Технологический Болт Генона
9.55K subscribers
3.38K photos
438 videos
221 files
4.32K links
До Декарта никогда не существовало рационализма.

Музыкальный Болт Генона: @mus_b0lt_Genona
Мемный Болт Генона: @mem_b0lt_Genona
Кадровый Болт Генона: @kadr_b0lt_Genona
Генеалогический Болт Генона: @gen_b0lt_Genona
Обратная связь: @rusdacent
Download Telegram
The Azure Kubernetes Workshop

Welcome to the Azure Kubernetes Workshop. In this lab, you’ll go through tasks that will help you master the basic and more advanced topics required to deploy a multi-container application to Kubernetes on Azure Kubernetes Service (AKS).
. . .
Some of the things you’ll be going through:

- Kubernetes deployments, services and ingress
- Deploying MongoDB using Helm 2 (the instructions below are specifically for Helm 2 and will be later updated to Helm 3)
- Azure Monitor for Containers, Horizontal Pod Autoscaler and the Cluster Autoscaler
- Building CI/CD pipelines using Azure DevOps and Azure Container Registry
- Scaling using Virtual Nodes, setting up SSL/TLS for your deployments, using Azure Key Vault for secrets

http://aksworkshop.io/
2019-12-10 - error_page request smuggling.pdf
78.2 KB
NGINX error_page request smuggling

> The error_page redirect is used by various products in conjunction with auth_request to redirect the user to an appropriate login page when their session has expired. For example the kubernetes NGINX ingress controller use this to protect resources and redirect on authorization failure.

+

https://twitter.com/bertjwregeer/status/1209470321327312896

За ссылку спасибо @ldviolet
SpiderFoot is an open source intelligence (OSINT) automation tool. Its goal is to automate the process of gathering intelligence about a given target, which may be an IP address, domain name, hostname, network subnet, ASN, e-mail address or person's name.

SpiderFoot can be used offensively, i.e. as part of a black-box penetration test to gather information about the target, or defensively to identify what information you or your organisation are freely providing for attackers to use against you.

https://github.com/smicallef/spiderfoot
This media is not supported in your browser
VIEW IN TELEGRAM
Checkov is a static code analysis tool for infrastructure-as-code. It scans cloud infrastructure provisioned using Terraform and detects security and compliance misconfigurations.
. . .
Features
- 50+ built-in policies cover security and compliance best practices for AWS, Azure & Google Cloud.
- Policies support variable scanning by building a dynamic code dependency graph (coming soon).
- Supports in-line suppression of accepted risks or false-positives to reduce recurring scan failures.
- Output currently available as CLI, JSON or JUnit XML.


https://github.com/bridgecrewio/checkov
This media is not supported in your browser
VIEW IN TELEGRAM
Итоги 2019

Канал начинался чуть больше года назад, как место для записей важного и ценного из интернетов, но непреодолимая тяга к шарингу знаний привела его к тому, что есть на сегодня: больше восьмиста подписчиков, большое количество обратной связи и нового общения (не только в интернетах).

Спасибо всем большое за то что читаете, пишете, критикуете, делитесь и репостите!
Всем новых свершений в 2020!

ЗЫ
$ clear; while :;do echo $LINES $COLUMNS $(($RANDOM%$COLUMNS)) $(printf "\u2744\n");sleep 0.1;done|gawk '{a[$3]=0;for(x in a) {o=a[x];a[x]=a[x]+1;printf "\033[%s;%sH ",o,x;printf "\033[%s;%sH%s \033[0;0H",a[x],x,$4;}}'
A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI
https://github.com/aquasecurity/trivy
Forwarded from oleg_log (Oleg Kovalov)
Поговорим о зависимостях? Опять.

Ты берешь либу BSD3, а в ней оказывается зависимость с Affero GPL (AGPL, такая лицензия для опенсурс веб-сервисов), и все, ты нарушитель и должен публиковать весь свой проект в опенсурс.

Большинство из нас конечно в СНГ, где царят чуть другие правила, но зачем лишний раз себе/бизнесу (своему и не) создавать проблемы, которые могут стоить очень дорого?

Соглашусь еще по теме Раста: когда открываешь Cargo.toml чаще хочется взвыть и закрыть. Я понимаю, глаза привыкли видеть другое, но колво одного и того же велосипедирования печалит.

https://www.agwa.name/blog/post/always_review_your_dependencies