Security in the DevOps loop
Shift-left without gate theater — secrets, supply chain, and shared responsibility for secure delivery.
DevOps without security is fast failure. Secure delivery means controls in the loop, not a final PDF audit that blocks releases surprising everyone.
Shift-left, realistically
Lint and scan early (deps, images, IaC, policies). Fail the build on high-confidence issues. Security partners on design for sensitive systems — not only on the Friday before launch.
Secrets and identity
Short-lived credentials, least privilege, no secrets in images or logs. App and pipeline identities are separate. Rotate and audit.
Supply chain
Pin actions and base images, sign when you can verify at deploy, control registries. Compromised CI is production compromise.
Runtime
Admission policies, NetworkPolicies, patched nodes, and least-privilege ServiceAccounts. Detection (audit logs, anomaly alerts) complements prevention.
Shared model
Security sets standards and enables; product owns fixing findings in their services; platform hardens the defaults. Finger-pointing is how vulns age in Jira.