This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do the right technology bets, help their organizations to deliver value, and last but not the least to have some fun. Tune in for talks about technology, ways of working, and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show n ...
…
continue reading

1
#79 - Going Local: What’S Driving The Move?
20:31
20:31
Play later
Play later
Lists
Like
Liked
20:31Andrey, Paulina, and Mattias kick off a miniseries on European infrastructure. We talk about infrastructure providers' options across Europe, ask what really drives the move away from hyperscalers, and wonder whether the trade-offs make sense for most teams. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are ha…
…
continue reading

1
#78 - Building AI Tools For IaC Compliance
41:12
41:12
Play later
Play later
Lists
Like
Liked
41:12In this guest episode, we chat with Davlet Dzhakishev, co-founder of Cloudgeni, who’s working on an AI-powered approach to fixing compliance issues in IaC. What’s the state of tools in this space? Where does his idea fit in? And how should we think about the relationship between compliance and security? Connect with us on LinkedIn or Twitter (see i…
…
continue reading

1
#77 - Chaos Engineering Explained: Part 2
34:30
34:30
Play later
Play later
Lists
Like
Liked
34:30Part two of our chaos engineering series is here! Join Andrey, Mattias, and Paulina as they talk through practical strategies for chaos engineering. Who should do it? How can you start? And what are the essential prerequisites? Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, he…
…
continue reading

1
#76 - Chaos Engineering Explained: Part 1
26:29
26:29
Play later
Play later
Lists
Like
Liked
26:29Chaos engineering—is it really chaos, or something more structured? Andrey, Paulina, and Mattias talk about what chaos engineering means, how it started, and why you might already be using it unintentionally. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for …
…
continue reading

1
#75 - Learning from the Crisis: Post-Incident Actions
24:18
24:18
Play later
Play later
Lists
Like
Liked
24:18This is the final episode of our three-part series on incident response. We focus on what happens after the dust settles. How do you learn from what went wrong and avoid repeating it? Tune in to hear our top recommendations. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear …
…
continue reading

1
#74 - From Preparation To Execution: Handling An Active Incident
27:50
27:50
Play later
Play later
Lists
Like
Liked
27:50What keeps an incident from spiraling out of control? How can you organize your team on the spot? We continue our series on incident response, moving from preparation to real-time actions. Mattias shares key points from his course. Listen to learn how we handle incidents step by step. Connect with us on LinkedIn or Twitter (see info at https://devs…
…
continue reading

1
#73 - Incident Response: Key Preparations You Need
38:23
38:23
Play later
Play later
Lists
Like
Liked
38:23Incident response can be complex, but where do you start? Andrey, Mattias, and Paulina dive into the preparation steps you need to take. Mattias shares his expertise from teaching an incident response course. What’s their top recommendation? Listen and find out! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We ar…
…
continue reading

1
#72 - AWS Resource Control Policies (RCPs)
21:25
21:25
Play later
Play later
Lists
Like
Liked
21:25We are looking into recently announced AWS Resource Control Policies. What are they? How are they different from Service Control Policies? What is a Data Perimeter? Tune in to find out! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear f…
…
continue reading

1
#71 - Unpacking The Dora Accelerate State Of Devops Report
40:49
40:49
Play later
Play later
Lists
Like
Liked
40:49In this episode, Andrey, Mattias, and Paulina break down the new DORA Accelerate State of DevOps report. What’s changed since the last report? What do these insights mean for your team? Tune in for our insightful conversation! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hea…
…
continue reading
Andrey, Mattias, and Paulina are joined by Paul Stack, an IaC tools developer and a frequent guest on the show. He’s back to discuss the general availability of System Initiative and share what has changed since his last visit when they talked about the early beta of the tool. Will this be a revolution or evolution in Infrastructure as Code tooling…
…
continue reading
Join Andrey and Mattias as they sit down with Paulina Dubas, an independent DevOps consultant and public speaker. Who is Paulina, and what experiences does she bring to the table? What topics particularly resonate with her? Tune in to learn more about Paulina since we have a feeling that she is here to stay Connect with us on LinkedIn or Twitter (s…
…
continue reading
Julien shares big news with co-hosts Mattias and Andrey. What led to his decision to step down? And what does the future hold for him? Tune in for the off-boarding interview as we look back at the past four years and 60+ episodes we did together! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answe…
…
continue reading
Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they delve into building Minimum Viable Products (MVPs) and selecting the best solutions for them. Andrey goes first and, as an AWS consultant, kicks off the discussion by outlining his preferred AWS services for MVP development. Connect with us on LinkedIn or Twitter (see info …
…
continue reading

1
#66 - Multi-Account Strategy And Landing Zones: Account Segmentation Approaches For Security And Efficiency On AWS
58:14
58:14
Play later
Play later
Lists
Like
Liked
58:14In this episode of DevSecOps Talks, co-hosts Andrey, Julien, and Mattias are joined by AWS Consultant Fernando Gonçalves to explore the complexities of AWS organization and account segmentation. Get insights into the debate over development, stage, and production accounts versus micro-segmentation. Don’t miss Julien's take on why he believes stagin…
…
continue reading

1
#65 - Understanding Nats: An Explainer Of Its Features And Capabilities
37:18
37:18
Play later
Play later
Lists
Like
Liked
37:18Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they discuss Nats.io, a messaging system popular among people building on top of Kubernetes. Julien explains how Nats is different from Kafka and shares his personal experience with the product. The hosts discuss the various use cases of Nats and explore its features and capabil…
…
continue reading

1
DEVSECOPS Talks #64 - From Terraform To Opentofu: Story From The Trenches
39:40
39:40
Play later
Play later
Lists
Like
Liked
39:40In this episode of DevSecOps Talks, Andrey and Mattias are joined by Timur Bublik, Platform Engineering Lead at TIER Mobility. As always, it's practitioners for practitioners as they discuss the migration from Terraform to OpenTofu, TACOS tools, and how SpaceLift is used in Timur's organization. Listen in as they dive into their three favorite feat…
…
continue reading

1
DEVSECOPS Talks #63 - Yet Another AI Episode
34:36
34:36
Play later
Play later
Lists
Like
Liked
34:36Julien has returned with some exciting AI news. A startup has made the bold claim that they are capable of building AI software engineer. Andrey shares details about another startup that generates infrastructure based on application source code. He also mentions his upcoming talk on the use of LLM-based tools. We also discuss how individuals can st…
…
continue reading

1
DEVSECOPS Talks #62 - The DevSecOps Perspective: Key Takeaways From Re:Invent 2023
33:22
33:22
Play later
Play later
Lists
Like
Liked
33:22In this episode of DevSecOps Talks, Andrey and Mattias discuss the latest announcements from re:Invent 2023 that are most relevant to DevSecOps practitioners. Which announcements are worth paying attention to? What are the implications for the DevSecOps community? Join us as we dive into the latest developments from AWS. Connect with us on LinkedIn…
…
continue reading

1
DEVSECOPS Talks #61 - GitHub Actions And Evolution Of CI/CD Tools
46:21
46:21
Play later
Play later
Lists
Like
Liked
46:21Andrey has been exploring GitHub Actions and has some insights to share. How have CI/CD solutions transformed over time, and what innovations do GitHub Actions bring to the table? Julien drops a few tools that could be useful for GitHub Actions users. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to …
…
continue reading

1
DEVSECOPS Talks #60 - ChatGPT Anniversary: Where Are We With AI In Our Everyday Work
41:37
41:37
Play later
Play later
Lists
Like
Liked
41:37Welcome to the first DevSecOps Talks episode of the new year! It's been a whole year since ChatGPT hit the scene – but how has AI adoption shaped our world since then? Join Julien, Mattias, and Andrey as they dive into the impact of AI on their workflows. How have their daily tech tools and practices evolved with AI integration? Plus, Julien gives …
…
continue reading

1
DEVSECOPS Talks #59 - Migration Off The Cloud: To Leave or Not to Leave?
29:41
29:41
Play later
Play later
Lists
Like
Liked
29:41Is the grass greener outside the cloud? This episode dives into the trend of companies (notably Hey and Dropbox) migrating away from cloud services. Why are they leaving, and who would benefit from such a move? We also scrutinize the common belief that public clouds are overly expensive. Join us as we dissect various cloud cost optimization tools a…
…
continue reading

1
DEVSECOPS Talks #58 - AWS CDK with Igor Soroka
40:03
40:03
Play later
Play later
Lists
Like
Liked
40:03You know our fondness for Terraform, but we are also open to exploring other tools. This episode is no different. We are joined by Igor Soroka, an expert in AWS serverless technology whose tool of choice is AWS CDK, but at the same time, he is no stranger to Terraform. We ask him practical questions about the tool and get answers based on his exper…
…
continue reading

1
DEVSECOPS Talks #57 - Terraform Best Practices with Ben Goodman
36:38
36:38
Play later
Play later
Lists
Like
Liked
36:38In this episode, Mattias is joined by Ben Goodman, the founder of dragondrop.cloud, a platform that offers Terraform Best Practices as a Pull Request. They discuss the best workflows for Terraform, open-source tools that can be used in conjunction with Terraform, the most effective best practices, and common pitfalls to avoid when implementing infr…
…
continue reading

1
DEVSECOPS Talks #56 - Backstage and Internal Development Platforms (IDP)
36:02
36:02
Play later
Play later
Lists
Like
Liked
36:02In this episode of DevSecOps Talks, join Andrey, Julien, and Mattias as they dive into the world of Backstage, the notable internal development platform. Mattias is keen to peel back the layers and understand what makes people think of Backstage as a must-have in modern DevOps toolchains. Andrey highlights the platform's core feature: a comprehensi…
…
continue reading

1
DEVSECOPS Talks #55 - Unpacking System Initiative with Paul Stack
57:47
57:47
Play later
Play later
Lists
Like
Liked
57:47Our dialogue with Paul Stack resumes on DevSecOps Talks, almost two years after our initial podcast about his work on Pulumi (episode 25). As a warm-up, we talk about what prompted his move from Pulumi and his take on Open Terraform drama. The main topic of the episode is Paul's current focus, System Initiative; we probe into its purpose, the progr…
…
continue reading

1
DEVSECOPS Talks #54 - HashiCorp’s BSL Move and OpenTF: What DevSecOps Practitioners Need to Know
33:36
33:36
Play later
Play later
Lists
Like
Liked
33:36In this episode of DevSecOps Talks, we dive deep into HashiCorp's recent shift to the Business Source License and its implications. Join Andrey, Julien, and Mattias as they unpack what this means for practitioners and explore the timeline of OpenTF initiative. Stay informed about what comes ahead with our latest discussion. Tune in! Connect with us…
…
continue reading

1
DEVSECOPS Talks #53 - Open Software Supply Chain Attack Reference Framework with Neatsun
49:22
49:22
Play later
Play later
Lists
Like
Liked
49:22We had the opportunity to talk with Neatsun Ziv, one of the founders of Ox Security, about the Open Source Software Supply Chain Attack Reference Framework (https://pbom.dev). We delved deeper into possible attack vectors and explored ways to mitigate some of them. During our discussions, we also had a couple of unusual takes on supply chain securi…
…
continue reading

1
DEVSECOPS Talks #52 - Lingon a.k.a Juliens and Jacobs open source project
37:32
37:32
Play later
Play later
Lists
Like
Liked
37:32This time we got to talk about Lingon, an open-source project developed by Julian and Jacob who is a frequent podcast guest. Discover the motivations behind Lingon's creation and how it bridges the gap between Terraform and Kubernetes. Learn how Lingon simplifies infrastructure management, tackles frustrations with YAML and HCL, and offers greater …
…
continue reading

1
DEVSECOPS Talks #51 - Provisioning bare-metal servers
48:56
48:56
Play later
Play later
Lists
Like
Liked
48:56Diving into the world of bare-metal servers, Mattias takes the helm solo for this episode. He's accompanied by special guests Michael Wagner and Ian Evans from Metify, the company that powers Mojo - a leading platform for bare-metal provisioning automation. While we often chat about the big cloud service providers, this time we're switching gears. …
…
continue reading

1
DEVSECOPS Talks #50 - History of AWS networking and new ways to design your VPC setup
31:10
31:10
Play later
Play later
Lists
Like
Liked
31:10In this episode, we discuss the evolution of AWS networking capabilities from EC2-classic to VPC and advanced networking features. Andrey highlights that while many companies only use VPC and VPC peerings, there are lesser-known features that can significantly change how we approach networking setups on AWS. Connect with us on LinkedIn or Twitter (…
…
continue reading

1
DEVSECOPS Talks #49 - Password managers, ways to share sensitive info, email aliases, ChatGPT and much more
52:39
52:39
Play later
Play later
Lists
Like
Liked
52:39This is a mixed bag of an episode, we chat about all sorts of digital tools and security practices that we use in our day-to-day lives. We start by talking about password managers, and why Julien still using LastPass after the recent LastPass data breach. Julien gives us the lowdown on his personal approach to handling passwords and two-factor auth…
…
continue reading

1
DEVSECOPS Talks #48 - Building Data Platforms
46:08
46:08
Play later
Play later
Lists
Like
Liked
46:08Julien has extensive experience building data platforms for data engineering, so we got him talking and sharing. If infra for data engineering is your cup of tea, then this episode is for you. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or…
…
continue reading
We discussed tracing before but never got around to explaining details such as fundamentals, terminology, etc. This time Julien goes into detail about what tracing is, what the benefits are, the basic terms you need to understand, and where to start. Great episode for those who are considering adding tracing capabilities to their systems. Connect w…
…
continue reading

1
DEVSECOPS Talks #46 - Software supply chain attacks
50:10
50:10
Play later
Play later
Lists
Like
Liked
50:10We are happy to welcome back Jacob Lärfors, CEO and Senior Consultant from Verifa, to talk about software supply chain attacks. It feels important to raise this topic since those attacks start to be utilized more often by sophisticated adversaries. At the same time, software supply chain security is something that companies often overlook. We as pr…
…
continue reading

1
DEVSECOPS Talks #45 - What is happening with Docker?
55:02
55:02
Play later
Play later
Lists
Like
Liked
55:02Have you heard any recent news from Docker? We haven't. That is why we decided to check up on Docker to see how it is doing and go through the tool's history and adoption. Clueless about the difference between Docker, Containerd, CRI-O? We got you covered. Also, we will highlight a couple of new handy capabilities added recently. Connect with us on…
…
continue reading

1
DEVSECOPS Talks #44 - Kosli with Mike Long. From compliance to answering questions about the production environment
46:51
46:51
Play later
Play later
Lists
Like
Liked
46:51We are excited about the new breed of tools coming to the market. We often had to put together tools to find out what was in production and what broke it. Your monitoring tools go as far as only telling you that something isn't working as expected but not why it is so, and then you have to scramble to figure out what versions of services are in pro…
…
continue reading

1
DEVSECOPS Talks #43 - Terraform 1.0 to 1.3.0. One year in review
37:51
37:51
Play later
Play later
Lists
Like
Liked
37:51We are discussing what has happened in Terraform world since the 1.0 release last year and if there are new features worth mentioning, trends in Terraform development, etc. As well as doing a recap of the road to 1.0 and how long it took us to get there. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy …
…
continue reading

1
DEVSECOPS Talks #42 - Prometheus - a practitioner take
51:10
51:10
Play later
Play later
Lists
Like
Liked
51:10If you follow CloudNative hype wave, you might feel that Prometheus is the must-use monitoring tool for everything CloudNative. Plus, almost everything nowadays has a Prometheus exporter. Just get that helm chart installed, and here you go - metrics question sorted out. Want to monitor endpoints - here is BlackBox exporter for you. Want to get noti…
…
continue reading

1
DEVSECOPS Talks #41 - Great communication FTW
40:07
40:07
Play later
Play later
Lists
Like
Liked
40:07Communication in co-located teams is quite often complicated. It is even more complex and, at the same time, important in distributed teams. Have you ever got an issue report that says this thing is failing? No logs, no explanation of context, no nothing. Pretty sure we've all been in such situations. How do you step up your communication game? Thi…
…
continue reading

1
DEVSECOPS Talks #40 - Web3 and its implications for DevSecOps practitioners
43:33
43:33
Play later
Play later
Lists
Like
Liked
43:33web3 has gotten a lot of attention lately; thus, it is time for us to separate facts from the hype. In this episode, we are trying to understand its implications for us as DevSecOps practitioners. Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.…
…
continue reading

1
DEVSECOPS Talks #39 - Setting up tools and environments
27:41
27:41
Play later
Play later
Lists
Like
Liked
27:41Andrey feels frustrated that he has to develop a way to configure environments for every customer. Think for yourself - you arrive at a new project or company. It is day one, and you need to get the right tools as well as the correct environment configuration. During this episode, we are trying to figure out how companies solve it. And is there a s…
…
continue reading

1
DEVSECOPS Talks #38 - Platform teams with Henrik
1:02:15
1:02:15
Play later
Play later
Lists
Like
Liked
1:02:15Henrik Hoegh is back to talk about his experiences working in the platform team at his new job, but before that, we are getting through the following topics:- bash is the future of automation (not really, but some people think so)- building multi-cloud solutions using k8s and service mesh solutions- Shuttle - CLI for handling shared build and deplo…
…
continue reading

1
DEVSECOPS Talks #37 - Surviving AWS outage (revised for 2021)
33:47
33:47
Play later
Play later
Lists
Like
Liked
33:47us-east-1 will never go down, and if it would, half of the internet would go down. It is what people used to say. So, us-east-1 went down big time. What does it mean for us as practitioners? What should we consider going forward? In this episode, we talk through the incident and disaster recovery strategies you can consider to keep your company up …
…
continue reading

1
DEVSECOPS Talks #36 - Sturdy. Is it time for a new version control tool?
43:17
43:17
Play later
Play later
Lists
Like
Liked
43:17We have had Git around for more than 15 years, and during that time, it has become a standard de-facto to share code and track code changes. While Git is a superior version control system to most of what we have seen before, it has been 15 years since the first release. Should we be looking for new ways to approach version control systems? Is the t…
…
continue reading

1
DEVSECOPS Talks #35 - Infrastructure as code (IAC) revisited 2021
38:49
38:49
Play later
Play later
Lists
Like
Liked
38:49Our first episode was about Infrastructure as code, and we feel that it is time to revisit the topic after almost two years. Another reason is the release of the second edition of Infrastructure as Code book by Keif Morris. Thus, in this episode, we revisit the definition of Infrastructure as code and try to summarize what has changed over the year…
…
continue reading

1
DEVSECOPS Talks #34 - Google Next and HashiConf recap
36:23
36:23
Play later
Play later
Lists
Like
Liked
36:23Julien gives his impressions of Google Cloud Next 2021, and Andrey recaps HashiConf Global 2021 as well as gives his take with the twist on why do we might need HashiCorp Waypoint Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.…
…
continue reading

1
DEVSECOPS Talks #33 - Do I need a service mesh?
28:21
28:21
Play later
Play later
Lists
Like
Liked
28:21Everyone seems to be talking about service mesh. Mattias, Julien, and Andrey are trying to separate hype and real value. Most importantly, they dig into when is the good time for the organization is to embrace service mesh and what are the prerequisites Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questi…
…
continue reading

1
DEVSECOPS Talks #32 - Getting hired as an infrastructure automation person
25:36
25:36
Play later
Play later
Lists
Like
Liked
25:36As a follow-up to the [last episode about hiring an infrastructure automation person](https://devsecops.fm/episodes/31-hiring/) we decided to reverse the view and talk about how do you get hired as an infrastructure automation person. This episode is full of career advice for people who are just only from university as well as people who already ha…
…
continue reading

1
DEVSECOPS Talks #31 - Hiring an infrastructure automation person
32:47
32:47
Play later
Play later
Lists
Like
Liked
32:47Have you ever conducted an interview to hire an infrastructure automation person? What would you ask? How do you check their skills? And what skills are essential? Tune in for our tips on hiring and finding the right person for your team! Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we wil…
…
continue reading

1
DEVSECOPS Talks #30 - Logs, metrics and traces
32:03
32:03
Play later
Play later
Lists
Like
Liked
32:03Logs, metrics, and traces are the three pillars of observability. Where should you start? What are the common mistakes to avoid? And if you are to pick one - which one should you do? Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.…
…
continue reading