Kubernetes Security Baselines for Regulated Industries

Implementing Pod Security Standards, Network Policies, and Policy-as-Code for FedRAMP, NIST SP 800-53, and CMMC compliance in Kubernetes environments. Introduction Organizations operating Kubernetes clusters in regulated environments face complex compliance requirements: FedRAMP: Federal Risk and Authorization Management Program NIST SP 800-53: Security and Privacy Controls for Information Systems CMMC 2.0: Cybersecurity Maturity Model Certification for DoD contractors PCI DSS: Payment Card Industry Data Security Standard HIPAA: Health Insurance Portability and Accountability Act This guide provides actionable security baselines based on production deployments in healthcare, financial services, and government-adjacent workloads. ...

September 10, 2025 · 2 min · Gustavo de Oliveira Ferreira

Container Orchestration with Azure Red Hat OpenShift (ARO) for Banking

Introduction The banking sector demands infrastructure that is robust, scalable, and above all, secure. At Banco Bradesco, we faced the challenge of orchestrating thousands of containers efficiently and securely while ensuring high availability and regulatory compliance. Our solution was to implement Azure Red Hat OpenShift (ARO). This article explores our journey with ARO, the benefits it brought to the banking environment, and how GitOps was crucial for the success of large-scale orchestration. ...

June 12, 2025 · 2 min · Gustavo de Oliveira Ferreira