From a security-first platform run by one person.
Engineering notes from running the lab’s own systems. Everything described is in production, not theory. Published through Aqilra; the failures are the useful half.

Part 0: Security Without a Security Team
The whole posture behind live production systems, on one page. Four rings, six principles, and the disclosure discipline behind all of it.

Part 1: What a WAF Monitor Taught Me About the Real Cost of a Public IP
Three minutes after DNS resolved, the first bot arrived. What a live WAF monitor showed me, and the drift I found when I finally looked.

Part 2: The Morning I Realized the Door Had No Lock
Short-lived tokens, rotating refresh, 2FA, email-match OAuth, and the one-call revocation I built the day I couldn’t cleanly remove one person.

Part 3: From Silent Servers to a Real-Time View
The disk filled at 4pm. I found out at 9pm. Going from a silent server to a real-time view of everything, without a per-seat SaaS bill.

Part 4: Five Red Runs Before a Single Container Shipped
The fail-closed pipeline every change clears before production, the day it went red five times, and signed artifacts verified at runtime.

Capstone: The Incident I Rehearse For
I have not been breached by a supply-chain attack. This is the drill I rehearse for anyway, in three acts: crisis, survival, advancement.
The full feed, with new posts as they land: aqilra.com/read/mannat-ai-labs.