Encryption

gocrypt: a tiny AES-GCM file encryption CLI

A small Go command-line tool to encrypt and decrypt files with AES-128 or AES-256 in GCM mode

Sometimes you just need to encrypt a file. Not set up a key management system, not learn the gpg command line again, not pull a heavy dependency — just turn secrets.txt into secrets.bin with a key you control. That’s the niche gocrypt fills for me.

Tools golang encryption aes

Securely Deleting Files on Linux and macOS (Beyond shred)

A practical guide to securely erasing files on Linux and macOS — secure-delete, wipe, blkdiscard, hdparm, nvme-cli, and why encryption is the real answer

shred is the tool everyone reaches for, but it’s far from the only one — and on modern SSDs and journaling filesystems, it’s often the wrong one. This post covers the alternatives: secure-delete, wipe, blkdiscard, hdparm, nvme-cli, and the macOS equivalents — plus why full-disk encryption is now the recommended approach for serious data hygiene.

Linux linux macos security

gitlab-backup2s3: Encrypted GitLab Backups to S3, with Kubernetes Support

A Docker image wrapping gitlab-backup with AES-GCM encryption and Kubernetes CronJob deployment for automated, secure GitLab backups to S3

gitlab-backup2s3: Encrypted GitLab Backups to S3, with Kubernetes Support

Source code: github.com/sgaunet/gitlab-backup2s3 Helm chart: github.com/sgaunet/helm-gitlab-backup2s3

In the previous article, I covered gitlab-backup, a CLI tool for exporting GitLab projects and groups as portable archives. It handles the export, the restore, and supports both local and S3 storage natively.

But for production backup workflows — especially in a Kubernetes environment — you often want more: scheduled execution, optional encryption at rest, and a container image that bundles everything together. That’s exactly what gitlab-backup2s3 brings to the table.

DevOps gitlab backup s3