DevSecOps Engineering Bootcamp
Chapter 4
Implementation Workflow
Developer Push
|
v
GitLab CI
|-- Gitleaks secrets scan
|-- Semgrep SAST
|-- Trivy dependency scan
|-- Build Image
|-- Trivy image scan
|-- Syft generate SBOM
+-- Cosign sign image
|
v
Kubernetes Cluster
|-- Kyverno admission control policies
|-- External Secrets Operator secrets from Vault
+-- Falco runtime threat detection -> Grafana
Security Controls Reference
| # | Control | Tools | Where It Runs |
|---|---|---|---|
| 1 | Pipeline Security | Gitleaks · Semgrep · Trivy | GitLab CI, before build |
| 2 | Secrets Management | External Secrets Operator · Vault | Kubernetes cluster |
| 3 | Manifest Security | Checkov | Local + GitLab CI |
| 4 | Admission Control | Kyverno | Kubernetes cluster, admission webhook |
| 5 | Supply Chain Security | Syft · Cosign | GitLab CI build stage + registry |
| 6 | Runtime Security | Falco | Kubernetes cluster, runtime (eBPF) |