DevTestSecOps
138 subscribers
468 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
Infrastructure_as_Code_Patterns_and_Practices_With_examples_in_Python.pdf
12.8 MB
Infrastructure as Code with #Python

Book will be useful for #DevOps beginning to use #cloud infrastructure and IaC.

The book has examples in Python, run by HashiCorp Terraform, and deployed to Google Cloud Platform (GCP)
#DevOps #job

Good choice for interviews.
#testing

What should you learn to become a Quality Engineer? What languages should you pick up, what tools should you master, what skills should you practice? If someone was interested in this career, where would you tell them to start—what’s critical, what’s nice-to-have, and what is yesterday’s technology that is no longer relevant?

https://medium.com/slalom-build/quality-engineer-learning-roadmap-fddfcb77409e
👏1
😁2🤯1
- So, can you switch your logs to just go to stdout instead of file?
- Yeah, sure. So, orchestrator will pick them up?
- Right.
- And redirect them where?
- File.
🔥1
Zero-Trust-K8s.pdf
599.7 KB
How the Zero Trust model improves the #security posture of #k8s infrastructure and prevents security incidents from damaging organization.

Find out:

* The key concepts and principles of the Zero Trust security model
* How Zero Trust improves the security posture
* The technical requirements for Zero Trust in Kubernetes
* How to apply Zero Trust best practices in Kubernetes environment
#security

Q: I am looking for some benchmarking/overview/comparison for SAST Tools to help to the customer with the selection. Maybe somebody has something like that? It must not be fancy. Even your personal opinion is appreciated here.

Right now I am preferring to have 2x tools witched in the pipeline one after the other:
* SonarQube/SonarCloud
* Snyk

Thanks a lot for every hint in advance!

A1: Personally I prefer SonarQube for it's easiness of use and configuration and plethora of plugins.
But SNYK would add you also DAST capabilities - so, maybe it should be your tool of a choice, as it effectively replaces 2 tools

A2: As a good starting point I'll recommend to read the following pages:

1. https://owasp.org/www-project-benchmark/

2. https://owasp.org/www-community/Source_Code_Analysis_Tools

3. https://www.nist.gov/itl/ssd/software-quality-group/samate/static-analysis-tool-exposition-sate

4. https://www.gartner.com/reviews/market/application-security-testing
👍1
Happy Computer Security Day!
😁2🎉2👨‍💻1👀1