Digest #43: Azure Penetration Testing 📛

#43: Azure Penetration Testing

🎧 PODCAST/WEBINAR OF THE WEEK
Kubernetes won the container wars (over Swarm, CF and Mesos) and continues to grow in use across many industries. But how did something that was about Cloud-native Applications gain traction without a developer experience? 🤔
📖 POSTS OF THE WEEK
Fantastic Infrastructure as Code security attacks and how to find them
This post we will dive into these IaC risks and focus on IaC management tools such as Terraform, cloud providers, and deployment platforms involving containers and Kubernetes. For each scenario, it will look into threats, tools, integrations, and best practices to reduce risk.
Read more »
"Stop using branches for deploying to different GitOps environments" - Branch-per-environment mostly works, but there are some issues with it - Read more »
"Azure penetration testing: the user-friendly guide" - A great guide on how you can go about performing penetration tests on Azure and what you need to consider before starting - Read more »
"Hands-on with PostgreSQL authorization" - How you can limit users to reading and mutating only their own data with row-level security (RLS) policies - Read more »
"Who’s attacking my server?" - A hands-on tutorial on how to secure a server against brute-forcing SSH access and visualize potential attackers IPs in a map - Read more »
"Contributing to complex projects" - Mitchell Hashimoto (the guy behind Terraform & others) cover in this blog post how to approach with confidence a complex open-source project - Read more »
"CRI-O vulnerability could allow container escape" - A newly discovered vulnerability in the container runtime tool CRI-O could allow attackers who are able to create pods in a Kubernetes or OpenShift to break out to the underlying cluster node, effectively escalating their privileges - Read more »
📕 BOOK OF THE WEEK
This is the book I read these past few weeks. It’s the story of Elon Musk, Peter Thiel, Reid Hoffman, David Sachs and the entire Paypal Mafia surviving the tumultuous time that was the .com era. It’s interesting to hear it from the perspective of an insider writing this before any of these people became as famous as they are today. It’s a genuinely inspiring story because it’s so different from the “young dropout starts a social media app” story we are using to hearing a lot these days.
🛠 PROJECTS OF THE WEEK
The company 0x4447 builds products to increase standardization and security in AWS Organizations. They do this with automated pipelines that use well structured projects to create secure, easy to maintain and fail tolerant solutions. One of which is their VPN product – built on top of the popular OpenVPN® project, which has no license restrictions. You are only limited by the network card in the instance - Read more »
ValidIaC combines the best open-source tools (tflint, tfsec, infracost and inframap under the same roof) to help ensure Infrastructure-as-Code best practices, hygiene & security - Read more »
In order to scan all used images in a K8s cluster for vulnerabilities this application runs scans of all used images on an interval and outputs Prometheus metrics to indicate the problematic images and their vulnerabilities - Read more »
Vim Reference Guide is intended as a concise learning free resource for beginner to intermediate level Vim users. It has more in common with cheatsheets than a typical text book. Topics like Regular Expressions and Macros have more detailed explanations and examples due to their complexity - Read more »
💼 OPEN JOBS OF THE WEEK
Site Reliability Engineer @RetailNext
GCP, Golang, Terraform, Elasticsearch

🌎 Remote, USA
💰 $140K - $170K
Read more »
DevOps Engineer @OMG
AWS, ClickHouse, Elasticsearch

🌎 Remote, anywhere
Read more »
DevOps SRE @Close
AWS, MongoDB, Kubernetes

🌎 Remote, anywhere
Read more »
🐦 TWEET OF THE WEEK
Great tweet that summarizes the top security findings on K8s clusters.
😂 MEMES OF THE WEEK
How to choose the best answer in StackOverflow 😅
Share Share
Tweet Tweet
Forward Forward
Remember to share if you enjoyed this issue!
@devopsbulletin @devopsbulletin
devopsbulletin.com devopsbulletin.com
Copyright © 2022 DevOps Bulletin, All rights reserved.
Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp

Older messages

Digest #44: You're Doing SSH Wrong 😬

Friday, March 25, 2022

Digest #44: You're Doing SSH Wrong 😬 #44: You're Doing SSH Wrong 🎧 PODCAST/WEBINAR OF THE WEEK This episode from DevOps Pradox discusses the challenges with StatesfulSet applications and the

You Might Also Like

Import AI 399: 1,000 samples to make a reasoning model; DeepSeek proliferation; Apple's self-driving car simulator

Friday, February 14, 2025

What came before the golem? ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏

Defining Your Paranoia Level: Navigating Change Without the Overkill

Friday, February 14, 2025

We've all been there: trying to learn something new, only to find our old habits holding us back. We discussed today how our gut feelings about solving problems can sometimes be our own worst enemy

5 ways AI can help with taxes 🪄

Friday, February 14, 2025

Remotely control an iPhone; 💸 50+ early Presidents' Day deals -- ZDNET ZDNET Tech Today - US February 10, 2025 5 ways AI can help you with your taxes (and what not to use it for) 5 ways AI can help

Recurring Automations + Secret Updates

Friday, February 14, 2025

Smarter automations, better templates, and hidden updates to explore 👀 ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏

The First Provable AI-Proof Game: Introducing Butterfly Wings 4

Friday, February 14, 2025

Top Tech Content sent at Noon! Boost Your Article on HackerNoon for $159.99! Read this email in your browser How are you, @newsletterest1? undefined The Market Today #01 Instagram (Meta) 714.52 -0.32%

GCP Newsletter #437

Friday, February 14, 2025

Welcome to issue #437 February 10th, 2025 News BigQuery Cloud Marketplace Official Blog Partners BigQuery datasets now available on Google Cloud Marketplace - Google Cloud Marketplace now offers

Charted | The 1%'s Share of U.S. Wealth Over Time (1989-2024) 💰

Friday, February 14, 2025

Discover how the share of US wealth held by the top 1% has evolved from 1989 to 2024 in this infographic. View Online | Subscribe | Download Our App Download our app to see thousands of new charts from

The Great Social Media Diaspora & Tapestry is here

Friday, February 14, 2025

Apple introduces new app called 'Apple Invites', The Iconfactory launches Tapestry, beyond the traditional portfolio, and more in this week's issue of Creativerly. Creativerly The Great

Daily Coding Problem: Problem #1689 [Medium]

Friday, February 14, 2025

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Google. Given a linked list, sort it in O(n log n) time and constant space. For example,

📧 Stop Conflating CQRS and MediatR

Friday, February 14, 2025

​ Stop Conflating CQRS and MediatR Read on: m​y website / Read time: 4 minutes The .NET Weekly is brought to you by: Step right up to the Generative AI Use Cases Repository! See how MongoDB powers your