SlideShare a Scribd company logo
Dev(Sec)Ops
at Tridens
Tomaž Kramberger
Agenda
• Tech Stack
• DevOps Stack
• DevOps Practices & Process
• DevSecOps
• Monitoring & Support
©2025 Tridens d.o.o. All rights reserved. 2
Tech Stack
©2025 Tridens d.o.o. All rights reserved. 3
DevOps Stack
©2025 Tridens d.o.o. All rights reserved. 4
Practices & Process
DevOps
Why DevOps?
©2025 Tridens d.o.o. All rights reserved. 6
• Higher speed and quality of
product releases.
• Faster responsiveness to
customer needs.
• Team can react to change
requests from customers
faster with adding new and
updating existing features.
• The time-to-market and
value-delivery rates increase.
DevOps Practices
• Continuous integration (CI)
• Merge changes back to the main branch as often as possible.
• Developer's changes are validated by creating a build and running automated tests against
the build.
• Continuous delivery (CD)
• Automatically deploys all code changes to a testing environment after the build stage.
• Continuous testing (CT)
• Testing at earlier stages of the release pipeline.
• Testing more often before release.
• Testing everywhere, that is, across environments and devices.
• Continuous monitoring (CM)
• Help monitor software operation, especially performance issues, identify the cause of the
error, and apply appropriate solutions before significant damage to uptime and revenue.
• Infrastructure as code (IaC)
©2025 Tridens d.o.o. All rights reserved. 7
DevOps – CI/CD process
©2025 Tridens d.o.o. All rights reserved. 8
DevOps – GitFlow Strategy
• Production uploads are always made from
Master.
• Master must always be stable and ready to
deploy.
• The work is always done on Develop. Putting
the focus on the product being releasable
and available.
• The Release branch is used to stabilize
development.
• When we develop a feature, it is done on a
Feature branch.
• Feature branches always merge with
Develop.
• Hotfix branch to resolve critical production
issues. In addition, this new branch will be
merged with Master and Develop as soon as
this problem is solved.
©2025 Tridens d.o.o. All rights reserved. 9
DevOps – Cheat Sheet
©2025 Tridens d.o.o. All rights reserved. 10
DevOps – GIT Operations
git commit --allow-empty -m “[<command>]“
Example:
git commit –allow-empty –m “[ci-release]“
git commit –allow-empty –m “[ci-review]“
git commit –allow-empty –m “[ci-run]“
git commit –allow-empty –m “[ci-run|ere:feature/some-feature|tgw:feature/some-feature]“
©2025 Tridens d.o.o. All rights reserved. 11
DevOps – CI Pipeline
.ci/Jenkinsfile
@Library('Tridens-CI’) _
JenkinsPipeline {
javaVersion='11'
buildTargetPrefix='app/'
dockerImageNamespace='monetization'
bddJobTag='monetizationIntegTag'
applicationType=si.tridenstechnology.jenkins.Configuration.ApplicationType.MAVEN
}
©2025 Tridens d.o.o. All rights reserved. 12
DevOps - JIRA Issue & Project Tracking Software
• Project tracking
• Reports
• Issue creation
• Time tracking
• Kanban board
©2025 Tridens d.o.o. All rights reserved. 13
AWS Cloudformation
• Easy to use
• Flexible and declarative
• Customisation through parameters
• Drag-and-drop UI for visualization
• DevOps principle IaC
©2025 Tridens d.o.o. All rights reserved. 14
DevOps
Live presentation
DevOps – AI Code Review
©2025 Tridens d.o.o. All rights reserved. 16
DevOps - Jenkins
©2025 Tridens d.o.o. All rights reserved. 17
DevOps - CI Pipeline
CI { … }
©2025 Tridens d.o.o. All rights reserved. 18
DevOps - SonarQube
©2025 Tridens d.o.o. All rights reserved. 19
DevOps – End-To-End Tests
©2025 Tridens d.o.o. All rights reserved. 20
DevOps – AI Generated Tests
©2025 Tridens d.o.o. All rights reserved. 21
DevOps – ER Diagram
©2025 Tridens d.o.o. All rights reserved. 22
Image from trickyenough.com
DevOps – OpenAPI & API docs
©2025 Tridens d.o.o. All rights reserved. 23
DevOps - Issue & project tracking
©2025 Tridens d.o.o. All rights reserved. 24
DevSecOps
Live presentation
Trivy – security scanner
©2025 Tridens d.o.o. All rights reserved. 26
Zed Attack Proxy – automated pentesting
©2025 Tridens d.o.o. All rights reserved. 27
GoPhish – phishing simulator
©2025 Tridens d.o.o. All rights reserved. 28
Monitoring and support
AWS – CloudWatch monitoring
• Built-in metrics
• Custom metrics
• Operational view with dashboards
• Alarms (MS Teams, AWS Lambda)
©2025 Tridens d.o.o. All rights reserved. 30
AWS – Performance Insights Monitoring
• Debug performance issues, for example, by identifying queries that are causing high
load.
• Tuning performance by identifying bottlenecks like CPU or I/O throughput.
• Monitor the performance by aggregating the core performance indicators of your
database.
• Analyse Queries, Analyse Bottlenecks
©2025 Tridens d.o.o. All rights reserved. 31
DevOps – Spring Boot Admin
©2025 Tridens d.o.o. All rights reserved. 32
Status and incident communication tool
©2025 Tridens d.o.o. All rights reserved. 33
Alerting
©2025 Tridens d.o.o. All rights reserved. 34
Questions?
Tomaž Kramberger
CTO, CISO
tomaz.kramberger@tridenstechnology.com
©2025 Tridens d.o.o. All rights reserved. 35

More Related Content

PDF
Storytelling For The Web: Integrate Storytelling in your Design Process
PDF
Artificial Intelligence, Data and Competition – SCHREPEL – June 2024 OECD dis...
PDF
2024 Trend Updates: What Really Works In SEO & Content Marketing
PDF
Tridens Monetization Cloud Billing Platform for XaaS
PPTX
Tridens automated Testing Solution - tATS
PDF
Brm insight data_sheet
PDF
Enterprise Service Manager (ESM) : data sheet1
PDF
Tridens Brochure
Storytelling For The Web: Integrate Storytelling in your Design Process
Artificial Intelligence, Data and Competition – SCHREPEL – June 2024 OECD dis...
2024 Trend Updates: What Really Works In SEO & Content Marketing
Tridens Monetization Cloud Billing Platform for XaaS
Tridens automated Testing Solution - tATS
Brm insight data_sheet
Enterprise Service Manager (ESM) : data sheet1
Tridens Brochure

Recently uploaded (20)

PDF
Complete Guide to Website Development in Malaysia for SMEs
PPTX
Patient Appointment Booking in Odoo with online payment
PDF
iTop VPN Crack Latest Version Full Key 2025
PPTX
Custom Software Development Services.pptx.pptx
PDF
Website Design Services for Small Businesses.pdf
PDF
Autodesk AutoCAD Crack Free Download 2025
PDF
MCP Security Tutorial - Beginner to Advanced
PDF
Topaz Photo AI Crack New Download (Latest 2025)
PPTX
Tech Workshop Escape Room Tech Workshop
PPTX
Weekly report ppt - harsh dattuprasad patel.pptx
PDF
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
PDF
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
PPTX
chapter 5 systemdesign2008.pptx for cimputer science students
PPTX
GSA Content Generator Crack (2025 Latest)
PDF
DNT Brochure 2025 – ISV Solutions @ D365
PPTX
assetexplorer- product-overview - presentation
PDF
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
PDF
Cost to Outsource Software Development in 2025
PDF
Ableton Live Suite for MacOS Crack Full Download (Latest 2025)
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
Complete Guide to Website Development in Malaysia for SMEs
Patient Appointment Booking in Odoo with online payment
iTop VPN Crack Latest Version Full Key 2025
Custom Software Development Services.pptx.pptx
Website Design Services for Small Businesses.pdf
Autodesk AutoCAD Crack Free Download 2025
MCP Security Tutorial - Beginner to Advanced
Topaz Photo AI Crack New Download (Latest 2025)
Tech Workshop Escape Room Tech Workshop
Weekly report ppt - harsh dattuprasad patel.pptx
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
chapter 5 systemdesign2008.pptx for cimputer science students
GSA Content Generator Crack (2025 Latest)
DNT Brochure 2025 – ISV Solutions @ D365
assetexplorer- product-overview - presentation
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
Cost to Outsource Software Development in 2025
Ableton Live Suite for MacOS Crack Full Download (Latest 2025)
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
Ad
Ad

How Tridens DevSecOps Ensures Compliance, Security, and Agility

  • 2. Agenda • Tech Stack • DevOps Stack • DevOps Practices & Process • DevSecOps • Monitoring & Support ©2025 Tridens d.o.o. All rights reserved. 2
  • 3. Tech Stack ©2025 Tridens d.o.o. All rights reserved. 3
  • 4. DevOps Stack ©2025 Tridens d.o.o. All rights reserved. 4
  • 6. Why DevOps? ©2025 Tridens d.o.o. All rights reserved. 6 • Higher speed and quality of product releases. • Faster responsiveness to customer needs. • Team can react to change requests from customers faster with adding new and updating existing features. • The time-to-market and value-delivery rates increase.
  • 7. DevOps Practices • Continuous integration (CI) • Merge changes back to the main branch as often as possible. • Developer's changes are validated by creating a build and running automated tests against the build. • Continuous delivery (CD) • Automatically deploys all code changes to a testing environment after the build stage. • Continuous testing (CT) • Testing at earlier stages of the release pipeline. • Testing more often before release. • Testing everywhere, that is, across environments and devices. • Continuous monitoring (CM) • Help monitor software operation, especially performance issues, identify the cause of the error, and apply appropriate solutions before significant damage to uptime and revenue. • Infrastructure as code (IaC) ©2025 Tridens d.o.o. All rights reserved. 7
  • 8. DevOps – CI/CD process ©2025 Tridens d.o.o. All rights reserved. 8
  • 9. DevOps – GitFlow Strategy • Production uploads are always made from Master. • Master must always be stable and ready to deploy. • The work is always done on Develop. Putting the focus on the product being releasable and available. • The Release branch is used to stabilize development. • When we develop a feature, it is done on a Feature branch. • Feature branches always merge with Develop. • Hotfix branch to resolve critical production issues. In addition, this new branch will be merged with Master and Develop as soon as this problem is solved. ©2025 Tridens d.o.o. All rights reserved. 9
  • 10. DevOps – Cheat Sheet ©2025 Tridens d.o.o. All rights reserved. 10
  • 11. DevOps – GIT Operations git commit --allow-empty -m “[<command>]“ Example: git commit –allow-empty –m “[ci-release]“ git commit –allow-empty –m “[ci-review]“ git commit –allow-empty –m “[ci-run]“ git commit –allow-empty –m “[ci-run|ere:feature/some-feature|tgw:feature/some-feature]“ ©2025 Tridens d.o.o. All rights reserved. 11
  • 12. DevOps – CI Pipeline .ci/Jenkinsfile @Library('Tridens-CI’) _ JenkinsPipeline { javaVersion='11' buildTargetPrefix='app/' dockerImageNamespace='monetization' bddJobTag='monetizationIntegTag' applicationType=si.tridenstechnology.jenkins.Configuration.ApplicationType.MAVEN } ©2025 Tridens d.o.o. All rights reserved. 12
  • 13. DevOps - JIRA Issue & Project Tracking Software • Project tracking • Reports • Issue creation • Time tracking • Kanban board ©2025 Tridens d.o.o. All rights reserved. 13
  • 14. AWS Cloudformation • Easy to use • Flexible and declarative • Customisation through parameters • Drag-and-drop UI for visualization • DevOps principle IaC ©2025 Tridens d.o.o. All rights reserved. 14
  • 16. DevOps – AI Code Review ©2025 Tridens d.o.o. All rights reserved. 16
  • 17. DevOps - Jenkins ©2025 Tridens d.o.o. All rights reserved. 17
  • 18. DevOps - CI Pipeline CI { … } ©2025 Tridens d.o.o. All rights reserved. 18
  • 19. DevOps - SonarQube ©2025 Tridens d.o.o. All rights reserved. 19
  • 20. DevOps – End-To-End Tests ©2025 Tridens d.o.o. All rights reserved. 20
  • 21. DevOps – AI Generated Tests ©2025 Tridens d.o.o. All rights reserved. 21
  • 22. DevOps – ER Diagram ©2025 Tridens d.o.o. All rights reserved. 22 Image from trickyenough.com
  • 23. DevOps – OpenAPI & API docs ©2025 Tridens d.o.o. All rights reserved. 23
  • 24. DevOps - Issue & project tracking ©2025 Tridens d.o.o. All rights reserved. 24
  • 26. Trivy – security scanner ©2025 Tridens d.o.o. All rights reserved. 26
  • 27. Zed Attack Proxy – automated pentesting ©2025 Tridens d.o.o. All rights reserved. 27
  • 28. GoPhish – phishing simulator ©2025 Tridens d.o.o. All rights reserved. 28
  • 30. AWS – CloudWatch monitoring • Built-in metrics • Custom metrics • Operational view with dashboards • Alarms (MS Teams, AWS Lambda) ©2025 Tridens d.o.o. All rights reserved. 30
  • 31. AWS – Performance Insights Monitoring • Debug performance issues, for example, by identifying queries that are causing high load. • Tuning performance by identifying bottlenecks like CPU or I/O throughput. • Monitor the performance by aggregating the core performance indicators of your database. • Analyse Queries, Analyse Bottlenecks ©2025 Tridens d.o.o. All rights reserved. 31
  • 32. DevOps – Spring Boot Admin ©2025 Tridens d.o.o. All rights reserved. 32
  • 33. Status and incident communication tool ©2025 Tridens d.o.o. All rights reserved. 33
  • 34. Alerting ©2025 Tridens d.o.o. All rights reserved. 34