<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Things Worth Sharing</title><description>Những ghi chép, góc nhìn và điều thú vị đáng chia sẻ.</description><link>https://cloudsecop.net/</link><item><title>Wildebeest: self-host Mastodon trên Cloudflare stack — federated trên Workers</title><link>https://cloudsecop.net/blog/wildebeest-mastodon-on-cloudflare/</link><guid isPermaLink="true">https://cloudsecop.net/blog/wildebeest-mastodon-on-cloudflare/</guid><description>Wildebeest = ActivityPub server tương thích Mastodon, chạy entirely trên Workers + D1 + R2 + KV. 1 Worker thay 10 service Mastodon truyền thống. $0-5/tháng vs $50-200 VPS.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>D1</category><category>R2</category><category>ActivityPub</category><category>Self-host</category><author>KhaVan</author></item><item><title>VibeSDK: build AI coding platform riêng trên Cloudflare stack</title><link>https://cloudsecop.net/blog/vibesdk-cloudflare-ai-coding-platform/</link><guid isPermaLink="true">https://cloudsecop.net/blog/vibesdk-cloudflare-ai-coding-platform/</guid><description>VibeSDK = open-source vibe coding platform (v0/Bolt/Lovable clone). Workers + Workers AI + AI Gateway + Containers + R2 + D1. AI Gateway cache cắt 60% LLM cost. Self-host wins về privacy.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AI Agents</category><category>Developer Tools</category><category>Self-host</category><author>KhaVan</author></item><item><title>Remote SWE agents: autonomous coding với AWS Strands Agents</title><link>https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</guid><description>AWS Strands Agents + Bedrock AgentCore cho autonomous SWE agent. GitHub issue → PR. Threat model, IAM blast radius, audit. So sánh Copilot Workspace và Devin.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>AWS</category><category>Bedrock</category><category>AI Agents</category><category>DevOps</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>Migration AWS/Vercel sang Cloudflare: playbook thực tế</title><link>https://cloudsecop.net/blog/migration-aws-to-cloudflare/</link><guid isPermaLink="true">https://cloudsecop.net/blog/migration-aws-to-cloudflare/</guid><description>Playbook migrate production từ AWS (Lambda, DynamoDB, RDS, S3, SQS, ElastiCache) sang Cloudflare: mapping primitive, 3 chiến lược, data migration, cutover, rollback, 10 pitfall.</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Migration</category><category>AWS</category><category>Serverless</category><author>KhaVan</author></item><item><title>Cost model Cloudflare Developer Platform: tier, so sánh AWS</title><link>https://cloudsecop.net/blog/cost-model-production/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cost-model-production/</guid><description>Pricing từng primitive Cloudflare (Workers, D1, KV, R2, Queues, DOs, Vectorize, Workers AI), breakpoint, so sánh AWS, 3 scenario: blog, SaaS 10k user, app 100M req/tháng.</description><pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Cost</category><category>AWS</category><category>Pricing</category><author>KhaVan</author></item><item><title>Security cho Worker: secrets, CSP, Bot Management, Turnstile</title><link>https://cloudsecop.net/blog/secrets-csp-bot-management/</link><guid isPermaLink="true">https://cloudsecop.net/blog/secrets-csp-bot-management/</guid><description>Defense-in-depth cho Cloudflare Worker: WAF + Bot Management, Turnstile, Access JWT, secret management, CSP/HSTS, 4 pattern auth, validation Zod, và anti-pattern cần tránh.</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Security</category><category>CSP</category><category>Bot Management</category><author>KhaVan</author></item><item><title>Observability cho Worker: Logs, Tail Workers, Analytics</title><link>https://cloudsecop.net/blog/logs-analytics-tail-workers/</link><guid isPermaLink="true">https://cloudsecop.net/blog/logs-analytics-tail-workers/</guid><description>4 tầng observability Cloudflare: Workers Logs (retention 3 ngày), Tail Workers (realtime), Logpush (batch tới R2/SIEM), Analytics Engine. Structured logging, alert, debug prod.</description><pubDate>Tue, 09 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Observability</category><category>Logs</category><category>Analytics Engine</category><author>KhaVan</author></item><item><title>Agentic Inbox: self-host email assistant trên Cloudflare stack</title><link>https://cloudsecop.net/blog/agentic-inbox-self-host-email/</link><guid isPermaLink="true">https://cloudsecop.net/blog/agentic-inbox-self-host-email/</guid><description>Tự host email AI assistant bằng Agentic Inbox: IMAP polling Worker, R2 attachment, Workers AI classify, D1 thread state, RBAC chống prompt injection. $5/tháng vs Superhuman $30.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AI Agents</category><category>Email</category><category>Self-host</category><author>KhaVan</author></item><item><title>Stream và Images: media pipeline ở edge, khi nào dùng product nào</title><link>https://cloudsecop.net/blog/stream-images-media/</link><guid isPermaLink="true">https://cloudsecop.net/blog/stream-images-media/</guid><description>3 cách xử lý media của Cloudflare: Stream cho video (HLS/DASH), Images cho upload-transform-deliver, Image Resizing / cf.image. Pipeline, giá, responsive, OG động.</description><pubDate>Mon, 01 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Stream</category><category>Images</category><category>Media</category><author>KhaVan</author></item><item><title>MCP server: Cloudflare Workers vs AWS Bedrock AgentCore — chọn cái nào</title><link>https://cloudsecop.net/blog/mcp-server-cloudflare-vs-bedrock-agentcore/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mcp-server-cloudflare-vs-bedrock-agentcore/</guid><description>So sánh MCP server Cloudflare (Workers + R2/D1/KV, OAuth) với AWS Bedrock AgentCore (IAM, dài-hạn). Latency, cost, auth, kịch bản dùng — và tôi chọn cái nào.</description><pubDate>Sun, 30 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AWS</category><category>MCP</category><category>AI Agents</category><author>KhaVan</author></item><item><title>Durable Objects cho realtime: chat, collab, game state</title><link>https://cloudsecop.net/blog/durable-objects-realtime/</link><guid isPermaLink="true">https://cloudsecop.net/blog/durable-objects-realtime/</guid><description>Durable Object là single-writer coordination của Cloudflare: 1 roomId = 1 instance, WebSocket hibernation, storage persistent. 6 pattern, API cốt lõi, và khi nào DO là quá mức.</description><pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Durable Objects</category><category>WebSocket</category><category>Realtime</category><author>KhaVan</author></item><item><title>Vectorize + RAG: embeddings, top-K, hybrid search edge</title><link>https://cloudsecop.net/blog/vectorize-rag-pattern/</link><guid isPermaLink="true">https://cloudsecop.net/blog/vectorize-rag-pattern/</guid><description>Vectorize là vector DB native của Cloudflare, kết hợp Workers AI bge-m3 cho RAG trọn edge. Pipeline ingest + query, chunking, lọc metadata, hybrid search D1, reranking.</description><pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Vectorize</category><category>RAG</category><category>AI</category><author>KhaVan</author></item><item><title>Workers AI + AI Gateway: catalog, pricing, vs Bedrock/OpenAI</title><link>https://cloudsecop.net/blog/workers-ai-model-catalog/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workers-ai-model-catalog/</guid><description>Workers AI chạy inference trên edge GPU, AI Gateway proxy OpenAI/Anthropic/Bedrock/Google với cache + rate limit. Catalog, giá, khi nào chọn cái nào, retry/fallback production.</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers AI</category><category>AI Gateway</category><category>LLM</category><author>KhaVan</author></item><item><title>CI/CD với Wrangler + GitHub Actions: pipeline, smoke test</title><link>https://cloudsecop.net/blog/ci-cd-wrangler-github-actions/</link><guid isPermaLink="true">https://cloudsecop.net/blog/ci-cd-wrangler-github-actions/</guid><description>Pipeline 4 bước: test → build → deploy → smoke. Scoped API token, smoke test 19 assertion, concurrent lock, preview env, rollback 10 giây. Full workflow file từ blog này.</description><pubDate>Sat, 01 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>CI/CD</category><category>GitHub Actions</category><category>Wrangler</category><author>KhaVan</author></item><item><title>Astro, Remix, SvelteKit trên Workers: adapter và trade-off</title><link>https://cloudsecop.net/blog/astro-remix-sveltekit-workers/</link><guid isPermaLink="true">https://cloudsecop.net/blog/astro-remix-sveltekit-workers/</guid><description>3 framework full-stack trên Workers khác nhau về render, JS client, adapter và bindings. Thiết lập thực tế từng cái, SSG vs SSR vs hybrid, và vì sao blog này chọn Astro.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Astro</category><category>Remix</category><category>SvelteKit</category><author>KhaVan</author></item><item><title>ORM cho D1: Drizzle, Prisma, hay raw SQL</title><link>https://cloudsecop.net/blog/orm-d1-drizzle-prisma/</link><guid isPermaLink="true">https://cloudsecop.net/blog/orm-d1-drizzle-prisma/</guid><description>3 lựa chọn: SQL thô (0KB), Drizzle (10KB, TS-first), Prisma (500KB WASM). Quy trình, pattern query phức tạp, migration, type safety, và khi nào ORM hại nhiều hơn lợi.</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>D1</category><category>ORM</category><category>Drizzle</category><category>Prisma</category><author>KhaVan</author></item><item><title>cloudflare/agents trên Workers + Durable Objects — production patterns</title><link>https://cloudsecop.net/blog/cloudflare-agents-production-patterns/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-agents-production-patterns/</guid><description>Cloudflare Agents framework dùng Durable Objects cho long-running state. Hibernation, tool calling, multi-agent WebSocket, schedule(). Cost ~$0.04/agent/tháng.</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>Durable Objects</category><category>AI Agents</category><category>Cloudflare Developer</category><author>KhaVan</author></item><item><title>Router cho Workers: vanilla, Itty, hay Hono</title><link>https://cloudsecop.net/blog/router-choice-hono-itty/</link><guid isPermaLink="true">https://cloudsecop.net/blog/router-choice-hono-itty/</guid><description>3 lựa chọn: vanilla fetch (0 bundle), Itty (3KB), Hono (13KB). Cú pháp, chuỗi middleware, validate Zod, khi nào chọn cái nào, và vì sao blog này dùng vanilla dù có 40 route.</description><pubDate>Wed, 08 Oct 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers</category><category>Routing</category><author>KhaVan</author></item><item><title>Queues và Durable Objects: async messaging và single-writer state</title><link>https://cloudsecop.net/blog/queues-durable-objects/</link><guid isPermaLink="true">https://cloudsecop.net/blog/queues-durable-objects/</guid><description>2 primitive khó nhất khi Worker cần state. Queues cho fire-and-forget job với retry và DLQ. Durable Objects cho single-writer coordination. Khi nào dùng cái nào, pattern và gotcha.</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Queues</category><category>Durable Objects</category><category>Storage</category><author>KhaVan</author></item><item><title>R2 object storage: S3-compat, egress free, và 4 access pattern</title><link>https://cloudsecop.net/blog/r2-object-storage/</link><guid isPermaLink="true">https://cloudsecop.net/blog/r2-object-storage/</guid><description>R2 là object storage S3-compatible của Cloudflare, không phí egress. So sánh R2 vs S3, 4 pattern phục vụ object, migration từ S3, gotcha về consistency, metadata, lifecycle.</description><pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>R2</category><category>Storage</category><author>KhaVan</author></item><item><title>D1 trong production: primary-replica, batch, và 7 gotcha</title><link>https://cloudsecop.net/blog/d1-production-patterns/</link><guid isPermaLink="true">https://cloudsecop.net/blog/d1-production-patterns/</guid><description>D1 là SQLite ở edge với primary region và read replica: kiến trúc, 5 query method, Sessions API cho read replica, prepared statement cache, migration, và 7 gotcha production.</description><pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>D1</category><category>Storage</category><category>SQL</category><author>KhaVan</author></item><item><title>AWS Well-Architected custom lens: build riêng cho cloud security ở scale</title><link>https://cloudsecop.net/blog/aws-well-architected-custom-lens/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-well-architected-custom-lens/</guid><description>Custom lens AWS Well-Architected: thêm pillar riêng cho org, JSON schema, deploy CloudFormation, attach workload. Use case Vietnam compliance Circular 09, Decree 53.</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Governance</category><category>Well-Architected</category><category>Architecture</category><author>KhaVan</author></item><item><title>KV deep-dive: cache toàn cầu, eventual consistency, vs D1</title><link>https://cloudsecop.net/blog/kv-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/kv-deep-dive/</guid><description>Cloudflare KV là eventually-consistent KV store với cache tại từng PoP. Consistency model thực tế, giới hạn, 5 pattern đúng, 3 anti-pattern phổ biến, và gotcha thực tế.</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>KV</category><category>Storage</category><author>KhaVan</author></item><item><title>Wrangler và Miniflare dev loop: từ init tới deploy trong 30 phút</title><link>https://cloudsecop.net/blog/wrangler-miniflare-dev-loop/</link><guid isPermaLink="true">https://cloudsecop.net/blog/wrangler-miniflare-dev-loop/</guid><description>Dev loop thực tế của Workers: wrangler init, dev local với Miniflare, vitest, D1 migration, secret, triển khai 300+ PoP trong 30 giây. Vòng đời từ file trống đến production.</description><pubDate>Sun, 31 Aug 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers</category><category>DevOps</category><author>KhaVan</author></item><item><title>Mental model 3 tầng binding: Request, Identity, Storage</title><link>https://cloudsecop.net/blog/mental-model-3-binding/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mental-model-3-binding/</guid><description>Khung tư duy chung cho mọi Worker: Request là cửa vào, Identity là ai đang gọi, Storage là đọc ghi đâu. Áp dụng vào Worker đang chạy blog này và cách chọn storage primitive đúng.</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers</category><category>Architecture</category><author>KhaVan</author></item><item><title>Workers runtime mental model: lifecycle, context, limit</title><link>https://cloudsecop.net/blog/workers-runtime-mental-model/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workers-runtime-mental-model/</guid><description>fetch handler, ExecutionContext, waitUntil, giới hạn subrequest, CPU vs wall time, cold start thực tế. 6 ngộ nhận khi dev từ Node/Lambda sang Workers. Code mẫu từ blog này.</description><pubDate>Sat, 16 Aug 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers</category><category>Runtime</category><author>KhaVan</author></item><item><title>eBPF metrics cho production — Cloudflare&apos;s ebpf_exporter pattern</title><link>https://cloudsecop.net/blog/ebpf-exporter-cloudflare-pattern/</link><guid isPermaLink="true">https://cloudsecop.net/blog/ebpf-exporter-cloudflare-pattern/</guid><description>ebpf_exporter expose kernel metrics qua Prometheus, không cần sidecar. So sánh CloudWatch agent và Datadog kernel module. Pattern Cloudflare dùng cho hàng ngàn host.</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Observability</category><category>Linux</category><category>Prometheus</category><category>Performance</category><author>KhaVan</author></item><item><title>Cloudflare developer platform là gì, và vì sao khác Lambda</title><link>https://cloudsecop.net/blog/cloudflare-developer-platform-la-gi/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-developer-platform-la-gi/</guid><description>Cloudflare không còn chỉ là CDN. Workers, D1, R2, KV, Queues, DOs, Workers AI, Vectorize tạo thành nền tảng edge-native. Mental model đầu tiên, so sánh với Lambda.</description><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Workers</category><category>Edge Computing</category><author>KhaVan</author></item><item><title>AWS Security Services Best Practices: đọc cuốn cẩm nang mới</title><link>https://cloudsecop.net/blog/aws-security-services-best-practices/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-services-best-practices/</guid><description>AWS vừa publish best-practices guide cho 10 dịch vụ bảo mật (GuardDuty, Security Hub, Macie, Inspector, WAF, Network Firewall). Cấu trúc guide và lộ trình triển khai thực tế.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Hub</category><category>Best Practices</category><author>KhaVan</author></item><item><title>AWS Security Maturity Model v2: 4 phase áp dụng thực tế</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-v2/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-v2/</guid><description>AWS Security Maturity Model v2: 74 kiểm soát chia 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized), thứ tự nên làm, bẫy thường gặp, ánh xạ vào Organization.</description><pubDate>Sun, 27 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Bedrock từ Workers qua OIDC federation — case study production</title><link>https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</link><guid isPermaLink="true">https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</guid><description>Worker mint RS256 JWT → STS AssumeRoleWithWebIdentity → Bedrock Claude Opus. Số liệu thực: token 5ms, STS 200ms, Bedrock 2-3s, cached 50ms.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AWS</category><category>Bedrock</category><category>OIDC</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>AWS SMM Assessment Tool: đánh giá posture trong một chiều</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</guid><description>Ghi chú dùng AWS Security Maturity Model Assessment Tool đánh giá posture theo 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized): kiến trúc, quy trình, JSON/Excel.</description><pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Assessment</category><category>Governance</category><author>KhaVan</author></item><item><title>Email Security: chặn phishing, BEC, và bài toán DMARC forwarder</title><link>https://cloudsecop.net/blog/email-security-area1-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/email-security-area1-deep-dive/</guid><description>Email Security deep-dive cho Cloudflare One: MX inline vs API journaling, bẫy DMARC forwarder/subdomain docs không nói, FP homoglyph, user report → retract &lt; 1h tự động.</description><pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Email Security</category><category>Phishing</category><author>KhaVan</author></item><item><title>DLP: pattern, classification và 55% false positive</title><link>https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</guid><description>DLP đào sâu cho Cloudflare One: tinh chỉnh từ 55% FP về 3%, regex vs Luhn vs context vs EDM, profile CCCD Việt Nam, Gateway HTTP inline vs CASB API.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DLP</category><category>Data Classification</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>CASB: posture và misconfig SaaS (GWorkspace, M365, SF)</title><link>https://cloudsecop.net/blog/casb-saas-posture-misconfig/</link><guid isPermaLink="true">https://cloudsecop.net/blog/casb-saas-posture-misconfig/</guid><description>CASB deep-dive cho Cloudflare One từ 3 lần triển khai: 4 trụ cột Gartner, inline vs API, phản ứng 8000 finding tuần đầu, shadow IT discovery, tenant lock, khi nào KHÔNG dùng CASB.</description><pubDate>Mon, 23 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>CASB</category><category>SaaS Security</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Browser Isolation (RBI): render risky web trong sandbox remote</title><link>https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</guid><description>Browser Isolation deep-dive cho Cloudflare One: kiến trúc remote browser (NVR), kích hoạt isolation, kiểm soát dữ liệu (copy/paste/print/download/keyboard), compliance, chi phí.</description><pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Browser Isolation</category><category>RBI</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Device posture và continuous verification mọi request</title><link>https://cloudsecop.net/blog/device-posture-continuous-verification/</link><guid isPermaLink="true">https://cloudsecop.net/blog/device-posture-continuous-verification/</guid><description>Device posture đào sâu cho Zero Trust: WARP check (OS, mã hóa ổ đĩa, firewall), EDR (CrowdStrike, SentinelOne, Defender), continuous verification trong Access policy, truy nguyên.</description><pubDate>Sat, 07 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Device Posture</category><category>EDR</category><author>KhaVan</author></item><item><title>hardeneks: EKS security checks ở CI vs sau-deploy</title><link>https://cloudsecop.net/blog/hardeneks-eks-security/</link><guid isPermaLink="true">https://cloudsecop.net/blog/hardeneks-eks-security/</guid><description>hardeneks là Python CLI chạy 100+ EKS best-practice check. Lý do tôi chạy ở PR thay vì weekly cron, so sánh kube-bench/kube-hunter, finding thực tế.</description><pubDate>Wed, 04 Jun 2025 00:00:00 GMT</pubDate><category>AWS</category><category>EKS</category><category>Kubernetes</category><category>Cloud Security</category><category>Compliance</category><author>KhaVan</author></item><item><title>DEX: Digital Experience Monitoring và proactive SLO</title><link>https://cloudsecop.net/blog/dex-digital-experience-monitoring/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dex-digital-experience-monitoring/</guid><description>DEX đào sâu cho Cloudflare One: khi control plane UP mà người dùng thấy chậm, chẩn đoán từng chặng (DNS/TCP/TLS/TTFB), SLO framework, 5 chế độ hỏng DEX không thấy.</description><pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DEX</category><category>Observability</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Logs pipeline: Logpush, R2, SIEM và cross-layer correlation</title><link>https://cloudsecop.net/blog/logs-pipeline-logpush-siem/</link><guid isPermaLink="true">https://cloudsecop.net/blog/logs-pipeline-logpush-siem/</guid><description>Logs deep-dive cho Cloudflare One: các dataset, Logpush (R2/S3/Splunk/Sentinel), tương quan đa tầng, retention hot/warm/cold, kiểm soát chi phí, rule phát hiện SIEM mẫu.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Logs</category><category>SIEM</category><category>Observability</category><author>KhaVan</author></item><item><title>Cloudflare Access vs AWS IAM Identity Center cho team admin</title><link>https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</guid><description>Đừng cố unify Cloudflare Access và AWS IAM Identity Center. Pattern thực dụng: Okta/Entra → SSO cả hai, SCIM provisioning, per-app policy, audit correlation.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>AWS</category><category>Identity</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Network policy L4: chặn non-HTTP, DoH bypass và app rule</title><link>https://cloudsecop.net/blog/network-policy-l4-non-http/</link><guid isPermaLink="true">https://cloudsecop.net/blog/network-policy-l4-non-http/</guid><description>Network policy deep-dive: chặn non-HTTP (SSH, RDP, SMTP), chặn DoH bypass DNS filter, app rule cho SaaS, kết hợp WARP, checklist production và playbook siết chặt.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Gateway HTTP filtering và TLS decryption: khi DNS không đủ</title><link>https://cloudsecop.net/blog/gateway-http-filtering-va-tls-decryption/</link><guid isPermaLink="true">https://cloudsecop.net/blog/gateway-http-filtering-va-tls-decryption/</guid><description>HTTP inspection deep-dive: cài root CA (MDM, GPO), cạm bẫy cert pinning, mẫu DLP, tenant CASB, lan can pháp lý/quyền riêng tư, playbook triển khai, checklist production.</description><pubDate>Sun, 11 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>TLS</category><category>DLP</category><category>CASB</category><author>KhaVan</author></item><item><title>Gateway DNS filtering: lớp đầu tiên của Secure Web Gateway</title><link>https://cloudsecop.net/blog/gateway-dns-filtering/</link><guid isPermaLink="true">https://cloudsecop.net/blog/gateway-dns-filtering/</guid><description>Gateway DNS deep-dive: kiến trúc resolver, thứ tự policy, DoH per-device vs DNS location per-site, threat intel category, custom list, log SIEM, checklist production.</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>DNS</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Magic WAN: kết nối site và cloud qua Cloudflare backbone</title><link>https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</link><guid isPermaLink="true">https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</guid><description>Magic WAN deep-dive: tunnel network-layer thay SD-WAN/MPLS. 4 tuỳ chọn tunnel (IPsec, GRE, Anycast IP, CNI), BGP peering, multi-cloud, Magic Firewall, playbook chuyển đổi.</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Magic WAN</category><category>Networking</category><category>SD-WAN</category><author>KhaVan</author></item><item><title>AWS KMS Key Policies: hiểu đúng để không mất quyền truy cập</title><link>https://cloudsecop.net/blog/kms-key-policies-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/kms-key-policies-deep-dive/</guid><description>Cơ chế evaluation của KMS key policy, cross-account access, condition keys, grants, key rotation, production patterns. Kèm JSON policy examples và checklist cho production.</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>KMS</category><category>Encryption</category><category>IAM</category><author>KhaVan</author></item><item><title>GuardDuty auto-remediation: cô lập EC2 và thu hồi IAM</title><link>https://cloudsecop.net/blog/guardduty-auto-remediation/</link><guid isPermaLink="true">https://cloudsecop.net/blog/guardduty-auto-remediation/</guid><description>Pipeline tự động phản ứng sự cố bảo mật với GuardDuty, EventBridge và Lambda: cô lập instance, snapshot forensic, thu hồi credentials, mở rộng multi-account với Organizations.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Automation</category><category>EventBridge</category><author>KhaVan</author></item><item><title>WARP client và device enrollment flow</title><link>https://cloudsecop.net/blog/warp-client-va-device-enrollment/</link><guid isPermaLink="true">https://cloudsecop.net/blog/warp-client-va-device-enrollment/</guid><description>Kiến trúc WARP, enrollment, device posture (built-in vs CrowdStrike/Intune), split tunnel 2 chế độ, Local Domain Fallback, DNS, triển khai MDM, truy nguyên 6 trường hợp.</description><pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Device Posture</category><author>KhaVan</author></item><item><title>lol-html: streaming HTML rewriter trên Workers — 3 production patterns</title><link>https://cloudsecop.net/blog/lol-html-streaming-rewriter/</link><guid isPermaLink="true">https://cloudsecop.net/blog/lol-html-streaming-rewriter/</guid><description>CSS-selector streaming HTML rewriter trên Cloudflare Workers. 3 pattern production: CSP nonce per request, rewrite analytics URL, A/B variant inject.</description><pubDate>Wed, 09 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>Cloudflare Developer</category><category>Performance</category><category>Edge</category><author>KhaVan</author></item><item><title>Cloudflare Tunnel deep-dive: đưa internal service ra ngoài</title><link>https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</guid><description>Kiến trúc daemon cloudflared, ingress rules, HA replicas, protocol non-HTTP (SSH/RDP/SMB), chuyển từ VPN, truy nguyên 6 trường hợp. Tunnel là nền tảng kết nối cho Zero Trust.</description><pubDate>Sun, 30 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>SCIM và group sync: tự động off-board khi nhân viên nghỉ</title><link>https://cloudsecop.net/blog/scim-va-group-sync/</link><guid isPermaLink="true">https://cloudsecop.net/blog/scim-va-group-sync/</guid><description>SCIM giải quyết cửa sổ lỗi thời: IdP đẩy cập nhật thời gian thực thay vì CF kéo claim khi đăng nhập. Thiết lập SCIM cho Okta/Entra/Google, vòng đời người dùng, xung đột.</description><pubDate>Sat, 22 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>SCIM</category><category>Lifecycle</category><author>KhaVan</author></item><item><title>Flan: vulnerability scanner Cloudflare dùng trong production</title><link>https://cloudsecop.net/blog/flan-vulnerability-scanner/</link><guid isPermaLink="true">https://cloudsecop.net/blog/flan-vulnerability-scanner/</guid><description>Flan wrap nmap NSE + Vulners API trong Docker, xuất HTML/JSON. Vì sao Cloudflare tự host thay vì mua Tenable/Qualys, và cách integrate vào CI gate CVE.</description><pubDate>Wed, 12 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Security</category><category>Vulnerability Management</category><category>Cloud Security</category><category>DevSecOps</category><author>KhaVan</author></item><item><title>Service tokens và mTLS: authentication cho CI/CD, bot, device</title><link>https://cloudsecop.net/blog/service-tokens-mtls-cho-non-human/</link><guid isPermaLink="true">https://cloudsecop.net/blog/service-tokens-mtls-cho-non-human/</guid><description>Khi client không phải người dùng. Phân biệt service token vs mTLS, cách thiết lập cả hai, chiến lược rotate, audit log, và anti-pattern phổ biến.</description><pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>mTLS</category><category>DevOps</category><author>KhaVan</author></item><item><title>Integrate IdP: Okta, Entra ID, Google Workspace, SAML generic</title><link>https://cloudsecop.net/blog/identity-provider-integration/</link><guid isPermaLink="true">https://cloudsecop.net/blog/identity-provider-integration/</guid><description>Ma trận 4 IdP phổ biến với Cloudflare Access: OIDC vs SAML, cạm bẫy group claim, claim mapping, group sync timing, pattern multi-IdP, checklist trước production.</description><pubDate>Fri, 07 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>Okta</category><category>Entra ID</category><author>KhaVan</author></item><item><title>AWS Secrets Manager vs Cloudflare Secrets Store: khi nào dùng cái nào</title><link>https://cloudsecop.net/blog/aws-secrets-manager-vs-cloudflare-secrets/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-secrets-manager-vs-cloudflare-secrets/</guid><description>AWS Secrets Manager $0.40/secret/mo + auto-rotation Lambda vs Cloudflare Secrets Store free trên Workers Paid. Khi nào chọn cái nào, replication pattern.</description><pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloudflare</category><category>Secrets Manager</category><category>Security</category><category>DevOps</category><author>KhaVan</author></item><item><title>Cloudflare Access: ZTNA cơ bản trong 30 phút</title><link>https://cloudsecop.net/blog/cloudflare-access-ztna-co-ban/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-ztna-co-ban/</guid><description>Thay VPN cho ứng dụng nội bộ bằng Cloudflare Access: giải phẫu, luồng đăng nhập, 5 bước thiết lập (app, IdP, policy, Tunnel, test), thứ tự đánh giá policy, truy nguyên.</description><pubDate>Sun, 23 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>ZTNA</category><author>KhaVan</author></item><item><title>Đọc lại roadmap.sh Cyber Security 2026: góc nhìn cloud sec</title><link>https://cloudsecop.net/blog/roadmap-sh-cyber-security-goc-nhin/</link><guid isPermaLink="true">https://cloudsecop.net/blog/roadmap-sh-cyber-security-goc-nhin/</guid><description>roadmap.sh chia con đường cyber security thành 6 khối kỹ năng. Đọc lại đối chiếu với cloud security và Zero Trust, chỗ đúng, chỗ đã cũ, và thứ tự học nếu bắt đầu lại hôm nay.</description><pubDate>Wed, 19 Feb 2025 00:00:00 GMT</pubDate><category>Security</category><category>Roadmap</category><category>Learning Path</category><category>Cloud Security</category><category>Career</category><author>KhaVan</author></item><item><title>Mental model 4 tầng: Client, Identity, Policy, Resource</title><link>https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</guid><description>Khung tư duy cho mọi tính năng Cloudflare One: mỗi request đi qua 4 tầng sinh tín hiệu, policy đánh giá rồi đi tới 1 trong 5 kết quả. Triển khai và truy nguyên dễ hơn nhiều.</description><pubDate>Sat, 15 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Architecture</category><author>KhaVan</author></item><item><title>Code review: thực hành tốt — từ roadmap.sh đến thực tế đi làm</title><link>https://cloudsecop.net/blog/code-review-best-practices/</link><guid isPermaLink="true">https://cloudsecop.net/blog/code-review-best-practices/</guid><description>roadmap.sh có trang tổng hợp thực hành code review. Mở rộng thành sổ tay: 4 trục (tác giả, reviewer, quy trình, công cụ), ví dụ, chỉ số đo, và lỗi hay gặp ở đội vừa và nhỏ.</description><pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate><category>Code Review</category><category>Software Engineering</category><category>DevOps</category><category>Code Quality</category><category>Pull Request</category><author>KhaVan</author></item><item><title>Pingora vs AWS ALB/NLB — khi nào self-host reverse proxy thắng</title><link>https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</link><guid isPermaLink="true">https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</guid><description>Pingora xử lý 40M+ req/sec ở Cloudflare. Khi nào self-host bằng pingora-core/pingora-proxy thắng AWS ALB $20/tháng + LCU và NLB managed.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Networking</category><category>Rust</category><category>AWS</category><category>Performance</category><author>KhaVan</author></item><item><title>SASE, SSE, Zero Trust, ZTNA: phân biệt thuật ngữ trước khi sa lầy</title><link>https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</link><guid isPermaLink="true">https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</guid><description>Ba thuật ngữ dễ dùng lẫn lộn trong RFP, design doc và tiếp thị. Phân biệt phạm vi, thời điểm xuất hiện, cách dùng đúng, và decision tree nhỏ để chọn đúng từ trong từng ngữ cảnh.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>SSE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS sang GCP: keyless auth</title><link>https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</guid><description>Workload Identity Federation deep dive: vì sao Service Account Key là anti-pattern, luồng token AWS STS → Google STS, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Xin chào, Things Worth Sharing</title><link>https://cloudsecop.net/blog/hello-things-worth-sharing/</link><guid isPermaLink="true">https://cloudsecop.net/blog/hello-things-worth-sharing/</guid><description>Một góc nhỏ trên internet để ghi lại những ý tưởng, bài học và điều thú vị đáng chia sẻ.</description><pubDate>Thu, 16 Jan 2025 00:00:00 GMT</pubDate><category>News</category><author>KhaVan</author></item><item><title>Cloudflare One là gì, và vì sao SASE quan trọng</title><link>https://cloudsecop.net/blog/cloudflare-one-la-gi/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-one-la-gi/</guid><description>Một tổng quan thực dụng về Cloudflare One: SASE, SSE, Zero Trust, 6 nhóm sản phẩm chính, cách so sánh với Zscaler/Netskope, và mô hình tư duy cần có trước khi triển khai.</description><pubDate>Sat, 04 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>AWS IAM Access Key rotation: Lambda + Secrets Manager</title><link>https://cloudsecop.net/blog/aws-iam-access-key-auto-rotation/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-iam-access-key-auto-rotation/</guid><description>Một giải pháp AWS-native để rotate, disable và delete IAM access key theo chính sách: đi sâu vào kiến trúc nhiều account, đánh đổi và vận hành thực tế.</description><pubDate>Tue, 31 Dec 2024 00:00:00 GMT</pubDate><category>AWS</category><category>IAM</category><category>Security Automation</category><category>Secrets Manager</category><category>Lambda</category><author>KhaVan</author></item><item><title>Chạy CSPM trên hơn chục AWS Landing Zone</title><link>https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</guid><description>Cách mình thiết kế CSPM engine nội bộ quét song song nhiều AWS Landing Zone bằng Prowler, lưu finding vào D1, artifact vào R2, dashboard duy nhất cho Security Operations.</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>CSPM</category><category>Prowler</category><category>Cloudflare</category><author>KhaVan</author></item><item><title>Chuyển blog tĩnh từ Cloudflare Pages sang Workers Assets</title><link>https://cloudsecop.net/blog/workers-assets-static-site/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workers-assets-static-site/</guid><description>Vì sao tôi chuyển blog từ Pages sang Workers Assets, những đánh đổi thực tế, và vài cấu hình nhỏ nên biết trước khi triển khai.</description><pubDate>Mon, 16 Dec 2024 00:00:00 GMT</pubDate><category>Programming</category><category>Workers</category><category>Cloudflare</category><author>KhaVan</author></item><item><title>Ghi chép sau 3 tháng triển khai Zero Trust</title><link>https://cloudsecop.net/blog/zero-trust-notes/</link><guid isPermaLink="true">https://cloudsecop.net/blog/zero-trust-notes/</guid><description>Những điều thực sự hiệu quả, những thứ không như kỳ vọng, và các bài học vận hành khi triển khai Cloudflare Zero Trust cho tổ chức quy mô hàng ngàn người dùng.</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate><category>Security</category><category>Zero Trust</category><category>Cloudflare</category><author>KhaVan</author></item><item><title>Năm lưu ý về schema D1 mình rút ra từ những bài học đau thương</title><link>https://cloudsecop.net/blog/d1-schema-tips/</link><guid isPermaLink="true">https://cloudsecop.net/blog/d1-schema-tips/</guid><description>Composite primary key, khi nào vẫn cần FTS, vì sao không nên index theo cảm tính, và vì sao row count ở edge quan trọng hơn bạn nghĩ.</description><pubDate>Sat, 30 Nov 2024 00:00:00 GMT</pubDate><category>Database</category><category>D1</category><category>Cloudflare</category><category>Programming</category><author>KhaVan</author></item><item><title>cloudflared internals — build from source, ingress patterns, debugging</title><link>https://cloudsecop.net/blog/cloudflared-internals-from-source/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflared-internals-from-source/</guid><description>Build cloudflared từ Go source, ingress.yaml advanced patterns (path routing, HTTP/2, origin cert), tunnel info JSON cho monitoring, top 5 debug technique.</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>Boringtun: WireGuard userspace cho WARP — tại sao nhanh hơn corporate VPN</title><link>https://cloudsecop.net/blog/boringtun-wireguard-warp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/boringtun-wireguard-warp/</guid><description>Boringtun Rust userspace WireGuard, kiến trúc bên trong WARP client, vì sao userspace WG thắng kernel module ở mobile/edge, MASQUE evolution.</description><pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Networking</category><category>WireGuard</category><author>KhaVan</author></item><item><title>CFSSL trong production — Cloudflare&apos;s PKI toolkit cho internal CA</title><link>https://cloudsecop.net/blog/cfssl-pki-toolkit-production/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cfssl-pki-toolkit-production/</guid><description>Tự host internal CA bằng CFSSL: cfssl init, intermediate CA, OCSP responder, multirootca, CI short-lived certs. So sánh AWS Private CA $400/tháng.</description><pubDate>Fri, 15 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloud Security</category><category>PKI</category><category>TLS</category><category>Certificates</category><author>KhaVan</author></item></channel></rss>