Slide 1

Slide 1 text

Secure your LINE Chatbot with Jirayut Nimsaeng (Dear) CEO & Founder, Opsta (Thailand) Co.,Ltd.

Slide 2

Slide 2 text

Do you think you are secure?

Slide 3

Slide 3 text

Jirayut Nimsaeng (Dear) Jirayut has been involved in DevSecOps, Container, Cloud Technology and Open Source for over 10 years. He has experienced and succeeded in transforming several companies to deliver greater values and be more agile. ● Founder and CEO of Opsta (Thailand) Co.,Ltd. ● Cloud/DevSecOps Transformation Consultant and Solution Architecture ● First Certified Kubernetes Administrator (CKA) and Certified Kubernetes Security Specialist (CKS) in Thailand ● First Thai Google Cloud Developer Expert (GDE) in Thailand ● Google Cloud Certified - Professional Cloud Architect and Associate Cloud Engineer #whoami

Slide 4

Slide 4 text

● What is DevSecOps? ● Cloud Native Security ● Live Demo Agenda

Slide 5

Slide 5 text

What is DevSecOps?

Slide 6

Slide 6 text

Generic DevOps Flow & Components Dev Ops VCS CI ARTIFACTS CD DEV UAT PRD LOAD TESTING MONITORING SUPPORT TOOLS AUTOMATION & INFRASTRUCTURE AS CODE COMMUNICATION INFRASTRUCTURE

Slide 7

Slide 7 text

Dev Ops Sec VCS CI ARTIFACTS CD COMMUNICATION DEV UAT PRD SECURITY LOAD TESTING MONITORING SUPPORT TOOLS AUTOMATION & INFRASTRUCTURE AS CODE When put Security into DevOps INFRASTRUCTURE

Slide 8

Slide 8 text

Dev Ops Sec VCS CI CD DEV UAT PRD LOAD TESTING MONITORING SUPPORT TOOLS AUTOMATION & INFRASTRUCTURE AS CODE COMMUNICATION DevSecOps Flow INFRASTRUCTURE SECURITY SHIFT LEFT WITH AUTOMATION ARTIFACTS

Slide 9

Slide 9 text

Dev Ops Sec VCS CI ARTIFACTS CD DEV UAT PRD INFRASTRUCTURE AUTOMATION SECURITY LOAD TESTING MONITORING SUPPORT TOOLS AUTOMATION & INFRASTRUCTURE AS CODE Automation Security COMMUNICATION

Slide 10

Slide 10 text

Secure Coding SAST SCA Vulnerability Assessment Penetration Testing IASTz Threat Intelligence Multi-Tenancy Landing Zone Secrets Management DAST Binary Analysis Threat Modeling SOC SOAR CWPP CSPM Security Automation in every steps Compliance Validation

Slide 11

Slide 11 text

Cloud Native Security

Slide 12

Slide 12 text

Cloud Native Technologies https://landscape.cncf.io

Slide 13

Slide 13 text

VCS CI ARTIFACTS CD DEV UAT PRD AUTOMATION SECURITY MONITORING AUTOMATION & INFRASTRUCTURE AS CODE Apps SUPPORT TOOLS Cloud Native and DevSecOps Components

Slide 14

Slide 14 text

Cloud-native application protection platforms (CNAPPs)

Slide 15

Slide 15 text

Shut up and Show me your CODE https://github.com/opsta/opsta-line-bot https://github.com/opsta/opsta-line-bot

Slide 16

Slide 16 text

● Are you sure you don’t have LINE channel secret in your code? ● DevSecOps is not easy (but worth it) ● DevSecOps will only benefit if you invest in it ● You can learn something new when you fix vulnerability ● START TODAY! Key Takeaways

Slide 17

Slide 17 text

What we offer DevSecOps Platform Engineering Portal (Subscription) End-to-end platform engineering ecosystem with self-service portal that provides a seamless experience from onboarding applications to day-2 operations. DevSecOps Transformation Security Automation Self-Service Automation Infrastructure Hybrid Multi-Cloud Infrastructure Kubernetes Service Provider Centralized Monitoring Training Consulting Service Centralized Application & DevSecOps Tools Management Streamline Access to All DevSecOps Tools, Build Application Structures, and Control Permissions. Security Governance Dashboard Centralized Dashboard for SAST, DAST, SCA, Container Scan, etc. Ready for Day 2 Operation Observability Dashboards to Quickly Identify Root Causes Best Practice DevSecOps Templates Zero-effort DevSecOps configuration on Cloud-Native application. Our Product Our Solution and Service

Slide 18

Slide 18 text

fb.me/DearJirayut www.linkedin.com/in/jirayut/ [email protected] www.opsta.co.th Jirayut Nimsaeng (Dear) Founder & CEO of Opsta https://github.com/opsta/opsta-line-bot https://github.com/opsta/opsta-line-bot

Slide 19

Slide 19 text

No content