August was a SOC 2 compliance sprint: shipped a fully tuned Web Application Firewall on dev with zero false positives, closed out SMACK encryption findings by migrating production disks and node pools to CMEK, and stood up a four-track compliance backlog with PR-blocking vulnerability scanning already live. Also wrapped dynamic per-branch/PR environments and a couple of small dev-experience wins.
SOC 2 Push: WAF Hardening, CMEK Encryption, Compliance Backlog
August 2026
Month
August 27, 2026
Published
Ivan Khropachov
DevOps Tech Lead
What I Shipped6
Finished dynamic per-branch/PR environments
Closed out remaining bugs for both tenant and shared environment setups; fully working at the start of the month.
Configured and debugged WAF on dev using OWASP CRS
~700 rules across ~15 attack categories (SQLi, probes/scanners, rate-limit abuse, etc.), tuned to zero false positives on dev.
Encrypted GCP resources with CMEK to close SOC 2 SMACK findings
Recreated GKE node pools (including production) and migrated production persistent disks to encrypted disks. Took ~1.5-2 weeks due to required restarts/recreation.
Built out the SOC 2 compliance backlog
Organized into four tracks: Security Command Center (GCP findings), Trivy (image/dependency scanning), planned Wiz integration, and firewall rule exclusions.
Enabled Trivy scanning to block PRs on high/critical vulnerabilities
Image and code scanning now runs on every PR; high/critical issues fail the build.
Minor dev-experience improvements
SSO-enabled access to Kafka UI, matching existing Grafana access.
Why It Mattered3
Directly closes SOC 2 gaps
WAF and CMEK encryption work map straight to SOC 2 requirements and reduce open GCP security findings, even though it's invisible to end users.
Shrinks the attack surface without breaking the product
OWASP CRS rules on dev now block real attack categories with zero false positives, proving the rules are safe to propagate to stage and prod.
Creates a clear, trackable path to full compliance
The four-track backlog (Security Command Center, Trivy, Wiz, firewall exclusions) gives DevOps and dev teams a shared, prioritized view of what's left.
What I Learned3
Encryption migrations are slow by nature
Most SMACK/encryption fixes require restarting or recreating the resource (node pools, disks), stretching a conceptually simple task into 1.5-2 weeks.
Firewall tuning is iterative and time-intensive
Getting to zero false positives across ~700 rules and ~15 attack categories took about a week of careful debugging and exclusion tuning.
Findings overlap across tools
Security Command Center and the upcoming Wiz integration will surface a lot of duplicate findings, so resolving Command Center issues now reduces future Wiz noise.
What's Next3
Propagate WAF rules to stage, then production
Dev is stable with zero false positives; next step is validating on stage before rolling out to prod.
Set up Wiz scanning
Planned integration to expand findings coverage alongside Security Command Center and Trivy.
Revisit and tighten current firewall exclusions
Re-include cookie/header handling and other currently-excluded traffic patterns without breaking the product; tracked as its own task set.
Ivan Khropachov
DevOps Tech Lead
Hi! I’m Ivan, and I’m the new DevOps Engineer here at Flamingo. I’ll be working across infrastructure, CI/CD, and automation to help keep everything stable, secure, and running like clockwork.