#IAC

2025-12-17

Tạo module Terraform tùy chỉnh để triển khai EKS: tái sử dụng mã, đơn giản hóa cấu hình & đảm bảo nhất quán across môi trường. Bao gồm VPC, IAM, EKS, Secrets Manager. Module giúp trừu tượng hóa độ phức tạp, giảm lỗi & tăng hiệu quả. Dùng output để truyền giá trị giữa các module, dependencies thông qua tham chiếu outputs.

#Terraform #EKS #Kubernetes #DevOps #IaC #Module #AWS #TerraformModule #InfrastructureAsCode #DevOpsVietnam #KubernetesVietnam #AWSVietnam

dev.to/anil_kumar_noolu/day-

2025-12-17

Salut les experts DevSecOps et Cyber !

🚨 Checkov : Le couteau suisse DevSecOps pour scanner vos IaC avant le déploiement !

On parle souvent de "shift-left" et d'intégrer la sécurité le plus tôt possible, mais concrètement, comment faire ça de manière efficace sans casser le workflow de dev ? Checkov mérite qu'on parle de lui sérieusement pour qui veut sécuriser son infra code dès la conception.

Checkov, ce n'est pas juste un scanner d'IaC, il fait aussi de l'analyse de composition logicielle (SCA) pour les images conteneurs et les packages open source. Ça veut dire qu'on a une vision assez complète, des vulnérabilités aux mauvaises configurations, tout ça avant même que le code ne touche l'environnement.

👉 Il couvre un spectre large de formats :
* Terraform
* CloudFormation
* Kubernetes
* Helm
* Kustomize
* Dockerfile
* Serverless Framework
* Bicep, OpenAPI, ARM Templates... la liste est longue.

Autant dire que peu importe votre stack IaC, il y a de fortes chances que Checkov s'y intègre sans souci. L'idée, c'est de choper les problèmes là où ils coûtent le moins cher à corriger : au moment où le dev écrit son code. Fini les surprises en prod !

Un point crucial qui revient souvent sur la table, c'est la détection des secrets. Checkov est là-dessus aussi, il sait repérer les identifiants et autres secrets qui traînent dans les configurations. On sait tous à quel point un secret exposé peut être dévastateur. C'est une couche de protection essentielle.

Enfin, et c'est souvent ce qui fait la différence avec ce genre d'outils : la personnalisation. On peut adapter les politiques de sécurité à nos besoins spécifiques, et surtout, gérer la suppression des faux positifs. Parce qu'une alerte trop bruyante, c'est une alerte ignorée. Avoir la main là-dessus est vital pour maintenir un outil utilisable et pertinent pour les équipes.

Pour creuser le sujet, le repo github: github.com/bridgecrewio/checkov

Pour une stratégie plus complète sur la supply chain, Checkov doit être complété par d'autres outils de SCA & SBOM: Trivy, Syft, Dependency-Track, etc. pour la visibilité sur les dépendances

Il y a d'autres outils de devSecOps, et Stephane ROBERT les courent dans sa doc:
* SAST: blog.stephane-robert.info/docs
* DAST: blog.stephane-robert.info/docs
* SCA: blog.stephane-robert.info/docs
* Sécurité des containers : blog.stephane-robert.info/docs

Avez-vous déjà testé Checkov dans votre pipeline CI/CD? Partagez votre expérience! Quels sont vos critères pour choisir un outil d'analyse statique comme Checkov ?

#CyberSecurite #DevSecOps #CloudSecurity #Kubernetes #DockerSecurity #SCA #IaC #StaticCodeAnalysis #CloudNativeSecurity

2025-12-17

🚀 DNSimple Terraform Adapter 2.0 is here!
We're thrilled to announce the release of DNSimple Terraform Adapter 2.0, packed with documentation updates, upgraded dependencies and new helpful validations. ⚠️ It requires Terraform 1.12+ for full compatibility.
Check out the latest docs 👉 registry.terraform.io/provider
if you have any questions about DNSimple Terraform Adapter 2.0, get in touch, we'd love to help.
Happy automating!

#Terraform #DNSimple #IaC #DevOps

Puppet Community Team :fedi:puppet@fosstodon.org
2025-12-16

PDK 3.6.0 is Now Available! Validate against Puppet or OpenVox and get loads of security patches in this release!

🔐 CVEs addressed via upgrades to Curl, OpenSSL, net-imap, and removing libxslt and nokogiri

👩‍💻 Other changes:
💠 Thank you to user cocker-cc for adding support to the pdk validate command to accept either openvox or puppet!
💠 License Update to latest Puppet Core license
💠 Dependency changes with Bolt and Rubocop

🧐Check release notes:

help.puppet.com/pdk/current/to

#Puppet #IaC

A Perforce Puppet announcement banner featuring the Perforce Puppet logo and two headings. The main heading reads “PDK 3.6.0” and the subheading reads “New release of the Puppet Development Kit now available!”
2025-12-15

OpenTofu v1.11 is out and now supports ephemeral resources and write-only attributes 🎉

I registered my provider in the OpenTofu registry: search.opentofu.org/provider/x

Enjoy ♥️

#iac #terraform #opentofu #webdav

2025-12-11

Ngày 16/30: Thực hành tạo hàng loạt 26 IAM User từ file CSV bằng Terraform, tự động gán nhóm (Education, Engineers, Managers) dựa trên thuộc tính, bật login console với mật khẩu tạm và yêu cầu đổi. Sử dụng backend S3 lưu state, áp dụng for_each, csvdecode() và conditional filtering. Tiết kiệm thời gian, tăng bảo mật và quản lý quyền truy cập IaC. #AWS #Terraform #IAM #DevOps #Cloud #QuảnTrị #IaC #AWSIAM

dev.to/anil_kumar_noolu/day-16

2025-12-10

Как я подружил WSL, VirtualBox и Ansible, чтобы быстро создавать VM Alpine на Windows

Хочешь быстро поднять несколько лёгких Linux-виртуалок из Windows, да так, чтобы процесс можно было легко повторить? Я, как любитель и самоучка, недавно решил с этим разобраться и всё получилось. Я сделал это так, на Windows через WSL установил Alpine сборки minirootfs, затем при помощи Ansible развернул в Oracle VM VirtualBox 3 виртуальные машины на базе Alpine сборки standard. Никаких облаков, только локальный контроль и минимум зависимостей. Для чего всё это? Сейчас всё чаще говорят о минималистичных системах, об оптимизации железа под конкретные задачи, о работе на граничных устройствах, вот и захотелось попробовать всё своими руками.

habr.com/ru/articles/974226/

#IaC #Ansible #linux #wsl #virtualbox #windows #alpinelinux #minirootfs #vm

2025-12-08

Managing files over #WebDAV with Terraform

broken-by-design.fr/posts/remo

In this blog post, I document the development of a #Terraform provider allowing practitioners to manage files over WebDAV.

This provider uses write-only attributes to handle sensitive content, which increases dramatically the complexity of this provider under the hood. The blog post explains why. There are takeaways and controls to add to your checklist if you are a security auditor.

#devops #devsecops #infosec #security #iac

2025-12-03

Препарируем VK Private Cloud: подробнейшие детали из первых уст

Привет, Хабр! У платформы VK Cloud есть продукт, который позволяет компаниям частично или полностью перенести свою инфраструктуру не в публичное, а в частное облако. То есть хранить все в своем ЦОД и под личным контролем — но пользоваться при этом интерфейсом и инструментами, разработанными VK Tech. В этой статье расскажем, как работает платформа VK Private Cloud и чем на самом деле она отличается от публичного облака. Будет много технических примеров, деталей и конфигураций и минимум общих описаний — только для уточнения нюансов. А также подробности о новой версии 4.3.

habr.com/ru/companies/vktech/a

#vk_cloud #private_cloud #частное_облако #IaC #виртуализация #vk_tech #приватное_облако

Man aging with nogpraxiscode@mastodon.online
2025-12-02

Why is it spelled "Yak Shaving" and not "IaC Shaving"?

#Kubernetes #K8s #YakShaving #IACShaving #IaC #InfrastructureAsCode

2025-11-30

This MCP server enables AI agents and tools to search, discover, and retrieve detailed information about Azure Verified #Bicep Modules (AVM) via the Model Context Protocol (#MCP).

#Azure #IaC #AI # Microsoft

github.com/stefanstranger/avm-

2025-11-28

I also discovered that #debian do not build #libvirt #vagrant box anymore so there is no debian13 available :(
Of course I still can build one by hand, or use #packer or one of those two projects which wraps it: github.com/chef/bento or github.com/boxcutter/kvm (if I absolutely need to use vagrant)

#sysadmin #infrastructureascode #iac #configurationmanagement

2025-11-28

Therefore it's time to evaluate #lima lima-vm.io/ which seems to be a direct #vagrant alternative and I found a #molecule driver github.com/filatof/molecule-li.

#sysadmin #infrastructureascode #iac #configurationmanagement

2025-11-28

What I had forgotten is that I need the integration with #ansible #molecule but there is no driver available. Of course I could test my ansible code in a completely different way but staying with the standard molecule tool is IMO better.
#pulumi is still quite interesting as an alternative to #terraform or #opentofu and their (awful?) HCL language, I'll look at it further later

#sysadmin #infrastructureascode #iac #configurationmanagement

2025-11-28

Billions in profit. Can't calculate a rough estimate or even display a progress bar. Thanks Amazon!

2025-11-26

Explore the entire IT architecture of Infinito.Nexus interactively with the Meta Infinite Graph! 🌐✨
Click the play button to dynamically resolve all Ansible and Docker dependencies — fully visual, fully explorable. 🚀🧩

Try it out: s.infinito.nexus/mig

#InfinitoNexus #MetaInfiniteGraph #Ansible #Docker #DevOps #Automation #OpenSource #InfrastructureAsCode #IaC #Architecture #Sysadmin #Linux #Engineering #Cloud #Developers #TechCommunity

AraInfo | Diario Libre d'Aragónarainfo.org@web.brid.gy
2025-11-24

El CUT trae a Zaragoza el testimonio de la represión contra la Flotilla Global Sumud

fed.brid.gy/r/https://arainfo.

2025-11-24

Managing domains and DNS at scale? Discover how DNSimple uses Terraform to bring the entire domain lifecycle into Infrastructure as Code. Read our latest blog for insights and practical tips, then experience the difference yourself.
👉 blog.dnsimple.com/2025/11/mana
#IaC #Terraform #DevOps

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst