Blog
Notes from operations: Cloudflare, Wazuh, AI, ecommerce, audit and FinOps.
AI threats, crawlers, leakage into a model and a fake counterparty
Training bots collect store and documentation content. People paste secrets into chat. The scope is crawler policy, DLP and a data boundary in the assistant. Origin stays out of reach, and the question log goes to on-call.
Cloudflare and malicious bots, score, challenge, origin off the internet
Credential stuffing, cart scanning and price scraping. Bot score, JS challenge and a WAF rule, before traffic reaches the store. Origin without a public address, and a playbook that says when to raise the threshold.
Ecommerce protection, checkout, edge and traffic you can name
Carding, stuffing and a jump during a campaign. WAF on the cart, origin hidden, and ntopng says whether these are customers or a scan. Before the peak we test the checkout path, not the homepage.
Wazuh, one picture of the host, the alert and on-call
Agents, FIM, SCA and MITRE in one console. An alert with an owner, not another email nobody closes. The playbook has a threshold, a ticket and a date when the failed check is closed.
A CIS audit that does not end as a PDF
A CIS scan or cloud posture becomes a backlog: priority, owner, change window and proof of closure. A 30/60/90 day plan can be settled at the next review.
FinOps, before the cloud invoice arrives
Tags, showback and rightsizing are not IT bookkeeping. They are an engineering discipline that protects product margin. The team sees its bill, then anomalies, rightsizing and commitments.
A load test before the peak, not during it
A traffic scenario from analytics, a database bottleneck and a scaling decision, before marketing starts the campaign. Soak shows a connection leak you will not see after two minutes.