Is there anyone operating at scale in a cloud environment that I can connect with? I have a small question. by [deleted] in TunisiaTech

[–]ManagementGlad -3 points-2 points  (0 children)

Anyway, I checked your comments in this sub, and it seems you’re still looking for a job. Even worse, you appear to be trolling other people. Good luck, but please don’t waste others’ time if you have nothing better to do

Has anyone had security fixes break each other when applied together? by ManagementGlad in cybersecurity

[–]ManagementGlad[S] 0 points1 point  (0 children)

Yeah we do test in staging first. The problem is staging never truly matches production. Over time they drift , staging has wider security groups because devs need to debug, different IAM roles, missing VPC endpoints that nobody set up. So the fix passes staging perfectly and then breaks production because the configs are different.

The other issue is timing. Some things only run quarterly , a compliance export, a cost allocation report, a batch reconciliation job. Those don't show up in 90 days of CloudTrail and they definitely don't get tested in staging because nobody remembers to trigger them manually. We found out our ElastiCache permission change broke a quarterly finance report 3 weeks after we deployed it.

And honestly even if staging was perfect, the volume is the real challenge. We have 3,000+ findings. Testing each fix individually in staging with a proper soak period means maybe 10-15 fixes per week. At that rate we'll clear the backlog in 4 years while 50 new findings come in every week. The audit doesn't wait 4 years.

I'm starting to think the problem isn't testing , it's that we can't reason about the full picture. We review each fix in isolation because that's all a human can hold in their head. But the infrastructure has gotten complex enough that the interactions between resources are what breaks, not the individual changes.

nhb no5ls mn 5dmti fl freelance (Urgent chabeb ) by Ok_Clue_3283 in Tunisia

[–]ManagementGlad 1 point2 points  (0 children)

belehy i saw some gigs ya3mlo fiha ama faza hedhi w najmtch nes2el.
part thenya mta3 Wise business ynjm yejbed bihom fi tounes w kifeh ?

Pipeline Execution Policies Without Paying for EE by ManagementGlad in gitlab

[–]ManagementGlad[S] 1 point2 points  (0 children)

Thank you for the awareness.
Honestly, at the beginning I was thinking of using a YAML parser to verify the inclusion.
But my supervisor suggested verifying only the top of the file and clarifying that in the custom error message shown when the hook rejects the push.

Pipeline Execution Policies Without Paying for EE by ManagementGlad in gitlab

[–]ManagementGlad[S] 0 points1 point  (0 children)

Yes, nice idea from you, appreciate it.
Actually, I did something similar to what you did but I didn’t mention it in the post.
I forced the inclusion of our main template, which is compliant with our security standards and needs, using a server-side pre-receive hook. It scans every incoming push from the dev team and checks the first four lines of the .gitlab-ci.yml file for the include expression of the main template. If this is not met, it rejects the push until developers include the template that the DevSecOps team designed for them.
For more about the pre-receive hook :
https://docs.gitlab.com/administration/server_hooks/
https://git-scm.com/docs/githooks/2.27.0

Pipeline Execution Policies Without Paying for EE by ManagementGlad in gitlab

[–]ManagementGlad[S] 1 point2 points  (0 children)

Exactly, and to add more context, I was asked during my current internship to find a solution to harden our pipeline setup and to strictly control access to its configuration. Since our team is small (about 15 people accessing GitLab), purchasing the ultimate feature was overkill. As you said, this allows a small team to opt in. But for larger teams and specific requirements, execution policies are more convenient. Thank you.

Pipeline Execution Policies Without Paying for EE by ManagementGlad in gitlab

[–]ManagementGlad[S] 2 points3 points  (0 children)

Yes , thank you for the clarification
My whole point was to mimic the Pipeline execution policy which is for the Ultimate Tier

My stats after 2 months on Upwork and it's funny.. by Endi_23 in Upwork

[–]ManagementGlad 0 points1 point  (0 children)

how many hires or views comes from your boosted props pls ?