Containerization dominates the market nowadays. Fancy buzzwords like continuous
integration/deployment/delivery, microservices, containers, DevOps are floating
around, but what do they mean? What benefits do they offer compared to the old
dogmas? You’re gonna find out in our training!
We are going to start with the basics of Docker, Containers and DevOps, but soon
you’ll end up with your own applications running inside containers with the
images residing in your own registry. Of course, following the microservices
approach, and the second day hasn’t even started.After the fundamental topics of
containerization are understood, you’re going to create and operate your own
Kubernetes cluster. A lot of fun and challenging exercises lie ahead, to give
you hands-on experience with all the technologies.
Some time ago I had the pleasure to speak at the BASTA!
Autumn 2019 conference. There, I promised to publish my
slides
such that they can be used as a reference for developers and security guys like
me. And with this blog post I would like to hold up to my promise.
Overall, the talk was about the challenges of “How to bring security into modern
DevOps processes”. Hence, I demonstrated how security can be integrated more or
less seamlessly into the modern agile software development workflow. I proposed
some risk-depended recommendations about which measurements should be
established, for example, within the CI pipeline.
I had the pleasure to give a presentation at the
Security Interest Group Switzerland Technology Conference
about modern application stacks and how they can be used to improve
infrastructure and application security posture – the slides can be found
here.
Besides seeing a lot of old friends, I
particularly enjoyed a round table discussion on security integration into CI/CD
pipelines. There was a relevant exchange on approaches that actually work and
were tested in environments beyond just recommending some container scanner
(product). One participant had an interesting case study on how they enabled
developers to maintain WAF policies in configuration files in their code
repository including automated deployment to the WAF. He also emphasized that
the environments with actual security benefits resulted from a close cooperation
between development and security team (were domain knowledge was combined 😉 ).
This blogpost contains summaries of talks from this year’s
TROOPERS18 Defense & Management Track.
All Your Cloud Are Belong to Us
The talk “All Your Cloud Belong Are Belong to Us” was held by
Nate Warfield, who is a Senior Security Program
Manager for the Microsoft Security Response Center (MSRC).
Before Microsoft he worked as a network engineer about 18 years and 10 of this
for a large amount of cell phone companies.
Nate gives an overview about the state of the cloud solution provided by
Microsoft, Azure, and how he hunts vulnerabilities in this environment.
Finally he concludes that the giving up your infrastructure to the cloud doesn’t
mean that you give up your responsibility.
I’m a big fan of Chris Gates’ publications on
DevOops
and
From Low to Pwned.
The content reflects a lot of issues that we also experience in many assessments
in general and assessments
in agile environments in particular.
In addition, we were supporting several projects recently that were organized in
an agile way. In this post, I want to summarize some thoughts on how security
work can/should be integrated into agile projects. The post was also a result
from the preparation of our upcoming Troopers workshop on
Docker Security & Devops,
which of course also covers organizational aspects, but not to the degree this
post describes them.