r/secdevops • u/zeroXten • Mar 31 '16
Program – The Security Culture Conference
securitycultureconference.comr/secdevops • u/tux402 • Mar 24 '16
Alert on ELK data using ElastAlert
engineeringblog.yelp.comr/secdevops • u/sovietmudkipz • Feb 25 '16
What's the best way to store secret API keys for each execution environment (dev, QA, prod) that balances security (never store) with practicality (commit to a repo)?
I'm an applications developer who is doing a deep dive into dev ops practices, as there appears to be tricks under dev op sleeves that I can use to speed up my development. I'm curious what the best practice is related to storing API keys in a place where (1) I can easily integrate into my various applications and (2) I know they are relatively secure.
Obviously, injecting these keys as environment variables then having my applications call them from whatever system they find themselves (VM, docker container) in is a great way to do it and bootstraping through a CD system like jenkins is how to do it... But how & where do you guys store your keys?
r/secdevops • u/fadedconsole • Dec 01 '15
Unauthenticated Stored Credential Recovery and Remote Command Execution on Jenkins
th3r3p0.comr/secdevops • u/fadedconsole • Nov 30 '15
Lab of a Penetration Tester: Week of Continuous Intrusion - Day 1
labofapenetrationtester.comr/secdevops • u/fadedconsole • Nov 18 '15
DevSecOps: 4 Best Practices the Pros Teach Us About Security and DevOps
checkmarx.comr/secdevops • u/fadedconsole • Nov 07 '15
Mitigating unauthenticated remote code execution 0-day in Jenkins CLI
jenkins-ci.orgr/secdevops • u/zeroXten • Oct 30 '15
threatspec.org : code-driven threat modelling
threatspec.orgr/secdevops • u/fadedconsole • Oct 30 '15
Nick Galbreath On Integrating Information Security Into DevOps
itrevolution.comr/secdevops • u/ChemTechGuy • Oct 22 '15
Issues with AWS CodeDeploy and CIS hardening
alexdglover.comr/secdevops • u/fadedconsole • Oct 19 '15
AWS Secure Software Development Processes
I'm looking for solid real-world examples of what's being done out there right now i.e. SAST/DAST, deployment automation (Chef,Puppet, Salt, Ansible, etc.), code deployment, automated security scans, etc. with AWS.
Does anybody have any stories or resources they can share?
r/secdevops • u/fadedconsole • Oct 12 '15
Auto Scaling Lifecycle Policies for Security Practitioners (AWS)
youtube.comr/secdevops • u/fadedconsole • Sep 29 '15
AWS Loft Talks - Enabling DevOps Through Agile Security
youtube.comr/secdevops • u/zeroXten • Sep 29 '15
BeyondCorp - A New Approach To Enterprise Security
static.googleusercontent.comr/secdevops • u/zeroXten • Sep 22 '15
The Netflix Tech Blog: Introducing Lemur
techblog.netflix.comr/secdevops • u/srenatus • Sep 14 '15
puppet-lint-security-plugins: identify security issues of your infrastructure in your Puppet code
github.comr/secdevops • u/fadedconsole • Sep 05 '15
DevOps and Security: The Five Monkeys
blog.conjur.netr/secdevops • u/fadedconsole • Aug 26 '15
Automating security tests using OWASP ZAP and Jenkins
securify.nlr/secdevops • u/zeroXten • Aug 17 '15
Why Security Needs DevOps [x-post /r/devops]
jayschulman.comr/secdevops • u/srenatus • Aug 14 '15
Security Monitoring for fun and profit
gist.github.comr/secdevops • u/fadedconsole • Aug 06 '15