CatOps
In less than a week will start HashiConf Global So, we have great proposal for our community - talk with Hashimoto and Dadgar on HUG Kyiv later this year in convenient for us time zone. And, in the brightest future, we would like HashiCorp to listen to…
Who won? We won!
Wiil be officially announced at Second Day of HashiConf Global that will start at 19:00 Kyiv TZ (16:00 UTC)
Wiil be officially announced at Second Day of HashiConf Global that will start at 19:00 Kyiv TZ (16:00 UTC)
Nginx playground by Julia Evans.
It works just like any other code playground out there, but for Nginx configurations.
Could be useful if you want to test a change without rolling new machines.
#nginx
It works just like any other code playground out there, but for Nginx configurations.
Could be useful if you want to test a change without rolling new machines.
#nginx
During our previous voice chat we briefly mentioned Wardley mapping.
This is an approach to map a strategy for product or process development.
Here's an awesome list of Wardley Maps, which contains a handful of resources that can help you get into mapping or improve your mapping skills.
#mapping #management
This is an approach to map a strategy for product or process development.
Here's an awesome list of Wardley Maps, which contains a handful of resources that can help you get into mapping or improve your mapping skills.
#mapping #management
GitHub
GitHub - wardley-maps-community/awesome-wardley-maps: Wardley maps community hub. Useful Wardley mapping resources
Wardley maps community hub. Useful Wardley mapping resources - wardley-maps-community/awesome-wardley-maps
And here is the video that inspired one of our subscribers to learn about Wardley mapping:
https://www.youtube.com/watch?v=2IW9L1uNMCs
https://www.youtube.com/watch?v=2IW9L1uNMCs
YouTube
Crossing the River by Feeling the Stones • Simon Wardley • GOTO 2018
This presentation was recorded at GOTO Copenhagen 2018. #gotocon #gotocph
https://gotocph.com
Simon Wardley - Researcher for The Leading Edge Forum @simonwardley
ABSTRACT
Deng Xiaoping once described managing the economy as crossing the river by feeling…
https://gotocph.com
Simon Wardley - Researcher for The Leading Edge Forum @simonwardley
ABSTRACT
Deng Xiaoping once described managing the economy as crossing the river by feeling…
There are multiple ways to define, which technology to use in a company or a project.
Sometimes, the decision-making point is simply "I have experience working with the technology A". This is especially common, when a company size is not that big and impact of such decisions seems not very broad.
However, if you're choosing a cache solution, and you're choosing between Memcached and Redis, this article may help you to make a more informed one.
#redis #memcached #cache
Sometimes, the decision-making point is simply "I have experience working with the technology A". This is especially common, when a company size is not that big and impact of such decisions seems not very broad.
However, if you're choosing a cache solution, and you're choosing between Memcached and Redis, this article may help you to make a more informed one.
#redis #memcached #cache
engineering.kablamo.com.au
Memcached vs Redis - More Different Than You Would Expect | Insights from the Kablamo Team.
Insights from the Kablamo Engineering Team
🔥1
Noice!
If you're using EC2 Auto Scaling or EC2 Fleet, now you can just tell it "gimme nodes with 2 to 4 vCPUs and 16 to 64 Gigs of RAM", instead of defining instance types explicitly!
It's available with the new Attribute-Based Instance Type Selection feature
#aws
If you're using EC2 Auto Scaling or EC2 Fleet, now you can just tell it "gimme nodes with 2 to 4 vCPUs and 16 to 64 Gigs of RAM", instead of defining instance types explicitly!
It's available with the new Attribute-Based Instance Type Selection feature
#aws
Amazon
New – Attribute-Based Instance Type Selection for EC2 Auto Scaling and EC2 Fleet | Amazon Web Services
The first AWS service I used, more than ten years ago, was Amazon Elastic Compute Cloud (Amazon EC2). Over time, EC2 has added a wide selection of instance types optimized to fit different use cases, with a varying combination of CPU/GPU, memory, storage…
Forwarded from DevOps Deflope News
Пару дней назад вышел новый Technology Radar от ThoughtWorks (https://a.e42.link/j1qLb).
На этот раз много пунктов относится к инфраструктуре и командообразованию, также немалое количество пунктов про удаленную работу:
— 4 ключевые метрики DORA перешли в Adopt и рекомендуются для применения всеми. Если у вас нет дашборда для их отслеживания можно периодически раз в квартал проходить DORA quick check: https://a.e42.link/j1qWj
— Платформенные команды также перешли в Adopt и рекомендуются как хороший подход. Важно отметить, что платформенная команда это не переименованные operations, а команда разработки точно такая же как и любые другие команды разработки — со своим product owner, продуктовым планированием, разбиением на фичи, работой с бэклогом, и т.д. Одним словом, платформенная команда — это команда разработки, которая пишет продукт для использования внутри компании другими командами
— Учитывание когнитивной нагрузки команд в проектировании архитектуры. Про это уже говорилось в предыдущем радаре и в книге https://a.e42.link/j1qW8 — кто еще не знаком с концепцией и подходом очень рекомендуем ознакомиться
— Remote mob-programming. Это как парное программирование, только больше чем вдвоем и не в одной комнате у доски, а удаленное. Парное программирование мы применяли с отличными результатами как раз через Zoom — оно хорошо подходит для случая когда не совсем ясно как именно и что писать, гораздо лучше чем параллельная работа с синками через каждые 2-3 часа.
— В блоке Assess появилось использование Kubernetes Operator для управления ресурсами за пределами Kubernetes. В предыдущих радарах уже упоминались инструменты для этого, теперь на радаре появилась и сама практика. Также в этом радаре появился и Crossplane (https://a.e42.link/j1qWT)
— В блоке Trial по-прежнему находится https://a.e42.link/j1qWz (инструмент для построения внутренних технологических порталов и витрин),
— Также в этом же блоке появились Clickhouse, Kafka REST Proxy, Kafka Mirrormaker 2.0, OPA Gatekeeper for Kubernetes и Sealed Secrets
— Из Assess в Trial поднялись GitHub Actions, K3s и Pulumi
— Написание скриптов командной строки на Clojure: Babashka (https://a.e42.link/j1qWY) — за счет использования GraalVM обещают, что он стартует мгновенно, а не как другие JVM-приложения
— ExternalDNS для синхронизации ингрессов с DNS-провайдерами появился в Assess
— Batect (https://a.e42.link/j1qWt) как способ настройки окружений локальных и тестовых
— Berglas (https://a.e42.link/j1qWm) для управления секретами в GCP
— Dive (https://a.e42.link/j1qWZ) — сканнер оптимальности сборки докер-образов. Может отслеживать неэффективность послойной сборки и вычислять «лишний» объем образа (например файлы создаются в нижнем слое, а затем удаляются в верхнем слое)
— Lens (https://a.e42.link/j1qWp) как UI для Kubernetes перешел в Trial
— cert-manager (https://a.e42.link/j1qWl) наконец-то появился на радаре
— Появились аж 2 инструмента для тестирования инфракода: Conftest (https://a.e42.link/j1qWB) и Regula (https://a.e42.link/j1qWn). Оба используют язык Open Policy Agent для написания тестов. Такие тесты могут использоваться, например, для автоматизированного тестирования Compliance
— Появился Cosign (https://a.e42.link/j1qWG) — инструмент для подписи и проверки подписи контейнеров
— Забавно, но в этом радаре появились и современные альтернативы командам из Coreutils (под именем Modern Unix commands) наподобие ripgrep, ag, jq, httpie. Большой список таких команд можно посмотреть на https://a.e42.link/j1qWx
— Mozilla Sops (https://a.e42.link/j1qWf) для безопасного хранения шифрованных секретов в гит-репозиториях (с расшифровкой например через AWS KMS)
— Pactflow (https://a.e42.link/j1qWC) — инструмент для тестирования контрактов
— Proxyman (https://a.e42.link/j1qWk) — прокси для отладки веб-приложений
— Telepresence (https://a.e42.link/j1qWe) — инструмент для подключения локально запущенного приложения к удаленному кластеру кубернетес. Может пригодиться например для песочниц разработки
На этот раз много пунктов относится к инфраструктуре и командообразованию, также немалое количество пунктов про удаленную работу:
— 4 ключевые метрики DORA перешли в Adopt и рекомендуются для применения всеми. Если у вас нет дашборда для их отслеживания можно периодически раз в квартал проходить DORA quick check: https://a.e42.link/j1qWj
— Платформенные команды также перешли в Adopt и рекомендуются как хороший подход. Важно отметить, что платформенная команда это не переименованные operations, а команда разработки точно такая же как и любые другие команды разработки — со своим product owner, продуктовым планированием, разбиением на фичи, работой с бэклогом, и т.д. Одним словом, платформенная команда — это команда разработки, которая пишет продукт для использования внутри компании другими командами
— Учитывание когнитивной нагрузки команд в проектировании архитектуры. Про это уже говорилось в предыдущем радаре и в книге https://a.e42.link/j1qW8 — кто еще не знаком с концепцией и подходом очень рекомендуем ознакомиться
— Remote mob-programming. Это как парное программирование, только больше чем вдвоем и не в одной комнате у доски, а удаленное. Парное программирование мы применяли с отличными результатами как раз через Zoom — оно хорошо подходит для случая когда не совсем ясно как именно и что писать, гораздо лучше чем параллельная работа с синками через каждые 2-3 часа.
— В блоке Assess появилось использование Kubernetes Operator для управления ресурсами за пределами Kubernetes. В предыдущих радарах уже упоминались инструменты для этого, теперь на радаре появилась и сама практика. Также в этом радаре появился и Crossplane (https://a.e42.link/j1qWT)
— В блоке Trial по-прежнему находится https://a.e42.link/j1qWz (инструмент для построения внутренних технологических порталов и витрин),
— Также в этом же блоке появились Clickhouse, Kafka REST Proxy, Kafka Mirrormaker 2.0, OPA Gatekeeper for Kubernetes и Sealed Secrets
— Из Assess в Trial поднялись GitHub Actions, K3s и Pulumi
— Написание скриптов командной строки на Clojure: Babashka (https://a.e42.link/j1qWY) — за счет использования GraalVM обещают, что он стартует мгновенно, а не как другие JVM-приложения
— ExternalDNS для синхронизации ингрессов с DNS-провайдерами появился в Assess
— Batect (https://a.e42.link/j1qWt) как способ настройки окружений локальных и тестовых
— Berglas (https://a.e42.link/j1qWm) для управления секретами в GCP
— Dive (https://a.e42.link/j1qWZ) — сканнер оптимальности сборки докер-образов. Может отслеживать неэффективность послойной сборки и вычислять «лишний» объем образа (например файлы создаются в нижнем слое, а затем удаляются в верхнем слое)
— Lens (https://a.e42.link/j1qWp) как UI для Kubernetes перешел в Trial
— cert-manager (https://a.e42.link/j1qWl) наконец-то появился на радаре
— Появились аж 2 инструмента для тестирования инфракода: Conftest (https://a.e42.link/j1qWB) и Regula (https://a.e42.link/j1qWn). Оба используют язык Open Policy Agent для написания тестов. Такие тесты могут использоваться, например, для автоматизированного тестирования Compliance
— Появился Cosign (https://a.e42.link/j1qWG) — инструмент для подписи и проверки подписи контейнеров
— Забавно, но в этом радаре появились и современные альтернативы командам из Coreutils (под именем Modern Unix commands) наподобие ripgrep, ag, jq, httpie. Большой список таких команд можно посмотреть на https://a.e42.link/j1qWx
— Mozilla Sops (https://a.e42.link/j1qWf) для безопасного хранения шифрованных секретов в гит-репозиториях (с расшифровкой например через AWS KMS)
— Pactflow (https://a.e42.link/j1qWC) — инструмент для тестирования контрактов
— Proxyman (https://a.e42.link/j1qWk) — прокси для отладки веб-приложений
— Telepresence (https://a.e42.link/j1qWe) — инструмент для подключения локально запущенного приложения к удаленному кластеру кубернетес. Может пригодиться например для песочниц разработки
There was a question in CatOps chat regarding the resources to learn the Go programming language from scratch with the background in other technologies.
So, here is a quick ad-hoc list of resources, we came up with:
Books:
- Go in Practice
- The Go Programming Language
Courses and tutorials:
- Practical Go Lessons
- Algorythms with Go
- Go by Example
- Effective Go
Blogs:
- Three Dots Labs
Of course, you can also find a great list of learning materials in the Awesome Go list
If you would like to add to this short list - welcome in the comments!
#programming #go
So, here is a quick ad-hoc list of resources, we came up with:
Books:
- Go in Practice
- The Go Programming Language
Courses and tutorials:
- Practical Go Lessons
- Algorythms with Go
- Go by Example
- Effective Go
Blogs:
- Three Dots Labs
Of course, you can also find a great list of learning materials in the Awesome Go list
If you would like to add to this short list - welcome in the comments!
#programming #go
Telegram
CatOps Chat
Chat of the @catops channel
1Password promise two years free membership for their service for Open Source software maintenaners and their teams.
However, to get access you have to be a project lead or a core contributor for an active open source project that is at least 30 days old. We’ll also accept applications from the organisers of community meetups and events, as well as some conferences.
Open source projects need to use a standard open source license and must be non-commercial. Your project should not have paid support or pay contributors.
More details on the linked page.
#security #free_stuff
However, to get access you have to be a project lead or a core contributor for an active open source project that is at least 30 days old. We’ll also accept applications from the organisers of community meetups and events, as well as some conferences.
Open source projects need to use a standard open source license and must be non-commercial. Your project should not have paid support or pay contributors.
More details on the linked page.
#security #free_stuff
GitHub
GitHub - 1Password/for-open-source: Get a 1Password team account for free to support your open source initiatives!
Get a 1Password team account for free to support your open source initiatives! - 1Password/for-open-source
TIL:
AWS has much higher environmental impact comparing to Google Cloud and Azure.
Would it drive decisions on what cloud to chose? I don’t know. Probably not.
However, if you’re looking for a cloud provider for your pet project or a startup, this is something to consider.
#cloud #aws #gcp #azure
AWS has much higher environmental impact comparing to Google Cloud and Azure.
Would it drive decisions on what cloud to chose? I don’t know. Probably not.
However, if you’re looking for a cloud provider for your pet project or a startup, this is something to consider.
#cloud #aws #gcp #azure
Greenpeace USA
Microsoft, Google, Amazon – Who’s the Biggest Climate Hypocrite? - Greenpeace USA
Some of the world’s biggest tech companies want you to know they take climate change seriously. In fact, Amazon, Microsoft, and Google have each developed a plan to address its contributions to climate change. While each company’s plan is unique, none address…
DevOps-ish community loves Go.
So, here's a short story about simple re-arranging fields in a
#programming #go #performance
So, here's a short story about simple re-arranging fields in a
struct that saved 1/3 of memory consumption.#programming #go #performance
From time to time people bring the topic of testing during our voice chests.
Here Kent Beck, a creator of extreme programming, provides 11 properties for good tests:
- Isolated — tests should return the same results regardless of the order in which they are run.
- Composable — if tests are isolated, then I can run 1 or 10 or 100 or 1,000,000 and get the same results.
- Fast — tests should run quickly.
- Inspiring — passing the tests should inspire confidence
- Writable — tests should be cheap to write relative to the cost of the code being tested.
- Readable — tests should be comprehensible for reader, invoking the motivation for writing this particular test.
- Behavioral — tests should be sensitive to changes in the behavior of the code under test. If the behavior changes, the test result should change.
- Structure-insensitive — tests should not change their result if the structure of the code changes.
- Automated — tests should run without human intervention.
- Specific — if a test fails, the cause of the failure should be obvious.
- Deterministic — if nothing changes, the test result shouldn’t change.
- Predictive — if the tests all pass, then the code under test should be suitable for production.
#programming #testing
Here Kent Beck, a creator of extreme programming, provides 11 properties for good tests:
- Isolated — tests should return the same results regardless of the order in which they are run.
- Composable — if tests are isolated, then I can run 1 or 10 or 100 or 1,000,000 and get the same results.
- Fast — tests should run quickly.
- Inspiring — passing the tests should inspire confidence
- Writable — tests should be cheap to write relative to the cost of the code being tested.
- Readable — tests should be comprehensible for reader, invoking the motivation for writing this particular test.
- Behavioral — tests should be sensitive to changes in the behavior of the code under test. If the behavior changes, the test result should change.
- Structure-insensitive — tests should not change their result if the structure of the code changes.
- Automated — tests should run without human intervention.
- Specific — if a test fails, the cause of the failure should be obvious.
- Deterministic — if nothing changes, the test result shouldn’t change.
- Predictive — if the tests all pass, then the code under test should be suitable for production.
#programming #testing
Medium
Test Desiderata
Go placidly amid the noise and haste, and remember what peace there may be in silence
Some people use to think that a job interview is a one-way road. Like an exam: there’s a person or two who ask questions to evaluate your skills and you should excel in answering everything.
While in reality interviews are bi-directional process. It is important for a company to hire matching talent, but it’s not less important for an individual to look for a matching company.
Here Gergely Orosz, an author of The Pragmatic Engineer Blog, proposes a test to evaluate the engineering culture in a team (eng culture may be different from team to ten in the large companies). This tests consists of 12 questions, which you can ask at any stage of the interviewing process.
As a bonus, you can evaluate you current company as well!
#culture #hiring
While in reality interviews are bi-directional process. It is important for a company to hire matching talent, but it’s not less important for an individual to look for a matching company.
Here Gergely Orosz, an author of The Pragmatic Engineer Blog, proposes a test to evaluate the engineering culture in a team (eng culture may be different from team to ten in the large companies). This tests consists of 12 questions, which you can ask at any stage of the interviewing process.
As a bonus, you can evaluate you current company as well!
#culture #hiring
The Pragmatic Engineer
The Pragmatic Engineer Test: 12 Questions on Engineering Culture
12 questions to get a sense of what a tech company is like to work at, based on
things most job postings do not mention.
I created this test to reflect healthy software engineering cultures in 2021
better. I've found the now 20-year-old the Joel test
[…
things most job postings do not mention.
I created this test to reflect healthy software engineering cultures in 2021
better. I've found the now 20-year-old the Joel test
[…
I have already recommended CUE (or cuelang) in a few chats to validate Kubernetes manifests.
However, the language itself is capable of many more things than just validate some configuration files.
For example, you can write your configuration in CUE as well!
Here is a blog post, which describes the basic concepts of this language as well as some real world use cases.
#cue #kubernetes
However, the language itself is capable of many more things than just validate some configuration files.
For example, you can write your configuration in CUE as well!
Here is a blog post, which describes the basic concepts of this language as well as some real world use cases.
#cue #kubernetes
Bitfield Consulting
CUE is an exciting configuration language — Bitfield Consulting
CUE is a new data language, inspired by Go, that promises to make JSON, YAML, and other annoying formats much easier to work with. It features type checking, validation, and an excellent set of tooling.
Some useful resources for Kubernetes CKA exam preparation:
- Kubectl Cheat Sheet for Kubernetes Admins & CKA Exam Prep
- Useful bookmarks. You are allowed to use those
- Killer.sh - CKS, CKA, CKAD simulator
Good luck to those, who is looking forward to complete one of those exams!
#kubernetes #education
- Kubectl Cheat Sheet for Kubernetes Admins & CKA Exam Prep
- Useful bookmarks. You are allowed to use those
- Killer.sh - CKS, CKA, CKAD simulator
Good luck to those, who is looking forward to complete one of those exams!
#kubernetes #education
Upcoming features of Go 1.18
Yes, generics, but not only.
Also, here's the draft for release notes, but it's still in progress.
#go #programming
Yes, generics, but not only.
Also, here's the draft for release notes, but it's still in progress.
#go #programming
sebastian-holstein.de
Upcoming Features in Go 1.18 | Sebastian Holstein
Nice overview of policy enforcement tools for Kubernetes by Viktor Farcic. Gatekeeper (OPA implementation for K8s) vs Kyverno specifically.
tl;dr: Kyverno won this one.
However, I would like to make a few personal additions in favor of Gatekeeper. The first important point - and Viktor mentions it as well - is that you can use OPA to enforce policies outside Kubernetes. For example, you can write policy checks for your Terraform code and why not. Also, you can use something like Conftest to check your resources even before they are applied in a cluster!
Another important thing I want to point out is that Rego is a real programming language, even though it‘s not the most obvious one. You can write tests for your constraint templates, which is very powerful in terms of keeping your policies in a good shape. With Kyverno you have YAML, which is easier, but you need to validate YAML somehow. With Rego you get tests out of the box. Here is a good article that helped me write tests for Rego back in a day.
#kubernetes #security #kyverno #opa #gatekeeper #rego
tl;dr: Kyverno won this one.
However, I would like to make a few personal additions in favor of Gatekeeper. The first important point - and Viktor mentions it as well - is that you can use OPA to enforce policies outside Kubernetes. For example, you can write policy checks for your Terraform code and why not. Also, you can use something like Conftest to check your resources even before they are applied in a cluster!
Another important thing I want to point out is that Rego is a real programming language, even though it‘s not the most obvious one. You can write tests for your constraint templates, which is very powerful in terms of keeping your policies in a good shape. With Kyverno you have YAML, which is easier, but you need to validate YAML somehow. With Rego you get tests out of the box. Here is a good article that helped me write tests for Rego back in a day.
#kubernetes #security #kyverno #opa #gatekeeper #rego
YouTube
Kubernetes Policy Management Tools Compared - OPA with Gatekeeper vs. Kyverno
Which Kubernetes policy management tool should you choose? Which one fits your needs the best? Should you use Open Policy Agent (OPA) with Gatekeeper or Kyverno? What are the pros and cons of each? Which one is better?
#Gatekeeper #OPA #Kyverno #Kubernetes…
#Gatekeeper #OPA #Kyverno #Kubernetes…
I have two recommendations of books bundles today. I was thinking if it makes sense to combine them into one message, but decided to push them separately.
So, the first one is a bundle of Python books by O'Reilly:
- Web Scrapping with Python
- Test Driven Development with Python
- Using Asyncio in Python
- High Performance Python
- Introducing Python
- Think Python
- Hands-On Unsupervised Learning Using Python
- Python Data Science Handbook
- Thoughtful Machine Learning with Python
- Flask Web Development
- Machine Learning Pocket Reference
- Hitchhiker's Guide to Python
- Elegant SciPy
- NLP with Python
As usual, you can pay at least €15.55 to unlock all of these books or pay less to unlock some of them. There's no upper limit, though. You can pay whatever you want and Humble Bundle will redirect your funds to charity.
# books #python #programming
So, the first one is a bundle of Python books by O'Reilly:
- Web Scrapping with Python
- Test Driven Development with Python
- Using Asyncio in Python
- High Performance Python
- Introducing Python
- Think Python
- Hands-On Unsupervised Learning Using Python
- Python Data Science Handbook
- Thoughtful Machine Learning with Python
- Flask Web Development
- Machine Learning Pocket Reference
- Hitchhiker's Guide to Python
- Elegant SciPy
- NLP with Python
As usual, you can pay at least €15.55 to unlock all of these books or pay less to unlock some of them. There's no upper limit, though. You can pay whatever you want and Humble Bundle will redirect your funds to charity.
# books #python #programming
Humble Bundle
Humble Book Bundle: Python Programming by O'Reilly
We’ve teamed up with O’Reilly for our newest bundle. Get ebooks like Introducing Python, 2nd Edition & High Performance Python, 2nd Edition. Plus, pay what you want & support charity!
The next book bundle is about security.
- Microsoft Azure Security and Privacy Concepts
- Hack Yourself First: How to go on the Cyber-Offense
- Security in the Cloud
- Security Compliance: The Big Picture
- Security for Hackers and Developers: Overview
- Threats, Attacks, and Vulnerabilities for CompTIA Security+
- Incident Detection and Investigation with QRadar
- AWS Cloud Security Best Practices
- Microsoft 365 Security: Threat Protection Implementation and Management
- Cisco CyberOps: Security Monitoring
- Cloud Security: Introduction to Certified Cloud Security Professional (CCSP(r))
- Linux Host Security
- Operationalizing Cyber Threat Intel: Pivoting & Hunting
- Security Awareness: Basic Concepts and Terminology
- Splunk Enterprise Security: Big Picture
- Threat Intelligence: Cyber Threats and Kill Chain Methodology
- Cyber Security Essentials: Your Role in Protecting the Company
- Security Management: A Case Study
- Security Awareness: Phishing - How Hackers Get Your Secrets
- Cyber Security Careers for IT Professionals
As usual, you can pay what you want. Minimum payment of €21.59 will unlock all 20 books.
#books #security
- Microsoft Azure Security and Privacy Concepts
- Hack Yourself First: How to go on the Cyber-Offense
- Security in the Cloud
- Security Compliance: The Big Picture
- Security for Hackers and Developers: Overview
- Threats, Attacks, and Vulnerabilities for CompTIA Security+
- Incident Detection and Investigation with QRadar
- AWS Cloud Security Best Practices
- Microsoft 365 Security: Threat Protection Implementation and Management
- Cisco CyberOps: Security Monitoring
- Cloud Security: Introduction to Certified Cloud Security Professional (CCSP(r))
- Linux Host Security
- Operationalizing Cyber Threat Intel: Pivoting & Hunting
- Security Awareness: Basic Concepts and Terminology
- Splunk Enterprise Security: Big Picture
- Threat Intelligence: Cyber Threats and Kill Chain Methodology
- Cyber Security Essentials: Your Role in Protecting the Company
- Security Management: A Case Study
- Security Awareness: Phishing - How Hackers Get Your Secrets
- Cyber Security Careers for IT Professionals
As usual, you can pay what you want. Minimum payment of €21.59 will unlock all 20 books.
#books #security
Humble Bundle
Humble Software Bundle: Cyber Security for Hackers and Developers
We’ve teamed up with Pluralsight for our newest bundle. Get software like Hack Yourself First: How to go on the Cyber-Offense & Security for Hackers and Developers: Overview. Plus, pay what you want & support charity!
An article about some attack vectors for your AWS environments and ways to protect yourself against them.
There's a neat tl;dr section on top of the article, so you can have a quick overview before diving deep into the article itself.
#aws #security
There's a neat tl;dr section on top of the article, so you can have a quick overview before diving deep into the article itself.
#aws #security
tl;dr sec
Lesser Known Techniques for Attacking AWS Environments
Techniques for initital access, recon, lateral movement, and exfil of AWS accounts, along with defensive mitigations