<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Primcoat Blog</title>
    <link>https://primcoat.app/blog</link>
    <description>Practical guides to building, hardening, and publishing golden VM images: OpenSCAP CIS and STIG automation, QCOW2-to-AMI conversion, Windows Server images on Linux, SBOMs, and signing.</description>
    <language>en</language>
    <lastBuildDate>Wed, 08 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://primcoat.app/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Building a Windows Server AMI on Linux</title>
      <link>https://primcoat.app/blog/windows-server-ami-on-linux</link>
      <guid isPermaLink="true">https://primcoat.app/blog/windows-server-ami-on-linux</guid>
      <description>You can build a hardened Windows Server AMI entirely on a Linux build host with QEMU/KVM, virtio drivers, an unattended answer file, and Cloudbase-Init. Here is how the pieces fit — and why it takes an hour.</description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Converting a QCOW2 image to an AWS AMI</title>
      <link>https://primcoat.app/blog/qcow2-to-aws-ami</link>
      <guid isPermaLink="true">https://primcoat.app/blog/qcow2-to-aws-ami</guid>
      <description>A step-by-step guide to turning a QCOW2 disk built under QEMU/KVM into a bootable EC2 AMI using VM Import/Export — with the IAM, format, and regional gotchas that trip people up.</description>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Automating CIS and STIG hardening with OpenSCAP</title>
      <link>https://primcoat.app/blog/automating-cis-stig-hardening-openscap</link>
      <guid isPermaLink="true">https://primcoat.app/blog/automating-cis-stig-hardening-openscap</guid>
      <description>How to evaluate and auto-remediate a Linux image against a CIS Benchmark or DISA STIG using OpenSCAP and the SCAP Security Guide — and where doing it by hand goes wrong.</description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
