<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Yogesh Thanvi</title>
    <link>https://yogeshthanvi.com/</link>
    <description>Recent content on Yogesh Thanvi</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 08 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://yogeshthanvi.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Enforcing Pod Security on AKS with Azure Policy and OPA Gatekeeper</title>
      <link>https://yogeshthanvi.com/posts/enforcing-pod-security-aks-azure-policy/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/posts/enforcing-pod-security-aks-azure-policy/</guid>
      <description>Detecting insecure pods on Azure Kubernetes Service is not the same as preventing them. Here is how Azure Policy and OPA Gatekeeper move enforcement to admission time, so a misconfigured workload never reaches the cluster.</description>
    </item>
    <item>
      <title>Engineering Trust: Building Systems That Prove Compliance Continuously</title>
      <link>https://yogeshthanvi.com/posts/engineering-trust/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/posts/engineering-trust/</guid>
      <description>In cloud-native and AI-driven systems, compliance can no longer be a periodic activity. It has to be continuously demonstrated. Here is the architecture for engineering that trust.</description>
    </item>
    <item>
      <title>From Detection to Enforcement: Making CSPM Actually Stop Misconfigurations</title>
      <link>https://yogeshthanvi.com/posts/from-detection-to-enforcement/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/posts/from-detection-to-enforcement/</guid>
      <description>Most Cloud Security Posture Management tools detect misconfigurations and stop there. Detection without enforcement leaves the exposure in place. Here is what changes when policy-as-code blocks and remediates at admission time.</description>
    </item>
    <item>
      <title>Incident-Aware CI/CD: Turning Production Failures Into Permanent Guardrails</title>
      <link>https://yogeshthanvi.com/posts/incident-aware-cicd/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/posts/incident-aware-cicd/</guid>
      <description>Every production incident is a lesson the system has already paid for. Most teams capture that lesson in a postmortem document and then reintroduce the same failure months later. Here is how to convert incidents into automated controls that make a failure mode impossible to repeat.</description>
    </item>
    <item>
      <title>Securing AI Workloads on Azure: Governance Patterns for Azure OpenAI and AI Foundry</title>
      <link>https://yogeshthanvi.com/posts/securing-ai-workloads-on-azure/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/posts/securing-ai-workloads-on-azure/</guid>
      <description>Generative AI on Azure introduces control points that traditional application security never had to handle. Here are practical governance patterns for Azure OpenAI and AI Foundry workloads, mapped to where the real risks live.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://yogeshthanvi.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/about/</guid>
      <description>Cloud security and DevSecOps leader with 14+ years securing internet-scale distributed infrastructure.</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://yogeshthanvi.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/contact/</guid>
      <description>Get in touch with Yogesh Thanvi for talks, collaboration, or professional inquiries.</description>
    </item>
    <item>
      <title>Professional Service &amp; Leadership</title>
      <link>https://yogeshthanvi.com/service/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/service/</guid>
      <description>Standards development, peer review, and judging across ISACA, IEEE, and industry.</description>
    </item>
    <item>
      <title>Publications</title>
      <link>https://yogeshthanvi.com/publications/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/publications/</guid>
      <description>Peer-reviewed research on DevSecOps governance, cloud security, Kubernetes, and AI risk.</description>
    </item>
    <item>
      <title>Speaking</title>
      <link>https://yogeshthanvi.com/speaking/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://yogeshthanvi.com/speaking/</guid>
      <description>Conference talks and panels on cloud security, DevSecOps governance, and trusted AI infrastructure.</description>
    </item>
  </channel>
</rss>
