
55.1K
Downloads
111
Episodes
This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do the right technology bets, help their organizations to deliver value, and last but not the least to have some fun. Tune in for talks about technology, ways of working, and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show notes, and discussion of past and upcoming episodes visit devsecops.fm
Episodes

Aug 24, 2021
Aug 24, 2021
32 min
Have you ever conducted an interview to hire an infrastructure automation person? What would you ask? How do you check their skills? And what skills are essential? Tune in for our tips on hiring and finding the right person for your team!
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.

Jun 23, 2021
Jun 23, 2021
32 min
Logs, metrics, and traces are the three pillars of observability. Where should you start? What are the common mistakes to avoid? And if you are to pick one - which one should you do?
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.

May 19, 2021
May 19, 2021
47 min
This time we are talking unikernles! Ian Eyberg from NanoVMs joins us to discuss how far this technology is from prime time. And it turns out that you don't have to be a kernel developer to take advantage of unikernes. Today, there are tools available to package, distribute, and run them locally as well as in the public cloud. While talking to Ian, it felt that the state of the technology is very similar to Linux containers at the beginning of 2010x, just before Docker made Linux containers available for everyone.
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.

May 4, 2021
May 4, 2021
36 min
The real cloud lock-in is security! Every service/cloud provider has its own levels of granularity regarding resources. Cloud engineering is mainly about compute, storage, and networking and how to make them scale. Scaling security is often left out as it is hard to measure on so many levels.
We think that it is a myth and that we can measure how many steps it takes to add, modify or remove access rights. It all starts with monitoring, knowing what is there in a cloud infrastructure is a very good first step. By making it easy to see and manage access rights, we make it easier for ourselves to keep resources secured.
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.

Apr 12, 2021
Apr 12, 2021
41 min
AWS released AWS Bottlerocket OS in March of 2020, and version 1.0.0 got released in August 2020.
What is it? Should you be using it? What are the benefits?
Is it ready for prime time? We answer all of those questions during this episode of DevSecOps Talks. Tune in!
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.

Mar 29, 2021
Mar 29, 2021
44 min
Johan Abildskov (@RandomSort, see episode 6) is back, and we are talking branching strategies! In particular, why you shouldn't be doing git-flow, and what are other options out there. This conversation takes us down memory lane to a more broad discussion about version control systems, mono-repositories, continuous integration, and delivery. We hope you will like it!
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.

Mar 12, 2021
Mar 12, 2021
54 min
This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about
- what is Pulumi is?
- understand the difference between Pulumi vs. Terraform (and if we should compare them at all)
- What is hard about Pulumi?
- What people ask the most? What are the common confusions?
- Cross-language infra libraries? How is it even possible?!
- Is there a possibility of a supply chain attack via Pulumi library?
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.

Feb 22, 2021
Feb 22, 2021
36 min
Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion

Feb 5, 2021
Feb 5, 2021
36 min
How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings?
We go through the list of things you might be missing out on if not yet using a managed solution.
Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion

Jan 22, 2021
Jan 22, 2021
29 min
It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion
