diff --git a/src/content/blog/workload-least-privilege.md b/src/content/blog/workload-least-privilege.md index 17791b5..1287525 100644 --- a/src/content/blog/workload-least-privilege.md +++ b/src/content/blog/workload-least-privilege.md @@ -1,5 +1,5 @@ --- -title: "The most secure credential is the one you never mount" +title: "Every pod holds a key to a door it never opens" date: 2026-06-23 summary: "Least privilege for Kubernetes workloads doesn't start with an RBAC role — it starts with revoking the API token every pod silently carries, then layering identity, non-root, and Pod Security on top." tags: ["kubernetes", "security", "least-privilege", "rbac", "service-accounts"] diff --git a/src/styles/global.css b/src/styles/global.css index 0406185..d424a57 100644 --- a/src/styles/global.css +++ b/src/styles/global.css @@ -371,8 +371,10 @@ svg { position: absolute; top: 50%; left: 50%; - width: 168%; - height: 168%; + /* Zoomed in — larger than viewport so the board reads big/immersive and the + scroll-pan has room to travel. */ + width: 215%; + height: 215%; object-fit: cover; transform: translate(-50%, -50%); will-change: transform;