SlideShare a Scribd company logo
24.08.2020I Finnova 1
Finnova – Christian Reinhard, Head Application Management
VSHN - Aarno Aukia, CTO & Partner
CISO SUMMIT
ZURICH
INTRODUCTION
1
USER STORY – FROM
THE IDEA TO
OPENSHIFT
PLATFORM
2
SECURITY WITHIN THE
PLATFORM
3
4
Agenda
CISO Summit
5
DEVOPS (VSHN) KEY TAKEAWAYS
Introduction
24.08.2020 I Finnova3
Digitization within Finnova
Finnova Application Management Seewen
more than just Application Management
4
FINNOVA APPLICATION
MANAGEMENT SEEWEN
FINNOVA SOLUTIONS FINNOVA CONSULTING FINNOVA PRODUKTHAUS
INTRODUCTION
1
USER STORY – FROM
THE IDEA TO
OPENSHIFT
PLATFORM
2
SECURITY WITHIN THE
PLATFORM
3Agenda
CISO Summit
4 5
DEVOPS (VSHN) KEY TAKEAWAYS
03.08.20207
A solution arises from a customer need together with the customer –
Finnova Portal as a Service
CMS-Portal TechnologieFinnova Omega Platform Development PartnerFinnova Open Platform
Orchestrierung mit
Prozessen und FIL-Services
Finnova Core
Betrieb des CMS-Portals im SaaS-Modell
| Workshop Neobank
OPERATION AND APPLICATION MANAGEMENT AT FINNOVA AM IN SEEWEN
Finnova Plattform
8
Portal as a Service
Portal
WAF WAF WAF
Core Γ Core Γ Core Γ
OMEGA
Ω
OMEGA
Ω
OMEGA
Ω
Finnova Core Suite
3rd Party Portal
„Liferay“ – ti&m
INTRODUCTION
1
USER STORY – FROM
THE IDEA TO
OPENSHIFT
PLATFORM
2
SECURITY WITHIN THE
PLATFORM
3Agenda
CISO Summit
4 5
DEVOPS (VSHN) KEY TAKEAWAYS
24.08.2020 Hier steht der Präsentationstitel I10
12
Deployment Process & Security
DEV
(Repository)
Files (Pods)
Docker
Images
Container
(OpenShift)
Betrieb AM
Seewen
(PRD)
GitHub
Code Image-Scan (Security & Compliance Policies)
» Code Analyse
» Image Scanning
» Container Hardening
Runtime
» Network Security
» Monitoring
» Logging & Reporting
» Code Security
» Access
» Security & Auditing
SecurityDeployment
24.08.2020 Portal as a Service13
Architecture and Security
INTRODUCTION
1
USER STORY – FROM
THE IDEA TO
OPENSHIFT
PLATFORM
2
SECURITY WITHIN THE
PLATFORM
3Agenda
CISO Summit
KEY TAKEAWAYS
4 5
DEVOPS (VSHN)
VSHN - The DevOps Company
Collaboration between Software Development (Dev) and IT-Operations (Ops)
● Automate as much as possible (“Infrastructure as code”)
● use standard services (layers of abstractions with clear API) to abstract
complexity
● Cost efficient and lean way of working
● Agility: ability to react to new/changing requirements
● One team with a common goal: ship stable features
● Continuous improvement
1515
DevOps
VSHN - The DevOps Company 1616
DevOps:
People, Processes & Tools
VSHN - The DevOps Company
DevOps + Security Engineering = DevSecOps
1717
VSHN - The DevOps Company
● “Full Stack Audit”
● Review design document
● Every layer was custom built
○ physical hardware
○ handcrafted servers
○ manual application deployment
● Review each layer
● Review each layer again next year...
1818
Traditional IT governance
VSHN - The DevOps Company
● Standardized components
○ already audited, some even externally certified
○ re-used, economies of scale, CMMI level 5
○ tech controls (AAI, RBAC, logs/SIEM) implemented once
○ financial controls implemented once
● Infrastructure: private/public cloud, onprem
● Ops: Container orchestration platform
● Review design document & platform
configuration
1919
Cloud native IT governance
VSHN - The DevOps Company
● prevent configuration drift
○ immutable (application) infrastructure using containers
○ deploy dev/test/stage/prod envs from CI/CD
● prevent manual errors
○ validate configuration in CI/CD before deployment
○ standardization on (minimal, hardened) OS and container orchestrator
○ deployment automation removes need for (most) root prod access
● security by default
○ image scanning, dependency vulnerability management
○ process/storage/network separation of applications/environments
○ volumes & ingresspoints best practice (documentation, monitoring, backup, SSL/TLS/WAF)
○ AAI for admin & application, audit trail logging of CI/CD, control & application planes
○ key & secrets management
● 2020
IT governance controls in container platforms
VSHN - The DevOps Company
● compute resources billable by project
● self-service-onboarding possible
● autoscaling, scale-down dev envs outside office hours
● vendor procurement/due diligence/certification management
● SLA, 24x7, service process, escalation management clearly defined
2121
IT governance financial/compliance controlling
INTRODUCTION
1
USER STORY – FROM
THE IDEA TO
OPENSHIFT
PLATFORM
2
SECURITY WITHIN THE
PLATFORM
3Agenda
CISO Summit
KEY TAKEAWAYS
4 5
DEV OPS (VSHN)
VSHN - The DevOps Company
● Modularization
○ Modular digitalization platform enabling multi-tenancy and development autonomy
○ clearly defined layers for API and operations for alignment
● Collaboration
○ BPF orchestration engine to provide end-to-end process for Dev & Ops (Application
Management) at Finnova
○ clearly defined layers for operations and specialization
2323
Key takeaways
VSHN - The DevOps Company
@aarnoaukia http://about.me/aarno a@vshn.ch
ETH → Google → Atrila → VSHN
VSHN - The DevOps Company
Since 2014, currently 45 VSHNeers in Zürich, Switzerland
Helping Developers run applications on any infrastructure making both visitors
happy with stability and developers happy with agility
2424
About Aarno & VSHN.ch
Come visit us for a coffee!
VSHN AG - Neugasse 10 - CH-8005 Zürich - +41 44 545 53 00 - https://vshn.ch/ - info@vshn.ch
https://vshn.ch/kontakt/
Follow us on Twitter!
@vshn_ch
25

More Related Content

PDF
Next gen software operations models in the cloud
PDF
[WSO2Con USA 2018] Architecting for Container-native Environments
PDF
[WSO2Con EU 2018] OpenAPI Specification 3 - The Evolution of Swagger
PDF
„GitOps with Flux and Flagger“
PDF
Modern Post-Exploitation Strategies - 44CON 2012
PDF
[WSO2Con EU 2018] Architecting for a Container Native Environment
PDF
Strengthen Security and Traffic Visibility on Amazon EKS with NGINX
PDF
Process Automation: an Update from the Trenches
Next gen software operations models in the cloud
[WSO2Con USA 2018] Architecting for Container-native Environments
[WSO2Con EU 2018] OpenAPI Specification 3 - The Evolution of Swagger
„GitOps with Flux and Flagger“
Modern Post-Exploitation Strategies - 44CON 2012
[WSO2Con EU 2018] Architecting for a Container Native Environment
Strengthen Security and Traffic Visibility on Amazon EKS with NGINX
Process Automation: an Update from the Trenches

What's hot (20)

PDF
Cas d'usage ProtoStellar Cloud replatforming de l'application 1Logistic pour...
PDF
Exposing Lambda Functions as Managed APIs
ODP
Case management applications with BPM
PDF
What Makes up a Modern Application Platform?
PDF
CNCF Singapore - Introduction to Envoy
PPTX
Avoid SPOF in Cloud-native Apps
PDF
Building successful business Java apps: How to deliver more, code less, and c...
PDF
GitLab's Acquisition Strategy & Approach
PDF
Xpdays: Kubernetes CI-CD Frameworks Case Study
PDF
Meetup talk Red Hat OpenShift service mesh
PPTX
Bring Service Mesh To Cloud Native-apps
PPTX
Control Kubernetes Ingress and Egress Together with NGINX
PDF
The what, why and how of knative
PPTX
GitLab Product Roadmap and Approach
PDF
API design-first and Microservices
PPTX
Flexible, Powerful, and Easy-to-Use Ingress Load Balancing with NGINX and Ope...
PPTX
Accelerate Your Development: CI/CD using AWS and Serverless
PPTX
DevOps Fest 2019. Дмитрий Лагоза. CD for StartUp, cheap and furious
PPTX
MuleSoft Meetup Roma - Processi di Automazione su CloudHub
PDF
Microservice API Gateways with NGINX
Cas d'usage ProtoStellar Cloud replatforming de l'application 1Logistic pour...
Exposing Lambda Functions as Managed APIs
Case management applications with BPM
What Makes up a Modern Application Platform?
CNCF Singapore - Introduction to Envoy
Avoid SPOF in Cloud-native Apps
Building successful business Java apps: How to deliver more, code less, and c...
GitLab's Acquisition Strategy & Approach
Xpdays: Kubernetes CI-CD Frameworks Case Study
Meetup talk Red Hat OpenShift service mesh
Bring Service Mesh To Cloud Native-apps
Control Kubernetes Ingress and Egress Together with NGINX
The what, why and how of knative
GitLab Product Roadmap and Approach
API design-first and Microservices
Flexible, Powerful, and Easy-to-Use Ingress Load Balancing with NGINX and Ope...
Accelerate Your Development: CI/CD using AWS and Serverless
DevOps Fest 2019. Дмитрий Лагоза. CD for StartUp, cheap and furious
MuleSoft Meetup Roma - Processi di Automazione su CloudHub
Microservice API Gateways with NGINX
Ad

Similar to Security in the DevOps pipeline of containerized core application: Case Study Finnova (20)

PDF
DevSecOps: Bringing security to the DevOps pipeline
PDF
DevSecOps - Security in DevOps
PDF
DevSecOps: Bringing security to the DevOps pipeline
PDF
DevSecOps: Bringing security to the DevOps pipeline
PDF
Securing DevOps
PDF
DevOps & DevSecOps in Swiss Banking
PDF
Moving Applications to the cloud
PDF
SecDevOps 2017
PDF
DevOps on AWS
PDF
A guide to modern software development 2018
PDF
Continuous security improvements in the DevOps process
PDF
It delivery 2016 v5
PDF
DevOps for E-Commerce
PDF
Transforming to OpenStack: a sample roadmap to DevOps
PPTX
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
PPTX
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
PDF
How to Design a Backend for IoT
PDF
Wie macht man aus Software einen Online-Service in der Cloud
PDF
DevOps - Top Trends In 2019
PDF
IT Governance and Security Architecture in Docker, Kubernetes, OpenShift
DevSecOps: Bringing security to the DevOps pipeline
DevSecOps - Security in DevOps
DevSecOps: Bringing security to the DevOps pipeline
DevSecOps: Bringing security to the DevOps pipeline
Securing DevOps
DevOps & DevSecOps in Swiss Banking
Moving Applications to the cloud
SecDevOps 2017
DevOps on AWS
A guide to modern software development 2018
Continuous security improvements in the DevOps process
It delivery 2016 v5
DevOps for E-Commerce
Transforming to OpenStack: a sample roadmap to DevOps
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
How to Design a Backend for IoT
Wie macht man aus Software einen Online-Service in der Cloud
DevOps - Top Trends In 2019
IT Governance and Security Architecture in Docker, Kubernetes, OpenShift
Ad

More from Aarno Aukia (18)

PDF
DevOps for AI: running LLMs in production with Kubernetes and KubeFlow
PDF
The printing press of 2021 - using GitLab to publish the VSHN Handbook
PDF
Applikationsmodernisierung: Der Weg von Legacy in die Cloud
PDF
Von der Straße in die Cloud: Optimierung von Logistikprozessen mit Docker, Ku...
PDF
Kubecon 2019 Recap
PDF
My broken container is gone - how to debug containers on container platforms
PDF
Automated Server Administration for DevSecOps
PDF
Wir arbeiten in der Cloud – eine Herausforderung für das IT Management?
PDF
Application Portability using Cloud Native Technology: Docker, Kubernetes
PDF
Migration von Applikationen in die Cloud
PDF
IPv6 on Container Plattforms
PDF
Cloud Native Computing & DevOps
PDF
Cloud Native Computing
PDF
Cloud Native Computing Meetup Zürich Jan 11 2018
PDF
Wie nutzen wir Cloud-Infrastruktur @ VSHN.ch
PDF
Scalable Web Applications with 100% open source
PDF
Cloud Native Computing Meetup Zürich
PDF
Scalable Python with Docker, Kubernetes, OpenShift
DevOps for AI: running LLMs in production with Kubernetes and KubeFlow
The printing press of 2021 - using GitLab to publish the VSHN Handbook
Applikationsmodernisierung: Der Weg von Legacy in die Cloud
Von der Straße in die Cloud: Optimierung von Logistikprozessen mit Docker, Ku...
Kubecon 2019 Recap
My broken container is gone - how to debug containers on container platforms
Automated Server Administration for DevSecOps
Wir arbeiten in der Cloud – eine Herausforderung für das IT Management?
Application Portability using Cloud Native Technology: Docker, Kubernetes
Migration von Applikationen in die Cloud
IPv6 on Container Plattforms
Cloud Native Computing & DevOps
Cloud Native Computing
Cloud Native Computing Meetup Zürich Jan 11 2018
Wie nutzen wir Cloud-Infrastruktur @ VSHN.ch
Scalable Web Applications with 100% open source
Cloud Native Computing Meetup Zürich
Scalable Python with Docker, Kubernetes, OpenShift

Recently uploaded (20)

PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PPTX
Introduction to Artificial Intelligence
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
history of c programming in notes for students .pptx
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PPTX
Reimagine Home Health with the Power of Agentic AI​
PDF
top salesforce developer skills in 2025.pdf
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
CHAPTER 2 - PM Management and IT Context
Operating system designcfffgfgggggggvggggggggg
How to Migrate SBCGlobal Email to Yahoo Easily
Introduction to Artificial Intelligence
Which alternative to Crystal Reports is best for small or large businesses.pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Design an Analysis of Algorithms I-SECS-1021-03
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
How to Choose the Right IT Partner for Your Business in Malaysia
PTS Company Brochure 2025 (1).pdf.......
history of c programming in notes for students .pptx
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Reimagine Home Health with the Power of Agentic AI​
top salesforce developer skills in 2025.pdf
wealthsignaloriginal-com-DS-text-... (1).pdf
How Creative Agencies Leverage Project Management Software.pdf
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
2025 Textile ERP Trends: SAP, Odoo & Oracle
CHAPTER 2 - PM Management and IT Context

Security in the DevOps pipeline of containerized core application: Case Study Finnova

  • 1. 24.08.2020I Finnova 1 Finnova – Christian Reinhard, Head Application Management VSHN - Aarno Aukia, CTO & Partner CISO SUMMIT ZURICH
  • 2. INTRODUCTION 1 USER STORY – FROM THE IDEA TO OPENSHIFT PLATFORM 2 SECURITY WITHIN THE PLATFORM 3 4 Agenda CISO Summit 5 DEVOPS (VSHN) KEY TAKEAWAYS
  • 4. Finnova Application Management Seewen more than just Application Management 4 FINNOVA APPLICATION MANAGEMENT SEEWEN FINNOVA SOLUTIONS FINNOVA CONSULTING FINNOVA PRODUKTHAUS
  • 5. INTRODUCTION 1 USER STORY – FROM THE IDEA TO OPENSHIFT PLATFORM 2 SECURITY WITHIN THE PLATFORM 3Agenda CISO Summit 4 5 DEVOPS (VSHN) KEY TAKEAWAYS
  • 6. 03.08.20207 A solution arises from a customer need together with the customer – Finnova Portal as a Service CMS-Portal TechnologieFinnova Omega Platform Development PartnerFinnova Open Platform Orchestrierung mit Prozessen und FIL-Services Finnova Core Betrieb des CMS-Portals im SaaS-Modell | Workshop Neobank OPERATION AND APPLICATION MANAGEMENT AT FINNOVA AM IN SEEWEN
  • 7. Finnova Plattform 8 Portal as a Service Portal WAF WAF WAF Core Γ Core Γ Core Γ OMEGA Ω OMEGA Ω OMEGA Ω Finnova Core Suite 3rd Party Portal „Liferay“ – ti&m
  • 8. INTRODUCTION 1 USER STORY – FROM THE IDEA TO OPENSHIFT PLATFORM 2 SECURITY WITHIN THE PLATFORM 3Agenda CISO Summit 4 5 DEVOPS (VSHN) KEY TAKEAWAYS
  • 9. 24.08.2020 Hier steht der Präsentationstitel I10
  • 10. 12 Deployment Process & Security DEV (Repository) Files (Pods) Docker Images Container (OpenShift) Betrieb AM Seewen (PRD) GitHub Code Image-Scan (Security & Compliance Policies) » Code Analyse » Image Scanning » Container Hardening Runtime » Network Security » Monitoring » Logging & Reporting » Code Security » Access » Security & Auditing SecurityDeployment
  • 11. 24.08.2020 Portal as a Service13 Architecture and Security
  • 12. INTRODUCTION 1 USER STORY – FROM THE IDEA TO OPENSHIFT PLATFORM 2 SECURITY WITHIN THE PLATFORM 3Agenda CISO Summit KEY TAKEAWAYS 4 5 DEVOPS (VSHN)
  • 13. VSHN - The DevOps Company Collaboration between Software Development (Dev) and IT-Operations (Ops) ● Automate as much as possible (“Infrastructure as code”) ● use standard services (layers of abstractions with clear API) to abstract complexity ● Cost efficient and lean way of working ● Agility: ability to react to new/changing requirements ● One team with a common goal: ship stable features ● Continuous improvement 1515 DevOps
  • 14. VSHN - The DevOps Company 1616 DevOps: People, Processes & Tools
  • 15. VSHN - The DevOps Company DevOps + Security Engineering = DevSecOps 1717
  • 16. VSHN - The DevOps Company ● “Full Stack Audit” ● Review design document ● Every layer was custom built ○ physical hardware ○ handcrafted servers ○ manual application deployment ● Review each layer ● Review each layer again next year... 1818 Traditional IT governance
  • 17. VSHN - The DevOps Company ● Standardized components ○ already audited, some even externally certified ○ re-used, economies of scale, CMMI level 5 ○ tech controls (AAI, RBAC, logs/SIEM) implemented once ○ financial controls implemented once ● Infrastructure: private/public cloud, onprem ● Ops: Container orchestration platform ● Review design document & platform configuration 1919 Cloud native IT governance
  • 18. VSHN - The DevOps Company ● prevent configuration drift ○ immutable (application) infrastructure using containers ○ deploy dev/test/stage/prod envs from CI/CD ● prevent manual errors ○ validate configuration in CI/CD before deployment ○ standardization on (minimal, hardened) OS and container orchestrator ○ deployment automation removes need for (most) root prod access ● security by default ○ image scanning, dependency vulnerability management ○ process/storage/network separation of applications/environments ○ volumes & ingresspoints best practice (documentation, monitoring, backup, SSL/TLS/WAF) ○ AAI for admin & application, audit trail logging of CI/CD, control & application planes ○ key & secrets management ● 2020 IT governance controls in container platforms
  • 19. VSHN - The DevOps Company ● compute resources billable by project ● self-service-onboarding possible ● autoscaling, scale-down dev envs outside office hours ● vendor procurement/due diligence/certification management ● SLA, 24x7, service process, escalation management clearly defined 2121 IT governance financial/compliance controlling
  • 20. INTRODUCTION 1 USER STORY – FROM THE IDEA TO OPENSHIFT PLATFORM 2 SECURITY WITHIN THE PLATFORM 3Agenda CISO Summit KEY TAKEAWAYS 4 5 DEV OPS (VSHN)
  • 21. VSHN - The DevOps Company ● Modularization ○ Modular digitalization platform enabling multi-tenancy and development autonomy ○ clearly defined layers for API and operations for alignment ● Collaboration ○ BPF orchestration engine to provide end-to-end process for Dev & Ops (Application Management) at Finnova ○ clearly defined layers for operations and specialization 2323 Key takeaways
  • 22. VSHN - The DevOps Company @aarnoaukia http://about.me/aarno a@vshn.ch ETH → Google → Atrila → VSHN VSHN - The DevOps Company Since 2014, currently 45 VSHNeers in Zürich, Switzerland Helping Developers run applications on any infrastructure making both visitors happy with stability and developers happy with agility 2424 About Aarno & VSHN.ch
  • 23. Come visit us for a coffee! VSHN AG - Neugasse 10 - CH-8005 Zürich - +41 44 545 53 00 - https://vshn.ch/ - info@vshn.ch https://vshn.ch/kontakt/ Follow us on Twitter! @vshn_ch 25