Learning · DevOps

Security in the DevOps loop

Shift-left without gate theater — secrets, supply chain, and shared responsibility for secure delivery.

DevOps without security is fast failure. Secure delivery means controls in the loop, not a final PDF audit that blocks releases surprising everyone.

Shift-left, realistically

Lint and scan early (deps, images, IaC, policies). Fail the build on high-confidence issues. Security partners on design for sensitive systems — not only on the Friday before launch.

Secrets and identity

Short-lived credentials, least privilege, no secrets in images or logs. App and pipeline identities are separate. Rotate and audit.

Supply chain

Pin actions and base images, sign when you can verify at deploy, control registries. Compromised CI is production compromise.

Runtime

Admission policies, NetworkPolicies, patched nodes, and least-privilege ServiceAccounts. Detection (audit logs, anomaly alerts) complements prevention.

Shared model

Security sets standards and enables; product owns fixing findings in their services; platform hardens the defaults. Finger-pointing is how vulns age in Jira.

← DevOps