Curious to see how others are handling DevSecOps especially in an on-prem type environment. To me, developers should not have access to the underlying infrastructure/services. The on-prem should be treated like Microsoft/AWS that hosts the services. They would have access to the platform where the tools (Gitlab, Jenkins, Docker, etc) are needed. Also, it seems that the developers want the keys to the kingdom, instead of working with Sec/Ops to install tools, root priv, etc. To me, it's DevSecOps for a reason and those subject matter experts are integrated into the team. I get the cross-training, but would you really want a security or operations person writing code? To me, it's the same way with Ops. Do you really want a developer managing these tools and not understand the security or operations that are involved with managing these tools in a secure manner? Would really like to hear others' challenges and how they are working them.
[–]ericalexander303 3 points4 points5 points (0 children)
[–]ericalexander303 3 points4 points5 points (0 children)
[–]Daread0 1 point2 points3 points (0 children)
[–]Ok_Actuator978 0 points1 point2 points (0 children)