Digest #43: Azure Penetration Testing 📛

#43: Azure Penetration Testing

🎧 PODCAST/WEBINAR OF THE WEEK
Kubernetes won the container wars (over Swarm, CF and Mesos) and continues to grow in use across many industries. But how did something that was about Cloud-native Applications gain traction without a developer experience? 🤔
📖 POSTS OF THE WEEK
Fantastic Infrastructure as Code security attacks and how to find them
This post we will dive into these IaC risks and focus on IaC management tools such as Terraform, cloud providers, and deployment platforms involving containers and Kubernetes. For each scenario, it will look into threats, tools, integrations, and best practices to reduce risk.
Read more »
"Stop using branches for deploying to different GitOps environments" - Branch-per-environment mostly works, but there are some issues with it - Read more »
"Azure penetration testing: the user-friendly guide" - A great guide on how you can go about performing penetration tests on Azure and what you need to consider before starting - Read more »
"Hands-on with PostgreSQL authorization" - How you can limit users to reading and mutating only their own data with row-level security (RLS) policies - Read more »
"Who’s attacking my server?" - A hands-on tutorial on how to secure a server against brute-forcing SSH access and visualize potential attackers IPs in a map - Read more »
"Contributing to complex projects" - Mitchell Hashimoto (the guy behind Terraform & others) cover in this blog post how to approach with confidence a complex open-source project - Read more »
"CRI-O vulnerability could allow container escape" - A newly discovered vulnerability in the container runtime tool CRI-O could allow attackers who are able to create pods in a Kubernetes or OpenShift to break out to the underlying cluster node, effectively escalating their privileges - Read more »
📕 BOOK OF THE WEEK
This is the book I read these past few weeks. It’s the story of Elon Musk, Peter Thiel, Reid Hoffman, David Sachs and the entire Paypal Mafia surviving the tumultuous time that was the .com era. It’s interesting to hear it from the perspective of an insider writing this before any of these people became as famous as they are today. It’s a genuinely inspiring story because it’s so different from the “young dropout starts a social media app” story we are using to hearing a lot these days.
🛠 PROJECTS OF THE WEEK
The company 0x4447 builds products to increase standardization and security in AWS Organizations. They do this with automated pipelines that use well structured projects to create secure, easy to maintain and fail tolerant solutions. One of which is their VPN product – built on top of the popular OpenVPN® project, which has no license restrictions. You are only limited by the network card in the instance - Read more »
ValidIaC combines the best open-source tools (tflint, tfsec, infracost and inframap under the same roof) to help ensure Infrastructure-as-Code best practices, hygiene & security - Read more »
In order to scan all used images in a K8s cluster for vulnerabilities this application runs scans of all used images on an interval and outputs Prometheus metrics to indicate the problematic images and their vulnerabilities - Read more »
Vim Reference Guide is intended as a concise learning free resource for beginner to intermediate level Vim users. It has more in common with cheatsheets than a typical text book. Topics like Regular Expressions and Macros have more detailed explanations and examples due to their complexity - Read more »
💼 OPEN JOBS OF THE WEEK
Site Reliability Engineer @RetailNext
GCP, Golang, Terraform, Elasticsearch

🌎 Remote, USA
💰 $140K - $170K
Read more »
DevOps Engineer @OMG
AWS, ClickHouse, Elasticsearch

🌎 Remote, anywhere
Read more »
DevOps SRE @Close
AWS, MongoDB, Kubernetes

🌎 Remote, anywhere
Read more »
🐦 TWEET OF THE WEEK
Great tweet that summarizes the top security findings on K8s clusters.
😂 MEMES OF THE WEEK
How to choose the best answer in StackOverflow 😅
Share Share
Tweet Tweet
Forward Forward
Remember to share if you enjoyed this issue!
@devopsbulletin @devopsbulletin
devopsbulletin.com devopsbulletin.com
Copyright © 2022 DevOps Bulletin, All rights reserved.
Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp

Older messages

Digest #44: You're Doing SSH Wrong 😬

Friday, March 25, 2022

Digest #44: You're Doing SSH Wrong 😬 #44: You're Doing SSH Wrong 🎧 PODCAST/WEBINAR OF THE WEEK This episode from DevOps Pradox discusses the challenges with StatesfulSet applications and the

You Might Also Like

Upgrade Your Git Game, Visual Studio Getting 'Command Palette,' Python/Java in VS Code, .NET 9 Preview, More

Thursday, April 25, 2024

Home | News | How To | Webcasts | Whitepapers | Advertise .NET Insight April 25, 2024 THIS ISSUE SPONSORED BY: ■ dtSearch® - INSTANTLY SEARCH TERABYTES Upgrade Your Git Game in Visual Studio 2022

🔒 The Vault Newsletter: April issue 🔑

Thursday, April 25, 2024

Get the latest business security news, updates, and advice from 1Password. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏

Top Tech 🏆 Lenovo ThinkPad X1 Carbon Gen 12 Laptop Review — Testing an AI Voice Recorder

Thursday, April 25, 2024

Also: The Roborock S8 MaxV Ultra Vacuum is Excellent, and More! How-To Geek Logo April 25, 2024 Take a look at our latest reviews, featuring fun tech like the Lenovo ThinkPad X1 Carbon laptop,

⚙️ r1

Thursday, April 25, 2024

Plus: UK investigating OpenAI ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

Charted | Economic Growth Forecasts for G7 and BRICS Countries in 2024 📊

Thursday, April 25, 2024

The IMF has released its economic growth forecasts for 2024. How do the G7 and BRICS countries compare in expected real GDP growth? View Online | Subscribe Presented by: Access European benchmarks with

Build5Nines Newsletter - April 25, 2024

Thursday, April 25, 2024

View this email in your browser Build5Nines Build5Nines Newsletter Thank you for subscribing! I look forward to sharing with you the latest cloud news, technical help, and other thoughts around DevOps

Discover the World's Easiest Parallel File System

Thursday, April 25, 2024

Join us in exploring the future of data management with Bjorn Kolbeck, a Google engineer turned CEO and Co-founder of Quobyte, the creators of the world's easiest parallel file system. ͏ ͏ ͏ ͏ ͏ ͏

Issue 314 - New Model 3 Performance is here

Thursday, April 25, 2024

View this email in your browser If you are just now finding out about Tesletter, you can subscribe here! If you already know Tesletter and want to support us, check out our Patreon page Issue 314 - New

Programmer Weekly - Issue 202

Thursday, April 25, 2024

View this email in your browser Programmer Weekly Welcome to issue 202 of Programmer Weekly. Let's get straight to the links this week. Quote of the Week "Computer science inverts the normal.

Python Weekly - Issue 647

Thursday, April 25, 2024

View this email in your browser Python Weekly Welcome to issue 647 of Python Weekly. Let's get straight to the links this week. From Our Sponsor Get Your Weekly Dose of Programming A weekly