A working record of building, breaking, and rebuilding security controls in real pipelines — secret scanning, SAST/SCA, policy enforcement, and the organizational work of getting engineering teams to actually adopt them.
// a pipeline you can trust, stage by stage
PipelineClear is written by Somesh Motupally, a DevSecOps and cloud security engineer working across Harness CI/CD, GitHub Actions, and Azure DevOps. It's a running record of real problems solved in production pipelines — not theory, not vendor marketing.
Secret scanning and secrets management, SAST/SCA and dependency security, container and Kubernetes hardening, policy-as-code enforcement, and building security tooling that teams adopt willingly rather than under mandate.
Every post here comes from something actually built and shipped: the problem it solved, how it was implemented, what changed as a result, and what didn't work the first time. The goal is a public, dated record of hands-on engineering work over time.
How we used OPA and Kyverno to turn security policy from a document nobody read into an automatic gate — privileged containers, unsigned images, and root access blocked before they ever reach production.
How we replaced inconsistent, team-by-team CI/CD security with a single set of versioned, account-level templates — and what changed once every pipeline inherited fixes automatically.
New posts on CI/CD and cloud security engineering go up regularly. For questions, collaboration, or speaking/review requests, reach out at hello@pipelineclear.com.