Andrzej Skrodzki

Security Engineer · Cloud · Kubernetes · Identity

I break and harden cloud infrastructure — finding the gaps in AWS, Kubernetes, and IAM before attackers do, then closing them. I write about what actually breaks in production.

kubescout Detects runtime RBAC drift in Kubernetes clusters. iam-lint Scans AWS IAM policies for over-permissive grants. How SCPs really evaluate cross-account conditions A Kubernetes RBAC pattern that silently grants cluster-admin GuardDuty has a blind spot on VPC endpoint traffic