BuildKit: Docker's Hidden Gem That Can Build Almost Anything

Hope Is Not a Security Strategy: Why Secure-by-Default Beats Hardening

A bug is a bug, but a patch is a policy: The case for bootable containers

What has Docker become?

Architecture for Disposable Systems

Achieving a 0-CVE OS for VMs: The End of Traditional Patching

Cutting down AWS cost by $150k per year simply by shutting things off

We use Kubernetes and spot instances to reduce EC2 billing up to 80%