~/cheatsheets
Cheatsheets
135 cheatsheets. The 80/20 of tools I use daily — fact-checked, no fluff.
#all
#ai
#cicd
#cloud
#containers
#databases
#infrastructure
#languages
#messaging
#monitoring
#networking
#python
#security
#shell
#web
security/
- Cert-Manager A Kubernetes add-on for automating the management and issuance of TLS certificates from various sources.
- Clair Running Clair v4 as a service: indexer, matcher, and notifier, the config file, clairctl, updaters, and the Quay integration.
- Container Security Runtime hardening for containerised workloads: Pod Security Admission, security contexts, Falco runtime detection, network isolation, and secret encryption at rest.
- Grype and Syft SBOM generation with Syft and vulnerability matching with Grype: catalogers, source schemes, match quality, and CI gating.
- Policy as Code (OPA/Conftest) Declarative policy enforcement using Open Policy Agent (OPA) and Conftest for infrastructure, Kubernetes, and CI/CD validation.
- Security Best Practices A comprehensive guide to implementing robust security patterns and practices across software development and infrastructure operations.
- SOPS A secrets management tool that encrypts files while keeping keys and structure visible for version control and GitOps workflows.
- TLS, OpenSSL & Certificates The everyday OpenSSL toolkit, modernised: keys and CSRs with SANs, self-signed and CA-signed certs, inspection and verification, s_client debugging, format conversion, expiry checks, and ACME troubleshooting.
- Trivy Scanning images, filesystems, repositories, Kubernetes, and IaC with Trivy: scanners, severity gating, SBOM, VEX, and CI integration.
- HashiCorp Vault A secrets management tool for securely storing, accessing, and managing sensitive data like tokens, passwords, certificates, and encryption keys.