DevSecOps
Manifestly Safer, Why Kubernetes Wants Developers to Speak KYAML
KYAML gives Kubernetes developers a stricter, more predictable YAML dialect designed to reduce configuration errors, ambiguity, indentation problems and unexpected type coercion ...
Adrian Bridgwater | | CI/CD, cloud native, cloud native security, cloud-native architecture, configuration management, containers, devops, DevSecOps, Helm, KEP 5295, kubectl, kubernetes, Kubernetes configuration, Kubernetes manifests, Kubernetes security, Kubernetes YAML, KYAML, open source, platform engineering, SIG CLI, YAML, YAML errors
From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
The standard process of building governance, risk, and compliance (GRC) programs has been straightforward: define a control, document a control, test the control on a regular basis, and generate a report for ...
Echo Acquires Hardened Container Assets from Minimus
Echo today revealed it has acquired technology assets from Minimus, a provider of hardened open source container images, that earlier this week revealed it is shutting down. Those assets will later be ...
Securing North-South Traffic in AKS Using Application Gateway, WAF and AGIC
Secure AKS north-south traffic with Application Gateway, WAF and AGIC, combining Layer 7 protection, end-to-end TLS, private back ends and strong ingress visibility ...
Olaitan Falolu | | AGIC, AKS security, Application Gateway Ingress Controller, application security, Azure Application Gateway, Azure Kubernetes Service, Azure security, cloud native security, DevSecOps, end-to-end TLS, Ingress controller, ingress protection, Kubernetes ingress security, Kubernetes networking, Kubernetes security, Layer 7 security, north-south traffic, private AKS, WAF, web application firewall
Docker Hub vs. Private Registries: Security Tradeoffs
In the race to accelerate software delivery, Docker Hub has become a default starting point for developers and organizations alike. It offers convenience, accessibility, and a vast ecosystem of pre-built images that ...
How Base Images Impact Software Supply Chain Security in Kubernetes
As organizations scale their Kubernetes environments, the software supply chain becomes increasingly complex, interconnected, and vulnerable. One of the most overlooked yet foundational components of this supply chain is the base image ...
Container Runtime Security in Kubernetes: What Teams Overlook
Kubernetes security conversations tend to center on the things that happen on the left-hand side of the process. Scanning images, hardening Dockerfiles, and working with registry access controls all tend to frontload ...
Hardening the Core: Container Validation and Malicious Package Defense
Docker images are becoming a major software supply chain risk. Learn why scanning alone is not enough and how layered security can protect containers from build to runtime ...
Sean Roth | | CI/CD security, cloud native security, container image vulnerabilities, container isolation, container registries, container runtime security, container security, container vulnerability scanning, dependency security, DevSecOps, Docker hardening, Docker image security, image lifecycle security, image validation, malicious container images, malicious packages, minimal base images, non-root containers, runtime protection, SBOM, secure build practices, secure Docker images, software supply chain security, zero-day threats
Building a Secure Software Development Lifecycle (SSDLC) for Cloud-Native Teams
As cloud-native architectures continue to redefine how applications are built and deployed, security must evolve alongside them. Often bolted on at the end of development, traditional approaches are no longer sufficient in ...
The Pipeline That Thinks: Building an AI-Powered DevSecOps Pipeline on AWS EKS
The organizations building pipelines that think, review, secure, monitor and recover, are defining what the next baseline looks like ...

