This media is not supported in your browser
VIEW IN TELEGRAM
Loki, centralization of logs using the Prometheus way
https://medium.com/@yannig.perre_32769/loki-centralization-of-logs-using-the-prometheus-way-3e2d3c7f6227
https://medium.com/@yannig.perre_32769/loki-centralization-of-logs-using-the-prometheus-way-3e2d3c7f6227
GitLab 12.6 released with Security Scorecard and Release Evidence
https://about.gitlab.com/blog/2019/12/22/gitlab-12-6-released/
https://about.gitlab.com/blog/2019/12/22/gitlab-12-6-released/
The Azure Kubernetes Workshop
http://aksworkshop.io/
Welcome to the Azure Kubernetes Workshop. In this lab, you’ll go through tasks that will help you master the basic and more advanced topics required to deploy a multi-container application to Kubernetes on Azure Kubernetes Service (AKS).
. . .
Some of the things you’ll be going through:
- Kubernetes deployments, services and ingress
- Deploying MongoDB using Helm 2 (the instructions below are specifically for Helm 2 and will be later updated to Helm 3)
- Azure Monitor for Containers, Horizontal Pod Autoscaler and the Cluster Autoscaler
- Building CI/CD pipelines using Azure DevOps and Azure Container Registry
- Scaling using Virtual Nodes, setting up SSL/TLS for your deployments, using Azure Key Vault for secrets
http://aksworkshop.io/
2019-12-10 - error_page request smuggling.pdf
78.2 KB
NGINX error_page request smuggling
> The error_page redirect is used by various products in conjunction with auth_request to redirect the user to an appropriate login page when their session has expired. For example the kubernetes NGINX ingress controller use this to protect resources and redirect on authorization failure.
+
https://twitter.com/bertjwregeer/status/1209470321327312896
За ссылку спасибо @ldviolet
> The error_page redirect is used by various products in conjunction with auth_request to redirect the user to an appropriate login page when their session has expired. For example the kubernetes NGINX ingress controller use this to protect resources and redirect on authorization failure.
+
https://twitter.com/bertjwregeer/status/1209470321327312896
За ссылку спасибо @ldviolet
My Business Card Runs Linux
https://www.thirtythreeforty.net/posts/2019/12/my-business-card-runs-linux/
https://www.thirtythreeforty.net/posts/2019/12/my-business-card-runs-linux/
Технологический Болт Генона
Каждый год, начиная с 2009, проходит огромное количество конференций под общим названием DevOpsDays Оценить масштаб действа можно на главном сайте https://devopsdays.org/ Прикоснуться к прекрасному можно будет на DevOpsDays Moscow 2019. Конференция является…
YouTube
DevOpsDays Moscow 2019 - YouTube
Пост от @kvaps
Пробуем новые инструменты для сборки и автоматизации деплоя в Kubernetes
https://habr.com/post/481662/
Пробуем новые инструменты для сборки и автоматизации деплоя в Kubernetes
https://habr.com/post/481662/
Habr
Пробуем новые инструменты для сборки и автоматизации деплоя в Kubernetes
Привет! За последнее время вышло много классных инструментов автоматизации как для сборки Docker-образов так и для деплоя в Kubernetes. В связи с этим решил поиграться с гитлабом, как следует...
Forwarded from Пятничный деплой
Давно ждал это сравнение https://habr.com/ru/post/482272/
Хабр
Выбираем хранилище данных для Prometheus: Thanos vs VictoriaMetrics
Всем привет. Ниже представлена расшифровка доклада с Big Monitoring Meetup 4. Prometheus – система мониторинга различных систем и сервисов, с помощью которой системные администраторы могут...
SpiderFoot is an open source intelligence (OSINT) automation tool. Its goal is to automate the process of gathering intelligence about a given target, which may be an IP address, domain name, hostname, network subnet, ASN, e-mail address or person's name.
SpiderFoot can be used offensively, i.e. as part of a black-box penetration test to gather information about the target, or defensively to identify what information you or your organisation are freely providing for attackers to use against you.
https://github.com/smicallef/spiderfoot
Запись докладов с HighLoad++ Siberia 2019
https://www.youtube.com/playlist?list=PLH-XmS0lSi_yY4rQCIZyx5Np57zc77OyE
Программа
http://www.highload.ru/siberia/2019/schedule
https://www.youtube.com/playlist?list=PLH-XmS0lSi_yY4rQCIZyx5Np57zc77OyE
Программа
http://www.highload.ru/siberia/2019/schedule
Forwarded from Пятничный деплой
В выходные можно развлечь себя чтением про ТОП 10 багов в opensource проектах на C++, C# и Java за 2019 год - https://habr.com/ru/company/pvs-studio/blog/481178/
https://habr.com/ru/company/pvs-studio/blog/481186/
https://habr.com/ru/company/pvs-studio/blog/481190/
https://habr.com/ru/company/pvs-studio/blog/481186/
https://habr.com/ru/company/pvs-studio/blog/481190/
Хабр
Топ 10 ошибок в проектах C# за 2019 год
Приветствуем всех любителей багов. Уже скоро наступит Новый год, так что самое время подвести итоги года уходящего. По традиции — рейтинг самых интересных ошибок, которые были обнаружены командой...
This media is not supported in your browser
VIEW IN TELEGRAM
Checkov is a static code analysis tool for infrastructure-as-code. It scans cloud infrastructure provisioned using Terraform and detects security and compliance misconfigurations.
. . .
Features
- 50+ built-in policies cover security and compliance best practices for AWS, Azure & Google Cloud.
- Policies support variable scanning by building a dynamic code dependency graph (coming soon).
- Supports in-line suppression of accepted risks or false-positives to reduce recurring scan failures.
- Output currently available as CLI, JSON or JUnit XML.
https://github.com/bridgecrewio/checkov
This media is not supported in your browser
VIEW IN TELEGRAM
Итоги 2019
Канал начинался чуть больше года назад, как место для записей важного и ценного из интернетов, но непреодолимая тяга к шарингу знаний привела его к тому, что есть на сегодня: больше восьмиста подписчиков, большое количество обратной связи и нового общения (не только в интернетах).
Спасибо всем большое за то что читаете, пишете, критикуете, делитесь и репостите!
Всем новых свершений в 2020!
ЗЫ
Канал начинался чуть больше года назад, как место для записей важного и ценного из интернетов, но непреодолимая тяга к шарингу знаний привела его к тому, что есть на сегодня: больше восьмиста подписчиков, большое количество обратной связи и нового общения (не только в интернетах).
Спасибо всем большое за то что читаете, пишете, критикуете, делитесь и репостите!
Всем новых свершений в 2020!
ЗЫ
$ clear; while :;do echo $LINES $COLUMNS $(($RANDOM%$COLUMNS)) $(printf "\u2744\n");sleep 0.1;done|gawk '{a[$3]=0;for(x in a) {o=a[x];a[x]=a[x]+1;printf "\033[%s;%sH ",o,x;printf "\033[%s;%sH%s \033[0;0H",a[x],x,$4;}}'Выложили доклады с PromCon EU 2019
https://www.youtube.com/playlist?list=PLoz-W_CUquUmIYKS97RBghcWumZIX2kvv
Программа тут
https://promcon.io/2019-munich/schedule/
https://www.youtube.com/playlist?list=PLoz-W_CUquUmIYKS97RBghcWumZIX2kvv
Программа тут
https://promcon.io/2019-munich/schedule/
YouTube
Share your videos with friends, family, and the world
Epic Failures - Volume 1.pdf
8.1 MB
Epic Failures in DevSecOps. Volume 1.
Use GitHub actions at your own risk
https://julienrenaux.fr/2019/12/20/github-actions-security-risk/
https://julienrenaux.fr/2019/12/20/github-actions-security-risk/
Forwarded from Sysadmin Tools 🇺🇦
CI/CD для фронтенда: обзор инструментов и практик для автоматизации разработки | DOU
https://dou.ua/lenta/articles/ci-cd-for-frontend/
https://dou.ua/lenta/articles/ci-cd-for-frontend/
DOU
CI/CD для фронтенда: обзор инструментов и практик для автоматизации разработки
Разобраться в том, как ваше приложение будет автоматически собираться и деплоиться - хорошая идея для разработчика. Тем более сейчас тренд на T-shaped people. В статье подробно рассмотрим деплой- и релиз-шаги.
A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI
https://github.com/aquasecurity/trivy
https://github.com/aquasecurity/trivy
Forwarded from Sysadmin Tools 🇺🇦
Backporting #BCC & #bpftrace for
Ubuntu 18.04 “Bionic Beaver” 😏
https://chabik.com/2020/01/backporting-bcc-bpftrace/
Ubuntu 18.04 “Bionic Beaver” 😏
https://chabik.com/2020/01/backporting-bcc-bpftrace/
This media is not supported in your browser
VIEW IN TELEGRAM
A hybrid command-line/UI development experience for cloud-native development
https://github.com/IBM/kui
Forwarded from oleg_log (Oleg Kovalov)
Поговорим о зависимостях? Опять.
Ты берешь либу BSD3, а в ней оказывается зависимость с Affero GPL (AGPL, такая лицензия для опенсурс веб-сервисов), и все, ты нарушитель и должен публиковать весь свой проект в опенсурс.
Большинство из нас конечно в СНГ, где царят чуть другие правила, но зачем лишний раз себе/бизнесу (своему и не) создавать проблемы, которые могут стоить очень дорого?
Соглашусь еще по теме Раста: когда открываешь Cargo.toml чаще хочется взвыть и закрыть. Я понимаю, глаза привыкли видеть другое, но колво одного и того же велосипедирования печалит.
https://www.agwa.name/blog/post/always_review_your_dependencies
Ты берешь либу BSD3, а в ней оказывается зависимость с Affero GPL (AGPL, такая лицензия для опенсурс веб-сервисов), и все, ты нарушитель и должен публиковать весь свой проект в опенсурс.
Большинство из нас конечно в СНГ, где царят чуть другие правила, но зачем лишний раз себе/бизнесу (своему и не) создавать проблемы, которые могут стоить очень дорого?
Соглашусь еще по теме Раста: когда открываешь Cargo.toml чаще хочется взвыть и закрыть. Я понимаю, глаза привыкли видеть другое, но колво одного и того же велосипедирования печалит.
https://www.agwa.name/blog/post/always_review_your_dependencies
www.agwa.name
This Is Why You Always Review Your Dependencies, AGPL Edition