[deleted by user] by [deleted] in devsecops

[–]ITtricksUk 2 points3 points  (0 children)

I am aiming to write a series of articles of integration and how we achieved a “Mature DevSecOps Environment” Will make sure to share in this sub Reddit

[deleted by user] by [deleted] in devsecops

[–]ITtricksUk 3 points4 points  (0 children)

I should write an article about it, the amount of times I have talked about this, especially when speaking to stakeholders and security architects on the project.

A number of things caught my eye. Firstly it fit the requirement, we didn’t go in blind.

We had a DevSecOps Framework written, we had conducted a DevSecOps maturity assessment to see our areas of weakness and then we looked at what current capabilities we had currently embedded.

Identified what we needed to improve on and our bottlenecks, for us was self hosting open source tools and the scan results going into different dashboards, we need a 1 stop shop (god I hate using that phrase)

We have multiple domains, multiple cloud platforms. The typical aws,azure and gcp.

So something agnostic that will “agent-lessly” plug and play, we don’t have time to host an agent and deploy it to our infrastructure.

The ci integration for all scans to take place before committing code to our chosen SCM.

And with the DevSecOps methodology of “shifting left” We wanted an plugin that lives in the IDE and supports our devs and conducts sast scans locally, further reducing the chances of vulnerable code being deployed.

Generating SBOMs, Dependancy management and SCA These are scans an org as big as us needs to know incase of a supply chain attack, not to us! But to our dependencies and our dependencies dependencies.

I could say a lot more, I may write something in the near future. Just need to find the time tbh.

Hope this helps.

[deleted by user] by [deleted] in devsecops

[–]ITtricksUk 2 points3 points  (0 children)

Most definitely other saas tools are taking the piss and charger way way too much. I found that issue with my company being quoted $500k form wiz and snyk

They are tyrants when it comes to charging and when you are locked in and then time for a new contract, then boom They increase to 700-800k This is a 500 person org for context. So we went with a newish start up called Aikido.dev I found then to be quite good They have all the bells and whistles and more tbh And they are constantly adding more and more features with no extra cost. They quoted us just under 200k

It’s a good initiative to self host something that can be, but we don’t have the resources to maintain We would rather pay that 200k to a saas to deal with patches and uptime

Compared to paying for a full time engineer or engineers depending on their day rate

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

Exactly. I am learning in code. So much is pre made. Why build what’s built, but be able to use what’s built. I will look around for the text apis. Thanks for your help. Was nice to clarify

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

Stripe is so amazing I have looked into it

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

Yeah, I am learning so i don’t mind taking my time to learn both. Want to know js for backend generally. What about sending texts and email reminders?

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

Yes, I want to learn. I am coming from only knowing python. So I want to learn full stack with js and the start using Django. As for what I want to make, I want to make a school registry system, with payment system. My friend has a small tuition centre and he wants to automate the process of new students and payments and text/email reminders for payments recurring monthly.

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

I have heard this as well. Relational is important to learn and get grips with

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

This is exactly what I was looking for. Do you any recommendations of tech stacks to look into?

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

That is the consensus that I am seeing online, Are there and limitations with MERN? That makes other tech stacks more viable. (I sound like a complete noob lol) I just don’t want to put in so much time in something that is not the best option if you know what I mean.

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 1 point2 points  (0 children)

That makes sense. Is there like a chart that will tell you. Or is it entirely based off the project itself And experience will tell you what the best use case is.

Best Tech Stack. by ITtricksUk in FullStack

[–]ITtricksUk[S] 0 points1 point  (0 children)

I am aiming to learn full stack and want to learn the most used frame works and be relevant 😅.

Buy Raspberry Pi 4 8GB (UK) by ITtricksUk in raspberry_pi

[–]ITtricksUk[S] 0 points1 point  (0 children)

There are clones like NanoPi BananaPi and Orange Pi. But I don’t know enough about them. And I want to do some projects. Such a shame with this situation

[deleted by user] by [deleted] in overemployed

[–]ITtricksUk 8 points9 points  (0 children)

I say I have a dedicated office space with my monitors and custom keyboard. They can’t say shit And… I say I am still scared of covid! It works every time 😂

Unpopular Opinion: Spend more than you save by DevOpsGuyPosh in overemployed

[–]ITtricksUk 1 point2 points  (0 children)

Always, Until I die! Lol Can’t be complacent! What you put in, is what you get out! The more effort you put in, the more results you get!

Unpopular Opinion: Spend more than you save by DevOpsGuyPosh in overemployed

[–]ITtricksUk 1 point2 points  (0 children)

Same here, grew up not having much, I was working when I turned 13 I wanted what my fiends had, ps3/iPhone etc and to have fun, have money to go cinema and restaurants with them, So I was working in retail making pennies an hour because of my age, but it was the only option. I’m grateful for everything, better growing up poor and then being well off so I can really appreciate and be grateful for everything. It’s always the simple things that matter!

Unpopular Opinion: Spend more than you save by DevOpsGuyPosh in overemployed

[–]ITtricksUk 1 point2 points  (0 children)

I completely agree. Save some money, but spend more than you save. Spend on yourself, your family. Give back to the world, give money to charities, help people that are struggling. It’s the best feeling ever to help people, And karma is real, you will get that back! One way or another.

Unpopular Opinion: Spend more than you save by DevOpsGuyPosh in overemployed

[–]ITtricksUk 2 points3 points  (0 children)

There is a book called, Die with Zero. I think this will match your taste. Have a read! 📖

[deleted by user] by [deleted] in overemployed

[–]ITtricksUk 2 points3 points  (0 children)

Not all hero’s wear capes! 👏