<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>安全 on BvBeJ的小站</title><link>https://www.bvbej.com/tags/%E5%AE%89%E5%85%A8/</link><description>Recent content in 安全 on BvBeJ的小站</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Wed, 27 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.bvbej.com/tags/%E5%AE%89%E5%85%A8/feed.xml" rel="self" type="application/rss+xml"/><item><title>Docker Rootless 模式：落地路径与限制</title><link>https://www.bvbej.com/posts/docker-rootless-mode-practice/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-rootless-mode-practice/</guid><description>最小权限运行可以提升安全性，但要评估网络和存储差异</description></item><item><title>Kubernetes Secret 轮换：不中断更新实践</title><link>https://www.bvbej.com/posts/kubernetes-secret-rotation/</link><pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/kubernetes-secret-rotation/</guid><description>密钥轮换要设计双版本兼容窗口，避免瞬时全量失败</description></item><item><title>容器运行时隔离权衡：runc、gVisor、Kata 的场景选择</title><link>https://www.bvbej.com/posts/container-runtime-isolation-tradeoff/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/container-runtime-isolation-tradeoff/</guid><description>隔离强度越高越安全吗？答案取决于威胁模型和性能预算。</description></item><item><title>Kubernetes NetworkPolicy：从默认放通到最小权限</title><link>https://www.bvbej.com/posts/kubernetes-networkpolicy-baseline/</link><pubDate>Wed, 13 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/kubernetes-networkpolicy-baseline/</guid><description>网络隔离要先划清信任边界，再逐步收敛规则</description></item><item><title>Docker 运行时安全：Seccomp 与 AppArmor 基线</title><link>https://www.bvbej.com/posts/docker-runtime-security-profiles/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-runtime-security-profiles/</guid><description>镜像安全只是第一层，运行时策略才是最后防线</description></item><item><title>Rust unsafe 审计清单：把风险控制在可解释范围</title><link>https://www.bvbej.com/posts/rust-unsafe-audit-checklist/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/rust-unsafe-audit-checklist/</guid><description>unsafe 不可避免，但必须可审计、可证明、可回归</description></item><item><title>Docker 供应链安全：SBOM 与镜像签名落地</title><link>https://www.bvbej.com/posts/docker-sbom-signing-pipeline/</link><pubDate>Sat, 02 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-sbom-signing-pipeline/</guid><description>镜像安全要从构建阶段开始，把可追溯和可验证做进流水线</description></item><item><title>Docker 镜像安全与瘦身：从能跑到适合上线</title><link>https://www.bvbej.com/posts/docker-image-security-hardening/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-image-security-hardening/</guid><description>镜像优化不只是减小体积，真正上线时还要关心攻击面、权限模型和供应链风险</description></item></channel></rss>