<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DevOps on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/devops/</link>
    <description>Recent content in DevOps on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 02 Dec 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/devops/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS20 Training Teaser: Swim with the whales – Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Mon, 02 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Containerization dominates the market nowadays. Fancy buzzwords like continuous integration/deployment/delivery, microservices, containers, DevOps are floating around, but what do they mean? What benefits do they offer compared to the old dogmas? You’re gonna find out in our training!&lt;/p&gt;&#xA;&lt;p&gt;We are going to start with the basics of Docker, Containers and DevOps, but soon you’ll end up with your own applications running inside containers with the images residing in your own registry. Of course, following the microservices approach, and the second day hasn’t even started.After the fundamental topics of containerization are understood, you’re going to create and operate your own Kubernetes cluster. A lot of fun and challenging exercises lie ahead, to give you hands-on experience with all the technologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Autumn 2019 – Security in DevOps</title>
      <link>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</guid>
      <description>&lt;p&gt;Some time ago I had the pleasure to speak at the &lt;a href=&#34;https://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Autumn 2019 conference. There, I promised to publish my &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2019/11/201909_BASTA_DevOps-Sc_v1.0.pdf&#34;&gt;slides&lt;/a&gt; such that they can be used as a reference for developers and security guys like me. And with this blog post I would like to hold up to my promise.&lt;/p&gt;&#xA;&lt;p&gt;Overall, the talk was about the challenges of “How to bring security into modern DevOps processes”. Hence, I demonstrated how security can be integrated more or less seamlessly into the modern agile software development workflow. I proposed some risk-depended recommendations about which measurements should be established, for example, within the CI pipeline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Modern Application Stacks &amp; Security</title>
      <link>https://insinuator.net/2018/06/modern-application-stacks-security/</link>
      <pubDate>Fri, 15 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/modern-application-stacks-security/</guid>
      <description>&lt;p&gt;I had the pleasure to give a presentation at the &lt;a href=&#34;https://www.sig-switzerland.ch/conference/sigs-technology-conference/&#34;&gt;Security Interest Group Switzerland Technology Conference&lt;/a&gt; about modern application stacks and how they can be used to improve infrastructure and application security posture – the slides can be found &lt;a href=&#34;https://ernw.de/download/ERNW_SIG_Cloud_ModernAppStackSecurity_mluft.pdf&#34;&gt;here&lt;/a&gt;. Besides seeing a lot of &lt;a href=&#34;https://twitter.com/ioshints&#34;&gt;old friends&lt;/a&gt;, I particularly enjoyed a round table discussion on security integration into CI/CD pipelines. There was a relevant exchange on approaches that actually work and were tested in environments beyond just recommending some container scanner (product). One participant had an interesting case study on how they enabled developers to maintain WAF policies in configuration files in their code repository including automated deployment to the WAF. He also emphasized that the environments with actual security benefits resulted from a close cooperation between development and security team (were domain knowledge was combined 😉 ).&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Defense &amp; Management Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Defense &amp;amp; Management Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;all-your-cloud-are-belong-to-us&#34;&gt;All Your Cloud Are Belong to Us&lt;/h1&gt;&#xA;&lt;p&gt;The talk “All Your Cloud Belong Are Belong to Us” was held by &lt;a href=&#34;https://twitter.com/dk_effect&#34;&gt;Nate Warfield&lt;/a&gt;, who is a Senior Security Program Manager for the Microsoft Security Response Center (MSRC).&lt;br&gt;&#xA;Before Microsoft he worked as a network engineer about 18 years and 10 of this for a large amount of cell phone companies.&lt;br&gt;&#xA;Nate gives an overview about the state of the cloud solution provided by Microsoft, Azure, and how he hunts vulnerabilities in this environment.&lt;br&gt;&#xA;Finally he concludes that the giving up your infrastructure to the cloud doesn’t mean that you give up your responsibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Agile Development &amp; Security</title>
      <link>https://insinuator.net/2017/02/agile-development-security/</link>
      <pubDate>Sun, 26 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/agile-development-security/</guid>
      <description>&lt;p&gt;I’m a big fan of Chris Gates’ publications on &lt;a href=&#34;https://www.slideshare.net/chrisgates/devoops-redux-ken-johnson-chris-gates-appsec-usa-2016&#34;&gt;DevOops&lt;/a&gt; and &lt;a href=&#34;http://www.carnal0wnage.com/papers/LARES-From-Low-To-Pwned.pdf&#34;&gt;From Low to Pwned&lt;/a&gt;. The content reflects a lot of issues that we also experience in many assessments in general and assessments &lt;a href=&#34;https://wycd.net/posts/2017-02-21-ibm-whole-cluster-privilege-escalation-disclosure.html&#34;&gt;in agile environments in particular&lt;/a&gt;. In addition, we were supporting several projects recently that were organized in an agile way. In this post, I want to summarize some thoughts on how security work can/should be integrated into agile projects. The post was also a result from the preparation of our upcoming Troopers workshop on &lt;a href=&#34;https://www.troopers.de/events/troopers17/730_docker_security__secdevops/&#34;&gt;Docker Security &amp;amp; Devops&lt;/a&gt;, which of course also covers organizational aspects, but not to the degree this post describes them.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
