.dev/articles/when-prevention-isnt-detection</link>
      <guid>https://unresolved.dev/articles/when-prevention-isnt-detection</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <description>Most security stacks conflate &apos;we stopped it&apos; with &apos;we understood it.&apos; The gap between those two claims is where the expensive incidents live.</description>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Elastic GPU Service Is Elastic Until You Actually Need It to Be</title>
      <link>https://unresolved.dev/articles/elastic-gpu-service-and-the-myth-of-elastic</link>
      <guid>https://unresolved.dev/articles/elastic-gpu-service-and-the-myth-of-elastic</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Elasticity is a claim about behavior under contention, not behavior under normal conditions. Most of us only ever test the second one.</description>
      <category>AI Infrastructure</category>
    </item>
    <item>
      <title>The Castle Was Never the Problem</title>
      <link>https://unresolved.dev/articles/the-castle-was-never-the-problem</link>
      <guid>https://unresolved.dev/articles/the-castle-was-never-the-problem</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>The castle-and-moat model isn&apos;t wrong because perimeters are useless. It&apos;s wrong because it teaches you to stop asking questions the moment something is denied entry.</description>
      <category>Security</category>
    </item>
    <item>
      <title>I Gave an AI Agent Real Alibaba Cloud Credentials. Here&apos;s What It Did.</title>
      <link>https://unresolved.dev/articles/i-gave-an-ai-agent-real-cloud-credentials</link>
      <guid>https://unresolved.dev/articles/i-gave-an-ai-agent-real-cloud-credentials</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <description>Agentic AI tools are increasingly given direct cloud access to get things done. The interesting risk isn&apos;t that they&apos;ll refuse the task. It&apos;s what they&apos;ll do in service of completing it.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>I Thought Security Meant Blocking the Attack</title>
      <link>https://unresolved.dev/articles/i-thought-security-meant-blocking-the-attack</link>
      <guid>https://unresolved.dev/articles/i-thought-security-meant-blocking-the-attack</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <description>The first thing I had to unlearn about infrastructure security wasn&apos;t a technique. It was what &apos;working&apos; meant.</description>
      <category>Security</category>
    </item>
    <item>
      <title>Anti-DDoS Basic Is a Default, Not a Defense</title>
      <link>https://unresolved.dev/articles/anti-ddos-basic-is-a-default-not-a-defense</link>
      <guid>https://unresolved.dev/articles/anti-ddos-basic-is-a-default-not-a-defense</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <description>Free, built-in DDoS protection sounds like a solved problem until you find the specific number where it stops being free protection and starts being a decision you need to make.</description>
      <category>Infrastructure</category>
    </item>
    <item>
      <title>An OSS Bucket Set to &apos;Private&apos; Isn&apos;t Always Private</title>
      <link>https://unresolved.dev/articles/an-oss-bucket-set-to-private</link>
      <guid>https://unresolved.dev/articles/an-oss-bucket-set-to-private</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <description>Public bucket exposure is one of the oldest cloud misconfiguration classes there is. Testing it directly on OSS showed exactly how a bucket set to private can still leak individual objects.</description>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>ACK Removes the Cluster You Manage. Not the One You&apos;re Responsible For.</title>
      <link>https://unresolved.dev/articles/an-ack-cluster-is-not-the-cluster-you-think-it-is</link>
      <guid>https://unresolved.dev/articles/an-ack-cluster-is-not-the-cluster-you-think-it-is</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description>Moving to Alibaba Cloud&apos;s managed Kubernetes service removed a real category of operational burden. It removed none of the security decisions that actually determine whether a cluster is safe.</description>
      <category>Infrastructure</category>
    </item>
    <item>
      <title>The Model You Deployed on PAI Is Not the Model You Trained</title>
      <link>https://unresolved.dev/articles/the-model-you-deployed-on-pai</link>
      <guid>https://unresolved.dev/articles/the-model-you-deployed-on-pai</guid>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <description>It&apos;s comforting to think of deployment as a copy operation. Testing that assumption on Alibaba Cloud&apos;s PAI platform turned up a measurable gap between training-time and serving-time behavior.</description>
      <category>AI Infrastructure</category>
    </item>
    <item>
      <title>A Security Group Is Not a Firewall, Even Though Alibaba Cloud Lets You Pretend It Is</title>
      <link>https://unresolved.dev/articles/a-security-group-is-not-a-firewall</link>
      <guid>https://unresolved.dev/articles/a-security-group-is-not-a-firewall</guid>
      <pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate>
      <description>It&apos;s tempting to treat an ECS security group as &apos;the firewall&apos; for a workload. That framing quietly drops the parts of the traffic path a security group was never designed to see.</description>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>What ActionTrail Actually Records When Something Goes Wrong</title>
      <link>https://unresolved.dev/articles/what-actiontrail-actually-records</link>
      <guid>https://unresolved.dev/articles/what-actiontrail-actually-records</guid>
      <pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate>
      <description>Turning on ActionTrail feels like turning on visibility. It&apos;s closer to turning on one particular kind of visibility, with real gaps that only show up when you go looking for them.</description>
      <category>Observability</category>
    </item>
    <item>
      <title>RAM Policies Look Like RBAC. They Don&apos;t Behave Like It.</title>
      <link>https://unresolved.dev/articles/ram-policies-look-like-rbac</link>
      <guid>https://unresolved.dev/articles/ram-policies-look-like-rbac</guid>
      <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
      <description>RAM and RBAC both use roles and policies. That surface similarity hides a structural difference that changes how a permission mistake actually plays out.</description>
      <category>Cloud Security</category>
    </item>
  </channel>
</rss>