Spinning the Wheel of Fortune for security
Security took center stage at Edgecase 2026 in Hilversum. Gerrit Tamboer, Chief Evangelist at TrueFullstaq, has learned a thing or two on that front, with some valuable lessons from Marcel Claassen of Sysdig. Together, they reported back in an interactive quiz.
Call it confidence or call it bravado, but Gerrit Tamboer once called himself the “LeBron James of vibe coding.” Yet his colleagues hacked his app within minutes. So what did he do? He called Marcel Claassen and asked for help. In public, mind you. What followed were a few tough lessons. At Edgecase, Tamboer took his final exam live, with the audience playing along as Claassen put some tough questions on cloud native security to everyone in the room.
A crash course
Tamboer told the audience he still remembers Claassen’s crash course vividly. “It was on one of the hottest days of the year. Over 40 degrees outside, and no air conditioning inside.” The sweaty sessions were recorded, and you can watch them in the video series Gerrit Learns Cloud Native Security. Highly educational for anyone.
Edgecase 2026: Gotta read 'em all
All the speakers, sessions, and insights from Edgecase 2026 in one place.
Encoded isn’t encrypted
That much became clear during the quiz at Edgecase 2026. Securing a Kubernetes environment takes more than scanning images and blocking vulnerabilities during the build. Plenty more comes into play: limited runtime visibility, misunderstood container permissions, and new vulnerabilities that surface after an image has already been deployed. One question asked whether Kubernetes Secrets are encrypted by default. Fortunately, the vast majority of participants picked the right answer: no. The session drew a clear line between encoding and actual encryption. Just because sensitive information isn’t stored as plain text doesn’t mean it’s protected by encryption.
Security concepts
Different security concepts are easily confused, as Gerrit’s final exam showed. Container permissions, privileges, and access to host paths are separate security aspects. That was the message. Many of the questions underlined that Kubernetes security isn’t a set of one-off checks you run at the start of a deployment. It covers the entire lifecycle of your workloads and infrastructure.
Wheel of Fortune
The jingles between questions were borrowed from Wheel of Fortune (remember that, boomer?), and the hosts wore glitter blazers. It turned out to be a tough session, but above all a fun one. And guess what? Gerrit passed! He didn’t take the top spot of the afternoon, though. The “LeBron James of vibe coding” finished ninth, which at least kept him in the top 10.