# control-plane.io > AI-optimized mirror of control-plane.io containing 50 pages totalling 19,894 words of clean markdown content, structured data, and semantic HTML. Original source: https://control-plane.io/. Last updated: 2026-06-13T20:45:05.657Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Cybersecurity consulting and advisory](/content/site-root.html): Delivering world-leading consulting solutions for Cloud, Kubernetes, and supply chain security. Secure-by-design and secure-by-default are in our DNA. (724 words) ## Articles & Blog Posts - [case-studies/verisign-security-assurance-of-critical-internet-scale-on-premises-kubernetes-platform.html](/content/case-studies/verisign-security-assurance-of-critical-internet-scale-on-premises-kubernetes-platform.html) (1 words) - [How LLMs Are Ending The Attacker-Defender Stalemate (And What to Do About It)](/content/posts/llms-ending-attacker-defender-stalemate/index.html) (1,441 words) - [Defusing CanisterWorm: How Bun and Deno Secure the JavaScript Supply Chain](/content/posts/defusing-canisterworm-bun-deno-supply-chain/index.html): TeamPCP's CanisterWorm is exploiting npm's postinstall hooks. Learn how modern JavaScript runtimes like Bun and Deno neutralise this threat by default. (932 words) - [Validating Zero Trust: Network Policy Testing with Flux CD and Netassert](/content/posts/validating-zero-trust/index.html) (1,284 words) - [The Post Quantum Radar](/content/posts/the-post-quantum-radar/index.html): Keeping track of PQC availability (971 words) - [The End of Safe Software? No, It's Not.](/content/posts/the-end-of-safe-software/index.html) (923 words) - [Tampered Tokenizers: An AI Supply Chain Meltdown](/content/posts/tampered-tokenizers-an-ai-supply-chain-meltdown/index.html): The tokenizer attack that existing scanners can't catch, and the supply chain tooling that can. (1,494 words) - [O'Reilly: Kubernetes Security and Threat Modelling Courseware](/content/case-studies/oreilly-kubernetes-security-and-threat-modelling-courseware.html): How a leading educational and online learning provider enhanced their cloud native training portfolio through cutting-edge Kubernetes security live events (816 words) - [UK Government: Critical National Infrastructure Migration](/content/case-studies/uk-home-office-critical-national-infrastructure-migration.html): How a UK Government department maintained availability and optimised deployment safety by securely adopting Public Cloud (659 words) - [Google Cloud: Center for Internet Security Benchmarks for Google Kubernetes Engine](/content/case-studies/google-cloud-gke-cis-benchmarks/index.html): How a leading public cloud provider lowered the barrier for securing managed Kubernetes clusters by publishing best practice benchmarks (703 words) - [OpenAI: Red Teaming GPT-4o, Operator, o3-mini, and Deep Research](/content/case-studies/openai-red-teaming/index.html): How an external Red Teaming engagement supported OpenAI’s evaluation and hardening of frontier models through systematic adversarial testing. (1,407 words) - [Citigroup: Continuous Secure Ingestion for OSS Software Packages](/content/case-studies/citigroup-continuous-secure-ingestion-for-oss-software-packages.html): How a multinational bank implemented automated provenance verification of over three million external packages (809 words) - [We value your privacy](/content/tags/secrets-management/index.html) (14 words) - [We value your privacy](/content/tags/ai-security/index.html) (14 words) - [We value your privacy](/content/tags/openbao/index.html) (14 words) - [OpenAI Internal Model Red Teaming](/content/publications/openai-red-teaming/index.html): Red Team Network contributions to Operator, GPT-4o, o3-mini, and Deep Research system cards. (126 words) - [We value your privacy](/content/tags/governance/index.html) (14 words) - [We value your privacy](/content/tags/kubernetes/index.html) (14 words) - [We value your privacy](/content/tags/assurance/index.html) (14 words) - [We value your privacy](/content/tags/red-team/index.html) (14 words) - [We value your privacy](/content/tags/networking/index.html) (14 words) - [We value your privacy](/content/tags/zero-trust/index.html) (14 words) - [We value your privacy](/content/tags/threat-modeling/index.html) (14 words) - [We value your privacy](/content/tags/open-source/index.html) (14 words) - [We value your privacy](/content/tags/gitops/index.html) (14 words) - [BP: Universal Cryptographically-Verifiable Workload Identities](/content/case-studies/bp-machine-identity/index.html): How a multinational energy company accelerated the adoption of cloud-agnostic workload identity mechanisms, through options analysis and security architecture (707 words) - [We value your privacy](/content/tags/ci-cd/index.html) (14 words) - [Flux D1 Reference GitOps Architecture](/content/publications/flux-d1-architecture/index.html): A hardened reference architecture for GitOps with Flux CD. (168 words) - [We value your privacy](/content/tags/blue-team/index.html) (14 words) - [Hacking Kubernetes](/content/publications/hacking-kubernetes/index.html): The definitive guide to Kubernetes offensive and defensive security. (231 words) - [We value your privacy](/content/tags/flux-cd/index.html) (14 words) - [We value your privacy](/content/tags/supply-chain/index.html) (14 words) - [eBPF Foundation Security Threat Model](/content/publications/ebpf-threat-model/index.html): A comprehensive threat model for eBPF-based security solutions. (121 words) - [We value your privacy](/content/tags/security/index.html) (14 words) - [FINOS AI Security Reference Architecture](/content/publications/finos-ai-reference-architecture/index.html): AI security reference architecture for financial services. (164 words) - [We value your privacy](/content/tags/index.html) (14 words) - [NIST SP 800-233 Service Mesh Proxy Models](/content/publications/nist-service-mesh/index.html): Security guide to service mesh proxy models for cloud-native applications. (135 words) - [We value your privacy](/content/tags/generative-ai/index.html) (14 words) - [FINOS AI Governance Framework](/content/publications/finos-ai-governance/index.html): AI governance framework for financial services. (167 words) - [CNCF FluxCD Threat Model](/content/publications/fluxcd-threat-model/index.html): Security assessment and threat model for Flux CD as part of CNCF graduation. (169 words) - [Blogs and News](/content/posts/index.html): The ControlPlane blog features news about Software Supply Chain Security, container security, CI/CD, Kubernetes, AI/ML, Cloud Native & more. (4,602 words) - [Kubernetes for Security Operations Centres](/content/publications/kubernetes-for-soc/index.html): Community collaboration with JP Morgan CyberOps. (143 words) - [Hardening Git for GitOps](/content/publications/git-hardening-gitops/index.html): How to secure Git workflows for GitOps. (114 words) - [Financial Services User Group Kubernetes Threat Model](/content/publications/fs-kubernetes-threat-model/index.html): Financial services-specific threat model for Kubernetes. (156 words) - [CNCF Flatcar Threat Model](/content/publications/flatcar-threat-model/index.html): A project graduation threat model with the TAG Security community. (148 words) - [CIS Benchmarks for Google Kubernetes Engine](/content/publications/cis-gke-benchmarks/index.html): Center for Internet Security hardening guide for GKE. (73 words) - [CNCF Envoy Gateway Threat Model](/content/publications/envoy-gateway-threat-model/index.html): A comprehensive threat model for the Envoy Gateway. (116 words) - [CNCF ArgoCD End User Hardening Guide](/content/publications/argocd-hardening-guide/index.html): A guide to hardening ArgoCD for end users. (123 words) - [sitemap-xml.html](/content/sitemap-xml.html) (1 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives