SlideShare a Scribd company logo
Secure Your Pipeline
While Keeping Your Developers and Admins
Happy
http://tremolo.io
http://tremolo.io
Who Is Tremolo Security?
● Founded in 2010
● Cloud Native Identity Management
● Open Source
● Working with OpenShift since 2015
● First class of Red Hat certified containers
● First class of Red Hat certified operators
http://tremolo.io
Kubernetes - A Rube Goldberg Machine
http://tremolo.io
OpenShift - Lego Technic
http://tremolo.io
Pipeline Goal with OCP
http://tremolo.io
How To Get There - Developer
● LET ME CODE
● YAML?
● I like Git
http://tremolo.io
How To Get There - Administrator
● Slack gives me a nervous tick
● You need access to what?
● OK Google, how to add a user to a group?
● Ms Auditor, I have no idea why that person has access
● Why did we do a rollout of that service on a Friday? Not
sure. No one asked me.
http://tremolo.io
How To Get There - Security
● Why are all these projects here?
● Who approved access?
● MFA?
● You are running different environments, right?
● You’re scanning everything, right? promise?
http://tremolo.io
Why Is Identity Management Important?
● “Pipeline” is made of multiple systems
http://tremolo.io
Why Is Identity Management Important?
● Walk A Path
○ Single trail through systems
○ Map every action to an owner
○ Accountability
○ Toll gates and approvals
● Automate the process
○ Workflows provide consistent deployments
○ Auditability at each step
http://tremolo.io
Multi-Environment OCP Pipeline
http://tremolo.io
“Dev” Pipeline
Checkout Build
Code
Analysis
Create
Container
Push to
Test
On merge to master:
http://tremolo.io
Production Pipeline
Responsible Dev
Requests
Production
Deployment
Approved?
Push container to
production
Yes
http://tremolo.io
Demo
http://tremolo.io
Get The Code
https://github.com/OpenUnison/openunison-openshift-pipeline
http://tremolo.io
Questions
Connect with us
● Web - http://tremolo.io
● Twitter - @tremolosecurity / @mlbiam
● Github - http://github.com/tremolosecurity/

More Related Content

What's hot (19)

PPTX
Script
David Evans
 
PDF
PortsCamp Taiwan
Marcelo Araujo
 
PDF
Contributing to Koha
Libriotech
 
PPTX
Finding bugs in seconds php limburg
Gert de Pagter
 
PDF
Montreal.rb ruby debugging basics - march 20th 2012
Rafael Rosa
 
PDF
Acquia Drupal 8 Hackathon Demo 2015
Angela Byron
 
PDF
Contract Testing of Web Sockets: Functional Programming is taking the Stage
Artem Demchenkov
 
PDF
Perl wants you
Augustina Ragwitz
 
PDF
Contribuire al Qt Project
QT-day
 
PDF
Manila Project Onboarding - Denver Open Infrastructure Summit - May 2019
TomBarron
 
ODP
Introduction to Open Source
Gluster.org
 
PPTX
TC39 - the exciting parts
Itamar Kestenbaum
 
ODP
Responsibilities of gluster_maintainers
Gluster.org
 
PDF
Introduction To ICT Security Audit OWASP Day Malaysia 2011
Linuxmalaysia Malaysia
 
PDF
Is there a Future for devops ?
Kris Buytaert
 
PDF
Improve the deployment process step by step
Daniel Fahlke
 
PDF
Go in Production
John-Alan Simmons
 
ODP
ATLRUG May 2015 Announcements
jasnow
 
PDF
Tetuan Valley Startup School - Guest mentor Angel Luis Quesada (Kubide)
Luis Rivera
 
Script
David Evans
 
PortsCamp Taiwan
Marcelo Araujo
 
Contributing to Koha
Libriotech
 
Finding bugs in seconds php limburg
Gert de Pagter
 
Montreal.rb ruby debugging basics - march 20th 2012
Rafael Rosa
 
Acquia Drupal 8 Hackathon Demo 2015
Angela Byron
 
Contract Testing of Web Sockets: Functional Programming is taking the Stage
Artem Demchenkov
 
Perl wants you
Augustina Ragwitz
 
Contribuire al Qt Project
QT-day
 
Manila Project Onboarding - Denver Open Infrastructure Summit - May 2019
TomBarron
 
Introduction to Open Source
Gluster.org
 
TC39 - the exciting parts
Itamar Kestenbaum
 
Responsibilities of gluster_maintainers
Gluster.org
 
Introduction To ICT Security Audit OWASP Day Malaysia 2011
Linuxmalaysia Malaysia
 
Is there a Future for devops ?
Kris Buytaert
 
Improve the deployment process step by step
Daniel Fahlke
 
Go in Production
John-Alan Simmons
 
ATLRUG May 2015 Announcements
jasnow
 
Tetuan Valley Startup School - Guest mentor Angel Luis Quesada (Kubide)
Luis Rivera
 

Similar to Secure Your Pipeline While Keeping Your Developers and Admins Happy (20)

PDF
Understanding and implementing website security
Drew Gorton
 
PPTX
Prometheus design and philosophy
Docker, Inc.
 
PDF
Its easy! contributing to open source - Devnexus 2020
César Hernández
 
PDF
Devops, Secops, Opsec, DevSec *ops *.* ?
Kris Buytaert
 
PDF
The working architecture of NodeJS applications, Виктор Турский
Sigma Software
 
PDF
The working architecture of node js applications open tech week javascript ...
Viktor Turskyi
 
PPTX
Me&g@home
Vytautas Dauksa
 
ODP
Introduce Python
M Asep Indrayana
 
ODP
Build and Deploy a Python Web App to Amazon in 30 Mins
Jeff Hull
 
PDF
Introduction to Kubernetes Security
All Things Open
 
PPTX
Open Source Dataweave - Surat March 2024 (1).pptx
nitishjain2015
 
PDF
Es fácil contribuir al open source - Bolivia JUG 2020
César Hernández
 
PDF
Big feature - small sprint
Igor Goldshmidt
 
PDF
It is easy contributing to open source - JCON 2020
César Hernández
 
PDF
Let's Encrypt
Amjad Mashaal
 
PDF
Devops Devops Devops, at Froscon
Kris Buytaert
 
PPTX
Flutter not yet another mobile cross-platform framework - i ox-kl19
oradoe
 
PDF
Bgoug 2019.11 building free, open-source, plsql products in cloud
Jacek Gebal
 
PDF
Creando microservicios con Java y Microprofile - Nicaragua JUG
César Hernández
 
PDF
All Aboard The Stateful Train
SmartLogic
 
Understanding and implementing website security
Drew Gorton
 
Prometheus design and philosophy
Docker, Inc.
 
Its easy! contributing to open source - Devnexus 2020
César Hernández
 
Devops, Secops, Opsec, DevSec *ops *.* ?
Kris Buytaert
 
The working architecture of NodeJS applications, Виктор Турский
Sigma Software
 
The working architecture of node js applications open tech week javascript ...
Viktor Turskyi
 
Me&g@home
Vytautas Dauksa
 
Introduce Python
M Asep Indrayana
 
Build and Deploy a Python Web App to Amazon in 30 Mins
Jeff Hull
 
Introduction to Kubernetes Security
All Things Open
 
Open Source Dataweave - Surat March 2024 (1).pptx
nitishjain2015
 
Es fácil contribuir al open source - Bolivia JUG 2020
César Hernández
 
Big feature - small sprint
Igor Goldshmidt
 
It is easy contributing to open source - JCON 2020
César Hernández
 
Let's Encrypt
Amjad Mashaal
 
Devops Devops Devops, at Froscon
Kris Buytaert
 
Flutter not yet another mobile cross-platform framework - i ox-kl19
oradoe
 
Bgoug 2019.11 building free, open-source, plsql products in cloud
Jacek Gebal
 
Creando microservicios con Java y Microprofile - Nicaragua JUG
César Hernández
 
All Aboard The Stateful Train
SmartLogic
 
Ad

More from DevOps.com (20)

PDF
Modernizing on IBM Z Made Easier With Open Source Software
DevOps.com
 
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
PDF
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
PPTX
Vulnerability Discovery in the Cloud
DevOps.com
 
PDF
2021 Open Source Governance: Top Ten Trends and Predictions
DevOps.com
 
PDF
A New Year’s Ransomware Resolution
DevOps.com
 
PPTX
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
DevOps.com
 
PDF
Don't Panic! Effective Incident Response
DevOps.com
 
PDF
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
DevOps.com
 
PDF
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
DevOps.com
 
PDF
Monitoring Serverless Applications with Datadog
DevOps.com
 
PDF
Deliver your App Anywhere … Publicly or Privately
DevOps.com
 
PPTX
Securing medical apps in the age of covid final
DevOps.com
 
PDF
How to Build a Healthy On-Call Culture
DevOps.com
 
PPTX
The Evolving Role of the Developer in 2021
DevOps.com
 
PDF
Service Mesh: Two Big Words But Do You Need It?
DevOps.com
 
PPTX
Secure Data Sharing in OpenShift Environments
DevOps.com
 
PPTX
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
DevOps.com
 
PDF
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
DevOps.com
 
Modernizing on IBM Z Made Easier With Open Source Software
DevOps.com
 
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
Vulnerability Discovery in the Cloud
DevOps.com
 
2021 Open Source Governance: Top Ten Trends and Predictions
DevOps.com
 
A New Year’s Ransomware Resolution
DevOps.com
 
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
DevOps.com
 
Don't Panic! Effective Incident Response
DevOps.com
 
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
DevOps.com
 
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
DevOps.com
 
Monitoring Serverless Applications with Datadog
DevOps.com
 
Deliver your App Anywhere … Publicly or Privately
DevOps.com
 
Securing medical apps in the age of covid final
DevOps.com
 
How to Build a Healthy On-Call Culture
DevOps.com
 
The Evolving Role of the Developer in 2021
DevOps.com
 
Service Mesh: Two Big Words But Do You Need It?
DevOps.com
 
Secure Data Sharing in OpenShift Environments
DevOps.com
 
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
DevOps.com
 
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
DevOps.com
 
Ad

Recently uploaded (20)

PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PDF
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
PPTX
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PDF
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PPTX
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 

Secure Your Pipeline While Keeping Your Developers and Admins Happy