Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DevOpsDays Lima 2026 Speaker!

DevOpsDays Lima 2026 Speaker!

Avatar for Amaury Borges Souza

Amaury Borges Souza

August 28, 2026

More Decks by Amaury Borges Souza

Other Decks in Technology

Transcript

  1. TEMATICA Terraform at Scale: Security Without Friction. Amaury Borges Souza

    Cloud Security Specialist | AWS Community Builder Hashicorp Champion | FIAP Professor DEVOPSDAYS.PE 27 - 28 AGO 2026
  2. Perfil del speaker Amaury Borges Souza Cloud Security Specialist ·

    CI&T / AWS Community Builder · Hashicorp Champions Amaury Borges Souza is a Cloud Security Engineer and postgraduate professor with 12+ years of experience in technology, specializing in AWS Security, DevSecOps, Infrastructure as Code, and AI-assisted security automation. FOTO DEL SPEAKER An international speaker and active member of the tech community, Amaury is a 4× AWS Community Builder, HashiCorp Ambassador, and HashiCorp User Group Leader. He regularly shares practical experiences in Cloud Security, DevSecOps, Terraform. DEVOPS DEVOPSDAYS.PE CLOUD SECURITY DEVSECOPS 02 / 45
  3. HashiConf last year (A lot of experience) At HashiConf 2025,

    I met platform engineers, security leaders, and Terraform practitioners facing the same challenge: How do we secure Terraform without friction into pipeline? DEVOPSDAYS.PE 03 / 45
  4. Métricas del speaker IMPACTO DEL SPEAKER +11 30+ 4 25Mil+

    Años de experiencia Charlas dictadas Países visitados Personas alcanzadas * Reemplaza estas cifras con tus propios datos. DEVOPSDAYS.PE 04 / 45
  5. Table of Contents TREND MARKETS 03 THE PROBLEM 05 THE

    DEVSECOPS MINDSET 08 REALLITY IN MOST ORGANIZATIONS 10 TERRAFORM FEATURES (SECURITY) 13 POLICY AS CODE 20 AGENTIC INFRASTRUCTURE AS CODE 25 QUESTIONS? 30 CONCLUSION 34 DEVOPSDAYS.PE 05/ 45
  6. Market Trends IaC Adoption & Security Pressure • Infrastructure as

    Code is no longer optional. • Security and governance are now the main challenge. DEVOPSDAYS.PE 07 / 45
  7. The Problem Security vs Speed dilemma: • Developers want fast

    delivery • Security teams want governance and compliance • Manual reviews create bottlenecks • Result: shadow IaC and risky deployments Question: How do we secure Terraform without blocking developers? DEVOPSDAYS.PE 08 / 45
  8. Reality in most organizations • Terraform deployed without guardrails •

    Security checks happen late • Manual approvals slow pipelines • Developers bypass processes Security becomes friction DEVOPSDAYS.PE 10 / 45
  9. The Entire SDLC Process • Software Supply Chain • AI

    Agents • Non-Human Identities • CI/CD • Artifacts • Third-party integration Security has never been as important as it is in this era. DEVOPSDAYS.PE 12 / 45
  10. The DevSecOps Mindset Security must be: • Automated • Invisible

    when compliant • Fast • Integrated into developer workflow • Shift-left DEVOPSDAYS.PE 14 / 45
  11. DevSecOps Culture Security is a shared responsibility. It is process

    + culture + automation + continuous security. It is about shifting security earlier into the development process. DEVOPSDAYS.PE 15 / 45
  12. Shift Left Workflow SAST/DAST SECURITY DEVSECOPS • Detects faults earlier

    and cheaper. • Reduces the time to find the root cause. • Decreases rework and speeds up deliveries. COMMUNITY IMAGE DEVOPSDAYS.PE 16 / 45
  13. DevSecOps: Integrated security from the start • Shift Left: security

    from the planning stage • Automated scanners and tests in the pipeline • Reduced risk of vulnerabilities in production • Meets compliance requirements without sacrificing agility DEVOPSDAYS.PE 17 / 45
  14. OWASP Guidelines for IaC Security • Scan IaC before deployment.

    • Never hardcode secrets. • Apply least privilege. • Enforce security policies in CI/CD. Security starts before DEVOPSDAYS.PE TERRAFORM APPLY 18 / 45
  15. Layered Infrastructure Security with HashiCorp Hashicorp tools enable: • Guardrails

    • Automation • Developer Autonomy • Secure Self-Service Infrastructure • IaC by security default DEVOPSDAYS.PE 20 / 45
  16. Security Across the Stack Security shouldn't be another step at

    the end of the pipeline. It needs to be embedded across infrastructure, networking, security services and the application layer. HASHICORP Infrastructure Networking Security Application Infrastructure as Code Service Registry & Discovery Secrets management Workload orchestration Compliance & Governance Secure Networking Encryption Application-centric networking Self-service infrastructure Service Mesh Advanced Data Protection Developer-centric application delivery Automated Networking DEVOPSDAYS.PE 21 / 45
  17. Security in the midle • From provisioning infrastructure to enforcing

    security controls. • Security is not a single tool. It spans the entire infrastructure lifecycle. DEVOPSDAYS.PE 22 / 45
  18. Terraform features that enable secure delivery Terraform capabilities that help

    security and governance: • Plan & Apply workflow • Reusable Modules • State management • Validation & formatting (validate / fmt) • Actions & automation DEVOPSDAYS.PE 23 / 45
  19. $tfpolicy: Policy as Code, closer to Terraform • Policy as

    Code using HCL • Understands resource relationships • Uses provider data sources • Evaluates before & after deployment DEVOPSDAYS.PE 24 / 45
  20. What is DevOps? PLATFORM CFP OPEN • LIVE DEVSECOPS CONFIRMED

    PENDING CLOSED ¿Necesitas más inspiración? Usa estos componentes listos desde la web: design-system.devopsdays.pe DEVOPSDAYS.PE 25 / 45
  21. Hashicorp Agent Skills General AI Agent ↓ HashiCorp Agent Skills

    ↓ Security + IaC Context ↓ Secure Terraform / Packer BEST PRACTICES POLICY DEVOPSDAYS.PE SECURE CONFIGURATIOM 26 / 45
  22. Hashicorp Agent Skills • Specialized knowledge for AI agents •

    Terraform & Packer best practices • Reusable and portable context • Works with multiple AI assistants DEVOPSDAYS.PE 27 / 45
  23. Code editor validation • AI-assisted Terraform development • Real-time code

    suggestions • Early security feedback • Fix issues before the pipeline DEVOPSDAYS.PE 28 / 45
  24. AI-Assisted IaC Security • Analyze Terraform in context • Detect

    risky configurations • Prioritize security findings • Suggest remediation before commit DEVOPSDAYS.PE 29 / 45
  25. Cards & Alerts CARDS ALERTS ÉXITO PLATFORM Tu registro se

    completó correctamente. Track principal Charlas y talleres sobre cultura DevOps, plataformas internas y developer experience. INFO La próxima edición será del 21 al 22 de agosto. Ver agenda ADVERTENCIA Los cupos para talleres son limitados. CFP OPEN Postula tu charla ERROR No se pudo procesar el pago, intenta de nuevo. Comparte tu experiencia con la comunidad. El CFP está abierto hasta agosto. Postular DEVOPSDAYS.PE 30 / 45
  26. Policy as Code turns governance rules into executable logic. FAST,

    PREDICTABLE FEEDBACK DEVOPSDAYS.PE 31 / 45
  27. Policy as Code (Key concepts) Guardrails instead of gates: •

    Define policy once • Enforce automatically • Developers get immediate feedback • No manual security tickets • Security becomes predictable and scalable DEVOPSDAYS.PE 32 / 45
  28. Policy as Code (Key concepts) Guardrails instead of gates: •

    Define policy once • Enforce automatically • Developers get immediate feedback • No manual security tickets • Security becomes predictable and scalable DEVOPSDAYS.PE 33 / 45
  29. Policy as Code Tools Hashicorp Sentinel Checkov Terrascan (Tanable) Policy

    as Code engine integrated with Terraform Cloud/Enterprise. Creates custom rules (Rego-like) that validate plans and apply compliance gates.. Checks Terraform, CloudFormation, ARM, Kubernetes, and Dockerfiles. Applies over 1,000 CIS/NIST policies and blocks insecure deployments before production. It implements CIS, NIST, PCI-DSS, and GDPR controls in an automated way. Example: blocks public buckets or roles with broad privileges. • Static analysis for Infrastructure as Code • Detects compliance drift • Enforces guardrails at plan and apply time • Integrates with Terraform Cloud run tasks DEVOPSDAYS.PE • Maps infrastructure to CIS, NIST, PCI-DSS, GDPR • Detects misconfigurations early in CI 34 / 45
  30. Policy as Code Workflow A policy is a rule, condition,

    or instruction that governs operations or processes. Policies become code. Code becomes automated guardrails. DEVOPSDAYS.PE 35 / 245
  31. Infrastructure Risks in CI/CD. PLANS ARE NOT VALIDATED, IAM IS

    NOT REVIEWED, STATE IS EXPOSED. DEVOPSDAYS.PE 36 / 45
  32. Real Failure Stories Here’s what happens when security is bolted

    on later. • Exposed S3 bucket • Over-permissive IAM role • Hardcoded secrets DEVOPSDAYS.PE 37 / 45
  33. Publicly Exposed Terraform State File Additional Real Failure Scenarios (Dev-Focused).

    • State file stored in public S3 • Credentials leaked via state • Lateral movement across environments DEVOPSDAYS.PE 38 / 45
  34. Example secure pipeline Developer workflow: • Write Terraform • Commit

    • CI pipeline runs: ◦ Terraform fmt / validate ◦ IaC security scan ◦ Policy checks • Auto-approve if compliant • Deploy Developers move fast, security stays enforced DEVOPSDAYS.PE 41 / 45
  35. Continue Your Terraform Journey These resources helped shape my Terraform

    journey. Excellent next steps. DEVOPSDAYS.PE 43/ 45
  36. Questions? Let’s talk about: • Terraform & Infrastructure as Code

    • DevSecOps & Security Automation • Policy as Code & Guardrails DEVOPSDAYS.PE 44 / 45
  37. Gracia s Conectemos Información de contacto Email: [email protected] Twitter @amaurybsouza

    Linkedin: /in/amaurybsouza DEVOPSDAYS.PE Información de contacto Slides: speakerdeck.com/amaurybsouza Code Examples: github.com/amaurybsouza Join the conversation: #DODLima #DevOpsDaysLima 45 / 45
  38. What is DevOps? PLATFORM CFP OPEN • LIVE DEVSECOPS CONFIRMED

    PENDING CLOSED ¿Necesitas más inspiración? Usa estos componentes listos desde la web: design-system.devopsdays.pe DEVOPSDAYS.PE 03 / 21
  39. The DevSecOps Mindset PENDING CLOSED • The DevSecOps Mindset] •

    asas • asasa • asasas • asasa • DEVOPSDAYS.PE 03 / 21
  40. Reality in most organizations • Terraform deployed without guardrails •

    Security checks happen late • Manual approvals slow pipelines • Developers bypass processes • Security becomes friction. DEVOPSDAYS.PE 03 / 21
  41. Largest risks at the code • Software Supply Chain •

    AI Agents • Non-Human Identities • CI/CD • Artifacts • Third-party integration Security has never been as important as it is in this era. DEVOPSDAYS.PE 04 / 21
  42. Cards & Alerts CARDS ALERTS ÉXITO PLATFORM Tu registro se

    completó correctamente. Track principal Charlas y talleres sobre cultura DevOps, plataformas internas y developer experience. INFO La próxima edición será del 21 al 22 de agosto. Ver agenda ADVERTENCIA Los cupos para talleres son limitados. CFP OPEN Postula tu charla ERROR No se pudo procesar el pago, intenta de nuevo. Comparte tu experiencia con la comunidad. El CFP está abierto hasta agosto. Postular DEVOPSDAYS.PE 04 / 21