Security Culture: The Best Tool Money Can’t Buy

Security Culture: The Best Tool Money Can’t Buy

| | Best Practices
Building positive relationships, sharing knowledge effectively, and making security "cool" are some of the most worthwhile security pursuits ... Read More
Argo CD GitOps Demo

Make Deployments Great Again: How to Use Helm with Continuous Deployment (CD)

| | DevSecOps, Tutorials
Learn how to automate Helm deployments with GitOps, using Argo CD for continuous delivery. Seamlessly handle secrets, pod auto-restart, and version propagation in Kubernetes with this production-ready integration ... Read More
How to Handle Secrets in Go

How to Handle Secrets in Go

| | Best Practices, Tutorials
Learn the best practices for handling secrets in Go in the cloud-native ecosystem ... Read More
A Comprehensive Guide to SOPS: Managing Your Secrets Like A Visionary, Not a Functionary

A Comprehensive Guide to SOPS: Managing Your Secrets Like A Visionary, Not a Functionary

| | DevSecOps, Tutorials
Have you heard about SOPS? If you have already been in a situation where you needed to share sensitive information with your teammates, this is for you. Today, let's have a look at how it works and how to use it with various key management services such as AWS KMS ... Read More
Multicloud Security Architecture

Multicloud Security Architecture

| | DevSecOps
Using multiple cloud service providers isn't all benefits, it has its challenges. Today, let's have a look at multicloud: What it is, what are the challenges, especially security challenges, and what are the best practices towards a secure multicloud architecture ... Read More
How to Handle Secrets in Helm

How to Handle Secrets in Helm

Learn step-by-step techniques and best practices to handle secrets in Helm charts safely and effectively. Level up your Helm deployments today! ... Read More
The Story of Crush: The Microservice That Navigated the Cloud Native O... Mattias Gees & Tom Meadows

Getting Started With SPIFFE For Multi-Cloud Secure Workload Authentication

| | DevSecOps, Tutorials
SPIFFE stands for Secure Production Identity Framework for Everyone, and aims to replace single-factor access credentials with a highly scalable identity solution. This blog post provides some practical applications of SPIFFE in real-world environments ... Read More

Dependency Confusion Attacks and Prevention: Register Your Private Package Names

| | supply chain security
Dependency confusion attacks exploit gaps in your software supply chain. Dive into modern dependency management and learn how to defend your systems with best practices ... Read More
Always Be Updating

Always Be Updating

DevSecOps Engineer Gene Gotimer explains why constant software dependency updates are crucial for security in DevSecOps practices ... Read More
Making Sense of Open-Source Vulnerability Databases: NVD, OSV, and more

Making Sense of Open-Source Vulnerability Databases: NVD, OSV, and more

| | DevSecOps, SCA
Essential reading for developers and security professionals alike: a comprehensive comparison of vulnerability databases to help you cut through the noise ... Read More