Aaron Rinehart takes us on a wonderful journey through Complexity, Testing in Production, and the advantages of Chaos Engineering for DevSecOps. Don't miss this great talk.
Monday, June 8, 2020
Sunday, June 7, 2020
Friday, June 5, 2020
Opinions!!
Everyone is very angry. I was looking for data and peer reviewed academic publications but they are difficult to sift through. This August 2019 study has almost no conclusions other than we don't gather enough data, But many journalists are citing that study to lend evidence to their own opinions. As Pinker keeps reminding us, the total number of urban fatal shootings keeps declining every year:
But this week we had car-b-q's, property damage, and theft, even in my sleepy little town.
Monday, June 1, 2020
Checklists are good
I am a fan of Atul Gawande's book and frequently try to use checklists for work-related activities. If you are trying to formulate a "launch readiness" checklist for your approval or release workflow for your backend applications, Aleksi Kornev's checklist is a good place to start.
Labels:
devops
Rejoiner Revisited
Google is seriously backing their GraphQL middleware (Rejoiner). Kris Sandoval takes us on a quick overview of why it is so appealing and cases where trying to use it are inappropriate (expensive database calls).
Labels:
devops
GitOps deployment pipelines explosion
It seems everyone and her uncle is jumping on the GitOps bandwagon to deploy continuously. Omer Kahani explains in his write-up how his company (Riskified) uses Argos continuous deployment in their pipeline.
Labels:
devops
GCP Audit Logging
DataDog gives us a guide to google cloud platform (GCP) audit logging and how to scan and use the logs. My company pushes our logs through existing scanners used for other types of logs. But these audit logs can be used for other purposes. It's relatively straightforward.
Labels:
devops
Meeker Report: Our New World - April 2020
Although her 2020 Internet report is not yet out, Mary Meeker published a report in April called "Our New World." Her reports and analysis are always worth skimming. I am hoping her Internet Report 2020 will come out this month.
Labels:
covid19
Sunday, May 31, 2020
Good primer for DevSecOps threat modeling
Jim Gumbley, writing in Martin Fowler's valuable web site, gives us a simple, and very-approachable primer for how to do threat modeling in DevSecOps. I had previously not seen the thrilling NotPetya story before and really enjoyed that real-life cyber thriller.
If you are a software developer or DevOps professional and your perception of DevSecOps and information security is simply "minimal compliance with draconian InfoSec policies," you are in for a frustrating experience and you will develop inferior software services.
Labels:
devops
Subscribe to:
Posts (Atom)












