Digest #43: Azure Penetration Testing 📛

#43: Azure Penetration Testing

🎧 PODCAST/WEBINAR OF THE WEEK
Kubernetes won the container wars (over Swarm, CF and Mesos) and continues to grow in use across many industries. But how did something that was about Cloud-native Applications gain traction without a developer experience? 🤔
📖 POSTS OF THE WEEK
Fantastic Infrastructure as Code security attacks and how to find them
This post we will dive into these IaC risks and focus on IaC management tools such as Terraform, cloud providers, and deployment platforms involving containers and Kubernetes. For each scenario, it will look into threats, tools, integrations, and best practices to reduce risk.
Read more »
"Stop using branches for deploying to different GitOps environments" - Branch-per-environment mostly works, but there are some issues with it - Read more »
"Azure penetration testing: the user-friendly guide" - A great guide on how you can go about performing penetration tests on Azure and what you need to consider before starting - Read more »
"Hands-on with PostgreSQL authorization" - How you can limit users to reading and mutating only their own data with row-level security (RLS) policies - Read more »
"Who’s attacking my server?" - A hands-on tutorial on how to secure a server against brute-forcing SSH access and visualize potential attackers IPs in a map - Read more »
"Contributing to complex projects" - Mitchell Hashimoto (the guy behind Terraform & others) cover in this blog post how to approach with confidence a complex open-source project - Read more »
"CRI-O vulnerability could allow container escape" - A newly discovered vulnerability in the container runtime tool CRI-O could allow attackers who are able to create pods in a Kubernetes or OpenShift to break out to the underlying cluster node, effectively escalating their privileges - Read more »
📕 BOOK OF THE WEEK
This is the book I read these past few weeks. It’s the story of Elon Musk, Peter Thiel, Reid Hoffman, David Sachs and the entire Paypal Mafia surviving the tumultuous time that was the .com era. It’s interesting to hear it from the perspective of an insider writing this before any of these people became as famous as they are today. It’s a genuinely inspiring story because it’s so different from the “young dropout starts a social media app” story we are using to hearing a lot these days.
🛠 PROJECTS OF THE WEEK
The company 0x4447 builds products to increase standardization and security in AWS Organizations. They do this with automated pipelines that use well structured projects to create secure, easy to maintain and fail tolerant solutions. One of which is their VPN product – built on top of the popular OpenVPN® project, which has no license restrictions. You are only limited by the network card in the instance - Read more »
ValidIaC combines the best open-source tools (tflint, tfsec, infracost and inframap under the same roof) to help ensure Infrastructure-as-Code best practices, hygiene & security - Read more »
In order to scan all used images in a K8s cluster for vulnerabilities this application runs scans of all used images on an interval and outputs Prometheus metrics to indicate the problematic images and their vulnerabilities - Read more »
Vim Reference Guide is intended as a concise learning free resource for beginner to intermediate level Vim users. It has more in common with cheatsheets than a typical text book. Topics like Regular Expressions and Macros have more detailed explanations and examples due to their complexity - Read more »
💼 OPEN JOBS OF THE WEEK
Site Reliability Engineer @RetailNext
GCP, Golang, Terraform, Elasticsearch

🌎 Remote, USA
💰 $140K - $170K
Read more »
DevOps Engineer @OMG
AWS, ClickHouse, Elasticsearch

🌎 Remote, anywhere
Read more »
DevOps SRE @Close
AWS, MongoDB, Kubernetes

🌎 Remote, anywhere
Read more »
🐦 TWEET OF THE WEEK
Great tweet that summarizes the top security findings on K8s clusters.
😂 MEMES OF THE WEEK
How to choose the best answer in StackOverflow 😅
Share Share
Tweet Tweet
Forward Forward
Remember to share if you enjoyed this issue!
@devopsbulletin @devopsbulletin
devopsbulletin.com devopsbulletin.com
Copyright © 2022 DevOps Bulletin, All rights reserved.
Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp

Older messages

Digest #44: You're Doing SSH Wrong 😬

Friday, March 25, 2022

Digest #44: You're Doing SSH Wrong 😬 #44: You're Doing SSH Wrong 🎧 PODCAST/WEBINAR OF THE WEEK This episode from DevOps Pradox discusses the challenges with StatesfulSet applications and the

You Might Also Like

🕹️ Retro Consoles Worth Collecting While You Still Can — Is Last Year's Flagship Phone Worth Your Money?

Saturday, November 23, 2024

Also: Best Outdoor Smart Plugs, and More! How-To Geek Logo November 23, 2024 Did You Know After the "flair" that servers wore—buttons and other adornments—was made the butt of a joke in the

JSK Daily for Nov 23, 2024

Saturday, November 23, 2024

JSK Daily for Nov 23, 2024 View this email in your browser A community curated daily e-mail of JavaScript news React E-Commerce App for Digital Products: Part 4 (Creating the Home Page) This component

Not Ready For The Camera 📸

Saturday, November 23, 2024

What (and who) video-based social media leaves out. Here's a version for your browser. Hunting for the end of the long tail • November 23, 2024 Not Ready For The Camera Why hasn't video

Daily Coding Problem: Problem #1617 [Easy]

Saturday, November 23, 2024

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Microsoft. You are given an string representing the initial conditions of some dominoes.

Ranked | The Tallest and Shortest Countries, by Average Height 📏

Saturday, November 23, 2024

These two maps compare the world's tallest countries, and the world's shortest countries, by average height. View Online | Subscribe | Download Our App TIME IS RUNNING OUT There's just 3

⚙️ Your own Personal AI Agent, for Everything

Saturday, November 23, 2024

November 23, 2024 | Read Online Subscribe | Advertise Good Morning. Welcome to this special edition of The Deep View, brought to you in collaboration with Convergence. Imagine if you had a digital

Educational Byte: Are Privacy Coins Like Monero and Zcash Legal?

Saturday, November 23, 2024

Top Tech Content sent at Noon! How the world collects web data Read this email in your browser How are you, @newsletterest1? 🪐 What's happening in tech today, November 23, 2024? The HackerNoon

🐍 New Python tutorials on Real Python

Saturday, November 23, 2024

Hey there, There's always something going on over at Real Python as far as Python tutorials go. Here's what you may have missed this past week: Black Friday Giveaway @ Real Python This Black

Re: Hackers may have stolen everyone's SSN!

Saturday, November 23, 2024

I wanted to make sure you saw Incogni's Black Friday deal, which is exclusively available for iPhone Life readers. Use coupon code IPHONELIFE to save 58%. Here's why we recommend Incogni for

North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn

Saturday, November 23, 2024

THN Daily Updates Newsletter cover Generative AI For Dummies ($18.00 Value) FREE for a Limited Time Generate a personal assistant with generative AI Download Now Sponsored LATEST NEWS Nov 23, 2024