Engineering notes from production

Dispatches from the infrastructure trenches_

Long-form writing on security, Kubernetes, platform engineering, and the operational realities of keeping production systems alive.

2026-03-25 security kubernetes supply-chain

The LiteLLM Supply Chain Attack and Why Your Secrets Shouldn't Survive Boot

Yesterday's PyPI compromise of LiteLLM harvested every credential it could find on disk. Here's how ephemeral filesystem secrets via the Kubernetes Secrets Store CSI Driver reduce the blast radius of exactly this class of attack.

Read article →