Reader small image

You're reading from  Enterprise DevOps for Architects

Product typeBook
Published inNov 2021
Reading LevelBeginner
PublisherPackt
ISBN-139781801812153
Edition1st Edition
Languages
Concepts
Right arrow
Author (1)
Jeroen Mulder
Jeroen Mulder
author image
Jeroen Mulder

Jeroen Mulder is a certified enterprise and security architect, and he works with Fujitsu (Netherlands) as a Principal Business Consultant. Earlier, he was a Sr. Lead Architect, focusing on cloud and cloud native technology, at Fujitsu, and was later promoted to become the Head of Applications and Multi-Cloud Services. Jeroen is interested in the cloud technology, architecture for cloud infrastructure, serverless and container technology, application development, and digital transformation using various DevOps methodologies and tools. He has previously authored “Multi-Cloud Architecture and Governance”, “Enterprise DevOps for Architects”, and “Transforming Healthcare with DevOps4Care”.
Read more about Jeroen Mulder

Right arrow

Composing the DevSecOps pipeline

Let's look at a common DevOps pipeline first. The basic pipeline is shown in the following diagram:

Figure 12.1 – DevOps pipeline

The basic steps in the pipeline are as follows:

  • Pull code from the repository
  • Build
  • Test
  • Deploy

In DevSecOps, we are embedding security into the pipeline, making security standards and policies an integrated part of it. Security is a layer that is applied to every step in the pipeline, but it does include several steps. This is shown in the following diagram:

Figure 12.2 – DevSecOps pipeline

These steps are as follows:

  1. Dependency check: First, any vulnerability that exposes the code to the risk of an exploit should be removed. This includes code that relies on other pieces of code to run. There are differences in code dependencies: developers can have controlled and uncontrolled dependencies. As a common practice, we don...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Enterprise DevOps for Architects
Published in: Nov 2021Publisher: PacktISBN-13: 9781801812153

Author (1)

author image
Jeroen Mulder

Jeroen Mulder is a certified enterprise and security architect, and he works with Fujitsu (Netherlands) as a Principal Business Consultant. Earlier, he was a Sr. Lead Architect, focusing on cloud and cloud native technology, at Fujitsu, and was later promoted to become the Head of Applications and Multi-Cloud Services. Jeroen is interested in the cloud technology, architecture for cloud infrastructure, serverless and container technology, application development, and digital transformation using various DevOps methodologies and tools. He has previously authored “Multi-Cloud Architecture and Governance”, “Enterprise DevOps for Architects”, and “Transforming Healthcare with DevOps4Care”.
Read more about Jeroen Mulder