Discovery and remediation are hard, but absorbing security updates is the final hurdle. What I’m seeing in 30 Red Hat Enterprise Linux customer meetings.
The Last Hurdle: Absorbing The Patches
Discovery and remediation are hard, but absorbing security updates is the final hurdle. What I’m seeing in 30 Red Hat Enterprise Linux customer meetings.
If you’ve been following Trentina, you know I’ve been beating the drum on prompt injection defense for a while now. I built a three-layer quarantine system, wrote about prompt injection in terms of epidemiology, and generally been that guy at the party who won’t shut up about how your AI agent is going to get
Sync Red Hat Hardened Images RPM packages to Red Hat Satellite with full GPG validation — ideal for building containers in disconnected environments.
Continue Reading “Synchronizing Red Hat Hardened Images Packages to Red Hat Satellite”
I’ve been having a lot of conversations lately with people who are evaluating hardened container image vendors, and one particular feature keeps coming up that, frankly, surprises me. Customers are asking vendors like Docker and Chainguard to pre-inject customizations into container images on their behalf, things like CA certificates, security configurations, and other environment-specific tweaks.
Continue Reading “Your Container Image Customizations Belong to You, Not Your Vendor”
How I got hacked twice in one month by two different attackers — and fixed it with 3-5 AI prompts while on work calls. My personal Mythos moment.
A prompt injection doesn’t have to act to be dangerous. It can hide, copy itself, and spread agent to agent. Why AI security is an epidemiology problem, and how to respond.
MCP-Airlock is becoming Trentina — named after the 1377 quarantine system from Ragusa that inspired its architecture. Same three-layer defense, same gateway, better name.
Continue Reading “MCP-Airlock Is Now Trentina: The 1377 Quarantine That Inspired Our Rename”
Six years ago, I wrote about the good, better, best approach to Linux quality when evaluating container images. The same framework applies to desktop Linux distributions – maybe even more so, because desktops have a GUI that’s notoriously hard to test automatically. Here’s what I wrote: Good: Use a bug tracker and collect problems as
Continue Reading “Project Bluefin is Helping Prove That Dark Factories Work for Operating Systems”
I’ve loved Tron since I was a kid. When I was about seven or eight years old (early 1980s!!!), my Mom took me to see Walt Disney’s Magic Kingdom on Ice at the Richfield Coliseum, which was this massive arena between Cleveland and Akron (sadly, torn down in 1999). The show had a Tron segment,
Continue Reading “Put The Tron Ares Album On and Build Something at Midnight”
I’ve been running Claude Code on my RHEL 10 workstation for a few months now, and I have to admit, with some embarrassment, I often run it with the ominous –dangerously-skip-permissions option. It reads and writes files, executes shell commands, installs packages, modifies system configs, all without asking permission first. I’ve been letting an AI
Continue Reading “image mode Gave Me the Confidence to Go Fully Agentic”