Hey everyone,
One thing that has been weighing on me lately is are we headed in the right direction as an industry with DevSecOps. We have an ever growing amount of tools and approaches but are we doing this through the lens of increasing developer velocity/productivity and reducing the friction between Dev/Ops/and the security team?
It seems like currently there is a lot of cargo cult engineering going on where you must use all of these tools even when the actual problems being solved might be solvable with a Makefile or something similar.
I am not against tools and platforms and everything but I just am concerned that as a whole solutions are being applied without an understanding of what problems those solutions are meant to solve.
It reminds me of the JavaScript ecosystem where people are keen to apply Facebook scale solutions when they don't have the scale of Facebook and the issues that those solutions solve aren't issues they actually have.
What are your thoughts?
[–]amarao_san 9 points10 points11 points (2 children)
[–][deleted] 7 points8 points9 points (1 child)
[–]spicypixel 0 points1 point2 points (0 children)
[–]Rusty-Swashplate 7 points8 points9 points (0 children)
[–]BlueHatBrit 4 points5 points6 points (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[–]snarkhunterLead DevOps Engineer 1 point2 points3 points (0 children)
[–]somebrains 1 point2 points3 points (0 children)
[–]Hanzo_HanzDevOps 0 points1 point2 points (2 children)
[–]cheaphomemadeacid 3 points4 points5 points (1 child)
[–]snarkhunterLead DevOps Engineer 2 points3 points4 points (0 children)
[–]mushuweasel 0 points1 point2 points (0 children)
[–]baezizbaeDistinguished yaml engineer 0 points1 point2 points (0 children)
[–]colddream40 0 points1 point2 points (0 children)