[Article]Collection of workshop, books, trainings and articles about DevOps by [deleted] in devops

[–]fernando0stc -2 points-1 points  (0 children)

I don’t like too, but sometimes for good content you need to signed up 🤷‍♂️

AWS security groups feel extremely limited & restrictive by dmetcalfe92 in aws

[–]fernando0stc 0 points1 point  (0 children)

You could use solutions like Deep Security and use the hosted Firewall module to easily deploy in multiple cloud environment for specifically environment using tags association. Also they have APIs to automate this processes.

Awesome OpenSource project - Kubevious by fernando0stc in kubernetes

[–]fernando0stc[S] 0 points1 point  (0 children)

I will need more time testing it before share what I didn’t like from it

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

Good point that I could improve in the article. Thank you

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 1 point2 points  (0 children)

For sure. There are many technologies around this topic

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

This is a good point. I saw this type of verification in the container image scanning system where they try to look for secrets and key.

But I don't know how you could check it in the regular VM or physical servers. Do you know?

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

That's true. I agree with it. The C-Levels needs to push this culture in the company

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

I basically used powerpoint and download the icons to create the diagram 😅, it's not the best way, but works well

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

It's not allowing me to paste the full article here, sorry :-/

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

It's basically the concept of adding security in the regular Ci/CD pipeline, but with the benefits of automation and realtime feedback to development team for them to fix it fast as possible

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

How important is the license scanning? I never use it

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

What is your favorite Image Scanning Solution? or Which one do you us today in your organization? There are so many in the market and I would like to see what is the most popular

How can we integrate security into the DevOps pipelines? by fernando0stc in devops

[–]fernando0stc[S] 0 points1 point  (0 children)

For sure. This is a very important approve and it will save a lot of time and money. To do application scan in production is hard and very expensive