home.social

#configurationascode — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #configurationascode, aggregated by home.social.

fetched live
  1. #Ansible nerds - for those of you managing large fleets and dynamic inventories, what have you found to be the most effective strategies to organize inventory groups?

    In this context it’s multiple domains, with their own group_vars but also trying to keep the roles and playbooks as deduplicated as possible.

    Are we creating elaborate groups for triggering the correct roles to apply, or are you pulling other metadata from your hypervisor/CMDB and firing roles based on tags? A combination of both?

    (I’m coming in to a brownfield environment where none of this was really well established, and needs a LOT of refactoring - but I need a sanity check and some inspiration. Presently working without #AAP, but driving towards that business case because we need it)

    #Ansible #DynamicInventory #ConfigurationAsCode #CaC #IaC #CMDB #Sysadmin #DevOps #linux

  2. #Terraform is all fun and games, until a provider makes breaking changes.

    Currently in severe pain trying to update @cloudflare from 4 to 5 :(

    #DevOps #ConfigurationAsCode

  3. Configuration-as-Code

    За последнее десятилетие мы убедились, что выполнение вручную процессов расследования и реагирования ограничивает нас по скорости, что сильно сказывается на возможности обрабатывать прирастающий с каждым днем поток инцидентов и угроз. Для того, чтобы помочь в решении складывающейся ситуации специалисты ИБ начинают применять в своей практике новые подходы, такие как Everything as Code (EaC), который зародился на базе практик разработки ПО. Одна из основных проблематик обнаружения инцидентов, процедур Threat hunting и обнаружения угроз (TI) — высокая гранулярность скриптов и функций, необходимость контроля версий и учета изменений. Поэтому инженеры по информационной безопасности, стремясь повысить эффективность детекта и улучшить качество работы переняли лучшие практики из IT-разработки и назвали этот метод Configuration-as-Code. Давайте разберемся, что он из себя представляет. Что такое обнаружение как код? Configuration-as-Code (или CI/CD в информационной безопасности) – это разбиение процессов и процедур на максимально атомарные функции, работа с которыми ведется по образу и подобию кода: они отдельно хранятся, редактируются, версионируются, тестируются, анализируются на качество и в последующем используются при необходимости в совершенно разных процессах. Например, процедура аудита учетной записи:

    habr.com/ru/companies/security

    #configurationascode #everything_as_code

  4. #ConfigurationAsCode Finally got that keycloak setup done in a repeatable, reproducible way.

  5. If anyone knows anyone looking for a #SoftwareDevelopment job, with 3 years #TestDrivenDevelopment experience in C#, #Java, #Golang, #Python or similar languages, 2 years in #ConfigurationAsCode tools like #Ansible, and 1 year in #CI #CD pipelines, hit me up! I’m hiring for two positions, hybrid roles at APG, MD. They must be SECRET clearance eligible, if not cleared already.

    Also looking for 3 100% On sure #Solaris #UNIX #SystemAdministrator as well, if you know someone :)