Linux

Gitea container registry with podman

December 16, 2025

Recently I’ve done a lot of reorganization with TrueNAS, migrating Plex and Gitea to TrueNAS-based virtual machines and just generally spending a bunch of time poking around with my home lab and improving things. A few weeks ago I started actually using containers in …

Weekend Shenanigans

December 2, 2025

I’ve written two articles previously, first was moving Gitea from FreeBSD to Linux and the second was a followup on accessing TrueNAS shares from a nested VM. The first was a few weeks ago, the second a few days. I took a long weekend and also took advantage of some Black …

Accessing TrueNAS shares from a nested VM

November 29, 2025

In my previous article on moving Gitea from FreeBSD to Linux I ended the post noting that I needed to be able to share the host NAS filesystem with a virtual machine it was hosting. In my case, this is so that Gitea backups could be stored on the NAS external to the virtual …

Moving Gitea from FreeBSD to Linux

November 18, 2025

I’ve been using TrueNAS for a number of years, from when it was FreeBSD-based to now that it’s Linux-based. Right now I use them both: TrueNAS Core (FreeBD) and TrueNAS Scale (Linux). The TrueNAS Scale box has been mostly for fiddling with containers, while the …

Compiler: The New Security Landscape

September 24, 2025

Tomorrow, the first episode of the new Compiler podcast season is coming out, and this season is all about product security topics! The season’s title is “The New Security Landscape” and we dive into quite a few topics pertinent to security practitioners (or …

Red Hat Summit 2025

June 3, 2025

A few weeks ago I was back in Boston for Red Hat Summit 2025. You can watch the keynote for day 1 and the keynote for day 2 on YouTube. This was probably one of the best Summit events that I’ve been to and the energy was absolutely electric. There were a ton of product …

Security Unscripted

February 15, 2025

Been working on this for a bit and now it’s here! I’m really pleased to announce that I’ve started a new podcast! It’s called Security Unscripted and the goal is to be short 10-12 minute episodes weekly about a variety of security topics. Bite-sized …

Holiday Hacking

December 30, 2024

Normally I do some coding over the holidays as it used to be the one time of the year I could have some dedicated time to work on personal projects, or just fiddle with random non-work things. Normally that would have been updates to the blog platform I had written to run this …

Using LetsEncrypt with Pi-hole

November 14, 2024

I’ve been running Pi-hole in a container on my TrueNAS Scale box for a while and had unfortunately experienced a number of upgrades that required deploying the container from scratch. This was due to incompatibilities in the Helm chart settings, which broke in-place …

ICCC 2024

November 12, 2024

Last week I had the opportunity to attend and speak at the International Common Criteria Conference (ICCC) in Doha, Qatar. This was a first in a number of areas: first time keynoting for longer than five minutes, first time attending a compliance-focused conference, first time …

SOSS Fusion 2024

October 31, 2024

Last week I had the opportunity to attend and speak at the OpenSSF SOSS Fusion 2024 event. This is the first full multi-day OpenSSF security event and it was a privilege to be able to attend and speak. I gave the same talk that I did at BSides back in September as I believe it …

BSides Edmonton 2024

September 28, 2024

Earlier this week I had the opportunity to attend and speak at the BSides Edmonton 2024 event. This is a local event that’s been running for a few years and oddly I’ve only been able to make it every second year, usually due to conflicts in my schedule. This year I …

Python module to read CSAF VEX files

August 9, 2024

Red Hat has been publishing VEX documents for some time now. VEX stands for Vulnerability Exploitability eXchange, and the documents are machine-readable JSON files that describe vulnerabilities and status for them. For example, one CVE could impact a number of different products …

Upstream 2024

June 5, 2024

Today I had the privilege of being involved in Tidelift’s Upstream 2024 virtual conference. The conference as a whole was fantastic, I watched every talk and there is some really great content there about open source security and how it’s being looked at and …

Red Hat Summit 2024

May 26, 2024

Last month I was in Denver for Red Hat Summit 2024. The keynotes are available on YouTube. This was perhaps the most energetic Summit that I’ve been to, even pre-COVID. There was a lot of activity and, of course, the primary topic was AI. We unveiled InstructLab and our …

OpenShift Commons Chicago 2023

November 27, 2023

I had the opportunity to speak at the recent OpenShift Commons in Chicago that was an event that coincided with Kubecon in Chicago a few weeks back. I spoke about the Evolution of risk management in software which is a more reent talk that I’ve given a few times; the first …

Red Hat Summit 2023

June 4, 2023

I had the opportunity to attend Red Hat Summit 2023 which you can watch on demand in Boston, MA. Unlike the OSS Summit, this was a 14h door-to-door trip, there and back, due to delays (typically 12h door-to-door). However the annoyance in travel was more than made up for by the …

OSS Summit 2023

May 13, 2023

I had the opportunity to attend the OSS Summit 2023 in Vancouver, BC. Probably the easiest conference I’ve ever attended, travel-wise, as it was about three hours door-to-door. Contrast that to Red Hat Summit in Boston, which is about 12 hours door-to-door. The conference …

SBOMs, CVEs, CVSS and more

April 7, 2023

There have been a few neat opportunities to write and discuss a variety of topics over the last few weeks that have been published. The most recent is a blog post I co-authored with Tracy Ragan at DeployHub entitled SBOMs, So Far, So Good, So What? where we take a look at the …

... And a pelican in a pear tree

December 22, 2022

For a number of years, since getting more and more into management, I’ve had less time to do any real programming. So a highlight of the year, for the first few years at least, was to take time during the Christmas break to do some work, mostly on this blog and for a few …

Interview: When is it secure enough?

December 5, 2022

I had the awesome opportunity to interview professor Daniel Gruss and one of his PhD students, Martin Schwarzl, a while back and the article recently was published in the Red Hat Research Quarterly magazine. For those who don’t know, Daniel was one of the folks behind the …

ZeroBytesGiven podcast appearance

November 22, 2022

I did an ad-hoc interview with Eddie Knight over at Sonatype during the Linux Foundation Member Summit, for his podcast ZeroBytesGiven. It was a lot of fun and got to talk about some supply chain concerns and even dig into little-known history of how we did security at Mandriva …