Making Life Simpler for DevOps with Security Practices
May 04, 2016

Anirban Banerjee
Onion ID

The next breach inside enterprises is expected to come from within. Many articles have been written about Insider Threats, the origination points, motivation, detection, DLP and more. I have talked to many an enterprise to understand the strategies and policies that are employed to manage this threat.

Privilege Management is a new age term, born from the crucible of Role Based Access Control (RBAC). Privilege Management refers to the ability of any enterprise to successfully manage, detect and mitigate any possibility of employee account misuse. The definition is quite terse and a bit wishful. In reality most organizations have very poor privilege management practices employed for their resources. In this blog, I will discuss why that is the case, what are some good strategies to launch effective privilege management in your organization and some of the gotchas that you can avoid.

The Many Faces of DevOps

Lets accept a fact: DevOps plays a multitude of roles inside most organizations. It is no longer: “Let's make sure our DNS stays up all the time.” It is: “Let's make sure our DNS stays up all the time and that we are DDoS resistant.”

Feel free to tag on a couple of more statements dealing with enhancing the security of the previously mentioned DNS system. The point is that DevOps is evolving at a breakneck speed and more enterprises are putting jobs on a DevOps person's plate than they can reasonably take off it.

The Pain Point

One of the constant thorns in the side is security. As if it's not hard enough to keep things running at web scale. It's great to read articles on hacker news about how you can use nodejs to power millions of requests a second without breaking a sweat. In reality though things are far from rosy. It's a lot of hard work, long nights, group huddles that get things to work, and, work with a good degree of reliability.

In this blog, I am going to talk about how a lot of DevOps teams are managing security practices and what can be done to reduce the amount of time spent on each aspect yet up the amount of security that you can actually eek out of the system.

Why Existing Tools Don't Alleviate the Pain

Using configuration management systems ensures that DevOps does not spend time on making sure the base OS images, packages and software on servers that make up a cluster are uniform and adhere to a common set of security guidelines.

Even though the tools mentioned above are very effective in providing network visibility they do not help DevOps when the proverbial (expletive deleted) hits the fan from a compliance perspective.

Consider the case where an employee account is misused to perform some actions that are not in compliance with a company's policies. In this case, using configuration management systems helps only to the effect that you can find out if someone accessed an account, when and possibly which server were affected. However if the employee is smart enough and tries to cover their tracks by wiping history, logs etc. it's a rabbit hole that DevOps and security teams have to now jump into.

This is a case of misalignment of expectations from a DevOps group. Unfortunately this happens more often than not because DevOps handles the heartbeat of any product and so is called in time and again to help with various teams like security.

Simple Fixes

To make life simpler for DevOps here are some high level tool category suggestions that will save time and headaches when push comes to shove:

1. Install and use a SSH key rotation system: This will help in keeping compliance reviews short and prevent attackers from causing massive damage.

2. Install and use a SSH session recording system: This helps in making sure that if ever a request comes in to analyze whether someone performed a specific action, DevOps does not have to spend a ton of time investigating issues.

3. Use an inventory management system for all your infrastructure: Something akin to security monkey for AWS. This helps you keep tabs on what you really see in the configuration management system is actually what is on your cloud IaaS account or not.

4. Use a blacklist of commands: Mistakes happen often in life and people often make costly mistakes. Don't let someone type rm -rf* on your production cluster by mistake(link is external).

I discussed the high level rationale for why a DevOps job is not easy. I followed that up with some concrete product areas that will help make life simpler and less hectic for everyone.

Dr. Anirban Banerjee is CEO of Onion ID.

Share this

Industry News

March 25, 2025

Chainguard announced Chainguard Libraries, a catalog of guarded language libraries for Java built securely from source on SLSA L2 infrastructure.

March 25, 2025

Cloudelligent attained Amazon Web Services (AWS) DevOps Competency status.

March 25, 2025

Platform9 formally launched the Platform9 Partner Program.

March 24, 2025

Cosmonic announced the launch of Cosmonic Control, a control plane for managing distributed applications across any cloud, any Kubernetes, any edge, or on premise and self-hosted deployment.

March 20, 2025

Oracle announced the general availability of Oracle Exadata Database Service on Exascale Infrastructure on Oracle Database@Azure(link sends e-mail).

March 20, 2025

Perforce Software announced its acquisition of Snowtrack.

March 19, 2025

Mirantis and Gcore announced an agreement to facilitate the deployment of artificial intelligence (AI) workloads.

March 19, 2025

Amplitude announced the rollout of Session Replay Everywhere.

March 18, 2025

Oracle announced the availability of Java 24, the latest version of the programming language and development platform. Java 24 (Oracle JDK 24) delivers thousands of improvements to help developers maximize productivity and drive innovation. In addition, enhancements to the platform's performance, stability, and security help organizations accelerate their business growth ...

March 18, 2025

Tigera announced an integration with Mirantis, creators of k0rdent, a new multi-cluster Kubernetes management solution.

March 18, 2025

SAP announced “Joule for Developer” – new Joule AI co-pilot capabilities embedded directly within SAP Build.

March 17, 2025

SUSE® announced several new enhancements to its core suite of Linux solutions.

March 13, 2025

Progress is offering over 50 enterprise-grade UI components from Progress® KendoReact™, a React UI library for business application development, for free.

March 13, 2025

Opsera announced a new Leadership Dashboard capability within Opsera Unified Insights.

March 13, 2025

Cycloid announced the introduction of Components, a new management layer enabling a modular, structured approach to managing cloud resources within the Cycloid engineering platform.