I work at the intersection of software supply chain security and cloud-native infrastructure — hardening container runtimes, locking down Kubernetes clusters, and making sure what ships to prod is actually what was built.
name: Utkarsh Tripathi
website: https://utkarshtripathi.in
focus:
- Software Supply Chain Security
- Container Hardening & Runtime Security
- Kubernetes Security & Policy Enforcement
- DevSecOps & Secure CI/CD Pipelines
stack:
security:
- SLSA / SBOM / Sigstore / Cosign
- OPA / Kyverno / Falco
- Trivy / Grype / Syft / RapidFort
- Distroless & Hardened Base Images
containers:
- Docker / Podman / containerd
- Kubernetes / Helm / Kustomize
- Istio / Cilium
infrastructure:
- AWS / GCP / Oracle Cloud
- Traefik / HAProxy / Kong / APISIX
- Bash / Go / Python
backend:
- Golang / Node.js / Python
- PostgreSQL / MongoDB / ClickHouse- Securing container supply chains — from image build to runtime
- Exploring eBPF-based observability and security enforcement
- Writing about DevSecOps and cloud-native security on Medium
- Open to collaborating on security tooling and infrastructure projects



