Category: IT Security
-

🛠️ Backstage Core Features Overview: 5 Weapons to Boost Developer Productivity
Hello! We’ve previously learned what Backstage is and why it’s needed. Now, we’re going to delve into the 5 core features of Backstage that developers most frequently access and use in the field. Let’s explore together how these features interact to create a ‘Golden Path’! 🌟 📌 Learning Objectives for This Post After reading this…
-
![🎸 [Backstage Introduction] The Ultimate Guide to Backstage, Spotify’s Best Developer Portal](https://cslab.cloudsecuritylab.co.kr/wp-content/uploads/2026/07/wrimo-image-6a4ed6cf6638f.png)
🎸 [Backstage Introduction] The Ultimate Guide to Backstage, Spotify’s Best Developer Portal
Hello! I’m Ilseon Choi, a cloud security and platform engineering expert. 🚀 If we discussed the necessity of a developer portal in the last post, today we’ll delve into the actual entity: Backstage. Let’s explore its philosophy and structure, understanding why it’s called a “framework” rather than just a “tool to install and use”! 📌…
-

🚀 The Core of Cloud-Native, Developer Portal Introduction Guide: Balancing Autonomy and Efficiency
Hello! Today, we’re going to delve deep into one of the biggest challenges faced by modern cloud-native organizations: how to simultaneously achieve ‘developer autonomy’ and ‘operational efficiency’. Shall we take a closer look at the Developer Portal, which is at the heart of this solution? 🔎 https://tag-app-delivery.cncf.io/whitepapers/platforms/#capabilities-of-platforms 📌 What This Post Will Cover (Chapter Overview)…
-

Is TPS, CPU, Memory, IOPS estimation still necessary in the cloud era?
When talking about performance and capacity planning, similar questions always arise. “What should the TPS be set to?” “How many CPUs will be needed?” “How much Memory should there be?” “How do I calculate IOPS?” “How many servers are needed to handle 500 concurrent users?” But when you work in practice, you start to think:…
-

🏗️ Governance and Automation at Once! A Complete Guide to Backstage Standard Scaffolder (Template)
Hello! Today, we’ll explore how to leverage Backstage Scaffolder, a core component of platform engineering, to “spin up standard projects with security guardrails.” We’ll share how to manage, through code, not just “copying code,” but who creates it, for what purpose, and in compliance with which security policies. 🛠️ 1. Anatomy of a Template 🦴…
-
![[Investor’s Note] TQQQ Pyramiding Buying Strategy to Turn a Bear Market into an Opportunity: A Precise Diagnosis of a Billion-Won Portfolio 📈](https://cslab.cloudsecuritylab.co.kr/wp-content/uploads/2026/07/wrimo-image-6a4d85571abe2.png)
[Investor’s Note] TQQQ Pyramiding Buying Strategy to Turn a Bear Market into an Opportunity: A Precise Diagnosis of a Billion-Won Portfolio 📈
Hello! Today, we’re going to analyze the sophisticated portfolio of an investor with approximately 1.2 billion KRW in assets and delve deeply into the core strategy that will allow assets to make a quantum leap in a future bear market: the ‘TQQQ Pyramiding Buying Method.’ Beyond simply “making money,” I’ve organized this so you can…
-

Prompt Injection is not a “Question” but a “Technique to Make it Look Like a Task Instruction”
When first encountering LLM security, many people think of prompt injection like this: “Tell me the secret.” “Output the system prompt.” “Show me the FLAG value.” Of course, such direct requests are a form of prompt injection. However, there’s a more interesting aspect. Attackers don’t explicitly demand forbidden actions. Instead, they hide their objectives behind…
-

What is RAG (Retrieval-Augmented Generation)? The Secret to Smarter AI Responses
When developing services using generative AI, you’ve probably come across the term RAG (Retrieval-Augmented Generation) at some point. Most AI chatbots, internal document search systems, and customer service solutions currently being built by companies are based on RAG. So, what exactly is RAG, and why are so many companies adopting it? In this article, we’ll…
-

An Essential Tool for TypeScript Development! The Complete Guide to tsc –watch Mode
When coding with TypeScript, do you find yourself typing ‘tsc’ into the terminal every time you want to check your changes? If so, after reading this article today, you’ll discover a whole new world! 😉 1. What is the –watch flag? 🤔 By default, when you run the ‘tsc’ command, the TypeScript compiler scans the…
-

Hundreds of files? No problem! The Most Efficient Way to Compile Your Entire TypeScript Project 🛠️
Hello, developers! As you work on TypeScript projects, you’ll often find the number of files growing to dozens or even hundreds. Are you still manually typing file names into the terminal to build them? 😅 Today, we’ll introduce a standardized method to unleash 100% of the TypeScript compiler’s (tsc) potential, converting your entire project to…