Stop Putting Secrets in process.env: Encrypt Env Vars with AWS KMS
After a CVSS 10.0 RCE (CVE-2025-66478), we stopped trusting process.env. Here’s what I built instead
Feb 21, 202610 min read10

Search for a command to run...
Articles tagged with #devops
After a CVSS 10.0 RCE (CVE-2025-66478), we stopped trusting process.env. Here’s what I built instead

How script skimming slipped past backend-focused defenses and the new PCI DSS 4.0 directives (6.4.3 & 11.6.1) you must build into frontend flows.

Zero-downtime deployments are not fluff. They’re essential!

Build, orchestrate, and ship multi-container apps like a pro

Modern APIs demand more than logs. Here’s how to instrument observability the right way with OpenTelemetry.

Build secure, scalable, and production-ready APIs using AWS API Gateway without getting lost in configuration hell.
