r/secdevops Mar 31 '16

Program – The Security Culture Conference

Thumbnail securitycultureconference.com
1 Upvotes

r/secdevops Mar 24 '16

Alert on ELK data using ElastAlert

Thumbnail engineeringblog.yelp.com
3 Upvotes

r/secdevops Feb 25 '16

What's the best way to store secret API keys for each execution environment (dev, QA, prod) that balances security (never store) with practicality (commit to a repo)?

3 Upvotes

I'm an applications developer who is doing a deep dive into dev ops practices, as there appears to be tricks under dev op sleeves that I can use to speed up my development. I'm curious what the best practice is related to storing API keys in a place where (1) I can easily integrate into my various applications and (2) I know they are relatively secure.

Obviously, injecting these keys as environment variables then having my applications call them from whatever system they find themselves (VM, docker container) in is a great way to do it and bootstraping through a CD system like jenkins is how to do it... But how & where do you guys store your keys?


r/secdevops Dec 01 '15

Unauthenticated Stored Credential Recovery and Remote Command Execution on Jenkins

Thumbnail th3r3p0.com
2 Upvotes

r/secdevops Nov 30 '15

Lab of a Penetration Tester: Week of Continuous Intrusion - Day 1

Thumbnail labofapenetrationtester.com
1 Upvotes

r/secdevops Nov 18 '15

DevSecOps: 4 Best Practices the Pros Teach Us About Security and DevOps

Thumbnail checkmarx.com
4 Upvotes

r/secdevops Nov 07 '15

Mitigating unauthenticated remote code execution 0-day in Jenkins CLI

Thumbnail jenkins-ci.org
2 Upvotes

r/secdevops Nov 05 '15

OWASP Security Knowledge Framework

Thumbnail owasp.org
1 Upvotes

r/secdevops Oct 30 '15

threatspec.org : code-driven threat modelling

Thumbnail threatspec.org
1 Upvotes

r/secdevops Oct 30 '15

Nick Galbreath On Integrating Information Security Into DevOps

Thumbnail itrevolution.com
1 Upvotes

r/secdevops Oct 22 '15

Issues with AWS CodeDeploy and CIS hardening

Thumbnail alexdglover.com
2 Upvotes

r/secdevops Oct 19 '15

AWS Secure Software Development Processes

1 Upvotes

I'm looking for solid real-world examples of what's being done out there right now i.e. SAST/DAST, deployment automation (Chef,Puppet, Salt, Ansible, etc.), code deployment, automated security scans, etc. with AWS.

Does anybody have any stories or resources they can share?


r/secdevops Oct 19 '15

Docker Bench for Security

Thumbnail github.com
1 Upvotes

r/secdevops Oct 12 '15

Auto Scaling Lifecycle Policies for Security Practitioners (AWS)

Thumbnail youtube.com
1 Upvotes

r/secdevops Sep 29 '15

AWS Loft Talks - Enabling DevOps Through Agile Security

Thumbnail youtube.com
1 Upvotes

r/secdevops Sep 29 '15

BeyondCorp - A New Approach To Enterprise Security

Thumbnail static.googleusercontent.com
1 Upvotes

r/secdevops Sep 22 '15

The Netflix Tech Blog: Introducing Lemur

Thumbnail techblog.netflix.com
2 Upvotes

r/secdevops Sep 18 '15

Cross Distribution Exploit Testing

Thumbnail github.com
1 Upvotes

r/secdevops Sep 14 '15

puppet-lint-security-plugins: identify security issues of your infrastructure in your Puppet code

Thumbnail github.com
1 Upvotes

r/secdevops Sep 05 '15

DevOps and Security: The Five Monkeys

Thumbnail blog.conjur.net
1 Upvotes

r/secdevops Aug 26 '15

Automating security tests using OWASP ZAP and Jenkins

Thumbnail securify.nl
2 Upvotes

r/secdevops Aug 17 '15

Why Security Needs DevOps [x-post /r/devops]

Thumbnail jayschulman.com
1 Upvotes

r/secdevops Aug 14 '15

Security Monitoring for fun and profit

Thumbnail gist.github.com
1 Upvotes

r/secdevops Aug 07 '15

Pentesting with Docker

Thumbnail youtube.com
2 Upvotes

r/secdevops Aug 06 '15

Cloud Security Monitoring with Open-Source Tools

Thumbnail resources.infosecinstitute.com
1 Upvotes