A working record of building, breaking, and rebuilding security controls in real pipelines — secret scanning, SAST/SCA, policy enforcement, and the organizational work of getting engineering teams to actually adopt them.
// a pipeline you can trust, stage by stage
PipelineClear is written by Somesh Motupally, a DevSecOps and cloud security engineer working across Harness CI/CD, GitHub Actions, and Azure DevOps. He writes from real problems solved in production pipelines — not theory, not vendor marketing. More about Somesh →
How we rolled out default-deny Kubernetes NetworkPolicies across namespaces — observing real traffic first, so the gates didn't take down production.
How we used OPA and Kyverno to turn security policy from a document nobody read into an automatic gate — privileged containers, unsigned images, and root access blocked before they ever reach production.
How we replaced inconsistent, team-by-team CI/CD security with a single set of versioned, account-level templates — and what changed once every pipeline inherited fixes automatically.
These posts are part of Pipeline to Runtime, a series on securing every stage of software delivery — best read in order.
New posts on CI/CD and cloud security engineering go up regularly. For questions, collaboration, or speaking/review requests, reach out at [email protected].