The Penwins Crew website

Penwins Crew

Three penguins breaking stuff and (sometimes) fixing it.

Sharing practical experiences and lessons learned from securing cloud environments. Exploring Kubernetes, OpenStack, AWS, Azure, EntraID, and more.

The Art of Not Drowning in Logs: A K8s Security Logging Strategy

The Logging Paradox Remember when I talked about Logging & Auditing as one of the 10 critical domains for K8s security? Well, here’s the thing nobody tells you: having logs is great, but having too many logs is almost as useless as having none. Picture this: you’re paying for a Splunk license šŸ’ø (or your preferred log aggregation tool), and every day you’re shipping 600MB of control plane noise per node. Most of it? INFO-level messages about lease renewals and cache syncs that nobody will ever read. It’s like buying the latest iPhone and using it exclusively as a flashlight šŸ”¦. ...

January 14, 2026 Ā· 8 min Ā· Coque

My Journey to Not Getting Fired: A K8s Security Strategy

The Boogeyman Under the Bed Let’s be honest: Kubernetes security is that thing everyone knows they should care about but nobody wants to touch. It’s like flossing – we all know it’s important, but somehow we keep pushing it to next quarter. I recently had to pitch a comprehensive K8s security strategy to management, and spoiler alert: they actually liked it. Here’s the story of how I went from ā€œKubernetes what?ā€ to ā€œhere’s our end-to-end security frameworkā€ without boring everyone to death (including myself). ...

December 19, 2025 Ā· 7 min Ā· Coque

Non Human Identities First Thoughts

These days I’m called sometimes Identity expert, sometimes ā€œSMEā€ (subject matter expert). But I still consider myself a classic sysadmin. I usually find it funny people who use the ā€œexpertā€ term so liberally, especially wide topics Networking, Infrastructure, Devops or the hot topic these days: AI. After more than 20 years of career I hardly feel myself expert on anything and I still consider that dedicated time, focus time, is a must to become an expert in something in particular. There would be lucky people who have been supported enough at work to develop their expertise in something in particular, but those like me who had to adapt their focus time based on business needs, hardly can focus more than 2/3 years in something in particular. ...

December 10, 2025 Ā· 5 min Ā· Krizio

Welcome to Penwins

Welcome to Penwins! So you’re probably wondering: why penguins? Well, we’re three friends and former Linux sysadmins who’ve been securing (and occasionally breaking) cloud infrastructure for years. After countless late-night debugging sessions, cryptic error messages, and that one time we accidentally locked ourselves out of production (don’t ask), we figured we should write this stuff down. What You’ll Find Here What our bosses want us to talk about: Kubernetes Security: Best practices, network policies, RBAC configurations OpenStack Security: Securing private cloud deployments AWS & Azure: Cloud-native security implementations Identity Management: EntraID, LDAP, and IAM strategies Infrastructure as Code: Terraform, security scanning, and automation But this isn’t your typical ā€œ10 Best Practicesā€ blog. We’re here to share: ...

November 26, 2025 Ā· 1 min Ā· S3t1LL0, Krizio, Coque