<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on SETE</title>
    <link>https://sete.at/en/categories/security/</link>
    <description>Recent content in Security on SETE</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 22 Oct 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://sete.at/en/categories/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>0 Vulnerabilities - Think twice about it</title>
      <link>https://sete.at/en/posts/0-vulnerabilities-think-twice/</link>
      <pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://sete.at/en/posts/0-vulnerabilities-think-twice/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://sete.at/linkedin/0-vulnerabilities/1761148970190.png&#34; alt=&#34;0 vulnerabilities in Alpine Linux scan result&#34;&gt;&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Originally published on &lt;a href=&#34;https://www.linkedin.com/pulse/0-vulnerabilities-think-twice-gerhard-sulzberger-9my8f&#34;  class=&#34;external-link&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;LinkedIn&lt;/a&gt; on 2025-10-22.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;Vulnerability scans can be tricky and there are different strategies. It starts already at the datasets provided by the different OS and how they are implemented from the scan tools. For example Alpine. A lot Engineers think it is secure because 0 vulnerabilities shown at scans with tools like trivy.&lt;/p&gt;&#xA;&lt;p&gt;But there is &lt;a href=&#34;http://security.alpinelinux.org&#34;  class=&#34;external-link&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;security.alpinelinux.org&lt;/a&gt; and information about potential CVEs within Alpine packages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>vault snap to S3 in kubernetes</title>
      <link>https://sete.at/en/posts/vault-snap-to-s3-in-kubernetes/</link>
      <pubDate>Wed, 24 May 2023 00:00:00 +0000</pubDate>
      <guid>https://sete.at/en/posts/vault-snap-to-s3-in-kubernetes/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://sete.at/linkedin/vault-snap-to-s3-in-kubernetes/vault-snap-to-s3-in-kubernetes.png&#34; alt=&#34;vault snap to S3 in kubernetes&#34;&gt;&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;em&gt;Originally published on &lt;a href=&#34;https://www.linkedin.com/pulse/vault-snap-s3-kubernetes-gerhard-sulzberger&#34;  class=&#34;external-link&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;LinkedIn&lt;/a&gt; on 2023-05-24.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;h2 id=&#34;hashicorp-vault&#34;&gt;&#xA;  Hashicorp Vault&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#hashicorp-vault&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;In vault-enterprise there would be an integrated solution to upload backups to S3 compatible storages. In the Open Source version of Vault this feature is missing, so I had to create some solution for this.&lt;/p&gt;&#xA;&lt;p&gt;Most times I use the integrated raft storage inside the vault cluster in kubernetes. Data of this StatefulSet is stored in PersistentVolumeClaims. (Where I also patched the default persistentVolumeReclaimPolicy to Retain the deletion of the StatefulSet, but that&amp;rsquo;s a different story)&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
