The DevSecOps Talks Podcast

Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin
undefined
Mar 12, 2021 • 55min

DEVSECOPS Talks #25 -All The Things You Wanted To Know About Pulumi. Explained

This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about - what is Pulumi is? - understand the difference between Pulumi vs. Terraform (and if we should compare them at all) - What is hard about Pulumi? - What people ask the most? What are the common confusions? - Cross-language infra libraries? How is it even possible?! - Is there a possibility of a supply chain attack via Pulumi library? Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show. Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.
undefined
Feb 22, 2021 • 36min

DEVSECOPS Talks #24 - Ways To Protect Yourself From Data Breaches And Mitigate Consequences

Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).   Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show. Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Feb 5, 2021 • 37min

DEVSECOPS Talks #23 - How Do We Run Kubernetes In The Cloud?

How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings? We go through the list of things you might be missing out on if not yet using a managed solution. Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Jan 22, 2021 • 30min

DEVSECOPS Talks #22 - Who are Mattias, Julien and Andrey?

It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Jan 5, 2021 • 35min

DEVSECOPS Talks #21 - Surviving AWS Outage

AWS had a severe incident at the end of November. Kinesis in us-east-1 went dark for quite some time, and a ripple effect caused degradation of other services like CloudWatch, ECS, and others. As a Cloud Engineering practitioner, how do you get yourself and your organization ready for a such turn of events?   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Dec 7, 2020 • 31min

DEVSECOPS Talks #20-2020 - Monitoring Done Wrong or Dreaming For A Better Monitoring

Andrey wants monitoring to be more magical, or does he want a wrong thing? What are the sane defaults? And why do we have to set up boilerplate monitoring again and again?    Mattias shares what he does for monitoring security events.    Julien explains why using logs to debug in a microservices architecture is costly and inefficient.    Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Nov 23, 2020 • 31min

DEVSECOPS Talks #19-2020 - Deleting Resources In The Cloud

How to decommission resources from your cloud environment to keep it clean? What to do when a resource is created without being in the infrastructure code? Andrey is going through a checklist he uses to delete resources and the utility serverless functions he wrote. ArgoCD is a project that does GitOps and automatically delete resources in Kubernetes namespaces if they are not defined. We talked about the different layers of abstraction for infrastructure as code and where it makes sense to have a terraform controller in a Kubernetes cluster to manage the application dependencies. Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Oct 26, 2020 • 50min

DEVSECOPS Talks #18-2020 - HashiConf Special

Initially, we planned this episode as a discussion about HashiCorp Nomad and invited Jacob Lärfors. He recently published a great article about his experience working with Nomad (see link in the show notes). However, because of a few postponements, and with HashiConf that happened just a week ago, we decided to extend the podcast’s scope to go over all of the announcements that they did during the conference. So here it is - HashiConf special: all you need to know about everything that HashiCorp announced during the conference plus a discussion about Nomad! Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Oct 13, 2020 • 33min

DEVSECOPS Talks #17-2020 - Best Practices for Building Docker Images

This is the first episode in the new format - 30 minutes short and crisp episodes, i.e., less water and side discussions, focusing on the topic, duration under (well, almost under) 30 minutes. We hope you like it!   The topic of this episode is building docker images - automation, security, best practices.   In this episode, we discuss: Saving money with T3a family Building Docker images locally and in CI Setting up deamonless Docker builds for CI and k8s Using multistage builds to keep your images nice and clean as well as encapsulate the build environment and make it portable Passing secrets to Docker build and inspecting image layers for secrets (ssh-agent and many more) Keeping Docker images updated with dependencies and updates Scanning Docker images for vulnerabilities Docker image layers caching - doing it right DockerHub is to delete old images stored for free, and GitHub is ready to host them for you Docker image naming so you can find all you need to debug quickly   In some of the information overlaps with episode #3 but greatly extends information provided before https://devsecops.fm/episodes/docker-secure-build/   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
undefined
Sep 29, 2020 • 49min

DEVSECOPS Talks #16-2020 - Do you need a staging environment?

In this episode, we discuss options for splitting your deployment stages. We hear people coming up with all possible type of environments - dev, test/QA, integration, stage, prod, etc How many do you actually need? What is the reason for having all those stages? Maybe do you need less? Why not deploy directly to production using some fancy technique? Put it simply - stage or not to stage?   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app