<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Carlos Ulloque</title><description>Carlos Ulloque is a Mission Critical Engineer focused on building reliable systems, securing what matters, and sharing real-world lessons from infrastructure and product engineering.</description><link>https://ulloque.com/</link><item><title>Cloudflare Access Java JWT Validation Patterns</title><link>https://ulloque.com/notes/cloudflare-access-java-jwt/</link><guid isPermaLink="true">https://ulloque.com/notes/cloudflare-access-java-jwt/</guid><description>Validating Cloudflare Access identity in Java services without over-trusting the client — and locking the origin so the gate cannot be bypassed.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>Designing Private Routes with Zero Trust</title><link>https://ulloque.com/notes/zero-trust-private-routes-design/</link><guid isPermaLink="true">https://ulloque.com/notes/zero-trust-private-routes-design/</guid><description>Choosing how to actually gate a private route with Cloudflare Access — what it secures, where the bypass gaps are, and the misconfigurations that quietly leave it open.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item></channel></rss>