DevSecOps in Practice: What I Actually Implement
The concrete pipeline configs, policy-as-code patterns, and runtime controls I set up to bake security into delivery.
Devsecops coverage in this archive spans 3 posts from Jul 2017 to Apr 2021 and frames devsecops as continuous risk reduction instead of one-time policy work. The strongest adjacent threads are security, devops, and ci/cd. Recurring title motifs include devsecops, practice, implement, and software.
The concrete pipeline configs, policy-as-code patterns, and runtime controls I set up to bake security into delivery.
What SolarWinds taught us about supply chain security, and the concrete steps I've been implementing at enterprise scale.
Your manual security gate is a bottleneck pretending to be a process. Here's how I moved security checks into the pipeline at the fintech startup so we could ship fast without shipping stupid.