Trivy for Kubernetes & DevSecOps: Build Secure Container Pipelines with SBOM, Supply Chain Scanning

Preis
Normaler Preis CHF 86.00
Normaler Preis CHF 119.00 Sonderpreis CHF 86.00
CHF 33 günstiger
/
  • Kostenlose Lieferung innerhalb der Schweiz
  • 3-5 Tage Lieferzeit
  • Kauf auf Rechnung möglich
  • 14 Tage Rückgabegarantie mit kostenloser Retoure
  • Auf Lager
  • Nachbestellt, bald verfügbar
inkl. MwSt.
Beschreibung

Marke: Alira Vexel

Variante: Taschenbuch

Eigenschaften:

Trivy for Kubernetes & DevSecOpsBuild Secure Container Pipelines with SBOM, Supply Chain Scanning & CI/CD Automation Using GitHub Actions, Jenkins, ArgoCD, Terraform & HelmModern software delivery is fast.Attack surfaces are faster.Container images, Helm charts, Terraform modules, CI pipelines, and GitOps promotions form a complex supply chain — and every stage is a potential entry point for risk.This book does not teach isolated Trivy commands.It teaches you how to design and operate a production-grade DevSecOps control system.What This Book DeliversYou will build a complete, real-world security architecture:Repository→ Container Build (Immutable Digest)→ Vulnerability Scan→ SBOM Generation (CycloneDX & SPDX)→ Helm Render Validation→ Misconfiguration & Secret Detection→ Policy-Based Gating→ GitOps Promotion with ArgoCD→ Audit-Ready Evidence Pack→ Continuous Validation & Security Debt ReductionEvery chapter connects to this system spine.Nothing is fragmented. Nothing is theoretical.What Makes This Book DifferentMost DevSecOps guides:Explain what SBOM isShow a few Trivy examplesProvide disconnected CI snippetsAvoid real governance designThis book goes further.You will implement:Deterministic PR gates with SARIF integrationEnterprise-grade Jenkins release pipelinesTerraform misconfiguration scanning with real guardrailsHelm pre-deploy security validationExpiry-based exception governanceBreak-glass workflows with audit traceabilityDigest-only production deploymentsEvidence bundles with policy snapshots and checksumsZero-to-production rollback validationMulti-environment promotion discipline using ArgoCDThis is not “scan and hope.”It is structured enforcement.Built for Real OperatorsThis book is written for:DevOps EngineersPlatform EngineersSREsSecurity Engineers (AppSec / CloudSec)Cloud ArchitectsTechnical Leaders building internal DevSecOps standardsIt assumes you want depth — not surface-level summaries.There are no “What is Kubernetes?” chapters.There are no toy examples.Every workflow is production-aligned.Fully Modern & 2026-ReadyYou will work with current, real-world tooling:Trivy for image, filesystem, repo, and Kubernetes scanningGitHub Actions for PR security gatesJenkins for enterprise release orchestrationTerraform for infrastructure-as-code validationHelm for controlled application deliveryArgoCD for GitOps promotion enforcementSBOM-first supply chain governanceThe final capstone builds a complete, audit-ready DevSecOps platform from scratch.What You Will Walk Away WithAfter completing this book, you will have:A repeatable security architecture you can deploy immediatelyCopy-paste CI/CD templates ready for productionGovernance patterns with expiry-based exceptionsA measurable security debt reduction modelA roadmap for enterprise scaling (policy-as-code, attestations, multi-cluster governance)A standalone DevSecOps blueprint suitable for serious environmentsSecurity is not a scanner.It is a workflow.It is a promotion discipline.It is a contract between build, release, and runtime.This book gives you the architecture to enforce that contract.If you build Kubernetes platforms, operate CI/CD systems, or are responsible for container supply chain integrity, this manual will become your operational reference.

Lieferzeit


Der Artikel ist innerhalb weniger Tage lieferbar, die Lieferzeit beträgt hierbei 3-5 Werktage.
Die Ware wird kostenlos mit der Schweizerischen Post oder DPD versendet.

Retouren

Rückgabe von Ware gemäss AGB

  • Kostenlose Retouren innert 14 Tagen nach Erhalt
  • Die Gutschrift erfolgt zu 100% der Kaufsumme
  • zu Einzelheiten siehe Ziffer 8.0 und Ziffer 8.1. der AGB
Dir könnte gefallen
Mehr von Alira Vexel
NEU
Zuletzt Angesehen