Alexandre Sieira shares all of his experience in securing agile environments.

mansplainer
João Brito

Have you ever stopped to think about the real role of security in DevOps and Cloud Native environments? In episode 164 of the seventh season of Kubicast, we welcomed Alexandre Sieira, founder of Tenchi Security, for a direct conversation about risks, maturity, and the dilemmas surrounding security in the cloud.
With a background of someone who lives security on the battlefield, Sieira shared practical experiences and raised important reflections on how prepared (or how unprepared) we are.
Problems Faced
Lack of maturity in security, especially in frameworks that scale too quickly.
Third-party cyber risk, which is often ignored by technical teams.
Conflicts among Dev, Ops, and Sec teams, creating critical gaps in the operation.
Indiscriminate use of shared environments (such as the default namespace).
Solutions Adopted
Building segmented environments, with compartmentalization of access.
Applying principles such as Zero Trust and Least Privilege right from the infrastructure level.
Conscious use of Infrastructure as Code (IaC) to ensure traceability and governance.
Strengthening communication between teams and redefining responsibilities.
Throughout the episode, some important lessons became very clear: security is not the responsibility of a single team — it must be shared among Dev, Ops, and Sec, right from the foundation of the infrastructure. The pursuit of agility cannot justify decisions that neglect structural risks. Invulnerability does not exist, but being prepared to handle attacks is what separates resilient environments from true operational blind spots.
Among the best practices discussed, the importance of avoiding the use of the default namespace became evident, as it often becomes a land with no owner and no governance. Thinking about blast radius when defining permissions is essential to limit the impact of any failure or breach. Smart centralization — where it makes sense — combined with conscious delegation helps balance autonomy with control. Finally, it was reinforced that security cannot be an impediment, but rather a natural part of the team's culture, which enables better and more sustainable deliveries.
🎧 Listen to Kubicast on Spotify as well, share it with your team, and comment on the video about what challenges you are currently facing!
Hosted by João Brito, your favorite host (@juniorjbn).
Newsletter Getup.
Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.
Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.
GET UP
© Getup · 2026

