--- title: "DJ Schleen — DevOps: The Sec is Silent" url: https://appsecpodcast.com/dj-schleen-devops-the-sec-is-silent/ date: 2020-01-30 duration_seconds: 2255 guests: ["DJ Schleen"] topics: ["Cloud and Infrastructure", "DevSecOps and CI/CD", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/8122615-dj-schleen-devops-the-sec-is-silent.mp3 transcript: true --- # DJ Schleen — DevOps: The Sec is Silent *January 30, 2020 · 38 min* with [DJ Schleen](https://appsecpodcast.com/guests/dj-schleen/) on [Cloud and Infrastructure](https://appsecpodcast.com/topics/cloud-and-infrastructure/), [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122615-dj-schleen-devops-the-sec-is-silent.mp3) ## Show notes What changes when security becomes part of delivering software instead of a separate gate? DJ Schleen joins Chris and Robert to explain why he prefers DevOps with a silent Sec, drawing on his journey from early programming and hacking to building delivery pipelines. They discuss the difference between genuine transformation and automating an existing process, why governance and compliance belong in the conversation, and how teams can grow their capabilities without adopting every tool at once. DJ walks through his DevSecOps reference architecture as an assembly line from idea to customer value. The conversation closes with learning Kubernetes through K3s, the tradeoffs of managed platforms, and the security thinking that matters more than a particular product. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with DJ Schleen: → [LinkedIn](https://www.linkedin.com/in/djschleen/) → [GitHub](https://github.com/djschleen) Mentioned in this episode: → [DevSecOps reference architecture](https://www.sonatype.com/blog/take-this-interactive-devsecops-reference-architecture-for-a-test-drive) → [K3s](https://k3s.io/) → [DevOpsDays](https://devopsdays.org/) → [The Unicorn Project](https://itrevolution.com/product/the-unicorn-project/) Chapters: 00:00 Introduction 02:12 DJ's programming and hacking roots 06:33 What DevOps is trying to accomplish 09:44 Adoption beyond automating the old process 12:20 Will DevOps become ordinary software delivery? 15:15 Bringing compliance and governance along 18:17 Observers, stakeholders, and participants 19:48 Growing the team with the work 20:34 Why the Sec is silent 24:43 The DevSecOps reference architecture 28:54 Starting small and adding capabilities 31:23 Learning Kubernetes with K3s 33:49 Managed platforms and security tradeoffs 35:53 Closing thoughts ## Transcript *6,739 words · assemblyai* **0:00 Chris Romeo:** DJ Schleen is a seasoned DevSecOps advocate at Sonatype and provides thought leadership to organizations looking to integrate security into their DevOps practices. He encourages organizations to deeply integrate a culture of security and trust into their core values and product development journey. DJ joins us to talk about the philosophy of DevOps and flow, DevSecOps and silos, and the DevSecOps reference architecture. We hope you enjoy this conversation with— **0:28 Robert Hurlbut:** DJ Schleen. DJ Schleen. **0:30 Chris Romeo:** You cannot hack yourself secure. **0:36 Robert Hurlbut:** Everyone wants to focus on the offensive side of the equation. The challenge is that developers get bored with hacking broken pieces of code after a while. Sure, it's a shiny, cool new thing in the beginning, but how about one year later? **0:48 Chris Romeo:** At Security Journey, we focus on long-term sustainable security culture with the developers as defenders. Our approach integrates experimentation together with learning. **0:57 Robert Hurlbut:** We believe that developers need hands-on experience, but not at the expense of fundamental knowledge. **1:03 Chris Romeo:** Visit www.securityjourney.com to sign up for a free trial of the Security Dojo or schedule a demo. **1:10 Robert Hurlbut:** Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey, and I am joined once again by my co-host Robert. Hey Robert, how's it going today? **1:32 DJ Schleen:** Hey Chris, it's going well. Yeah, this is Robert Hurlbut, Threat Modeling Architect. **1:36 Chris Romeo:** Good to be here. **1:37 Robert Hurlbut:** I'm super excited for the conversation we're gonna have today because I feel like this conversation actually started almost a year ago. When I was out at the RSA conference last year, I had a chance to meet our guest DJ Schleen through a connection that we both had at RSA. And he began telling me a number of things about his story, which made me think at that moment almost a year ago, I'm gonna interview this guy for the podcast. at some point. And so, DJ, we're going to jump right in with your security origin story. Tell us, as way— as far back as you want to go, how did you get into this crazy thing we call security? **2:12 DJ Schleen:** Oh, hey Chris. Hey Robert. Thanks for having me on the show today. Um, gosh, where do I start? I guess I could start with the, uh, saving my allowance back when I was 10 years old to get my first VIC-20. And, uh, when I got it, it was a matter of getting like a 300 baud modem hooked up. And I was just like, how do I— how does this work? Like, how are these bits and bytes going across the air? You know, and ripped the thing apart, put it back together. And I think that was the start of my whole hacking mentality and hacking career. You know, and for the longest time, like, this was a long time ago, there was no education. There's no, you know, hacking tutorials. There's no internet for that matter. It's just like all BBS systems, right? And so, yeah, that brings me up to a couple of years ago. ago, I started legitimizing myself, getting some certifications, uh, getting into some ethical hacking, penetration testing, red teaming, and after a while, ended up finding myself at a large Fortune 10 healthcare organization doing security architecture there. So, uh, see the gamut of things, Chris. **3:19 Robert Hurlbut:** Yeah, it's definitely a lot of, uh, a lot of different kind of unique perspectives. And so, have you ever actually worked as a developer? I want to say you did in the web world. **3:30 DJ Schleen:** Oh, absolutely. Back— gosh, I think it was in the mid-1990s, I formed one of the first web design companies in Canada. We were using— developing software for Netscape 0.99, gray backgrounds, running the server on ASP Beta on an NT 4 Beta machine. It was interesting. We were about 10 years ahead of our time. I was trying to sell websites to people who thought, yeah, we got brochures and we got fax machines, so why do we need to communicate via email? So, been involved right from the get-go. I've been programming since I've been 10 years old. You know, couldn't afford video games after I bought that VIC-20, so I had to create them. **4:09 Robert Hurlbut:** Yeah, this is great. Number of nostalgic kind of things that you're throwing out here, from VIC-20 to 300 baud modems to Windows NT 4. You know, any of our newer listeners, you might have to look a couple of these things up on Wikipedia, but that's okay. Those of us that lived through it, we, uh, we know what it— how it all came together. **4:27 DJ Schleen:** Was it a 5¼ floppy or was it— yeah, it was 3¼ and 5½, right? **4:34 Robert Hurlbut:** 3½. 3½ and 5¼. If you would have— you didn't have a Trash 80 then that had those giant Frisbee-sized 9¼-inch disks or 7¼ or something? **4:47 DJ Schleen:** No, I was more advanced than that with the 5¼ and 3½. The first Mac I ever got was one of the 1984 ones that had all the autographs inside Like Steve Jobs and, you know, all the people who were involved in manufacturing scratched their names on the inside of the cases. And I wish I still had that thing, but unfortunately it was my dad carting it back and forth from work and, you know, me printing the dot matrix printer, printing some stuff out at 11 o'clock at night, driving my folks crazy. **5:18 Robert Hurlbut:** Yeah, and so I know in our conversations in the past, you have told me quite a bit about experiences you've had with ethical hacking, red teaming, penetration testing. How does that relate to what you're doing now when we think about this whole world world of DevOps and DevSecOps? **5:33 DJ Schleen:** Well, you know, it's funny, 'cause I always say that DevSecOps professionals, or people who are practicing DevSecOps, you know, DevOps, DevSecOps, rainbow monkey unicorn pony, whatever you wanna call it, it's just programming, right? And I think when you start dealing with the ethical hacking and the experience around security, you're sort of putting the trifecta together, right? You're the original gangsters of DevSecOps are those hackers. They know that there's more than one layer to the OSI model. You know, they know how to compromise you from the outside, they know how to hack your software, and chances are they're just going to bypass all that, break into your— break the glass on your basement window and come in and just steal the stuff, right? They're not going to do it digitally, but everything comes together. I think that's where this whole DevSecOps movement comes from, where we're bringing in everything that we've ever known from development, almost unwinding the processes that have hindered us from developing great software and replacing with automation to ensure that it's safer software sooner. **6:33 Robert Hurlbut:** And so let's, let's even, I guess, back up a little bit further and think about this idea of, of DevOps and flow. And so how did you even get into thinking about this area and becoming someone who was even studying and learning about DevOps in general? **6:50 DJ Schleen:** You know, it's sort of by accident, right? You know, 10 years ago this October, uh, Patrick Dubois had the first DevOps, uh, Days in, in Ghent, Belgium, and they just had their anniversary in October of this year. So when you look at the term DevOps, it's only about 10 years old, but we've been doing DevOps for years before that, right? I remember, gosh, I started at a small startup in Denver, Colorado, and I walked in and I was supposed to push to production right away that day, the first day I was in there. And I'm like, okay, well, where's the server room? That's not there. It's in the cloud. I'm like, what? What is this witchcraft you're talking about? And, you know, of course we ended up like pushing into AWS and, you know, everything was cobbled together because there was nothing commercial that would enable it. But that was my first taste of automation supporting development processes. We've always talked about it, right? We've talked about build servers from as long ago as Team Foundation Server and those kind of things. But this is everything starting to come together and gel. About 8 years ago, I guess 9 years ago, people started using the term DevOps and it became a little bit of a phenomenon. know, then everyone starts saying, oh, we're hiring DevOps engineers and all this kind of thing. And, you know, today I'm like, okay, that's— it's a DevOps practice and we're just programmers, right? But, uh, you know, security, it started coming around about 4 years ago, uh, even 5 years ago, where people realized that secure software was becoming more and more, um, well, more and more of a necessity in, in the industry. And I remember at RSA 2017, getting up into a DevOps Connect conference, and it was the first time I actually got on stage, started talking, and I was bringing the hard tech, but hard tech from a security perspective, and called myself a DevSecOps evangelist. And I remember John Willis, who's really big in the DevOps community, he and Damon Edwards did the first DevOps Days in America. He said to me, he's like, you got a lot of cojones to say you're a DevSecOps evangelist at a DevOps conference. And that was sort of the turning point. industry, a lot of people started to use DevSecOps, not because they wanted to create more silos like a dev silo, SecOps, or a sec silo and ops silo, but to bring everyone together and just, you know, have that secure software and call security out specifically as an important part of the development process. So yeah, it's been a while since this has all been around and, you know, things are just gradually getting more and more known and people are refining the process and not really worrying so much about a lot of the hindrances that we had before in software development. **9:44 Robert Hurlbut:** As someone who travels around and gets to interact with a lot of different-sized organizations and talk to a lot of different people in the context here of DevOps, I'm curious from your perspective, what are you seeing as far as the types and sizes of companies that are doing this? And how many, if you had to take a guess, what do you think the percentages of software houses or people that are building products and applications and things that are actually using DevOps these days versus classical— I hope nobody's using waterfall anymore, but kind of a longer cycle agile process? **10:19 DJ Schleen:** You'd be surprised how many people are using waterfall still. It's absolutely insane, or even water scrum fall, where they just do standups, but it's still waterfall. Gosh, that's a great question. In my head, from the people I've talked to over the past years, either people are thinking about it, people know about it, There's the high performers, there's the folks that are just starting their journey, but everyone has it on their mind of something that they either want to try, they want to do, and some people have tried and failed because they're either automating too much, they don't know what their value stream map is, they really don't know what they're trying to deliver, and the cultural fit isn't there. That's the 3 tenets of DevSecOps and DevOps I talk about, which is culture, technique, and tools, and tools is always the thing that you do last, right? You got to have the, you know, the communication and the culture as a baseline. And then the technique is like, how do you produce software? And that's different from every organization, whether it's big or small. But, you know, smaller companies, they say that, you know, you can adopt it a lot quicker. And if you're a startup, you can just— you have a whole green field and away you go. And from a large organization perspective, there's a lot of challenges people are facing, especially when you start getting into the large Fortune 10s where different groups are at different maturity levels. Some might be still doing waterfall, and some might be still doing agile. DevOps isn't incompatible with either of those, but it's just a different way of producing software. It's not a replacement for agile or waterfall or Kanban or anything like that. But everyone's starting to do it, and I think it's starting to really go across the world almost like a tsunami, where we were in Australia and Singapore last year, and there's such a hunger for knowledge about what's going on, and the industry is really taking, uh, taking it seriously. **12:19 Chris Romeo:** Yeah, I've been— **12:20 Robert Hurlbut:** as I think more about it, I think that there's gonna come a time here, I don't know if it's gonna take 10 years or a little bit longer, but I see a future where this just becomes the normal way that everybody builds software because there are so many advantages based on the things you talked about here, you know, from changing the culture and, and the techniques and the tools that make this all possible to automate as much of this in that whole build pipeline idea. And so, do you kind of agree with that or do you think it's gonna be quicker, it's gonna take longer? I mean, how soon before DevOps is truly mainstream and those people that are building, maybe even someone who's not building a web service, microservice kind of web frontend application, but instead is building a product that's, you know, a doorbell or something that happens to be IoT. How long before those, where DevOps is really mainstream? Yeah. **13:13 DJ Schleen:** Well, from the IoT perspective, it's already here. I was having a conversation with some of the military, and their first question was, well, DevOps, if you say fail fast, fail often, how do you fail fast, fail often when you're launching a missile? And that's a great comment from the military side of the house, but there's emulation and that kind of thing. So folks are really starting to get into that, different ways to almost have test harnesses so they can go to a certain length of delivery and deployment, but not that final deployment until everything is hardened. So it's almost like a stopgate before it goes into a missile system, for example. But this might be a crazy opinion, but I think there's a lot we have to forget than we have to learn when it comes to DevOps. Rewinding about 30 years ago, and that's probably going to date me a little bit, I was working for the Government of Canada, the Department of Defense. And we were— actually, sorry, it was Statistics Canada, and we were producing a leave, a vacation application, a web application. I was sitting with the product owner, and they weren't even called product owner. It was just the client, and I was just the programmer. We were developing this system. We were pushing it out to production. Make a change. I don't like this button over here. We'd make another change. We'd push it out. The only difference between that and today is we've had 25 years of process process that has crushed developers and really reduced our productivity. And now we're trying to replace a lot of that and a lot of the gates and the attestations and the statuses and that kind of thing with automation. So it's, it's more of a business and cultural change because we're trying to get the confidence of the business back and put it back in the developers who know how to develop software more than, you know, the other folks in the organization do. They're, they're in the trenches digging the trenches. They're not the ones that are in the office wondering if the trench is ready or not. **15:15 Robert Hurlbut:** When I think about kind of the experiences you've shared here, and I think about this whole idea of DevSecOps, and I'm just curious, have you ever encountered DevSecOps from more of a compliance perspective? Like, how do you deal with compliance in the world of DevOps and delivering software fast? And I'm thinking about like almost the other side of the house when I think about the security people in an organization. **15:42 Chris Romeo:** Yeah. **15:43 Robert Hurlbut:** You have some folks that are focused on engineering, but then you have some folks in that governance, risk, and compliance teams on the other side focused on protecting the company. Have you ever seen anything where there's cohesion between kind of the compliance side, meeting regulations, meeting laws, and a place where DevOps and DevSecOps actually enables that? **16:04 DJ Schleen:** Yeah, absolutely. You know, I started getting there with my last position where I was at. From an architectural perspective, it's really important. It goes to a story that I was in England earlier this year doing a DevSecOps Days, and Eliza May Austin came on stage, and she keynoted this presentation. She said— she opened it up with like, I don't know what DevOps is. I never want to do anything with it. I don't program, and people keep telling me that I have to develop software, but I'm a threat hunter. That triggered something in my head that we talk about DevSecOps and say security has to program, security has to be more technical, but there's other roles like GRC, which is abstracted from the technical layer, right? So I look at it as how can technology enable and enforce the policies that are defined by the GRC organization, right? So policy is code, governance is code, and we're just starting to see some products coming out on the market that do this. But, you know, think about gated promotions, and the separation of duties, or this kind of thing. Enforcing it on a technical layer, even if a developer is pushing code out, you have these technical gateways that are applying separation of duty, and that's sometimes enough, but it's hard to explain, I guess. Things are constantly changing from how we develop software, and the regulations, and the compliance and governance can't keep up with it. So I think that we have to look at it from more of a technical layer. How do we enable not how do we get those people involved in DevOps itself. **17:42 Robert Hurlbut:** Yeah, it sounds like you're saying there's definitely a place for all of the different pieces that we've discussed so far, you know, with compliance, GRC, there's a way that DevOps and DevSecOps helps make their lives actually easier by meeting the requirements and proving that we're doing the right stuff so that when they're doing audits and things, they can say, yeah, you know what? I've checked out this pipeline thing we're using to build our products and we do have these gated promotions and here's why we're sure that code that we didn't, you know, we didn't test and think was good doesn't make its way to production. **18:17 DJ Schleen:** Yeah, absolutely. Like, you know, you can't put something to production without a static analysis, or you have to have dynamic analysis from a compliance perspective. Like, it's not just audit by checkbox, right? But it's, you know, ensuring that the information is available to, you know, those organizational units. Um, you know, and it's funny because every single person in an organization can either be an observer, or a stakeholder, or a participant in DevOps, right? So people who are observers, they just are monitoring some information coming in. So those are your data scientists. They could be your SOC, right, where information is coming in to your SOC, and then that's being actioned from that perspective. Or exceptions, like let's say you have a vulnerable component that comes into your system, but there's no other alternative, and the business says, push it out. Well, Sometimes you can't argue with the business and the business accepts the risks. And no matter how much security you want to have into your process, you have to put the code out, but automate the exception creation and the remediation plan and have this load lifted off of the developers and off the GRC, the other folks in the security organization. Because at the end of the day, they're probably a skeleton crew, right? When you look at the 100 to 10 to 1 ratio of developers to ops to security, it's a bandwidth issue. And if you automate, it's a lot better. So I see So I see those 3 roles being involved from, again, an observation participant or an observer, right? **19:48 Robert Hurlbut:** I've yet to find an organization where the security people are like, yeah, we feel like we're kind of overstaffed and there might be too many of us floating around here and we don't know what to do, so we're just going to hang out in the conference room and do nothing, right? I mean, every security organization seems like it's understaffed and every functional role is like, boy, we really need 2 more of these. these people, and we have one doing the job of 2 or 3 at this point. **20:14 DJ Schleen:** Well, that's the unicorn, right? So if you talk about DevOps and DevSecOps, there's a lot of references to the unicorn. And I look at the unicorn as being, if you find someone who knows development, operations, and security at the same time, that's like, you might as well find a unicorn because it's going to be about as easy to find that as it is an individual who has those skill sets, right? **20:34 Robert Hurlbut:** Julian Vahent from Mozilla was— has been on the show with us before. And he had a funny tweet from, I don't know, maybe 2 years ago now. I don't know if you saw it or if you remember it, but he was basically making fun of the DevSecOps name. And he said, you know, hey, DevSecOps, SecDevOps, OpsDev, double Sec and then Ops, you know, can't we just call this DevOps with security? And so that always stuck with me. And I always ask people that are involved deeply in this kind of specific field, 'cause I'm curious on what your take is on that. Like, do you love the idea of kind of the name DevSecOps? Or are you kind of like, hey, it's just DevOps and security? **21:13 DJ Schleen:** You know, it's funny because over the past 3 years, I've had a love-hate relationship with it. Uh, back at RSA, when I was telling you about being, uh, being, you know, having conversations with John Willis about it, I remember going off into the trade room floor of the expo afterwards, and there's this one young guy, and he's asking me like, oh, what do you do? And I'm like, I'm a DevSecOps evangelist. He's like, that's not even a word, dude. Like, what are you talking about? It's DevOps. And, and it's caused such a God, it's rattled the industry, right? 'Cause first it was rugged, and then it was SecOps, and then it was SecDev, and then DevSecOps. You know, I always have a slide in my decks now that's like rainbow monkey unicorn pony, 'cause I really don't care what it's called, right? It's just programming at the end of the day, but everyone likes putting labels to it. You know, another interesting tidbit is I met Gene Kim for the first time at GitHub Universe this year, and I got a copy of his Unicorn Project, and he signed it. It's like, DJ, thanks for everything, and long live SecOps, SecOps, Sec. And, you know, it's, uh, again, it just shows that, you know, did we create more silos by doing this, um, or are we breaking down silos, right? If we need to label something, um, chances are you just labeled a silo. And, you know, gosh, I, I've gone from the whole idea of DevSecOps to, you know, DevSecOps is the correct way to say DevOps. I think I did a presentation about that. And, and now I just I just prefer DevOps because I think security is silent, right? I tweeted once that I know it's called DevOps, but the sec sells. And it really— like, people can call it whatever they want, as long as they're thinking about developing safer software sooner. That's all that I really care about. But I don't know if we've done the world a disservice by calling it that or if we've called it out enough that it's in people's the forefront of the imagination. Maybe in the next decade, it's going to be called programming again, who knows, or full-stack development, right? That's what we've always talked about. And wow, now we finally have it. We gave it 15 names. **23:20 Robert Hurlbut:** Everything always comes back around too. I mean, remember when we had these things called mainframes, and then everything went to personal computers, and then everything went to the cloud, which is, in parentheses, like a mainframe, where it's just a single source of computing technology and everything. So it'll come back around again. Just wait long enough. **23:39 DJ Schleen:** So you said, remember when we had them, or remember that we still have them? **23:44 Robert Hurlbut:** I'm trying to forget. **23:45 DJ Schleen:** You know, mainframes still power a lot of the health insurance industry, right? And, uh, yeah, at CA World a couple of years ago, I, I saw the IBM Z/4, and I was like, wow, this is crazy cool, because it was just this big thing. It looked like a spaceship with big vacuum tubes out of it, and I had never seen something that big before. You know, it's— they're pretty miraculous. Ridiculous. But I asked them, I'm like, does this run Linux? And they're like, yeah, it runs Linux. I'm like, okay, I can run Docker on it. I can run Kubernetes. And so I was trying to think like, how can we do DevOps for folks that are deploying to mainframes? And so I did a little talk there and some of our mainframe resources from the company I was at are like, hey, thanks for mentioning us and not forgetting that we develop software too. So yeah, even, even though we still use mainframes, the culture behind it and the development techniques can still somewhat be in the DevOps frame of mind. **24:43 Robert Hurlbut:** So I know one of the big things, DJ, you've been working on here over the last 6, 9 months has been this idea of a DevSecOps reference architecture. And so why don't you tell us just as a starting point, like what is a DevSecOps reference architecture and why did you create one? **25:02 DJ Schleen:** Oh man, that's a big loaded question. So DevOps or DevSecOps reference architectures, if you just Google it online, online, you're going to see a lot of different things from an infinity logo, um, to something that looks more of a waterfall with like arrows. But, you know, a lot of it is trying to define the, almost the assembly line of how software goes from an idea to value delivered to your customers, right? Because at the end of the day, we're not developing software just for fun. We're developing it for some, you know, business use that's, uh, you know, a necessity, right? And, uh, So from a reference architecture perspective, I've always been really an architect for the longest time. I've been an enterprise architect for wealth management companies, a security architect, you name it. One of the things I've always tried to do is relate things back to an assembly line, like a manufacturing process, which was interesting because then I'm like, wow, this has everything to do with lean manufacturing, the whole Deming movement, which is DevOps, right? So this DevSecOps reference architecture that I've started is more of a, like, how do I even start putting these tools together? It's more of a pipeline definition, right? Where you can talk about, yep, we're gonna do an architecture that says we're gonna go from dev to prod, or dev to build to test to prod. And I'm like, yeah, you just invented waterfall, like, in your DevOps architecture, right? So again, this is Conway's Law, where we're like, you know, doing the same thing we've always done type of thing, right? Um, so the architecture I've been working on is more of a subway map where it's not just linear. There's parallel processes. There's things that shoot off out of band. Uh, and it really, it's a possibility diagram, right? It's like, where can you go with a DevOps or DevSecOps architecture or pipeline architecture? Really? How do you get that software from A to B? And as I started layering this together, I'm like, okay, well, these are the observers. These are the stakeholders. stakeholders, these are the tools you can put in, these are the techniques that you can have, and it really became a complicated diagram. But, you know, you can peel back the layers and start seeing, well, okay, this is why we do things in a certain order, to optimize flow, reduce waste, all the kind of lean manufacturing principles that have come into the automation of software. So that's where I've started going with it, and it's getting bigger and bigger, adding things like continuous training and continuous education. Because these are all things that enable the cultural aspect of DevSecOps, right? You gotta teach people about what tools they're using or what the techniques are if you're gonna expect them to implement the tools and manage the processes, right? So, and then secret management and all these different concepts need to be considered, mobile development, mobile application development, and how you test those, how you put things into production. So that's what I've been trying to accomplish with the reference architecture. architectures, and, uh, you know, it's, it's in a similar format as a subway system because, uh, it alludes to the fact that it's not the same for everybody, right? I was talking about Japan, and especially Tokyo, and then New York City. And if you take the New York City subway station and you lay it over top of Japan, Brighton Beach Station is going to be in the middle of Tokyo Bay. So the analogy there is that you can't just take these reference architectures and say, yeah, this is what we're going to do, but it's going to be something that hopefully triggers, uh, the imagination and how you can map certain concepts to the way your organization produces software. So, that's what I've been working on quite a bit lately and talking to a lot of industry leaders about. **28:54 Robert Hurlbut:** We'll put a link in the show notes so folks can find the reference architecture directly without having to search for it. And I can say, as somebody who's taken a pretty close look at it, it's definitely overwhelming at first. And so, I want to warn people, don't be overwhelmed at that first look. As DJ said, there's a number of ways you can deselect some of the layers to get back down to a very basic diagram, and then you can slowly add layers on top of it, which is how I looked at it because I thought, wow, there's like a lot of different things I want to focus on. But I said, let me get back to the simple, and then I'll get more complicated as I come back out. So definitely recommend that folks take a look at this. And as DJ said, like, it's— there are many pieces in this architecture that you can take and incorporate into what you're trying to do from a DevOps perspective. You might not use it all. That's how DJ intends it to be though, right? **29:45 DJ Schleen:** Absolutely. And, you know, the new one that I'm pushing out in the next few weeks is going to be a little bit more— it's a little bit more complicated than the one that's out now, but it's level 5. It's labeled as a level 5, and my intention is to have 4 previous layers or levels to that architecture where you can say, hey, I just want to get started with this stuff. This is just too much. Where do I start? So there'll be a level 1 architecture that's if you want to start automating and considering some of the softer skills that are involved in adopting DevSecOps or DevOps practices, this is where you can start. And then starting to get more layered as the maturity of your organization increases. So all of a sudden that large possibility level 5 diagram becomes a, we can get here. This is potentially the uber utopia of crazy, But you can start seeing how you can start adopting these practices and applying them to your business. **30:47 Robert Hurlbut:** Yeah, I think that's a wise way to approach it too. We were just doing an interview with Maja Keciorowski, who does a lot of speaking on Kubernetes and Docker and how these things come together. And she had a very similar approach, specifically from a Kubernetes perspective, but there are multiple phases of, hey, you shouldn't just expect to dive in and say, I'm going to do all this stuff immediately. There are some foundational things you can start with, and then you slowly build and add those layers on top. **31:14 DJ Schleen:** Exactly. You don't want to boil the ocean right away, especially if you're a startup and you don't have the bandwidth to implement all these techniques and tools, right? **31:23 Robert Hurlbut:** What are some of the coolest tools and techniques and things that you've seen in the past year? I know you're somebody who is— you're seeing a lot of new stuff, probably a lot more than almost anybody else that's listening here. What are some of the things that have really caught your eye in the last year and things our listeners should be looking at? **31:40 DJ Schleen:** Oh, man. The thing that I play with the most lately is K3s, which is Kubernetes with 5 less numbers. It's a product made by Rancher. I put a video out that's called Kubernetes in 10 Seconds, and within 9.5 seconds, I had a Kubernetes cluster set up with this K3s orchestration platform created by Rancher. Now, the cool thing is it's not necessarily for major production type of cluster rollouts. It's great for IoT and small ARM devices. You can run it on a Raspberry Pi and create a cluster of Raspberry Pis if you wanted to, but it's a great way to play around with Kubernetes. So I see it as a launchpad for doing labs and that kind of thing, which I'm gonna be trying to focus on next year. Like if you're gonna have a workshop, wouldn't it be great to create your own cluster with K3s in 10 seconds and then start layering technologies like, open-source software, and build servers, and orchestration, and dealing with security, and focusing on that, but still starting from scratch. So people can see that, yeah, there's a quick way of doing things. There might not be security involved in it, or as much as you want to, but it's a great way to play and kick the tires. It's that whole mentality of the right to tinker that hackers have always wanted and always campaigned for. The other thing is I'm happy to see that a lot of security scanning tools are starting to adopt Go. support Go as a first-class programming language. I've been using it for years now, and it's terse, it's great, multiplatform, compile it for everything. So I've been doing a lot of things with that, and especially compiling it for ARM7 and Raspberry Pis just for fun, right? So I've been playing a lot with a lot of Kubernetes, a lot of security around that. And I think that, you know, and then It's gonna be fun to see where the industry goes, I guess, in the next year, in the next couple of years around Kubernetes and some of these ways that we can deploy containerized applications in a secure fashion. **33:49 Robert Hurlbut:** Yeah, I mean, I think that's, it's likely gonna become part of the infrastructure as we look a few years into the future and the idea of orchestration being something that I have to manage, and you're seeing that in the cloud providers too, like with AWS and Azure, and they've got their own basically front end on Kubernetes so that you don't have to worry about kind of all the pieces behind the scenes. You can just deploy containers according to policies and they'll handle all the rest. **34:16 DJ Schleen:** Yeah, that's an interesting security issue though. Like think about from a risk management perspective, being locked in, vendor lock-in, it's a huge problem, right? From a disaster recovery perspective. So I always love when people host platforms for me, but I always wanna know exactly how can I back out of that platform if I needed to, right? Or, you know, push workloads multiple platforms at the same time. But, you know, the other thing that I think that is really cool that I've seen this year is people thinking that, you know, if you start putting security in front of a developer, you know, there's been this traditional love-hate, I guess, relationship between security organizations and developers, right? Especially from a trust perspective, 'cause, you know, you put a tool into a workflow and then everything gets jammed up and developers are like, oh my gosh, here we go again. You know, Phoenix Project touched on that quite a little bit, quite a lot actually, sorry. But, you know, I've seen things where security becomes invisible. So a developer checks in some code, it gets built, and then all of a sudden you have a pull request saying, you know, this component is vulnerable and this pull request will fix it for you. And if something is right in front of a developer like that and it looks like everything they're used to from a process perspective, then security starts becoming invisible. And that's what I really want to see. And I think that's where the silent sec and DevSecOps starts coming into play, where you can say, hey, we're securing software and there's no impact, uh, there's zero impact from a development perspective to you. And I think we're hopefully going to get there. **35:53 Robert Hurlbut:** Well, DJ, thanks for taking the time here to share your expertise with our listeners. And I'll just tell the audience real quick, hey folks, if you get a chance to catch one of DJ's talks somewhere at one of the various conferences that he travels around and does, definitely check check it out. There will be at least 2 Deadpool references in the talk, maybe more. He might have a hire. And but also a lot of experience that he is very good at communicating and sharing with, uh, with any audience he's in front of. And so, um, definitely recommend getting, uh, to see him in person. And so, DJ, what, what do you want to leave the listeners with here? **36:29 DJ Schleen:** You know, just think outside the box. Uh, you know, look at any, uh, practices around DevOps, DevSecOps, DevSecOps, and understand what you do. Like, value stream map first, see what value you're trying to create, see how you develop software. You know, don't take what other people do and just instantly think that's going to be perfect for you. Look at what you do and adopt all the things that are great that other people are doing, best practices, and make that your own. So that's my advice for everyone who's looking down the path of going to DevOps or DevSecOps. **36:59 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @EdgeRoute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/dj-schleen-devops-the-sec-is-silent/