<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Andrzej Skrodzki</title><description>Essays and notes on cloud and Kubernetes security.</description><link>https://skrodzki.dev/</link><item><title>How SCPs really evaluate cross-account conditions</title><link>https://skrodzki.dev/writing/scp-cross-account-conditions/</link><guid isPermaLink="true">https://skrodzki.dev/writing/scp-cross-account-conditions/</guid><description>A walk through a surprising AWS Organizations SCP evaluation case.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>A Kubernetes RBAC pattern that silently grants cluster-admin</title><link>https://skrodzki.dev/writing/k8s-rbac-cluster-admin/</link><guid isPermaLink="true">https://skrodzki.dev/writing/k8s-rbac-cluster-admin/</guid><description>Aggregated ClusterRoles can escalate without anyone noticing.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>