Solo.io is donating its open source API Gateway, Gloo Gateway, to the Cloud Native Computing Foundation (CNCF) to further its mission of building a complete omni-gateway connectivity solution.
In today's development lifecycle, fast, reliable and efficient define the model. DevOps is the driving force behind efficient software development as DevOps teams are now both reflecting and defining business models as they operate in a continuous cycle of development, integration, deployment and innovation. This coordination allows not only for organizations to be far more responsive, but also for speed to define the operations and data that function in runtime.
Microservices, container orchestration, virtualized machines; these and other tools have created an entire industry to support the fast, continuous development approach. But while efficiency and speed bring competitive advantages, something is still missing: security. With the luxury of speeds comes the by-product of overly pushed data during the development phase. This opens the question of which is more important — speed or security?
The reality is that while we all strive for fast and efficient solutions; the integrity and security of the work are compromised. The lack of coordination witnessed in recent cyber-attacks calls attention to the differing ideals of SecOps and DevOps teams.
In an attempt to merge these seemingly conflicting efforts, let's look at just a few of the latest security approaches and how to encompass the process of shifting left in order to apply concepts of security during the development and delivery stage.
Track Vulnerabilities vs. Being Vulnerable
Tracking vulnerabilities is a no-brainer but what you really want to know is how you have become vulnerable in the first place. This means you need to combine the latest vulnerabilities with your risk and exposures in your infrastructure. If you have a vulnerability that is open to the world that is a lot different than one that is sitting pre-deploy in your image repository.
As the lines between development and runtime overlap more and more, and because there is such a heavy reliance on the speed and output coming from DevOps, security has to operate at every point where data is created, transacted, integrated, and applied. Anything pushed into production that has a vulnerability creates the potential for a security issue later. Catching it while it's being created delivers demonstrable value because it reduces the burden on security operations teams and increases the availability of services.
What's needed is a complete approach not just a "unified" approach. Instead of pulling together functionality from various sources of IP, you can instead apply already underlying technologies to extend the security visibility and detection capabilities across everything an organization's infrastructure and data touch.
A Complete Security Approach
By extending security to the left side of the application continuum, developers participate in their organization's security approach; automation gives them the ability to actively contribute to effective security without placing constraints on speed or agility. The result is an organization-wide approach to the security and compliance of data and operations. This means:
■ Development teams can deploy services that have been developed with the discipline of security automatically embedded in their innate processes. Using the visibility and threat detection of a security platform, they can identify unexpected risks and threats much earlier in the development cycle. This also provides them with a greater understanding of where issues happen so they can create processes that eliminate them in the future. DevOps teams can rely on built-in security protections that are already blessed by the organization, which accelerates their development cycles.
■ Security teams will learn more from the results of anomaly detection and will benefit from continuous security and compliance in a way that gets them out of reactive mode and takes more control over DevOps and other IT operations. With some organizations pushing increasingly massive numbers of fixes and changes into production every day, security has to provide a way to monitor, detect, and alert. Complete, continuous security and compliance delivered with automation is the most effective way to do this.
■ Business teams are ultimately the biggest beneficiary of this modern approach. The dev process is accelerated, quality is improved, and compliance is monitored and addressed before it becomes a problem. Rather than accepting the inherent tension between DevOps and security teams, the business benefits from faster delivery, more security production, and an established place in their respective market.
By using a security approach that is complete and has been designed specifically to meet the challenges of public cloud environments in both build-time and run-time operations, organizations can take advantage of a security-first model that enables continuous visibility, automation, and the ability to move fast. This will not only strengthen security, but it will also provide compliance and DevOps teams with the tools and processes they need to successfully meet the requirements of the cloud era.
Industry News
LaunchDarkly announced a new approach to software delivery—Guarded Releases—that empowers organizations to ship with confidence and manage risk proactively.
Diagrid announced details of the upcoming release of Dapr 1.15, a Cloud Native Computing Foundation project maintained by Diagrid, Microsoft, Intel, Alibaba, and others.
Fermyon™ Technologies announced the release of Spin 3.0, enabling enterprises to quickly move toward more sophisticated production applications based on WebAssembly (Wasm).
Mirantis announced Mirantis Kubernetes Engine (MKE) 4, the latest evolution in its long-established product line that sets the standard for secure enterprise Kubernetes.
Cequence Security announced the launch of its new API Security Assessment Services.
Pulumi announced improvements including major updates to the EKS provider supporting Amazon Linux 2023 and Security Groups for pods, the release of Pulumi Kubernetes Operator 2.0 with dedicated workspace pods, Pulumi ESC integration with External Secrets Operator, and a new Kubernetes-native deployment agent for enhanced security and scalability.
Loft Labs announced the public beta of vCluster Cloud, a managed solution that simplifies and reduces the costs of Kubernetes clusters.
DevZero announced DXI (Developer Experience Index), an initiative aimed at transforming developer productivity by unifying engineering throughput and operational metrics.
Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.
The CNCF Technical Oversight Committee (TOC) has voted to accept wasmCloud as a CNCF incubating project.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of Dapr.
NetApp announced an expanded collaboration with Red Hat to offer new solutions to streamline and accelerate enterprise application development and management in virtual environments.
Akamai Technologies announced the Akamai App Platform, a ready-to-run solution that makes it easy to deploy, manage, and scale highly distributed applications.
Snyk has acquired Probely, a modern Dynamic Application Security Testing (DAST) provider based in Porto, Portugal, with coverage of API security testing and web applications.