Home/Templates/All templates
All templates
Every template on the site, named after what you end up with.
Ready to use
Send cloud audit logs to storage that refuses deletes for a set number of days.
Turn off password logins and root logins, and check the config before restarting so you cannot lock yourself out.
Forward system logs to a collector so they outlive the machine that wrote them.
The first Application, which then manages every other application from Git.
Runtime alerts installed by the same pipeline that ships the workloads, so they cannot fall behind.
Planned
Listed so the gaps are visible. Each page explains the problem and names the service each platform will use.
Policies that make dangerous actions fail outright, so there is nothing to alert on afterwards.
Continuous evaluation that flags a resource the moment it stops matching the standard.
A delivery pipe from cloud logging to the place your detections actually run.
A separate account that does not depend on your identity provider, and shouts every time it is used.
Reach a server for troubleshooting with nothing listening on the internet, and a recording of the session.
A managed store with automatic rotation, an access log, and a way to take access away.
Your own keys, rotated on a schedule, with a usage log and an off switch.
Traffic records stored cheaply for months, in a format you can query.
A clean-room virtual machine for looking at suspicious files, with no route to anything live.
The state file holds secrets in plain text. This stores it encrypted, versioned, and locked.