Skip to content
View some-natalie's full-sized avatar
πŸ’–
I may be slow to respond. Slack/text if urgent.
πŸ’–
I may be slow to respond. Slack/text if urgent.

Block or report some-natalie

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
some-natalie/README.md

Hi there πŸ‘‹πŸ»

I'm Natalie, a DevSecOps engineer and consultant experienced in developer experience and consolidation within a wide array of security-focused environments. I work at the intersection of technology, people, and highly-regulated industries as a Principal Solutions Engineer for Public Sector at Chainguard!

πŸ“ I write about tech, what I'm working on, and what I'm playing with on my blog. Here's what I've been up to lately:

  1. Images have their own risks, too: You've locked down your runtime, orchestrator, and hosts. Now how about what's actually running inside of those containers?
  2. Risks in the image registry: All of these containers are images ... somewhere. That 'somewhere' is a registry. What risks can we find in our container registry?
  3. Orchestrating chaos and containers: The magic of putting your application in a container is scaling to run even bigger workloads than could fit in a single machine. Container orchestrators have their own risks too. This new layer has its own permissions schema to learn and configurations to fiddle with. Let's dive in!

πŸ’Ό Day to day, I work with

You can find me in our work Slack sharing all sorts of neat things you can do with all that fun stuff and probably find out how I've broken and maybe fixed something too. πŸ˜€

πŸ‘Ύ I play with

  • All sorts of handy Raspberry Pi projects, including
  • I'm getting into the Flipper Zero lately - it's so handy and mischievous! (some fun uses)
  • Video games in a Windows VM on my Fedora desktop with libvirt, KVM, and a custom Linux kernel to pass hardware to it. It's got about 5% or so performance drop (just looking at frame rates) over a native install. You should check it out - code and write-up on how it works.

I have an awesome life outside of tech, so while I have a few projects that I enjoy, nothing above is close to where I spend most of my time / energy. If you need anything of mine above fixed, please feel free to fork it and send me a pull request! ❀️

🌸 Heads up!

  • 🌱 I’m currently studying to sit for my OSCP certification and learning the ropes at a container security startup.
  • 🎀 Public speaking is fun! Check out what I've been up to here.
  • πŸ˜„ Pronouns: she/her
  • ❓ Looking for my rΓ©sumΓ©? It's here, but you can also find some of what I've been up to in my profile. If you want to know about where else I've worked and went to school, you should go to LinkedIn.
  • πŸ’¬ Want to chat? I'm on Mastodon.

Pinned Loading

  1. kubernoodles kubernoodles Public

    k8s runners for GitHub Actions in the enterprise, made for humans

    Dockerfile 91 19

  2. fedora-acs-override fedora-acs-override Public

    Using the ACS override patch for Fedora to split identical hardware in the kernel

    Shell 54 17

  3. gitlog-to-csv gitlog-to-csv Public

    Creates a CSV file of `git log` data, useful for audit reports and other "chain of custody" type reports

    Shell 8 1

  4. advanced-security/ghas-to-csv advanced-security/ghas-to-csv Public

    Play with GHAS API to provide posture data over time

    Python 40 18

  5. jekyll-in-a-can jekyll-in-a-can Public

    πŸ§ͺπŸ₯« - it's Jekyll in a container

    Dockerfile 5 1

  6. advanced-security/enterprise-security-team advanced-security/enterprise-security-team Public

    Manage a uniform team of security managers for every organization in your enterprise

    Python 25 6