(OAuth & OpenID) Testing & Testing-Dr i ven Development (TDD) Continuous Delivery Pipelines-as-Code Infrastructure-as-Code REST API Standards Basic Networking Basic Linux/Windows Systems Basic Secur i ty (Vulnerability Management) Site Reliability Engineer i ng Observability (Monitor i ng, Logging, Tracing) Public Cloud Constructs Container i zation (Orchestrators & Runtimes) Secret Management Code (Python, Ruby, Golang) Chaos Engineer i ng Release & Deliver Software Microservices User Interfaces/APIs DevOps Site Reliability Engineer i ng “Platform”? PaaS which uses patterns like which you which you more easily by applying which has technologies classif i ed as sometimes packaged as which can be runs on All done as securely as possible Philosophy whose practical implementation can be through Physical Devices Pr i vate Cloud Datacenter Infrastructure Public Cloud (IaaS) Network, Systems & More composed of which can be which runs on Trying to put the terms together Confusing Job Descr i ptors Pr i vate Public Cloud Site Reliability Engineer/Developer Platform DevOps Release Infrastructure Systems Network
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale
Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Scale As code Self-service Systems of record
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale
Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Scale As code Self-service Systems of record
Lifecycle Management Access control • Isolate changes to parts of the system • Decouple infrastructure dependencies • Isolate least pr i vilege access • Decouple identity from access policy
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale
Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Scale As code Self-service Systems of record
Remediation • Develop consistent deployments • Improve predictability of changes and rollbacks • Develop baseline for detecting anomalous behavior • Improve speed of f i xes
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale
Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Scale As code Self-service Systems of record
Ephemerality • Change resource by creation and deletion • Support lower r i sk refactor i ng patterns • Change time-to-live of resources to reduce attack surface • Support resiliency patterns for short-lived resources
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale
Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Scale As code Self-service Systems of record
i zation Secur i ty Lifecycle Management Ephemerality Remediation Access control Standardization Immutability Delete Update Create Monitor i ng Read Observability Foundations for ILM/SLM Scale