SlideShare a Scribd company logo
5 ways to use
DevOps principles
in product
infrastructure
management
Pradeep Bohra
https://www.linkedin.com/in/pbohra/
Use Case & Constraints
1. Design the network using native best practices
2. Layered Security
3. Setup the CD Pipeline for IAAC
4. IAAC - Reuse Components and Re-contribute
5. Complete the feedback loop
SUMMARY OF TOPICS
USE CASE
CREATE INFRASTRUCTURE FOR
A 2 TIER APPLICATION
TECHNOLOGY
CONSTRAINTS
DOMAIN AND
CERTIFICATE
AWS
INFRA-
PROVIDER
AWS
IAAC
Terraform
SCM
GitHub
OS
CentOS 7.x
ORCHESTRATION
Jenkins
SERVER
CONFIG
Ansible
INFRA SIZING
SIZING
DOCUMENTATION
Design the network
using Native Best
Practices
1.
Resilency and Fault Tolerance
Minimal
Monitoring
Scaling
Backup and Restore
Audits and Compliance
Availability SLAs
Deployment Interfaces
2. Layered Security
NETWORK
ACLs (Blacklisting)
Security Group (Whitelisting)
SIEM
RESOURCE POLICY
AND IAM
Controlled Access
IP TABLES
OS level whitelisting
CIS
BENCHMARKING
OS Image Vulnerability
OPERATIONS
VA/PT, Threat Assesment, Threat
Detection, Threat response, Security
Patches,
APPLICATION
SAST, SCA, Container Image Scan,
DAST, WAF OWASP, ESAPI
DATA SECURITY
Encryption at REST
Encryption at Transit
FORENSICS
Framework to respond to a security
incident
3. CD Pipeline for IAAC 
https://github.com/pradeepbohra/leedsdevopsmeet1.git
Copy Right Image:MemeGenerator
4. IAAC - Reuse
Components and Re-
contribute
TERRAFORM
REGISTRY
https://registry.terraform.io
DO NOT REINVENT
THE WHEEL
5. Completing the
feedback loop
CREATE ROBUST
TEST FRAMEWORK
WRITE TEST
CONFIG ALONG
WITH CODE
WRITE
COMPARISION
CRITERIA
LEVERAGE NATIVE
SERVICES FOR
TEST
TECHNICAL DEBT
DECOMMISSIONING MAINTAIN DAR
QUESTIONS
THANKS

More Related Content

PDF
Automated Infrastructure Security: Monitoring using FOSS
PDF
淺談WAF在AWS的架構_20171027
PDF
Présentation kaspersky threat intelligence services
PPTX
Evaluating container security with ATT&CK Framework
PDF
DevSecOps, The Good, Bad, and Ugly
PPTX
Best Practices for Configuring Your OSSIM Installation
PDF
(SACON) Madhu Akula - Automated Defense Using Cloud Service Aws, Azure, Gcp
PDF
Prepare to defend thyself with Blue/Green
Automated Infrastructure Security: Monitoring using FOSS
淺談WAF在AWS的架構_20171027
Présentation kaspersky threat intelligence services
Evaluating container security with ATT&CK Framework
DevSecOps, The Good, Bad, and Ugly
Best Practices for Configuring Your OSSIM Installation
(SACON) Madhu Akula - Automated Defense Using Cloud Service Aws, Azure, Gcp
Prepare to defend thyself with Blue/Green

What's hot (20)

PPTX
Cloud Security Hardening та аудит хмарної безпеки за допомогою Scout Suite
PDF
Kubernetes security
PPTX
Continuous monitoring with OSSIM
PPTX
Fortify dev ops (002)
PDF
DevSecCon Lightning 2021- Container defaults are a hackers best friend
PDF
Inherent Security Design Patterns for SDN/NFV Deployments
PPTX
Security at the Speed of the Network
PDF
Policy as code what helm developers need to know about security
PDF
Alien vault _policymanagement
PPTX
Advanced OSSEC Training: Integration Strategies for Open Source Security
PPTX
Mod security
PDF
Apcera: Agility and Security in Docker Delivery
PDF
Practical Approaches to Container Security
PDF
Implementing ossec
PPTX
Are You Ready for a Cloud Pentest?
PDF
App sec in the time of docker containers
PDF
Stories from the Security Operations Center (S.O.C.)
PDF
Make your OpenStack Cloud Self-Defending with VESPA!
PDF
Realities of Security in the Cloud - CSS ATX 2017
DOC
Deploying cisco asa firewall features
Cloud Security Hardening та аудит хмарної безпеки за допомогою Scout Suite
Kubernetes security
Continuous monitoring with OSSIM
Fortify dev ops (002)
DevSecCon Lightning 2021- Container defaults are a hackers best friend
Inherent Security Design Patterns for SDN/NFV Deployments
Security at the Speed of the Network
Policy as code what helm developers need to know about security
Alien vault _policymanagement
Advanced OSSEC Training: Integration Strategies for Open Source Security
Mod security
Apcera: Agility and Security in Docker Delivery
Practical Approaches to Container Security
Implementing ossec
Are You Ready for a Cloud Pentest?
App sec in the time of docker containers
Stories from the Security Operations Center (S.O.C.)
Make your OpenStack Cloud Self-Defending with VESPA!
Realities of Security in the Cloud - CSS ATX 2017
Deploying cisco asa firewall features
Ad

Similar to 5 ways to use devops in product infrastructure management final (20)

DOCX
A Comprehensive Guide with DevOps Infrastructure Management Services at HEX64...
PDF
Cncf checkov and bridgecrew
PPTX
infrastructure management at digital ages
PDF
Lessons learned from writing over 300,000 lines of infrastructure code
PDF
Growing your Cloud Practice by Josh Lupresto VP Engineering
PDF
The Intersection of Security & DevOps
PDF
Proactive monitoring tools or services - Open Source
PDF
DevOpsDays - DevOps: Security 干我何事?
PDF
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
PDF
TW SEAT - DevOps: Security 干我何事?
PPTX
Cloud Native Applications - DevOps, EMC and Cloud Foundry
PPTX
EMC World 2016 - code.01 Everything as Code - How did we get here?
PPTX
Using Infrastructure as an Accelerator of DevOps Maturity
PPTX
Quality assurance in dev ops and secops world
PDF
The What, Why, and How of DevSecOps
PPTX
Cloud computing for microprocessor tools
PDF
The Intersection of Security & DevOps
PDF
Best CCNP (ENCOR 350 - 701) Training at NS3EDU
PPTX
Quality assurance in dev ops and secops world
PDF
NFV: Infrastructure as Code
A Comprehensive Guide with DevOps Infrastructure Management Services at HEX64...
Cncf checkov and bridgecrew
infrastructure management at digital ages
Lessons learned from writing over 300,000 lines of infrastructure code
Growing your Cloud Practice by Josh Lupresto VP Engineering
The Intersection of Security & DevOps
Proactive monitoring tools or services - Open Source
DevOpsDays - DevOps: Security 干我何事?
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
TW SEAT - DevOps: Security 干我何事?
Cloud Native Applications - DevOps, EMC and Cloud Foundry
EMC World 2016 - code.01 Everything as Code - How did we get here?
Using Infrastructure as an Accelerator of DevOps Maturity
Quality assurance in dev ops and secops world
The What, Why, and How of DevSecOps
Cloud computing for microprocessor tools
The Intersection of Security & DevOps
Best CCNP (ENCOR 350 - 701) Training at NS3EDU
Quality assurance in dev ops and secops world
NFV: Infrastructure as Code
Ad

Recently uploaded (20)

PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PPTX
L1 - Introduction to python Backend.pptx
PPTX
assetexplorer- product-overview - presentation
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
Digital Strategies for Manufacturing Companies
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
Nekopoi APK 2025 free lastest update
PPTX
Computer Software and OS of computer science of grade 11.pptx
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
Operating system designcfffgfgggggggvggggggggg
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Design an Analysis of Algorithms I-SECS-1021-03
Navsoft: AI-Powered Business Solutions & Custom Software Development
CHAPTER 2 - PM Management and IT Context
How to Migrate SBCGlobal Email to Yahoo Easily
L1 - Introduction to python Backend.pptx
assetexplorer- product-overview - presentation
Understanding Forklifts - TECH EHS Solution
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Digital Strategies for Manufacturing Companies
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
VVF-Customer-Presentation2025-Ver1.9.pptx
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Nekopoi APK 2025 free lastest update
Computer Software and OS of computer science of grade 11.pptx
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PTS Company Brochure 2025 (1).pdf.......
Operating system designcfffgfgggggggvggggggggg

5 ways to use devops in product infrastructure management final