<?xml version="1.0" encoding="UTF-8"?><!-- generator="podbean/5.5" -->
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
     xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"
     xmlns:spotify="http://www.spotify.com/ns/rss"
     xmlns:podcast="https://podcastindex.org/namespace/1.0"
    xmlns:media="http://search.yahoo.com/mrss/">

<channel>
    <title>The DevSecOps Talks Podcast</title>
    <atom:link href="https://feed.podbean.com/devsecops/feed.xml" rel="self" type="application/rss+xml"/>
    <link>https://devsecops.fm</link>
    <description>This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do the right technology bets, help their organizations to deliver value, and last but not the least to have some fun. Tune in for talks about technology, ways of working, and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show notes, and discussion of past and upcoming episodes visit devsecops.fm</description>
    <pubDate>Wed, 11 Mar 2026 20:18:56 -0300</pubDate>
    <generator>https://podbean.com/?v=5.5</generator>
    <language>en</language>
        <copyright>Copyright 2020 All rights reserved.</copyright>
    <category>Technology</category>
    <ttl>1440</ttl>
    <itunes:type>episodic</itunes:type>
          <itunes:summary>This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do right technology bets, help their organizations to deliver value and last but not the least to have some fun. Tune in for talks about technology, ways of working and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show notes, and discussion of past and upcoming episodes visit devsecops.fm</itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
<itunes:category text="Technology" />
    <itunes:owner>
        <itunes:name>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:name>
            </itunes:owner>
    	<itunes:block>No</itunes:block>
	<itunes:explicit>false</itunes:explicit>
    <itunes:image href="https://pbcdn1.podbean.com/imglogo/image-logo/7619951/pod_cover.png" />
    <image>
        <url>https://pbcdn1.podbean.com/imglogo/image-logo/7619951/pod_cover.png</url>
        <title>The DevSecOps Talks Podcast</title>
        <link>https://devsecops.fm</link>
        <width>144</width>
        <height>144</height>
    </image>
    <item>
        <title>#94 - Small Tasks, Big Wins: The AI Dev Loop at System Initiative</title>
        <itunes:title>#94 - Small Tasks, Big Wins: The AI Dev Loop at System Initiative</itunes:title>
        <link>https://devsecops.podbean.com/e/94-small-tasks-big-wins-the-ai-dev-loop-at-system-initiative/</link>
                    <comments>https://devsecops.podbean.com/e/94-small-tasks-big-wins-the-ai-dev-loop-at-system-initiative/#comments</comments>        <pubDate>Wed, 11 Mar 2026 20:18:56 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/84c78a8d-46ee-509a-9ce0-4de00bb8e907</guid>
                                    <description><![CDATA[We bring Paul Stack back to cover the parts we skipped last time. What changed when the models got better and we moved from one-shot Gen AI to agentic, human-in-the-loop work? How do plan mode and tight prompts stop AI from going rogue? Want to hear how six branches, git worktrees, and a TypeScript CLI came together?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[We bring Paul Stack back to cover the parts we skipped last time. What changed when the models got better and we moved from one-shot Gen AI to agentic, human-in-the-loop work? How do plan mode and tight prompts stop AI from going rogue? Want to hear how six branches, git worktrees, and a TypeScript CLI came together?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ykmvmvorwly0fv9v/094-small-tasks-big-wins-the-ai-dev-loop-at-system-initiative.mp3" length="25298251" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We bring Paul Stack back to cover the parts we skipped last time. What changed when the models got better and we moved from one-shot Gen AI to agentic, human-in-the-loop work? How do plan mode and tight prompts stop AI from going rogue? Want to hear how six branches, git worktrees, and a TypeScript CLI came together? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3162</itunes:duration>
                <itunes:episode>94</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#93 - The DevSecOps Perspective: Key Takeaways From Re:Invent 2025</title>
        <itunes:title>#93 - The DevSecOps Perspective: Key Takeaways From Re:Invent 2025</itunes:title>
        <link>https://devsecops.podbean.com/e/93-the-devsecops-perspective-key-takeaways-from-reinvent-2025/</link>
                    <comments>https://devsecops.podbean.com/e/93-the-devsecops-perspective-key-takeaways-from-reinvent-2025/#comments</comments>        <pubDate>Thu, 05 Mar 2026 19:25:08 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/0ae9693a-2a34-5cf4-b6d6-564882c785a0</guid>
                                    <description><![CDATA[Andrey and Mattias share a fast re:Invent roundup focused on AWS security. What do VPC Encryption Controls, post-quantum TLS, and org-level S3 block public access change for you? Which features should you switch on now, like ECR image signing, JWT checks at ALB, and air-gapped AWS Backup? Want simple wins you can use today?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Andrey and Mattias share a fast re:Invent roundup focused on AWS security. What do VPC Encryption Controls, post-quantum TLS, and org-level S3 block public access change for you? Which features should you switch on now, like ECR image signing, JWT checks at ALB, and air-gapped AWS Backup? Want simple wins you can use today?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/k7o6as3hzvgpjcom/093-the-devsecops-perspective-key-takeaways-from-re-invent-2025.mp3" length="13200840" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey and Mattias share a fast re:Invent roundup focused on AWS security. What do VPC Encryption Controls, post-quantum TLS, and org-level S3 block public access change for you? Which features should you switch on now, like ECR image signing, JWT checks at ALB, and air-gapped AWS Backup? Want simple wins you can use today? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1650</itunes:duration>
                <itunes:episode>93</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#92 - From System Initiative to SWAMP: Agent-Native Infra with Paul Stack</title>
        <itunes:title>#92 - From System Initiative to SWAMP: Agent-Native Infra with Paul Stack</itunes:title>
        <link>https://devsecops.podbean.com/e/92-from-system-initiative-to-swamp-agent-native-infra-with-paul-stack/</link>
                    <comments>https://devsecops.podbean.com/e/92-from-system-initiative-to-swamp-agent-native-infra-with-paul-stack/#comments</comments>        <pubDate>Fri, 20 Feb 2026 17:06:17 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/15bf51df-2263-5e6c-ab81-792100f55025</guid>
                                    <description><![CDATA[What can you automate with SWAMP today, from AWS to a Proxmox home lab? How do skills, scripts, and reusable workflows plug into your stack? Could this be your agent’s missing guardrails?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[What can you automate with SWAMP today, from AWS to a Proxmox home lab? How do skills, scripts, and reusable workflows plug into your stack? Could this be your agent’s missing guardrails?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ldzh2tsdodnr08nk/092-from-system-initiative-to-swamp-agent-native-infra-with-paul-stack.mp3" length="23005536" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What can you automate with SWAMP today, from AWS to a Proxmox home lab? How do skills, scripts, and reusable workflows plug into your stack? Could this be your agent’s missing guardrails? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2875</itunes:duration>
                <itunes:episode>92</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#91 - January security roundup: CVSS 10 in n8n, self-hosted AI scares, and nonstop patching</title>
        <itunes:title>#91 - January security roundup: CVSS 10 in n8n, self-hosted AI scares, and nonstop patching</itunes:title>
        <link>https://devsecops.podbean.com/e/91-january-security-roundup-cvss-10-in-n8n-self-hosted-ai-scares-and-nonstop-patching/</link>
                    <comments>https://devsecops.podbean.com/e/91-january-security-roundup-cvss-10-in-n8n-self-hosted-ai-scares-and-nonstop-patching/#comments</comments>        <pubDate>Wed, 04 Feb 2026 18:51:46 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b94c4f22-10e7-5295-9939-395429fe3210</guid>
                                    <description><![CDATA[We kick off with a CVSS 10 in n8n, then look at self-hosted AI assistants with weak defaults and prompt injection risks. Are your API keys, inbox, and drives safe if a bot is open to the web? What should you rotate, patch, and hide behind a VPN?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[We kick off with a CVSS 10 in n8n, then look at self-hosted AI assistants with weak defaults and prompt injection risks. Are your API keys, inbox, and drives safe if a bot is open to the web? What should you rotate, patch, and hide behind a VPN?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/z1k76t3qzt6xs7y7/091-january-security-roundup-cvss-10-in-n8n-self-hosted-ai-scares-and-nonstop-patching.mp3" length="21130153" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We kick off with a CVSS 10 in n8n, then look at self-hosted AI assistants with weak defaults and prompt injection risks. Are your API keys, inbox, and drives safe if a bot is open to the web? What should you rotate, patch, and hide behind a VPN? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2641</itunes:duration>
                <itunes:episode>91</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#90 - K8s vs Managed Services: Cost, Lock-In, and Reality</title>
        <itunes:title>#90 - K8s vs Managed Services: Cost, Lock-In, and Reality</itunes:title>
        <link>https://devsecops.podbean.com/e/90-k8s-vs-managed-services-cost-lock-in-and-reality/</link>
                    <comments>https://devsecops.podbean.com/e/90-k8s-vs-managed-services-cost-lock-in-and-reality/#comments</comments>        <pubDate>Mon, 19 Jan 2026 11:40:00 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/55cdd99e-f57e-5eb6-98d6-2d89274ef3ba</guid>
                                    <description><![CDATA[We get into K8s vs native orchestrators. Do you still need Kubernetes when managed services cover most needs? How do cost, lock-in, and team skills change the choice? Expect a heated debate.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[We get into K8s vs native orchestrators. Do you still need Kubernetes when managed services cover most needs? How do cost, lock-in, and team skills change the choice? Expect a heated debate.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hm1x62yujy3ns5r7/090-k8s-vs-managed-services-cost-lock-in-and-reality.mp3" length="24837869" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We get into K8s vs native orchestrators. Do you still need Kubernetes when managed services cover most needs? How do cost, lock-in, and team skills change the choice? Expect a heated debate. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3104</itunes:duration>
                <itunes:episode>90</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#89 - Agents, Reviews, and Secrets: Real Talk on AI in Dev</title>
        <itunes:title>#89 - Agents, Reviews, and Secrets: Real Talk on AI in Dev</itunes:title>
        <link>https://devsecops.podbean.com/e/89-agents-reviews-and-secrets-real-talk-on-ai-in-dev/</link>
                    <comments>https://devsecops.podbean.com/e/89-agents-reviews-and-secrets-real-talk-on-ai-in-dev/#comments</comments>        <pubDate>Mon, 05 Jan 2026 11:25:00 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b550f032-c9ee-570a-9e13-2ca6e437a3aa</guid>
                                    <description><![CDATA[Are devs ignoring AI, misusing it, or getting real value? What happens when agents touch your env vars, repos, and pipelines? How do you share prompts, set team defaults, and keep trust? Could an AI engineer role lead culture as well as tools?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Are devs ignoring AI, misusing it, or getting real value? What happens when agents touch your env vars, repos, and pipelines? How do you share prompts, set team defaults, and keep trust? Could an AI engineer role lead culture as well as tools?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zvdc20oo4nril2wf/089-agents-reviews-and-secrets-real-talk-on-ai-in-dev.mp3" length="16329892" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Are devs ignoring AI, misusing it, or getting real value? What happens when agents touch your env vars, repos, and pipelines? How do you share prompts, set team defaults, and keep trust? Could an AI engineer role lead culture as well as tools? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2041</itunes:duration>
                <itunes:episode>89</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#88 - EU Compliance 101: DSA, MiCA explained</title>
        <itunes:title>#88 - EU Compliance 101: DSA, MiCA explained</itunes:title>
        <link>https://devsecops.podbean.com/e/88-eu-compliance-101-dsa-mica-explained/</link>
                    <comments>https://devsecops.podbean.com/e/88-eu-compliance-101-dsa-mica-explained/#comments</comments>        <pubDate>Mon, 22 Dec 2025 11:15:00 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/09c98e1b-9247-5e99-a614-ac8dab8b09a0</guid>
                                    <description><![CDATA[Which parts of AI Act, NIS2, DORA, and DSA overlap so you can cover more with less? What basics raise your baseline fast: central logs, backups, risk assessments, and human-in-the-loop governance? Could a simple mailing list make incident comms painless?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Which parts of AI Act, NIS2, DORA, and DSA overlap so you can cover more with less? What basics raise your baseline fast: central logs, backups, risk assessments, and human-in-the-loop governance? Could a simple mailing list make incident comms painless?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/u18qoj48bc1hup70/088-eu-compliance-101-dsa-mica-explained.mp3" length="14855959" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Which parts of AI Act, NIS2, DORA, and DSA overlap so you can cover more with less? What basics raise your baseline fast: central logs, backups, risk assessments, and human-in-the-loop governance? Could a simple mailing list make incident comms painless? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1856</itunes:duration>
                <itunes:episode>88</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#87 - EU Compliance 101: AI Act, DORA, NIS2 explained</title>
        <itunes:title>#87 - EU Compliance 101: AI Act, DORA, NIS2 explained</itunes:title>
        <link>https://devsecops.podbean.com/e/87-eu-compliance-101-ai-act-dora-nis2-explained/</link>
                    <comments>https://devsecops.podbean.com/e/87-eu-compliance-101-ai-act-dora-nis2-explained/#comments</comments>        <pubDate>Mon, 08 Dec 2025 09:31:26 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/79bebac2-cd77-5142-8b49-a86fdfdadc6a</guid>
                                    <description><![CDATA[Want a quick map of EU compliance for engineers? How do you classify AI by risk and tell users when AI is used? When do you send a 24-hour heads-up and a one-month report after an incident? Does NIS2 make your board liable and your logs mandatory?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Want a quick map of EU compliance for engineers? How do you classify AI by risk and tell users when AI is used? When do you send a 24-hour heads-up and a one-month report after an incident? Does NIS2 make your board liable and your logs mandatory?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4o2gsjyxtlftaj80/087-eu-compliance-101-ai-act-dora-nis2-explained.mp3" length="18403178" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Want a quick map of EU compliance for engineers? How do you classify AI by risk and tell users when AI is used? When do you send a 24-hour heads-up and a one-month report after an incident? Does NIS2 make your board liable and your logs mandatory? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2300</itunes:duration>
                <itunes:episode>87</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#86 - MCP plugins: your next security blind spot?</title>
        <itunes:title>#86 - MCP plugins: your next security blind spot?</itunes:title>
        <link>https://devsecops.podbean.com/e/86-mcp-plugins-your-next-security-blind-spot/</link>
                    <comments>https://devsecops.podbean.com/e/86-mcp-plugins-your-next-security-blind-spot/#comments</comments>        <pubDate>Fri, 21 Nov 2025 12:25:23 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d694c130-cf36-5eaa-8ce8-984e73144949</guid>
                                    <description><![CDATA[Is MCP just another server you need to threat model, patch, and monitor? How do you keep users from over-privileged access, block LLM injection, and stop blind spots? We unpack the VentureBeat article https://venturebeat.com/security/mcp-stacks-have-a-92-exploit-probability-how-10-plugins-became-enterprise with real-world tips.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Is MCP just another server you need to threat model, patch, and monitor? How do you keep users from over-privileged access, block LLM injection, and stop blind spots? We unpack the VentureBeat article https://venturebeat.com/security/mcp-stacks-have-a-92-exploit-probability-how-10-plugins-became-enterprise with real-world tips.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yav59mghnfkix817/086-mcp-plugins-your-next-security-blind-spot-.mp3" length="31154486" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Is MCP just another server you need to threat model, patch, and monitor? How do you keep users from over-privileged access, block LLM injection, and stop blind spots? We unpack the VentureBeat article https://venturebeat.com/security/mcp-stacks-have-a-92-exploit-probability-how-10-plugins-became-enterprise with real-world tips. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3894</itunes:duration>
                <itunes:episode>86</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#85 - Is It Time for OpenTofu? Our HashiConf Takeaways</title>
        <itunes:title>#85 - Is It Time for OpenTofu? Our HashiConf Takeaways</itunes:title>
        <link>https://devsecops.podbean.com/e/85-is-it-time-for-opentofu-our-hashiconf-takeaways/</link>
                    <comments>https://devsecops.podbean.com/e/85-is-it-time-for-opentofu-our-hashiconf-takeaways/#comments</comments>        <pubDate>Thu, 23 Oct 2025 10:36:36 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/2e0b2014-ba53-5731-a38f-9c664435e22e</guid>
                                    <description><![CDATA[We break down 10 years of HashiConf and this year's Terraform-heavy news. What do Terraform Actions with Ansible, Stacks GA, and HCP-only features mean for day two work? Is open source getting left behind, and is OpenTofu worth a look?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[We break down 10 years of HashiConf and this year's Terraform-heavy news. What do Terraform Actions with Ansible, Stacks GA, and HCP-only features mean for day two work? Is open source getting left behind, and is OpenTofu worth a look?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dgyvrx9ntrxbmjt4/085-is-it-time-for-opentofu-our-hashiconf-takeaways.mp3" length="14771113" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We break down 10 years of HashiConf and this year's Terraform-heavy news. What do Terraform Actions with Ansible, Stacks GA, and HCP-only features mean for day two work? Is open source getting left behind, and is OpenTofu worth a look? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1846</itunes:duration>
                <itunes:episode>85</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#84 - AI for DevSecOps: Current Wins and Ongoing Gaps</title>
        <itunes:title>#84 - AI for DevSecOps: Current Wins and Ongoing Gaps</itunes:title>
        <link>https://devsecops.podbean.com/e/84-ai-for-devsecops-current-wins-and-ongoing-gaps/</link>
                    <comments>https://devsecops.podbean.com/e/84-ai-for-devsecops-current-wins-and-ongoing-gaps/#comments</comments>        <pubDate>Tue, 30 Sep 2025 07:50:04 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/96c9e32f-406a-5e36-b68c-86754bab4842</guid>
                                    <description><![CDATA[Can AI really help us build more secure software? What’s working in practice right now, and where do the tools still fall short? Mattias and Paulina share their views.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[Can AI really help us build more secure software? What’s working in practice right now, and where do the tools still fall short? Mattias and Paulina share their views.<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jnyp573zrx3edmzv/084-ai-for-devsecops-current-wins-and-ongoing-gaps.mp3" length="16981908" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Can AI really help us build more secure software? What’s working in practice right now, and where do the tools still fall short? Mattias and Paulina share their views. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2122</itunes:duration>
                <itunes:episode>84</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#83 - Opentofu Vs Terraform: Where We Are Now With Cole Bittel</title>
        <itunes:title>#83 - Opentofu Vs Terraform: Where We Are Now With Cole Bittel</itunes:title>
        <link>https://devsecops.podbean.com/e/83-opentofu-vs-terraform-where-we-are-now-with-cole-bittel/</link>
                    <comments>https://devsecops.podbean.com/e/83-opentofu-vs-terraform-where-we-are-now-with-cole-bittel/#comments</comments>        <pubDate>Wed, 17 Sep 2025 10:23:58 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/ea2918d9-6fa1-5032-9990-84a94bca2e90</guid>
                                    <description><![CDATA[<p>It’s been a while since OpenTofu was released to the public, so we wanted to check in on where it stands today. How is the community adopting it? What’s the public sentiment? And how does it differ from Terraform in terms of features?</p>
<p class="p1">This time we’re joined by Cole Bittel, an experienced SRE, platform engineer, and contributor to OpenTofu. He shares his hands-on experience migrating to OpenTofu, and we look into the problems teams face with infrastructure as code and how both Terraform and OpenTofu approach solving them.</p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>It’s been a while since OpenTofu was released to the public, so we wanted to check in on where it stands today. How is the community adopting it? What’s the public sentiment? And how does it differ from Terraform in terms of features?</p>
<p class="p1">This time we’re joined by Cole Bittel, an experienced SRE, platform engineer, and contributor to OpenTofu. He shares his hands-on experience migrating to OpenTofu, and we look into the problems teams face with infrastructure as code and how both Terraform and OpenTofu approach solving them.</p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/1xmrtewpnr0i1zag/083-opentofu-vs-terraform-where-we-are-now-with-cole-bittel.mp3" length="18600455" type="audio/mpeg"/>
        <itunes:summary><![CDATA[It’s been a while since OpenTofu was released to the public, so we wanted to check in on where it stands today. How is the community adopting it? What’s the public sentiment? And how does it differ from Terraform in terms of features?
This time we’re joined by Cole Bittel, an experienced SRE, platform engineer, and contributor to OpenTofu. He shares his hands-on experience migrating to OpenTofu, and we look into the problems teams face with infrastructure as code and how both Terraform and OpenTofu approach solving them.
We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
DevSecOps Talks podcast LinkedIn page
DevSecOps Talks podcast website
DevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2325</itunes:duration>
                <itunes:episode>83</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#82 - Tools, Mcps, And Attack Scenarios</title>
        <itunes:title>#82 - Tools, Mcps, And Attack Scenarios</itunes:title>
        <link>https://devsecops.podbean.com/e/82-tools-mcps-and-attack-scenarios/</link>
                    <comments>https://devsecops.podbean.com/e/82-tools-mcps-and-attack-scenarios/#comments</comments>        <pubDate>Mon, 25 Aug 2025 04:45:39 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/8f4c5a38-714c-5187-997f-14b8757f4679</guid>
                                    <description><![CDATA[This time we talk about how LLMs use tools and what the Model Context Protocol (MCP) brings to the table. What are the risks? How can an attacker exploit MCPs? And why are LLMs a bit like grandpas — helpful but forgetful?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></description>
                                                            <content:encoded><![CDATA[This time we talk about how LLMs use tools and what the Model Context Protocol (MCP) brings to the table. What are the risks? How can an attacker exploit MCPs? And why are LLMs a bit like grandpas — helpful but forgetful?<p> </p>
<p>We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p><a href='https://www.linkedin.com/company/101418030'>DevSecOps Talks podcast LinkedIn page</a></p>
<p><a href='https://devsecops.fm/'>DevSecOps Talks podcast website</a></p>
<p><a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>DevSecOps Talks podcast YouTube channel</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8oei0mov7v07c1gf/082-tools-mcps-and-attack-scenarios.mp3" length="17740504" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time we talk about how LLMs use tools and what the Model Context Protocol (MCP) brings to the table. What are the risks? How can an attacker exploit MCPs? And why are LLMs a bit like grandpas — helpful but forgetful? We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2217</itunes:duration>
                <itunes:episode>82</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#81 - Keeping Secrets Safe</title>
        <itunes:title>#81 - Keeping Secrets Safe</itunes:title>
        <link>https://devsecops.podbean.com/e/81-keeping-secrets-safe/</link>
                    <comments>https://devsecops.podbean.com/e/81-keeping-secrets-safe/#comments</comments>        <pubDate>Mon, 30 Jun 2025 10:45:21 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d63aa0a3-89bf-5356-a275-237eeba9ab75</guid>
                                    <description><![CDATA[<p>Still pasting tokens into Slack? What types of secrets are at risk, and which tools fit which consumer—humans, CI/CD, or workloads? Where do most teams stumble, and how do you fix it fast? Hear our no-nonsense checklist.</p>
<p> </p>
<p>Connect with us on LinkedIn or X (see info at <a href='https://devsecops.fm/about/)'>https://devsecops.fm/about/)</a>. We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p>The video version of this episode is available on our <a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>YouTube channel</a></p>
<p>LinkedIn page of the DevSecOps Talks team is <a href='https://www.linkedin.com/company/101418030'>here</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Still pasting tokens into Slack? What types of secrets are at risk, and which tools fit which consumer—humans, CI/CD, or workloads? Where do most teams stumble, and how do you fix it fast? Hear our no-nonsense checklist.</p>
<p> </p>
<p>Connect with us on LinkedIn or X (see info at <a href='https://devsecops.fm/about/)'>https://devsecops.fm/about/)</a>. We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
<p>The video version of this episode is available on our <a href='https://youtube.com/channel/UCRjpE9xKxZeBkRgYiLErEjw'>YouTube channel</a></p>
<p>LinkedIn page of the DevSecOps Talks team is <a href='https://www.linkedin.com/company/101418030'>here</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zjoj1d2y8csyoxbq/081-keeping-secrets-safe.mp3" length="16122166" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Still pasting tokens into Slack? What types of secrets are at risk, and which tools fit which consumer—humans, CI/CD, or workloads? Where do most teams stumble, and how do you fix it fast? Hear our no-nonsense checklist.
 
Connect with us on LinkedIn or X (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.
The video version of this episode is available on our YouTube channel
LinkedIn page of the DevSecOps Talks team is here]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2015</itunes:duration>
                <itunes:episode>81</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#80 - Understanding Passkeys: Benefits And Limitations</title>
        <itunes:title>#80 - Understanding Passkeys: Benefits And Limitations</itunes:title>
        <link>https://devsecops.podbean.com/e/80-understanding-passkeys-benefits-and-limitations/</link>
                    <comments>https://devsecops.podbean.com/e/80-understanding-passkeys-benefits-and-limitations/#comments</comments>        <pubDate>Wed, 21 May 2025 10:57:04 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/7d5be75a-a742-5bf1-a594-e171cb2b32ab</guid>
                                    <description><![CDATA[<p>Passkeys are gaining attention as a new way to log in without passwords. How do they work, and how do they compare to traditional multi-factor authentication (MFA)? In this episode, we explore the history of passwords, the strengths and weaknesses of common MFA methods, and the potential of passkeys to enhance security. What threats do passkeys mitigate, and what still remain?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Passkeys are gaining attention as a new way to log in without passwords. How do they work, and how do they compare to traditional multi-factor authentication (MFA)? In this episode, we explore the history of passwords, the strengths and weaknesses of common MFA methods, and the potential of passkeys to enhance security. What threats do passkeys mitigate, and what still remain?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kaqvpwzgo1xe9ew2/080-understanding-passkeys-benefits-and-limitations.mp3" length="17725458" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Passkeys are gaining attention as a new way to log in without passwords. How do they work, and how do they compare to traditional multi-factor authentication (MFA)? In this episode, we explore the history of passwords, the strengths and weaknesses of common MFA methods, and the potential of passkeys to enhance security. What threats do passkeys mitigate, and what still remain?
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2215</itunes:duration>
                <itunes:episode>80</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#79 - Going Local: What’S Driving The Move?</title>
        <itunes:title>#79 - Going Local: What’S Driving The Move?</itunes:title>
        <link>https://devsecops.podbean.com/e/79-going-local-what-s-driving-the-move/</link>
                    <comments>https://devsecops.podbean.com/e/79-going-local-what-s-driving-the-move/#comments</comments>        <pubDate>Wed, 23 Apr 2025 17:57:21 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/403f02bd-a3d4-53ba-bfc6-ecf7f9d4fac4</guid>
                                    <description><![CDATA[Andrey, Paulina, and Mattias kick off a miniseries on European infrastructure. We talk about infrastructure providers' options across Europe, ask what really drives the move away from hyperscalers, and wonder whether the trade-offs make sense for most teams.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Andrey, Paulina, and Mattias kick off a miniseries on European infrastructure. We talk about infrastructure providers' options across Europe, ask what really drives the move away from hyperscalers, and wonder whether the trade-offs make sense for most teams.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/3ip5y43gg3fhc0vl/079-going-local-what-s-driving-the-move-.mp3" length="9853614" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey, Paulina, and Mattias kick off a miniseries on European infrastructure. We talk about infrastructure providers' options across Europe, ask what really drives the move away from hyperscalers, and wonder whether the trade-offs make sense for most teams. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1231</itunes:duration>
                <itunes:episode>79</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#78 - Building AI Tools For IaC Compliance</title>
        <itunes:title>#78 - Building AI Tools For IaC Compliance</itunes:title>
        <link>https://devsecops.podbean.com/e/78-building-ai-tools-for-iac-compliance/</link>
                    <comments>https://devsecops.podbean.com/e/78-building-ai-tools-for-iac-compliance/#comments</comments>        <pubDate>Wed, 09 Apr 2025 13:20:00 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/7035adcb-82cc-5821-973b-5a2e78a3c6b8</guid>
                                    <description><![CDATA[<p>In this guest episode, we chat with Davlet Dzhakishev, co-founder of Cloudgeni, who’s working on an AI-powered approach to fixing compliance issues in IaC. What’s the state of tools in this space? Where does his idea fit in? And how should we think about the relationship between compliance and security?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this guest episode, we chat with Davlet Dzhakishev, co-founder of Cloudgeni, who’s working on an AI-powered approach to fixing compliance issues in IaC. What’s the state of tools in this space? Where does his idea fit in? And how should we think about the relationship between compliance and security?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/s1hjel0jnbo94e3p/078-building-ai-tools-for-iac-compliance.mp3" length="19777219" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this guest episode, we chat with Davlet Dzhakishev, co-founder of Cloudgeni, who’s working on an AI-powered approach to fixing compliance issues in IaC. What’s the state of tools in this space? Where does his idea fit in? And how should we think about the relationship between compliance and security?
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2472</itunes:duration>
                <itunes:episode>78</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#77 - Chaos Engineering Explained: Part 2</title>
        <itunes:title>#77 - Chaos Engineering Explained: Part 2</itunes:title>
        <link>https://devsecops.podbean.com/e/77-chaos-engineering-explained-part-2/</link>
                    <comments>https://devsecops.podbean.com/e/77-chaos-engineering-explained-part-2/#comments</comments>        <pubDate>Wed, 26 Mar 2025 13:40:53 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/c8ad6db5-eedb-5bc5-866a-aebd4099391a</guid>
                                    <description><![CDATA[Part two of our chaos engineering series is here! Join Andrey, Mattias, and Paulina as they talk through practical strategies for chaos engineering. Who should do it? How can you start? And what are the essential prerequisites?<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Part two of our chaos engineering series is here! Join Andrey, Mattias, and Paulina as they talk through practical strategies for chaos engineering. Who should do it? How can you start? And what are the essential prerequisites?<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/lxdeij0111rjfj0i/077-chaos-engineering-explained-part-2.mp3" length="16565830" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Part two of our chaos engineering series is here! Join Andrey, Mattias, and Paulina as they talk through practical strategies for chaos engineering. Who should do it? How can you start? And what are the essential prerequisites? Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2070</itunes:duration>
                <itunes:episode>77</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#76 - Chaos Engineering Explained: Part 1</title>
        <itunes:title>#76 - Chaos Engineering Explained: Part 1</itunes:title>
        <link>https://devsecops.podbean.com/e/76-chaos-engineering-explained-part-1/</link>
                    <comments>https://devsecops.podbean.com/e/76-chaos-engineering-explained-part-1/#comments</comments>        <pubDate>Tue, 11 Mar 2025 18:47:57 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b5ba0da0-ee87-50e1-8ab5-c2d244fd9a30</guid>
                                    <description><![CDATA[Chaos engineering—is it really chaos, or something more structured? Andrey, Paulina, and Mattias talk about what chaos engineering means, how it started, and why you might already be using it unintentionally.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Chaos engineering—is it really chaos, or something more structured? Andrey, Paulina, and Mattias talk about what chaos engineering means, how it started, and why you might already be using it unintentionally.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/r28c7fgm3t8du7f4/076-chaos-engineering-explained-part-1.mp3" length="12712873" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Chaos engineering—is it really chaos, or something more structured? Andrey, Paulina, and Mattias talk about what chaos engineering means, how it started, and why you might already be using it unintentionally. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1589</itunes:duration>
                <itunes:episode>76</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#75 - Learning from the Crisis: Post-Incident Actions</title>
        <itunes:title>#75 - Learning from the Crisis: Post-Incident Actions</itunes:title>
        <link>https://devsecops.podbean.com/e/75-learning-from-the-crisis-post-incident-actions/</link>
                    <comments>https://devsecops.podbean.com/e/75-learning-from-the-crisis-post-incident-actions/#comments</comments>        <pubDate>Thu, 27 Feb 2025 17:12:51 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/3268d696-1a13-593b-b154-4407f35d963a</guid>
                                    <description><![CDATA[This is the final episode of our three-part series on incident response. We focus on what happens after the dust settles. How do you learn from what went wrong and avoid repeating it? Tune in to hear our top recommendations.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[This is the final episode of our three-part series on incident response. We focus on what happens after the dust settles. How do you learn from what went wrong and avoid repeating it? Tune in to hear our top recommendations.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6ackl5co320mxri3/075-learning-from-the-crisis-post-incident-actions.mp3" length="11667139" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is the final episode of our three-part series on incident response. We focus on what happens after the dust settles. How do you learn from what went wrong and avoid repeating it? Tune in to hear our top recommendations. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1458</itunes:duration>
                <itunes:episode>75</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#74 - From Preparation To Execution: Handling An Active Incident</title>
        <itunes:title>#74 - From Preparation To Execution: Handling An Active Incident</itunes:title>
        <link>https://devsecops.podbean.com/e/74-from-preparation-to-execution-handling-an-active-incident/</link>
                    <comments>https://devsecops.podbean.com/e/74-from-preparation-to-execution-handling-an-active-incident/#comments</comments>        <pubDate>Mon, 10 Feb 2025 12:59:51 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/dd83e1b8-a5de-5867-93a7-239dc0627472</guid>
                                    <description><![CDATA[What keeps an incident from spiraling out of control? How can you organize your team on the spot? We continue our series on incident response, moving from preparation to real-time actions. Mattias shares key points from his course. Listen to learn how we handle incidents step by step.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[What keeps an incident from spiraling out of control? How can you organize your team on the spot? We continue our series on incident response, moving from preparation to real-time actions. Mattias shares key points from his course. Listen to learn how we handle incidents step by step.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/z80p2jngrrvl5nfk/074-from-preparation-to-execution-handling-an-active-incident.mp3" length="13361546" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What keeps an incident from spiraling out of control? How can you organize your team on the spot? We continue our series on incident response, moving from preparation to real-time actions. Mattias shares key points from his course. Listen to learn how we handle incidents step by step. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1670</itunes:duration>
                <itunes:episode>74</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#73 - Incident Response: Key Preparations You Need</title>
        <itunes:title>#73 - Incident Response: Key Preparations You Need</itunes:title>
        <link>https://devsecops.podbean.com/e/73-incident-response-key-preparations-you-need/</link>
                    <comments>https://devsecops.podbean.com/e/73-incident-response-key-preparations-you-need/#comments</comments>        <pubDate>Wed, 22 Jan 2025 12:04:32 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/7d271473-8b38-5258-9415-ca29dc6bd6fb</guid>
                                    <description><![CDATA[Incident response can be complex, but where do you start? Andrey, Mattias, and Paulina dive into the preparation steps you need to take. Mattias shares his expertise from teaching an incident response course. What’s their top recommendation? Listen and find out!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Incident response can be complex, but where do you start? Andrey, Mattias, and Paulina dive into the preparation steps you need to take. Mattias shares his expertise from teaching an incident response course. What’s their top recommendation? Listen and find out!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jn18n85dz1fnhwbg/073-incident-response-key-preparations-you-need.mp3" length="18425957" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Incident response can be complex, but where do you start? Andrey, Mattias, and Paulina dive into the preparation steps you need to take. Mattias shares his expertise from teaching an incident response course. What’s their top recommendation? Listen and find out! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2303</itunes:duration>
                <itunes:episode>73</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#72 - AWS Resource Control Policies (RCPs)</title>
        <itunes:title>#72 - AWS Resource Control Policies (RCPs)</itunes:title>
        <link>https://devsecops.podbean.com/e/72-devsecops-perspective-on-aws-reinvent-2024-announcements/</link>
                    <comments>https://devsecops.podbean.com/e/72-devsecops-perspective-on-aws-reinvent-2024-announcements/#comments</comments>        <pubDate>Tue, 14 Jan 2025 07:40:42 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/9ea3d7db-26be-5fc0-9e2c-c0d62e1ab42c</guid>
                                    <description><![CDATA[<p>We are looking into recently announced AWS Resource Control Policies. What are they? How are they different from Service Control Policies? What is a Data Perimeter? Tune in to find out!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We are looking into recently announced AWS Resource Control Policies. What are they? How are they different from Service Control Policies? What is a Data Perimeter? Tune in to find out!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fr41oieuvxh3rnum/072-devsecops-perspective-on-aws-re-invent-2024-announcements.mp3" length="10286829" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We are looking into recently announced AWS Resource Control Policies. What are they? How are they different from Service Control Policies? What is a Data Perimeter? Tune in to find out!
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1285</itunes:duration>
                <itunes:episode>72</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#71 - Unpacking The Dora Accelerate State Of Devops Report</title>
        <itunes:title>#71 - Unpacking The Dora Accelerate State Of Devops Report</itunes:title>
        <link>https://devsecops.podbean.com/e/71-unpacking-the-dora-accelerate-state-of-devops-report/</link>
                    <comments>https://devsecops.podbean.com/e/71-unpacking-the-dora-accelerate-state-of-devops-report/#comments</comments>        <pubDate>Fri, 20 Dec 2024 09:58:05 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/566c8560-16db-5dea-a6d4-4cb665118e99</guid>
                                    <description><![CDATA[In this episode, Andrey, Mattias, and Paulina break down the new DORA Accelerate State of DevOps report. What’s changed since the last report? What do these insights mean for your team? Tune in for our insightful conversation!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[In this episode, Andrey, Mattias, and Paulina break down the new DORA Accelerate State of DevOps report. What’s changed since the last report? What do these insights mean for your team? Tune in for our insightful conversation!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ueek3yrfsmfv7n1a/071-unpacking-the-dora-accelerate-state-of-devops-report.mp3" length="19597497" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, Andrey, Mattias, and Paulina break down the new DORA Accelerate State of DevOps report. What’s changed since the last report? What do these insights mean for your team? Tune in for our insightful conversation! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2449</itunes:duration>
                <itunes:episode>71</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#70 - System Initiative Goes Ga</title>
        <itunes:title>#70 - System Initiative Goes Ga</itunes:title>
        <link>https://devsecops.podbean.com/e/70-system-initiative-goes-ga/</link>
                    <comments>https://devsecops.podbean.com/e/70-system-initiative-goes-ga/#comments</comments>        <pubDate>Thu, 28 Nov 2024 17:35:26 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/35d8cff2-24fe-5033-b743-bce33d25723e</guid>
                                    <description><![CDATA[Andrey, Mattias, and Paulina are joined by Paul Stack, an IaC tools developer and a frequent guest on the show. He’s back to discuss the general availability of System Initiative and share what has changed since his last visit when they talked about the early beta of the tool. Will this be a revolution or evolution in Infrastructure as Code tooling? Do we really need collaborative infrastructure management tools? Tune in to find out! <p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Andrey, Mattias, and Paulina are joined by Paul Stack, an IaC tools developer and a frequent guest on the show. He’s back to discuss the general availability of System Initiative and share what has changed since his last visit when they talked about the early beta of the tool. Will this be a revolution or evolution in Infrastructure as Code tooling? Do we really need collaborative infrastructure management tools? Tune in to find out! <p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/xr216phfsdubvnxe/070-system-initiative-goes-ga.mp3" length="19411923" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey, Mattias, and Paulina are joined by Paul Stack, an IaC tools developer and a frequent guest on the show. He’s back to discuss the general availability of System Initiative and share what has changed since his last visit when they talked about the early beta of the tool. Will this be a revolution or evolution in Infrastructure as Code tooling? Do we really need collaborative infrastructure management tools? Tune in to find out!  Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2426</itunes:duration>
                <itunes:episode>70</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#69 - Who Is Paulina?</title>
        <itunes:title>#69 - Who Is Paulina?</itunes:title>
        <link>https://devsecops.podbean.com/e/69-who-is-paulina/</link>
                    <comments>https://devsecops.podbean.com/e/69-who-is-paulina/#comments</comments>        <pubDate>Fri, 08 Nov 2024 15:41:09 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/8f81703d-e115-538e-9061-c701a66a48c5</guid>
                                    <description><![CDATA[Join Andrey and Mattias as they sit down with Paulina Dubas, an independent DevOps consultant and public speaker. Who is Paulina, and what experiences does she bring to the table? What topics particularly resonate with her? Tune in to learn more about Paulina since we have a feeling that she is here to stay<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Join Andrey and Mattias as they sit down with Paulina Dubas, an independent DevOps consultant and public speaker. Who is Paulina, and what experiences does she bring to the table? What topics particularly resonate with her? Tune in to learn more about Paulina since we have a feeling that she is here to stay<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wfvaj59abtay18g7/069-who-is-paulina-.mp3" length="20288592" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Join Andrey and Mattias as they sit down with Paulina Dubas, an independent DevOps consultant and public speaker. Who is Paulina, and what experiences does she bring to the table? What topics particularly resonate with her? Tune in to learn more about Paulina since we have a feeling that she is here to stay Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2536</itunes:duration>
                <itunes:episode>69</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#68 - Julien’s Last Episode?</title>
        <itunes:title>#68 - Julien’s Last Episode?</itunes:title>
        <link>https://devsecops.podbean.com/e/68-julien-s-last-episode/</link>
                    <comments>https://devsecops.podbean.com/e/68-julien-s-last-episode/#comments</comments>        <pubDate>Thu, 17 Oct 2024 17:25:55 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/8a962f52-0c15-5a50-8ebd-f799c8bdc2ab</guid>
                                    <description><![CDATA[Julien shares big news with co-hosts Mattias and Andrey. What led to his decision to step down? And what does the future hold for him? Tune in for the off-boarding interview as we look back at the past four years and 60+ episodes we did together!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Julien shares big news with co-hosts Mattias and Andrey. What led to his decision to step down? And what does the future hold for him? Tune in for the off-boarding interview as we look back at the past four years and 60+ episodes we did together!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/z4j6fjig1ihssw3i/068-julien-s-last-episode-.mp3" length="13091544" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Julien shares big news with co-hosts Mattias and Andrey. What led to his decision to step down? And what does the future hold for him? Tune in for the off-boarding interview as we look back at the past four years and 60+ episodes we did together! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1636</itunes:duration>
                <itunes:episode>68</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#67 - Building MVP On AWS</title>
        <itunes:title>#67 - Building MVP On AWS</itunes:title>
        <link>https://devsecops.podbean.com/e/67-building-mvp-on-aws/</link>
                    <comments>https://devsecops.podbean.com/e/67-building-mvp-on-aws/#comments</comments>        <pubDate>Thu, 03 Oct 2024 17:20:50 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/285973b1-afa4-53be-b0c8-dd763012f7a9</guid>
                                    <description><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they delve into building Minimum Viable Products (MVPs) and selecting the best solutions for them. Andrey goes first and, as an AWS consultant, kicks off the discussion by outlining his preferred AWS services for MVP development.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they delve into building Minimum Viable Products (MVPs) and selecting the best solutions for them. Andrey goes first and, as an AWS consultant, kicks off the discussion by outlining his preferred AWS services for MVP development.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/0mqmnxgw2n7jzk3g/067-building-mvp-on-aws.mp3" length="14345004" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they delve into building Minimum Viable Products (MVPs) and selecting the best solutions for them. Andrey goes first and, as an AWS consultant, kicks off the discussion by outlining his preferred AWS services for MVP development. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1793</itunes:duration>
                <itunes:episode>67</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#66 - Multi-Account Strategy And Landing Zones:  Account Segmentation Approaches For Security And Efficiency On AWS</title>
        <itunes:title>#66 - Multi-Account Strategy And Landing Zones:  Account Segmentation Approaches For Security And Efficiency On AWS</itunes:title>
        <link>https://devsecops.podbean.com/e/66-multi-account-strategy-and-landing-zones-account-segmentation-approaches-for-security-and-efficiency-on-aws/</link>
                    <comments>https://devsecops.podbean.com/e/66-multi-account-strategy-and-landing-zones-account-segmentation-approaches-for-security-and-efficiency-on-aws/#comments</comments>        <pubDate>Mon, 27 May 2024 08:53:17 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/2bb950d6-e110-5118-a10d-56897b414162</guid>
                                    <description><![CDATA[In this episode of DevSecOps Talks, co-hosts Andrey, Julien, and Mattias are joined by AWS Consultant Fernando Gonçalves to explore the complexities of AWS organization and account segmentation. Get insights into the debate over development, stage, and production accounts versus micro-segmentation. Don’t miss Julien's take on why he believes staging is a waste of time and money, as well as Fernando’s explanation of what the AWS Landing Zone is. Learn about the tools provided by AWS for multi-account management and the pros and cons of various account segmentation approaches.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[In this episode of DevSecOps Talks, co-hosts Andrey, Julien, and Mattias are joined by AWS Consultant Fernando Gonçalves to explore the complexities of AWS organization and account segmentation. Get insights into the debate over development, stage, and production accounts versus micro-segmentation. Don’t miss Julien's take on why he believes staging is a waste of time and money, as well as Fernando’s explanation of what the AWS Landing Zone is. Learn about the tools provided by AWS for multi-account management and the pros and cons of various account segmentation approaches.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/aufqu2jrgcdnyq4a/066-multi-account-strategy-and-landing-zones_--account-segmentation-approaches-for-security-and-efficiency-on-aws.mp3" length="27957934" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of DevSecOps Talks, co-hosts Andrey, Julien, and Mattias are joined by AWS Consultant Fernando Gonçalves to explore the complexities of AWS organization and account segmentation. Get insights into the debate over development, stage, and production accounts versus micro-segmentation. Don’t miss Julien's take on why he believes staging is a waste of time and money, as well as Fernando’s explanation of what the AWS Landing Zone is. Learn about the tools provided by AWS for multi-account management and the pros and cons of various account segmentation approaches. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3494</itunes:duration>
                <itunes:episode>66</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>#65 - Understanding Nats: An Explainer Of Its Features And Capabilities</title>
        <itunes:title>#65 - Understanding Nats: An Explainer Of Its Features And Capabilities</itunes:title>
        <link>https://devsecops.podbean.com/e/65-understanding-nats-an-explainer-of-its-features-and-capabilities/</link>
                    <comments>https://devsecops.podbean.com/e/65-understanding-nats-an-explainer-of-its-features-and-capabilities/#comments</comments>        <pubDate>Tue, 07 May 2024 17:04:29 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/a0bd1ba2-a598-5e8f-8ebd-28603b7f78f9</guid>
                                    <description><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they discuss Nats.io, a messaging system popular among people building on top of Kubernetes. Julien explains how Nats is different from Kafka and shares his personal experience with the product. The hosts discuss the various use cases of Nats and explore its features and capabilities. Tune in to find out if Nats is the right messaging system for you!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they discuss Nats.io, a messaging system popular among people building on top of Kubernetes. Julien explains how Nats is different from Kafka and shares his personal experience with the product. The hosts discuss the various use cases of Nats and explore its features and capabilities. Tune in to find out if Nats is the right messaging system for you!<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dfyivyq0yn781d2d/065-understanding-nats_-an-explainer-of-its-features-and-capabilities.mp3" length="17908733" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Join Andrey, Julien, and Mattias in this episode of DevSecOps Talks as they discuss Nats.io, a messaging system popular among people building on top of Kubernetes. Julien explains how Nats is different from Kafka and shares his personal experience with the product. The hosts discuss the various use cases of Nats and explore its features and capabilities. Tune in to find out if Nats is the right messaging system for you! Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2238</itunes:duration>
                <itunes:episode>65</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #64 - From Terraform To Opentofu: Story From The Trenches</title>
        <itunes:title>DEVSECOPS Talks #64 - From Terraform To Opentofu: Story From The Trenches</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-64-from-terraform-to-opentofu-story-from-the-trenches/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-64-from-terraform-to-opentofu-story-from-the-trenches/#comments</comments>        <pubDate>Thu, 11 Apr 2024 16:45:08 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/8b5e88ad-6292-53ff-8bc8-857b80e2b8b9</guid>
                                    <description><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias are joined by Timur Bublik, Platform Engineering Lead at TIER Mobility. As always, it's practitioners for practitioners as they discuss the migration from Terraform to OpenTofu, TACOS tools, and how SpaceLift is used in Timur's organization. Listen in as they dive into their three favorite features of SpaceLift and how TACOS tools like SpaceLift fit into the classic CI/CD pipeline.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias are joined by Timur Bublik, Platform Engineering Lead at TIER Mobility. As always, it's practitioners for practitioners as they discuss the migration from Terraform to OpenTofu, TACOS tools, and how SpaceLift is used in Timur's organization. Listen in as they dive into their three favorite features of SpaceLift and how TACOS tools like SpaceLift fit into the classic CI/CD pipeline.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qoft111juqlx73vp/064-from-terraform-to-opentofu_-story-from-the-trenches.mp3" length="19047671" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias are joined by Timur Bublik, Platform Engineering Lead at TIER Mobility. As always, it's practitioners for practitioners as they discuss the migration from Terraform to OpenTofu, TACOS tools, and how SpaceLift is used in Timur's organization. Listen in as they dive into their three favorite features of SpaceLift and how TACOS tools like SpaceLift fit into the classic CI/CD pipeline. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2380</itunes:duration>
                <itunes:episode>64</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #63 - Yet Another AI Episode</title>
        <itunes:title>DEVSECOPS Talks #63 - Yet Another AI Episode</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-63-yet-another-ai-episode/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-63-yet-another-ai-episode/#comments</comments>        <pubDate>Thu, 14 Mar 2024 18:28:59 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/11cb27b3-f361-5834-bff7-f37208e508eb</guid>
                                    <description><![CDATA[Julien has returned with some exciting AI news. A startup has made the bold claim that they are capable of building AI software engineer. Andrey shares details about another startup that generates infrastructure based on application source code. He also mentions his upcoming talk on the use of LLM-based tools. We also discuss how individuals can stay ahead of the curve and be prepared for changes in their work life.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[Julien has returned with some exciting AI news. A startup has made the bold claim that they are capable of building AI software engineer. Andrey shares details about another startup that generates infrastructure based on application source code. He also mentions his upcoming talk on the use of LLM-based tools. We also discuss how individuals can stay ahead of the curve and be prepared for changes in their work life.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/tu6bos/063-yet-another-ai-episode.mp3" length="16609507" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Julien has returned with some exciting AI news. A startup has made the bold claim that they are capable of building AI software engineer. Andrey shares details about another startup that generates infrastructure based on application source code. He also mentions his upcoming talk on the use of LLM-based tools. We also discuss how individuals can stay ahead of the curve and be prepared for changes in their work life. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2076</itunes:duration>
                <itunes:episode>63</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #62 - The DevSecOps Perspective: Key Takeaways From Re:Invent 2023</title>
        <itunes:title>DEVSECOPS Talks #62 - The DevSecOps Perspective: Key Takeaways From Re:Invent 2023</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-62-the-devsecops-perspective-key-takeaways-from-reinvent-2023/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-62-the-devsecops-perspective-key-takeaways-from-reinvent-2023/#comments</comments>        <pubDate>Sat, 02 Mar 2024 18:00:41 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/54187f2a-3df6-5b83-b705-1d436ddb12f2</guid>
                                    <description><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias discuss the latest announcements from re:Invent 2023 that are most relevant to DevSecOps practitioners. Which announcements are worth paying attention to? What are the implications for the DevSecOps community? Join us as we dive into the latest developments from AWS.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias discuss the latest announcements from re:Invent 2023 that are most relevant to DevSecOps practitioners. Which announcements are worth paying attention to? What are the implications for the DevSecOps community? Join us as we dive into the latest developments from AWS.<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cvyuq3my9zqpxjk2/062-the-devsecops-perspective_-key-takeaways-from-re_invent-2023.mp3" length="16016840" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of DevSecOps Talks, Andrey and Mattias discuss the latest announcements from re:Invent 2023 that are most relevant to DevSecOps practitioners. Which announcements are worth paying attention to? What are the implications for the DevSecOps community? Join us as we dive into the latest developments from AWS. Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2002</itunes:duration>
                <itunes:episode>62</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #61 - GitHub Actions And Evolution Of CI/CD Tools</title>
        <itunes:title>DEVSECOPS Talks #61 - GitHub Actions And Evolution Of CI/CD Tools</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-61-github-actions-and-evolution-of-cicd-tools/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-61-github-actions-and-evolution-of-cicd-tools/#comments</comments>        <pubDate>Thu, 08 Feb 2024 17:44:54 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/0143ae2e-de5c-3a1c-9871-98a3c9d7feb5</guid>
                                    <description><![CDATA[<p>Andrey has been exploring GitHub Actions and has some insights to share. How have CI/CD solutions transformed over time, and what innovations do GitHub Actions bring to the table? Julien drops a few tools that could be useful for GitHub Actions users. </p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Andrey has been exploring GitHub Actions and has some insights to share. How have CI/CD solutions transformed over time, and what innovations do GitHub Actions bring to the table? Julien drops a few tools that could be useful for GitHub Actions users. </p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yjk888/episode61.mp3" length="22248821" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey has been exploring GitHub Actions and has some insights to share. How have CI/CD solutions transformed over time, and what innovations do GitHub Actions bring to the table? Julien drops a few tools that could be useful for GitHub Actions users. 
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2781</itunes:duration>
                <itunes:episode>61</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #60 - ChatGPT Anniversary: Where Are We With AI In Our Everyday Work</title>
        <itunes:title>DEVSECOPS Talks #60 - ChatGPT Anniversary: Where Are We With AI In Our Everyday Work</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-60-chatgpt-anniversary-where-are-we-with-ai-in-our-every-day-work/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-60-chatgpt-anniversary-where-are-we-with-ai-in-our-every-day-work/#comments</comments>        <pubDate>Thu, 25 Jan 2024 17:36:32 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b5e38fc0-851a-3389-b800-a0e13bbc0ddc</guid>
                                    <description><![CDATA[<p>Welcome to the first DevSecOps Talks episode of the new year! It's been a whole year since ChatGPT hit the scene – but how has AI adoption shaped our world since then? Join Julien, Mattias, and Andrey as they dive into the impact of AI on their workflows. How have their daily tech tools and practices evolved with AI integration? Plus, Julien gives us an insider's look at running models locally. Are these AI tools enhancing our efficiency? Tune in to find out how these advancements are reshaping the landscape of DevSecOps.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Welcome to the first DevSecOps Talks episode of the new year! It's been a whole year since ChatGPT hit the scene – but how has AI adoption shaped our world since then? Join Julien, Mattias, and Andrey as they dive into the impact of AI on their workflows. How have their daily tech tools and practices evolved with AI integration? Plus, Julien gives us an insider's look at running models locally. Are these AI tools enhancing our efficiency? Tune in to find out how these advancements are reshaping the landscape of DevSecOps.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ypxy8z/episode60.mp3" length="19982019" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Welcome to the first DevSecOps Talks episode of the new year! It's been a whole year since ChatGPT hit the scene – but how has AI adoption shaped our world since then? Join Julien, Mattias, and Andrey as they dive into the impact of AI on their workflows. How have their daily tech tools and practices evolved with AI integration? Plus, Julien gives us an insider's look at running models locally. Are these AI tools enhancing our efficiency? Tune in to find out how these advancements are reshaping the landscape of DevSecOps.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2497</itunes:duration>
                <itunes:episode>60</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #59 - Migration Off The Cloud: To Leave or Not to Leave?</title>
        <itunes:title>DEVSECOPS Talks #59 - Migration Off The Cloud: To Leave or Not to Leave?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-59-migration-off-the-cloud-to-leave-or-not-to-leave/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-59-migration-off-the-cloud-to-leave-or-not-to-leave/#comments</comments>        <pubDate>Tue, 16 Jan 2024 05:02:33 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/3924079a-c3c9-3881-8a24-2418be2fddd8</guid>
                                    <description><![CDATA[<p>Is the grass greener outside the cloud? This episode dives into the trend of companies (notably Hey and Dropbox) migrating away from cloud services. Why are they leaving, and who would benefit from such a move? We also scrutinize the common belief that public clouds are overly expensive. Join us as we dissect various cloud cost optimization tools and techniques.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Is the grass greener outside the cloud? This episode dives into the trend of companies (notably Hey and Dropbox) migrating away from cloud services. Why are they leaving, and who would benefit from such a move? We also scrutinize the common belief that public clouds are overly expensive. Join us as we dissect various cloud cost optimization tools and techniques.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6huezm/episode59-move-off-the-cloud-and-cost-optimization.mp3" length="14253889" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Is the grass greener outside the cloud? This episode dives into the trend of companies (notably Hey and Dropbox) migrating away from cloud services. Why are they leaving, and who would benefit from such a move? We also scrutinize the common belief that public clouds are overly expensive. Join us as we dissect various cloud cost optimization tools and techniques.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1781</itunes:duration>
                <itunes:episode>59</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #58 - AWS CDK with Igor Soroka</title>
        <itunes:title>DEVSECOPS Talks #58 - AWS CDK with Igor Soroka</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-58-aws-cdk-with-igor-soroka/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-58-aws-cdk-with-igor-soroka/#comments</comments>        <pubDate>Thu, 28 Dec 2023 09:38:55 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/86ac7527-d059-3fe1-81eb-1e407930f996</guid>
                                    <description><![CDATA[<p>You know our fondness for Terraform, but we are also open to exploring other tools. This episode is no different. We are joined by Igor Soroka, an expert in AWS serverless technology whose tool of choice is AWS CDK, but at the same time, he is no stranger to Terraform. We ask him practical questions about the tool and get answers based on his experience applying it to real-life projects. If you have been curious about CDK, how it functions, and if it's appropriate for you, then tune in to learn more.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>You know our fondness for Terraform, but we are also open to exploring other tools. This episode is no different. We are joined by Igor Soroka, an expert in AWS serverless technology whose tool of choice is AWS CDK, but at the same time, he is no stranger to Terraform. We ask him practical questions about the tool and get answers based on his experience applying it to real-life projects. If you have been curious about CDK, how it functions, and if it's appropriate for you, then tune in to learn more.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wc577z/episode58.mp3" length="19231155" type="audio/mpeg"/>
        <itunes:summary><![CDATA[You know our fondness for Terraform, but we are also open to exploring other tools. This episode is no different. We are joined by Igor Soroka, an expert in AWS serverless technology whose tool of choice is AWS CDK, but at the same time, he is no stranger to Terraform. We ask him practical questions about the tool and get answers based on his experience applying it to real-life projects. If you have been curious about CDK, how it functions, and if it's appropriate for you, then tune in to learn more.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2403</itunes:duration>
                <itunes:episode>58</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #57 - Terraform Best Practices with Ben Goodman</title>
        <itunes:title>DEVSECOPS Talks #57 - Terraform Best Practices with Ben Goodman</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-57-terraform-best-practices-with-ben-goodman/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-57-terraform-best-practices-with-ben-goodman/#comments</comments>        <pubDate>Thu, 23 Nov 2023 07:44:29 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/2fe896be-d74b-3a35-b92a-181f3cb2114f</guid>
                                    <description><![CDATA[<p>In this episode, Mattias is joined by Ben Goodman, the founder of dragondrop.cloud, a platform that offers Terraform Best Practices as a Pull Request. They discuss the best workflows for Terraform, open-source tools that can be used in conjunction with Terraform, the most effective best practices, and common pitfalls to avoid when implementing infrastructure as code using Terraform.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, Mattias is joined by Ben Goodman, the founder of dragondrop.cloud, a platform that offers Terraform Best Practices as a Pull Request. They discuss the best workflows for Terraform, open-source tools that can be used in conjunction with Terraform, the most effective best practices, and common pitfalls to avoid when implementing infrastructure as code using Terraform.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/as4i2r/episode57.mp3" length="17586486" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, Mattias is joined by Ben Goodman, the founder of dragondrop.cloud, a platform that offers Terraform Best Practices as a Pull Request. They discuss the best workflows for Terraform, open-source tools that can be used in conjunction with Terraform, the most effective best practices, and common pitfalls to avoid when implementing infrastructure as code using Terraform.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2198</itunes:duration>
                <itunes:episode>57</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #56 - Backstage and Internal Development Platforms (IDP)</title>
        <itunes:title>DEVSECOPS Talks #56 - Backstage and Internal Development Platforms (IDP)</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-56-backstage-and-internal-development-platforms-idp/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-56-backstage-and-internal-development-platforms-idp/#comments</comments>        <pubDate>Wed, 08 Nov 2023 07:44:20 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/dc2830f2-b224-31e8-aa37-32936086dd80</guid>
                                    <description><![CDATA[<p>In this episode of DevSecOps Talks, join Andrey, Julien, and Mattias as they dive into the world of Backstage, the notable internal development platform. Mattias is keen to peel back the layers and understand what makes people think of Backstage as a must-have in modern DevOps toolchains. Andrey highlights the platform's core feature: a comprehensive registry that keeps track of every software service running within a company. Could this signify a revival of IT change management, but with a twist? We've moved on from the days of cumbersome ticketing systems to streamlined internal development platforms. The team also ponders the future role of infrastructure engineers as they navigate the rising tides of AI—will AI become the new face behind these developer portals? Tune in to find out!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode of DevSecOps Talks, join Andrey, Julien, and Mattias as they dive into the world of Backstage, the notable internal development platform. Mattias is keen to peel back the layers and understand what makes people think of Backstage as a must-have in modern DevOps toolchains. Andrey highlights the platform's core feature: a comprehensive registry that keeps track of every software service running within a company. Could this signify a revival of IT change management, but with a twist? We've moved on from the days of cumbersome ticketing systems to streamlined internal development platforms. The team also ponders the future role of infrastructure engineers as they navigate the rising tides of AI—will AI become the new face behind these developer portals? Tune in to find out!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/h2iqis/episode56-backstage.mp3" length="17299557" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of DevSecOps Talks, join Andrey, Julien, and Mattias as they dive into the world of Backstage, the notable internal development platform. Mattias is keen to peel back the layers and understand what makes people think of Backstage as a must-have in modern DevOps toolchains. Andrey highlights the platform's core feature: a comprehensive registry that keeps track of every software service running within a company. Could this signify a revival of IT change management, but with a twist? We've moved on from the days of cumbersome ticketing systems to streamlined internal development platforms. The team also ponders the future role of infrastructure engineers as they navigate the rising tides of AI—will AI become the new face behind these developer portals? Tune in to find out!
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2162</itunes:duration>
                <itunes:episode>56</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #55 - Unpacking System Initiative with Paul Stack</title>
        <itunes:title>DEVSECOPS Talks #55 - Unpacking System Initiative with Paul Stack</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-55-unpacking-system-initiative-with-paul-stack/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-55-unpacking-system-initiative-with-paul-stack/#comments</comments>        <pubDate>Tue, 17 Oct 2023 05:58:04 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/a27da8b6-6ab8-3f69-b156-8bcb60e82788</guid>
                                    <description><![CDATA[<p class="p1">Our dialogue with Paul Stack resumes on DevSecOps Talks, almost two years after our initial podcast about his work on Pulumi (episode 25). As a warm-up, we talk about what prompted his move from Pulumi and his take on Open Terraform drama. The main topic of the episode is Paul's current focus, System Initiative; we probe into its purpose, the progress so far, and the promise it holds for redefining how we think of doing Infrastructure as Code and DevSecOps workflows in general.</p>
<p class="p1"> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p class="p1">Our dialogue with Paul Stack resumes on DevSecOps Talks, almost two years after our initial podcast about his work on Pulumi (episode 25). As a warm-up, we talk about what prompted his move from Pulumi and his take on Open Terraform drama. The main topic of the episode is Paul's current focus, System Initiative; we probe into its purpose, the progress so far, and the promise it holds for redefining how we think of doing Infrastructure as Code and DevSecOps workflows in general.</p>
<p class="p1"> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zgnj3m/episode55.mp3" length="27738297" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Our dialogue with Paul Stack resumes on DevSecOps Talks, almost two years after our initial podcast about his work on Pulumi (episode 25). As a warm-up, we talk about what prompted his move from Pulumi and his take on Open Terraform drama. The main topic of the episode is Paul's current focus, System Initiative; we probe into its purpose, the progress so far, and the promise it holds for redefining how we think of doing Infrastructure as Code and DevSecOps workflows in general.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3467</itunes:duration>
                <itunes:episode>55</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #54 - HashiCorp’s BSL Move and OpenTF: What DevSecOps Practitioners Need to Know</title>
        <itunes:title>DEVSECOPS Talks #54 - HashiCorp’s BSL Move and OpenTF: What DevSecOps Practitioners Need to Know</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-54-hashicorp-s-bsl-move-and-opentf-what-devsecops-practitioners-need-to-know/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-54-hashicorp-s-bsl-move-and-opentf-what-devsecops-practitioners-need-to-know/#comments</comments>        <pubDate>Thu, 14 Sep 2023 09:18:55 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d26f6e37-25df-300a-882a-c35059807e1a</guid>
                                    <description><![CDATA[<p>In this episode of DevSecOps Talks, we dive deep into HashiCorp's recent shift to the Business Source License and its implications. Join Andrey, Julien, and Mattias as they unpack what this means for practitioners and explore the timeline of OpenTF initiative. Stay informed about what comes ahead with our latest discussion. Tune in!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode of DevSecOps Talks, we dive deep into HashiCorp's recent shift to the Business Source License and its implications. Join Andrey, Julien, and Mattias as they unpack what this means for practitioners and explore the timeline of OpenTF initiative. Stay informed about what comes ahead with our latest discussion. Tune in!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2ecpi9/matte-julien-andrey_full_lengthsep13.mp3" length="16128853" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode of DevSecOps Talks, we dive deep into HashiCorp's recent shift to the Business Source License and its implications. Join Andrey, Julien, and Mattias as they unpack what this means for practitioners and explore the timeline of OpenTF initiative. Stay informed about what comes ahead with our latest discussion. Tune in!
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2016</itunes:duration>
                <itunes:episode>54</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #53 - Open Software Supply Chain Attack Reference Framework with Neatsun</title>
        <itunes:title>DEVSECOPS Talks #53 - Open Software Supply Chain Attack Reference Framework with Neatsun</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-53-open-software-supply-chain-attack-reference-framework-with-neatsun/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-53-open-software-supply-chain-attack-reference-framework-with-neatsun/#comments</comments>        <pubDate>Tue, 01 Aug 2023 10:47:07 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/26d39a06-cadb-3489-9162-c27d9119c346</guid>
                                    <description><![CDATA[<p>We had the opportunity to talk with Neatsun Ziv, one of the founders of Ox Security, about the Open Source Software Supply Chain Attack Reference Framework (<a href='https://pbom.dev/'>https://pbom.dev</a>). We delved deeper into possible attack vectors and explored ways to mitigate some of them. During our discussions, we also had a couple of unusual takes on supply chain security. If you are looking to understand the Open Source Software Supply Chain, then this episode is perfect for you.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We had the opportunity to talk with Neatsun Ziv, one of the founders of Ox Security, about the Open Source Software Supply Chain Attack Reference Framework (<a href='https://pbom.dev/'>https://pbom.dev</a>). We delved deeper into possible attack vectors and explored ways to mitigate some of them. During our discussions, we also had a couple of unusual takes on supply chain security. If you are looking to understand the Open Source Software Supply Chain, then this episode is perfect for you.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cv8js5/decsecops_Supply_Chain_Part_2_0-proccssed6luj1.mp3" length="41479401" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We had the opportunity to talk with Neatsun Ziv, one of the founders of Ox Security, about the Open Source Software Supply Chain Attack Reference Framework (https://pbom.dev). We delved deeper into possible attack vectors and explored ways to mitigate some of them. During our discussions, we also had a couple of unusual takes on supply chain security. If you are looking to understand the Open Source Software Supply Chain, then this episode is perfect for you.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2962</itunes:duration>
                <itunes:episode>53</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #52 - Lingon a.k.a Juliens and Jacobs open source project</title>
        <itunes:title>DEVSECOPS Talks #52 - Lingon a.k.a Juliens and Jacobs open source project</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-52-lingon-aka-juliens-and-jacobs-open-source-project/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-52-lingon-aka-juliens-and-jacobs-open-source-project/#comments</comments>        <pubDate>Thu, 13 Jul 2023 16:42:02 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/1a169880-1673-37d3-b83c-61765a62bd09</guid>
                                    <description><![CDATA[





<p>This time we got to talk about Lingon, an open-source project developed by Julian and Jacob who is a frequent podcast guest. Discover the motivations behind Lingon's creation and how it bridges the gap between Terraform and Kubernetes. Learn how Lingon simplifies infrastructure management, tackles frustrations with YAML and HCL, and offers greater control and automation.</p>






<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[





<p>This time we got to talk about Lingon, an open-source project developed by Julian and Jacob who is a frequent podcast guest. Discover the motivations behind Lingon's creation and how it bridges the gap between Terraform and Kubernetes. Learn how Lingon simplifies infrastructure management, tackles frustrations with YAML and HCL, and offers greater control and automation.</p>






<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kw6778/devsecops_lingon_17ppiq.mp3" length="90099505" type="audio/mpeg"/>
        <itunes:summary><![CDATA[





This time we got to talk about Lingon, an open-source project developed by Julian and Jacob who is a frequent podcast guest. Discover the motivations behind Lingon's creation and how it bridges the gap between Terraform and Kubernetes. Learn how Lingon simplifies infrastructure management, tackles frustrations with YAML and HCL, and offers greater control and automation.






Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2252</itunes:duration>
                <itunes:episode>52</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #51 - Provisioning bare-metal servers</title>
        <itunes:title>DEVSECOPS Talks #51 - Provisioning bare-metal servers</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-51-provisioning-bare-metal-servers/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-51-provisioning-bare-metal-servers/#comments</comments>        <pubDate>Fri, 30 Jun 2023 09:01:02 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b235f540-435c-36db-9a14-f9334dafe350</guid>
                                    <description><![CDATA[<p>Diving into the world of bare-metal servers, Mattias takes the helm solo for this episode. He's accompanied by special guests Michael Wagner and Ian Evans from Metify, the company that powers Mojo - a leading platform for bare-metal provisioning automation.</p>
<p>While we often chat about the big cloud service providers, this time we're switching gears. If you've been curious about how real-world, physical servers are set up and managed, this episode is just for you. Join Mattias, Michael, and Ian as they dive into the nuts and bolts of setting up servers - a topic that Mattias is super passionate about.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Diving into the world of bare-metal servers, Mattias takes the helm solo for this episode. He's accompanied by special guests Michael Wagner and Ian Evans from Metify, the company that powers Mojo - a leading platform for bare-metal provisioning automation.</p>
<p>While we often chat about the big cloud service providers, this time we're switching gears. If you've been curious about how real-world, physical servers are set up and managed, this episode is just for you. Join Mattias, Michael, and Ian as they dive into the nuts and bolts of setting up servers - a topic that Mattias is super passionate about.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ub7ade/podcast-metal-processed.mp3" length="41113115" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Diving into the world of bare-metal servers, Mattias takes the helm solo for this episode. He's accompanied by special guests Michael Wagner and Ian Evans from Metify, the company that powers Mojo - a leading platform for bare-metal provisioning automation.
While we often chat about the big cloud service providers, this time we're switching gears. If you've been curious about how real-world, physical servers are set up and managed, this episode is just for you. Join Mattias, Michael, and Ian as they dive into the nuts and bolts of setting up servers - a topic that Mattias is super passionate about.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2936</itunes:duration>
                <itunes:episode>51</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #50 - History of AWS networking and new ways to design your VPC setup</title>
        <itunes:title>DEVSECOPS Talks #50 - History of AWS networking and new ways to design your VPC setup</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-50-history-of-aws-networking-and-new-ways-to-design-your-vpc-setup/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-50-history-of-aws-networking-and-new-ways-to-design-your-vpc-setup/#comments</comments>        <pubDate>Thu, 18 May 2023 16:51:09 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d31389f4-e96a-3b79-84a9-e808c3c52316</guid>
                                    <description><![CDATA[<p>In this episode, we discuss the evolution of AWS networking capabilities from EC2-classic to VPC and advanced networking features. Andrey highlights that while many companies only use VPC and VPC peerings, there are lesser-known features that can significantly change how we approach networking setups on AWS.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, we discuss the evolution of AWS networking capabilities from EC2-classic to VPC and advanced networking features. Andrey highlights that while many companies only use VPC and VPC peerings, there are lesser-known features that can significantly change how we approach networking setups on AWS.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jq8bvs/devsecops-aws-network-2023.mp3" length="26182435" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, we discuss the evolution of AWS networking capabilities from EC2-classic to VPC and advanced networking features. Andrey highlights that while many companies only use VPC and VPC peerings, there are lesser-known features that can significantly change how we approach networking setups on AWS.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer any questions, hear suggestions for new episodes or hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1870</itunes:duration>
                <itunes:episode>50</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #49 - Password managers, ways to share sensitive info, email aliases, ChatGPT and much more</title>
        <itunes:title>DEVSECOPS Talks #49 - Password managers, ways to share sensitive info, email aliases, ChatGPT and much more</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-49-tools/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-49-tools/#comments</comments>        <pubDate>Wed, 12 Apr 2023 08:03:13 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/fa2d716d-f1c3-34f7-ba60-60446987eca0</guid>
                                    <description><![CDATA[<p>This is a mixed bag of an episode, we chat about all sorts of digital tools and security practices that we use in our day-to-day lives. We start by talking about password managers, and why Julien still using LastPass after the recent LastPass data breach. Julien gives us the lowdown on his personal approach to handling passwords and two-factor authentication (2FA) tokens, showing us why strong security measures matter.</p>
<p>Julien also shares his favorite email alias service and we discuss services for sharing sensitive information to keep mail inboxes cleaner and more private.</p>
<p>We also spoke about ChatGPT, an AI language model from OpenAI - will it replace jobs? should we be using it? And how?</p>
<p>Just a heads up, we aren't sponsored by companies we mention in this episode. We're just sharing our personal experiences and the stuff we like to use.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is a mixed bag of an episode, we chat about all sorts of digital tools and security practices that we use in our day-to-day lives. We start by talking about password managers, and why Julien still using LastPass after the recent LastPass data breach. Julien gives us the lowdown on his personal approach to handling passwords and two-factor authentication (2FA) tokens, showing us why strong security measures matter.</p>
<p>Julien also shares his favorite email alias service and we discuss services for sharing sensitive information to keep mail inboxes cleaner and more private.</p>
<p>We also spoke about ChatGPT, an AI language model from OpenAI - will it replace jobs? should we be using it? And how?</p>
<p>Just a heads up, we aren't sponsored by companies we mention in this episode. We're just sharing our personal experiences and the stuff we like to use.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x5stgs/devsecops49.mp3" length="44240471" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is a mixed bag of an episode, we chat about all sorts of digital tools and security practices that we use in our day-to-day lives. We start by talking about password managers, and why Julien still using LastPass after the recent LastPass data breach. Julien gives us the lowdown on his personal approach to handling passwords and two-factor authentication (2FA) tokens, showing us why strong security measures matter.
Julien also shares his favorite email alias service and we discuss services for sharing sensitive information to keep mail inboxes cleaner and more private.
We also spoke about ChatGPT, an AI language model from OpenAI - will it replace jobs? should we be using it? And how?
Just a heads up, we aren't sponsored by companies we mention in this episode. We're just sharing our personal experiences and the stuff we like to use.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3159</itunes:duration>
                <itunes:episode>49</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #48 - Building Data Platforms</title>
        <itunes:title>DEVSECOPS Talks #48 - Building Data Platforms</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-48-building-data-platforms/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-48-building-data-platforms/#comments</comments>        <pubDate>Wed, 08 Mar 2023 12:52:35 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/36c95727-2ecb-3622-bbeb-4eaaa550d219</guid>
                                    <description><![CDATA[<p>Julien has extensive experience building data platforms for data engineering, so we got him talking and sharing. If infra for data engineering is your cup of tea, then this episode is for you.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Julien has extensive experience building data platforms for data engineering, so we got him talking and sharing. If infra for data engineering is your cup of tea, then this episode is for you.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/73vfbu/podcast-data-platforms.mp3" length="38763638" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Julien has extensive experience building data platforms for data engineering, so we got him talking and sharing. If infra for data engineering is your cup of tea, then this episode is for you.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2768</itunes:duration>
                <itunes:episode>48</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #47 - Tracing explained</title>
        <itunes:title>DEVSECOPS Talks #47 - Tracing explained</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-47-tracing-explained/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-47-tracing-explained/#comments</comments>        <pubDate>Tue, 07 Feb 2023 07:43:47 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/18e45d9f-5564-3f1d-b12f-be1feb2c879e</guid>
                                    <description><![CDATA[<p>We discussed tracing before but never got around to explaining details such as fundamentals, terminology, etc. This time Julien goes into detail about what tracing is, what the benefits are, the basic terms you need to understand, and where to start. Great episode for those who are considering adding tracing capabilities to their systems.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We discussed tracing before but never got around to explaining details such as fundamentals, terminology, etc. This time Julien goes into detail about what tracing is, what the benefits are, the basic terms you need to understand, and where to start. Great episode for those who are considering adding tracing capabilities to their systems.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4bx2we/podcast50.mp3" length="25389460" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We discussed tracing before but never got around to explaining details such as fundamentals, terminology, etc. This time Julien goes into detail about what tracing is, what the benefits are, the basic terms you need to understand, and where to start. Great episode for those who are considering adding tracing capabilities to their systems.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1813</itunes:duration>
                <itunes:episode>47</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #46 - Software supply chain attacks</title>
        <itunes:title>DEVSECOPS Talks #46 - Software supply chain attacks</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-46-software-supply-chain-attacks/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-46-software-supply-chain-attacks/#comments</comments>        <pubDate>Thu, 01 Dec 2022 07:27:43 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/759df7ed-1865-32d0-92de-3025afa46eca</guid>
                                    <description><![CDATA[<p>We are happy to welcome back Jacob Lärfors, CEO and Senior Consultant from Verifa, to talk about software supply chain attacks. It feels important to raise this topic since those attacks start to be utilized more often by sophisticated adversaries. At the same time, software supply chain security is something that companies often overlook. We as practitioners have so many things to consider and do that, in most cases, we do not have enough cognitive capacity left when looking into our library sources. What are the things we need to be aware of, and what are the low-hanging fruits we could utilize to help developers do their job securely?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We are happy to welcome back Jacob Lärfors, CEO and Senior Consultant from Verifa, to talk about software supply chain attacks. It feels important to raise this topic since those attacks start to be utilized more often by sophisticated adversaries. At the same time, software supply chain security is something that companies often overlook. We as practitioners have so many things to consider and do that, in most cases, we do not have enough cognitive capacity left when looking into our library sources. What are the things we need to be aware of, and what are the low-hanging fruits we could utilize to help developers do their job securely?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vxu5uk/DevSecOps46-supply-chain.mp3" length="60203363" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We are happy to welcome back Jacob Lärfors, CEO and Senior Consultant from Verifa, to talk about software supply chain attacks. It feels important to raise this topic since those attacks start to be utilized more often by sophisticated adversaries. At the same time, software supply chain security is something that companies often overlook. We as practitioners have so many things to consider and do that, in most cases, we do not have enough cognitive capacity left when looking into our library sources. What are the things we need to be aware of, and what are the low-hanging fruits we could utilize to help developers do their job securely?
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3010</itunes:duration>
                <itunes:episode>46</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #45 - What is happening with Docker?</title>
        <itunes:title>DEVSECOPS Talks #45 - What is happening with Docker?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-45-what-is-happening-with-docker/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-45-what-is-happening-with-docker/#comments</comments>        <pubDate>Wed, 02 Nov 2022 08:15:52 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/2380004f-f8e7-3932-84bd-e439728d62e2</guid>
                                    <description><![CDATA[<p>Have you heard any recent news from Docker? We haven't. That is why we decided to check up on Docker to see how it is doing and go through the tool's history and adoption. Clueless about the difference between Docker, Containerd, CRI-O? We got you covered. Also, we will highlight a couple of new handy capabilities added recently.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Have you heard any recent news from Docker? We haven't. That is why we decided to check up on Docker to see how it is doing and go through the tool's history and adoption. Clueless about the difference between Docker, Containerd, CRI-O? We got you covered. Also, we will highlight a couple of new handy capabilities added recently.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/s5r85b/45-docker.mp3" length="46230586" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Have you heard any recent news from Docker? We haven't. That is why we decided to check up on Docker to see how it is doing and go through the tool's history and adoption. Clueless about the difference between Docker, Containerd, CRI-O? We got you covered. Also, we will highlight a couple of new handy capabilities added recently.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3302</itunes:duration>
                <itunes:episode>45</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #44 - Kosli with Mike Long. From compliance to answering questions about the production environment</title>
        <itunes:title>DEVSECOPS Talks #44 - Kosli with Mike Long. From compliance to answering questions about the production environment</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-44-kosli-with-mike-long-from-compliance-to-answering-questions-about-the-production-environment/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-44-kosli-with-mike-long-from-compliance-to-answering-questions-about-the-production-environment/#comments</comments>        <pubDate>Thu, 01 Sep 2022 08:08:03 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/abb7f437-2b97-3211-a4af-80ab72271165</guid>
                                    <description><![CDATA[<p>We are excited about the new breed of tools coming to the market. We often had to put together tools to find out what was in production and what broke it. Your monitoring tools go as far as only telling you that something isn't working as expected but not why it is so, and then you have to scramble to figure out what versions of services are in production, were there any recent deploys, etc. So you can understand what has changed to narrow down possible causes. Our good friend Mike and his team are building the tool to answer exactly such questions, so we thought you might be interested in hearing him out.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We are excited about the new breed of tools coming to the market. We often had to put together tools to find out what was in production and what broke it. Your monitoring tools go as far as only telling you that something isn't working as expected but not why it is so, and then you have to scramble to figure out what versions of services are in production, were there any recent deploys, etc. So you can understand what has changed to narrow down possible causes. Our good friend Mike and his team are building the tool to answer exactly such questions, so we thought you might be interested in hearing him out.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/269zn5/44-kosli.mp3" length="39362650" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We are excited about the new breed of tools coming to the market. We often had to put together tools to find out what was in production and what broke it. Your monitoring tools go as far as only telling you that something isn't working as expected but not why it is so, and then you have to scramble to figure out what versions of services are in production, were there any recent deploys, etc. So you can understand what has changed to narrow down possible causes. Our good friend Mike and his team are building the tool to answer exactly such questions, so we thought you might be interested in hearing him out.
 
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2811</itunes:duration>
                <itunes:episode>44</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #43 - Terraform 1.0 to 1.3.0. One year in review</title>
        <itunes:title>DEVSECOPS Talks #43 - Terraform 1.0 to 1.3.0. One year in review</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-43-terraform-10-to-130-one-year-in-review/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-43-terraform-10-to-130-one-year-in-review/#comments</comments>        <pubDate>Tue, 28 Jun 2022 09:06:02 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b1fdaf3a-9a81-3a0c-8ae7-5199ad9c198e</guid>
                                    <description><![CDATA[<p>We are discussing what has happened in Terraform world since the 1.0 release last year and if there are new features worth mentioning, trends in Terraform development, etc. As well as doing a recap of the road to 1.0 and how long it took us to get there.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We are discussing what has happened in Terraform world since the 1.0 release last year and if there are new features worth mentioning, trends in Terraform development, etc. As well as doing a recap of the road to 1.0 and how long it took us to get there.</p>
<p>Connect with us on LinkedIn or Twitter (see info at <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a>). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/89392f/podcastpro.mp3" length="31797445" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We are discussing what has happened in Terraform world since the 1.0 release last year and if there are new features worth mentioning, trends in Terraform development, etc. As well as doing a recap of the road to 1.0 and how long it took us to get there.
Connect with us on LinkedIn or Twitter (see info at https://devsecops.fm/about/). We are happy to answer your questions, hear suggestions for new episodes or just hear from you, our listeners.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2271</itunes:duration>
                <itunes:episode>43</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #42 - Prometheus - a practitioner take</title>
        <itunes:title>DEVSECOPS Talks #42 - Prometheus - a practitioner take</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-42-prometheus-a-practitioner-take/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-42-prometheus-a-practitioner-take/#comments</comments>        <pubDate>Thu, 19 May 2022 08:48:41 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/ecabbc82-b66a-32f1-b1b7-9cde84d4bb7c</guid>
                                    <description><![CDATA[<p>If you follow CloudNative hype wave, you might feel that Prometheus is the must-use monitoring tool for everything CloudNative. Plus, almost everything nowadays has a Prometheus exporter. Just get that helm chart installed, and here you go - metrics question sorted out. Want to monitor endpoints - here is BlackBox exporter for you. Want to get notifications - AlertManager got you covered. And so on and so on. But is it all rainbows and unicorns? You probably guessed that it depends. This time, Semyon is joining us to air his grievances with Prometheus and share insights on how to cook it if you decide to go down this route.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If you follow CloudNative hype wave, you might feel that Prometheus is the must-use monitoring tool for everything CloudNative. Plus, almost everything nowadays has a Prometheus exporter. Just get that helm chart installed, and here you go - metrics question sorted out. Want to monitor endpoints - here is BlackBox exporter for you. Want to get notifications - AlertManager got you covered. And so on and so on. But is it all rainbows and unicorns? You probably guessed that it depends. This time, Semyon is joining us to air his grievances with Prometheus and share insights on how to cook it if you decide to go down this route.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jhtavp/42.mp3" length="42982922" type="audio/mpeg"/>
        <itunes:summary><![CDATA[If you follow CloudNative hype wave, you might feel that Prometheus is the must-use monitoring tool for everything CloudNative. Plus, almost everything nowadays has a Prometheus exporter. Just get that helm chart installed, and here you go - metrics question sorted out. Want to monitor endpoints - here is BlackBox exporter for you. Want to get notifications - AlertManager got you covered. And so on and so on. But is it all rainbows and unicorns? You probably guessed that it depends. This time, Semyon is joining us to air his grievances with Prometheus and share insights on how to cook it if you decide to go down this route.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3070</itunes:duration>
                <itunes:episode>42</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #41 - Great communication FTW</title>
        <itunes:title>DEVSECOPS Talks #41 - Great communication FTW</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-41-great-communication-ftw/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-41-great-communication-ftw/#comments</comments>        <pubDate>Tue, 26 Apr 2022 04:57:43 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/c8c99010-0706-3e5b-af83-31b950eb92b9</guid>
                                    <description><![CDATA[<p>Communication in co-located teams is quite often complicated. It is even more complex and, at the same time, important in distributed teams. Have you ever got an issue report that says this thing is failing? No logs, no explanation of context, no nothing. Pretty sure we've all been in such situations. How do you step up your communication game? This episode of DevSecOps Talks is about great communication tips for DevSecOps practitioners in distributed (and not only) teams.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Communication in co-located teams is quite often complicated. It is even more complex and, at the same time, important in distributed teams. Have you ever got an issue report that says this thing is failing? No logs, no explanation of context, no nothing. Pretty sure we've all been in such situations. How do you step up your communication game? This episode of DevSecOps Talks is about great communication tips for DevSecOps practitioners in distributed (and not only) teams.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/s4pe2z/41.mp3" length="33709316" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Communication in co-located teams is quite often complicated. It is even more complex and, at the same time, important in distributed teams. Have you ever got an issue report that says this thing is failing? No logs, no explanation of context, no nothing. Pretty sure we've all been in such situations. How do you step up your communication game? This episode of DevSecOps Talks is about great communication tips for DevSecOps practitioners in distributed (and not only) teams.
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2407</itunes:duration>
                <itunes:episode>41</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #40 - Web3 and its implications for DevSecOps practitioners</title>
        <itunes:title>DEVSECOPS Talks #40 - Web3 and its implications for DevSecOps practitioners</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-40-web3-and-its-implications-for-devsecops-practitioners/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-40-web3-and-its-implications-for-devsecops-practitioners/#comments</comments>        <pubDate>Wed, 23 Mar 2022 09:47:57 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/8968689a-6060-37af-a2b4-1a5c3c3baa10</guid>
                                    <description><![CDATA[<p>web3 has gotten a lot of attention lately; thus, it is time for us to separate facts from the hype.
In this episode, we are trying to understand its implications for us as DevSecOps practitioners.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>web3 has gotten a lot of attention lately; thus, it is time for us to separate facts from the hype.<br>
In this episode, we are trying to understand its implications for us as DevSecOps practitioners.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/bc2um8/podcast-43-processed.mp3" length="36585121" type="audio/mpeg"/>
        <itunes:summary><![CDATA[web3 has gotten a lot of attention lately; thus, it is time for us to separate facts from the hype.In this episode, we are trying to understand its implications for us as DevSecOps practitioners.
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2613</itunes:duration>
                <itunes:episode>40</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #39 - Setting up tools and environments</title>
        <itunes:title>DEVSECOPS Talks #39 - Setting up tools and environments</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-39-setting-up-tools-and-environments/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-39-setting-up-tools-and-environments/#comments</comments>        <pubDate>Mon, 07 Feb 2022 14:23:00 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/4d09536c-f360-3d65-acd8-e3a212c8f489</guid>
                                    <description><![CDATA[<p>Andrey feels frustrated that he has to develop a way to configure environments for every customer. Think for yourself - you arrive at a new project or company. It is day one, and you need to get the right tools as well as the correct environment configuration. During this episode, we are trying to figure out how companies solve it. And is there a standard solution? What are the options?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Andrey feels frustrated that he has to develop a way to configure environments for every customer. Think for yourself - you arrive at a new project or company. It is day one, and you need to get the right tools as well as the correct environment configuration. During this episode, we are trying to figure out how companies solve it. And is there a standard solution? What are the options?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/sb989b/podcast36_processed.mp3" length="23256882" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey feels frustrated that he has to develop a way to configure environments for every customer. Think for yourself - you arrive at a new project or company. It is day one, and you need to get the right tools as well as the correct environment configuration. During this episode, we are trying to figure out how companies solve it. And is there a standard solution? What are the options?
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1661</itunes:duration>
                <itunes:episode>39</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #38 - Platform teams with Henrik</title>
        <itunes:title>DEVSECOPS Talks #38 - Platform teams with Henrik</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-38-platform-teams-with-henrik/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-38-platform-teams-with-henrik/#comments</comments>        <pubDate>Mon, 24 Jan 2022 13:18:18 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/c58164d2-a32a-39b2-93e1-e0c792e45e8f</guid>
                                    <description><![CDATA[
Henrik Hoegh is back to talk about his experiences working in the platform team at his new job, but before that, we are getting through the following topics:
- bash is the future of automation (not really, but some people think so)
- building multi-cloud solutions using k8s and service mesh solutions
- Shuttle - CLI for handling shared build and deploy tools between projects no matter what technologies the projects are using https://github.com/lunarway/shuttle
- when is it the time to start looking into the building application delivery platform
- platform team as an enabler or evil gatekeeper
- team topology

Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.]]></description>
                                                            <content:encoded><![CDATA[
Henrik Hoegh is back to talk about his experiences working in the platform team at his new job, but before that, we are getting through the following topics:
- bash is the future of automation (not really, but some people think so)
- building multi-cloud solutions using k8s and service mesh solutions
- Shuttle - CLI for handling shared build and deploy tools between projects no matter what technologies the projects are using https://github.com/lunarway/shuttle
- when is it the time to start looking into the building application delivery platform
- platform team as an enabler or evil gatekeeper
- team topology

Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/i3r5gn/podcast40_proccessd.mp3" length="52298619" type="audio/mpeg"/>
        <itunes:summary><![CDATA[
Henrik Hoegh is back to talk about his experiences working in the platform team at his new job, but before that, we are getting through the following topics:
- bash is the future of automation (not really, but some people think so)
- building multi-cloud solutions using k8s and service mesh solutions
- Shuttle - CLI for handling shared build and deploy tools between projects no matter what technologies the projects are using https://github.com/lunarway/shuttle
- when is it the time to start looking into the building application delivery platform
- platform team as an enabler or evil gatekeeper
- team topology

Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3735</itunes:duration>
                <itunes:episode>38</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #37 - Surviving AWS outage (revised for 2021)</title>
        <itunes:title>DEVSECOPS Talks #37 - Surviving AWS outage (revised for 2021)</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-37-surviving-aws-outage-revised-for-2021/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-37-surviving-aws-outage-revised-for-2021/#comments</comments>        <pubDate>Fri, 07 Jan 2022 17:58:42 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/c8accab9-0482-3155-a184-30f273309214</guid>
                                    <description><![CDATA[<p>us-east-1 will never go down, and if it would, half of the internet would go down. It is what people used to say. So, us-east-1 went down big time. What does it mean for us as practitioners? What should we consider going forward? In this episode, we talk through the incident and disaster recovery strategies you can consider to keep your company up</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>us-east-1 will never go down, and if it would, half of the internet would go down. It is what people used to say. So, us-east-1 went down big time. What does it mean for us as practitioners? What should we consider going forward? In this episode, we talk through the incident and disaster recovery strategies you can consider to keep your company up</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qj92zr/podcast41_processed.mp3" length="28391510" type="audio/mpeg"/>
        <itunes:summary><![CDATA[us-east-1 will never go down, and if it would, half of the internet would go down. It is what people used to say. So, us-east-1 went down big time. What does it mean for us as practitioners? What should we consider going forward? In this episode, we talk through the incident and disaster recovery strategies you can consider to keep your company up
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2027</itunes:duration>
                <itunes:episode>37</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #36 - Sturdy. Is it time for a new version control tool?</title>
        <itunes:title>DEVSECOPS Talks #36 - Sturdy. Is it time for a new version control tool?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-36-sturdy-is-it-time-for-a-new-version-control-tool/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-36-sturdy-is-it-time-for-a-new-version-control-tool/#comments</comments>        <pubDate>Tue, 07 Dec 2021 04:46:17 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/fd36bdb7-7fa2-3044-91bd-49c67e81c912</guid>
                                    <description><![CDATA[<p>We have had Git around for more than 15 years, and during that time, it has become a standard de-facto to share code and track code changes. While Git is a superior version control system to most of what we have seen before, it has been 15 years since the first release. Should we be looking for new ways to approach version control systems? Is the time right for the next generation of tools in this area?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We have had Git around for more than 15 years, and during that time, it has become a standard de-facto to share code and track code changes. While Git is a superior version control system to most of what we have seen before, it has been 15 years since the first release. Should we be looking for new ways to approach version control systems? Is the time right for the next generation of tools in this area?</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/e3nkis/podcast39_processed.mp3" length="36365545" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We have had Git around for more than 15 years, and during that time, it has become a standard de-facto to share code and track code changes. While Git is a superior version control system to most of what we have seen before, it has been 15 years since the first release. Should we be looking for new ways to approach version control systems? Is the time right for the next generation of tools in this area?
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2597</itunes:duration>
                <itunes:episode>36</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #35 - Infrastructure as code (IAC) revisited 2021</title>
        <itunes:title>DEVSECOPS Talks #35 - Infrastructure as code (IAC) revisited 2021</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-35-infrastructure-as-code-iac-revisited-2021/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-35-infrastructure-as-code-iac-revisited-2021/#comments</comments>        <pubDate>Tue, 16 Nov 2021 06:31:34 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/14f11fea-b94b-31d1-b5a3-2247855d47b7</guid>
                                    <description><![CDATA[<p>Our first episode was about Infrastructure as code, and we feel that it is time to revisit the topic after almost two years. Another reason is the release of the second edition of Infrastructure as Code book by Keif Morris. Thus, in this episode, we revisit the definition of Infrastructure as code and try to summarize what has changed over the years. We hope you like it!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Our first episode was about Infrastructure as code, and we feel that it is time to revisit the topic after almost two years. Another reason is the release of the second edition of Infrastructure as Code book by Keif Morris. Thus, in this episode, we revisit the definition of Infrastructure as code and try to summarize what has changed over the years. We hope you like it!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2u7b3m/podcast37_processed.mp3" length="32612219" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Our first episode was about Infrastructure as code, and we feel that it is time to revisit the topic after almost two years. Another reason is the release of the second edition of Infrastructure as Code book by Keif Morris. Thus, in this episode, we revisit the definition of Infrastructure as code and try to summarize what has changed over the years. We hope you like it!
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2329</itunes:duration>
                <itunes:episode>35</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #34 - Google Next and HashiConf recap</title>
        <itunes:title>DEVSECOPS Talks #34 - Google Next and HashiConf recap</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-34-google-next-and-hashiconf-recap/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-34-google-next-and-hashiconf-recap/#comments</comments>        <pubDate>Tue, 02 Nov 2021 10:17:20 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/3cc49bcb-6764-3360-8dad-cd8bf44cd07a</guid>
                                    <description><![CDATA[<p>Julien gives his impressions of Google Cloud Next 2021, and Andrey recaps HashiConf Global 2021 as well as gives his take with the twist on why do we might need HashiCorp Waypoint</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Julien gives his impressions of Google Cloud Next 2021, and Andrey recaps HashiConf Global 2021 as well as gives his take with the twist on why do we might need HashiCorp Waypoint</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/niqiix/podcast38_processed.mp3" length="30576653" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Julien gives his impressions of Google Cloud Next 2021, and Andrey recaps HashiConf Global 2021 as well as gives his take with the twist on why do we might need HashiCorp Waypoint
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2183</itunes:duration>
                <itunes:episode>34</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #33 - Do I need a service mesh?</title>
        <itunes:title>DEVSECOPS Talks #33 - Do I need a service mesh?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-33-do-i-need-a-service-mesh/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-33-do-i-need-a-service-mesh/#comments</comments>        <pubDate>Thu, 30 Sep 2021 05:28:14 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/1ef3aefe-b54e-39e0-8a0f-93648b521777</guid>
                                    <description><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Everyone seems to be talking about service mesh. Mattias, Julien, and Andrey are trying to separate hype and real value. Most importantly, they dig into when is the good time for the organization is to embrace service mesh and what are the prerequisites</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Everyone seems to be talking about service mesh. Mattias, Julien, and Andrey are trying to separate hype and real value. Most importantly, they dig into when is the good time for the organization is to embrace service mesh and what are the prerequisites</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rm2wbx/podcast35_processed.mp3" length="23827396" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Everyone seems to be talking about service mesh. Mattias, Julien, and Andrey are trying to separate hype and real value. Most importantly, they dig into when is the good time for the organization is to embrace service mesh and what are the prerequisites
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1701</itunes:duration>
                <itunes:episode>33</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #32 - Getting hired as an infrastructure automation person</title>
        <itunes:title>DEVSECOPS Talks #32 - Getting hired as an infrastructure automation person</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-32-getting-hired-as-an-infrastructure-automation-person/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-32-getting-hired-as-an-infrastructure-automation-person/#comments</comments>        <pubDate>Mon, 13 Sep 2021 10:37:02 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/839cab3d-3d87-32d7-855a-fa8d5f02792c</guid>
                                    <description><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">As a follow-up to the [last episode about hiring an infrastructure automation person](https://devsecops.fm/episodes/31-hiring/) we decided to reverse the view and talk about how do you get hired as an infrastructure automation person. This episode is full of career advice for people who are just only from university as well as people who already have experience in the industry.
</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">As a follow-up to the [last episode about hiring an infrastructure automation person](https://devsecops.fm/episodes/31-hiring/) we decided to reverse the view and talk about how do you get hired as an infrastructure automation person. This episode is full of career advice for people who are just only from university as well as people who already have experience in the industry.<br>
</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9dg5wx/podcast34_processed.mp3" length="21510596" type="audio/mpeg"/>
        <itunes:summary><![CDATA[As a follow-up to the [last episode about hiring an infrastructure automation person](https://devsecops.fm/episodes/31-hiring/) we decided to reverse the view and talk about how do you get hired as an infrastructure automation person. This episode is full of career advice for people who are just only from university as well as people who already have experience in the industry.
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1536</itunes:duration>
                <itunes:episode>32</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #31 - Hiring an infrastructure automation person</title>
        <itunes:title>DEVSECOPS Talks #31 - Hiring an infrastructure automation person</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-31-hiring-an-infrastructure-automation-person/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-31-hiring-an-infrastructure-automation-person/#comments</comments>        <pubDate>Tue, 24 Aug 2021 08:16:37 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/9726394c-9bbc-394d-ac16-0c2b7a708a52</guid>
                                    <description><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Have you ever conducted an interview to hire an infrastructure automation person? What would you ask? How do you check their skills? And what skills are essential? Tune in for our tips on hiring and finding the right person for your team!</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Have you ever conducted an interview to hire an infrastructure automation person? What would you ask? How do you check their skills? And what skills are essential? Tune in for our tips on hiring and finding the right person for your team!</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hzhyrw/podcast33_process.mp3" length="27551099" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ 
Have you ever conducted an interview to hire an infrastructure automation person? What would you ask? How do you check their skills? And what skills are essential? Tune in for our tips on hiring and finding the right person for your team!
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1967</itunes:duration>
                <itunes:episode>31</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #30 - Logs, metrics and traces</title>
        <itunes:title>DEVSECOPS Talks #30 - Logs, metrics and traces</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-30-log-metrics-and-traces/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-30-log-metrics-and-traces/#comments</comments>        <pubDate>Wed, 23 Jun 2021 08:41:06 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/daaee644-5d75-3ea6-b2ca-422a30a7fca4</guid>
                                    <description><![CDATA[<p>Logs, metrics, and traces are the three pillars of observability. Where should you start? What are the common mistakes to avoid? And if you are to pick one - which one should you do?</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Logs, metrics, and traces are the three pillars of observability. Where should you start? What are the common mistakes to avoid? And if you are to pick one - which one should you do?</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ppp9ah/podcast32_process.mp3" length="26926459" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Logs, metrics, and traces are the three pillars of observability. Where should you start? What are the common mistakes to avoid? And if you are to pick one - which one should you do?
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1923</itunes:duration>
                <itunes:episode>30</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #29 -Unikernels are here</title>
        <itunes:title>DEVSECOPS Talks #29 -Unikernels are here</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-29-unikernels-are-here/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-29-unikernels-are-here/#comments</comments>        <pubDate>Wed, 19 May 2021 09:29:19 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/35bcff54-0e70-3524-918d-2f781fca2cb5</guid>
                                    <description><![CDATA[<p>This time we are talking unikernles! Ian Eyberg from NanoVMs joins us to discuss how far this technology is from prime time. And it turns out that you don't have to be a kernel developer to take advantage of unikernes. Today, there are tools available to package, distribute, and run them locally as well as in the public cloud. While talking to Ian, it felt that the state of the technology is very similar to Linux containers at the beginning of 2010x, just before Docker made Linux containers available for everyone.</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This time we are talking unikernles! Ian Eyberg from NanoVMs joins us to discuss how far this technology is from prime time. And it turns out that you don't have to be a kernel developer to take advantage of unikernes. Today, there are tools available to package, distribute, and run them locally as well as in the public cloud. While talking to Ian, it felt that the state of the technology is very similar to Linux containers at the beginning of 2010x, just before Docker made Linux containers available for everyone.</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/sngaqa/podcast31_proccesd.mp3" length="39979899" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time we are talking unikernles! Ian Eyberg from NanoVMs joins us to discuss how far this technology is from prime time. And it turns out that you don't have to be a kernel developer to take advantage of unikernes. Today, there are tools available to package, distribute, and run them locally as well as in the public cloud. While talking to Ian, it felt that the state of the technology is very similar to Linux containers at the beginning of 2010x, just before Docker made Linux containers available for everyone.
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2855</itunes:duration>
                <itunes:episode>29</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #28 - Scaling Security</title>
        <itunes:title>DEVSECOPS Talks #28 - Scaling Security</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-28-scaling-security/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-28-scaling-security/#comments</comments>        <pubDate>Tue, 04 May 2021 03:49:11 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/112b9c51-47a6-3aec-a67a-744b2ecb2dcc</guid>
                                    <description><![CDATA[<p>The real cloud lock-in is security! Every service/cloud provider has its own levels of granularity regarding resources. Cloud engineering is mainly about compute, storage, and networking and how to make them scale. Scaling security is often left out as it is hard to measure on so many levels.</p>
<p>We think that it is a myth and that we can measure how many steps it takes to add, modify or remove access rights. It all starts with monitoring, knowing what is there in a cloud infrastructure is a very good first step. By making it easy to see and manage access rights, we make it easier for ourselves to keep resources secured.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The real cloud lock-in is security! Every service/cloud provider has its own levels of granularity regarding resources. Cloud engineering is mainly about compute, storage, and networking and how to make them scale. Scaling security is often left out as it is hard to measure on so many levels.</p>
<p>We think that it is a myth and that we can measure how many steps it takes to add, modify or remove access rights. It all starts with monitoring, knowing what is there in a cloud infrastructure is a very good first step. By making it easy to see and manage access rights, we make it easier for ourselves to keep resources secured.</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/q3b6vj/podcast30_1_60nhd.mp3" length="30894459" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The real cloud lock-in is security! Every service/cloud provider has its own levels of granularity regarding resources. Cloud engineering is mainly about compute, storage, and networking and how to make them scale. Scaling security is often left out as it is hard to measure on so many levels.
We think that it is a myth and that we can measure how many steps it takes to add, modify or remove access rights. It all starts with monitoring, knowing what is there in a cloud infrastructure is a very good first step. By making it easy to see and manage access rights, we make it easier for ourselves to keep resources secured.
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2206</itunes:duration>
                <itunes:episode>28</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #27 - AWS Bottlerocket - Open Source Contrainer OS from AWS. Explained</title>
        <itunes:title>DEVSECOPS Talks #27 - AWS Bottlerocket - Open Source Contrainer OS from AWS. Explained</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-27-aws-bottlerocket-open-source-contrainer-os-from-aws-explained/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-27-aws-bottlerocket-open-source-contrainer-os-from-aws-explained/#comments</comments>        <pubDate>Mon, 12 Apr 2021 04:23:28 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/0d244102-14ba-36ae-b2a1-eae14893e3b0</guid>
                                    <description><![CDATA[<p>AWS released AWS Bottlerocket OS in March of 2020, and version 1.0.0 got released in August 2020.
What is it? Should you be using it? What are the benefits?
Is it ready for prime time? We answer all of those questions during this episode of DevSecOps Talks. Tune in!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>AWS released AWS Bottlerocket OS in March of 2020, and version 1.0.0 got released in August 2020.<br>
What is it? Should you be using it? What are the benefits?<br>
Is it ready for prime time? We answer all of those questions during this episode of DevSecOps Talks. Tune in!</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ugxhfa/podcast_processed.mp3" length="34888798" type="audio/mpeg"/>
        <itunes:summary><![CDATA[AWS released AWS Bottlerocket OS in March of 2020, and version 1.0.0 got released in August 2020.What is it? Should you be using it? What are the benefits?Is it ready for prime time? We answer all of those questions during this episode of DevSecOps Talks. Tune in!
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2492</itunes:duration>
                <itunes:episode>27</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #26 - Git Branching Strategies. Do's and Don'ts</title>
        <itunes:title>DEVSECOPS Talks #26 - Git Branching Strategies. Do's and Don'ts</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-26-git-branching-strategies-dos-and-donts/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-26-git-branching-strategies-dos-and-donts/#comments</comments>        <pubDate>Mon, 29 Mar 2021 08:07:43 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d8de2b54-8181-38cc-9a06-3580185da0fc</guid>
                                    <description><![CDATA[<p>Johan Abildskov (@RandomSort, see episode 6) is back, and we are talking branching strategies! In particular, why you shouldn't be doing git-flow, and what are other options out there. This conversation takes us down memory lane to a more broad discussion about version control systems, mono-repositories, continuous integration, and delivery. We hope you will like it!</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Johan Abildskov (@RandomSort, see episode 6) is back, and we are talking branching strategies! In particular, why you shouldn't be doing git-flow, and what are other options out there. This conversation takes us down memory lane to a more broad discussion about version control systems, mono-repositories, continuous integration, and delivery. We hope you will like it!</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/r42dm8/podcast28-ready.mp3" length="36961659" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Johan Abildskov (@RandomSort, see episode 6) is back, and we are talking branching strategies! In particular, why you shouldn't be doing git-flow, and what are other options out there. This conversation takes us down memory lane to a more broad discussion about version control systems, mono-repositories, continuous integration, and delivery. We hope you will like it!
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2640</itunes:duration>
                <itunes:episode>26</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #25 -All The Things You Wanted To Know About Pulumi. Explained</title>
        <itunes:title>DEVSECOPS Talks #25 -All The Things You Wanted To Know About Pulumi. Explained</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-25-all-the-things-you-wanted-to-know-about-pulumi-explained/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-25-all-the-things-you-wanted-to-know-about-pulumi-explained/#comments</comments>        <pubDate>Fri, 12 Mar 2021 06:48:47 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/e63f2dc7-2989-3e10-afd4-ede18d0e6172</guid>
                                    <description><![CDATA[<p>This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about</p>
<p>- what is Pulumi is?</p>
<p>- understand the difference between Pulumi vs. Terraform (and if we should compare them at all)</p>
<p>- What is hard about Pulumi?</p>
<p>- What people ask the most? What are the common confusions?</p>
<p>- Cross-language infra libraries? How is it even possible?!</p>
<p>- Is there a possibility of a supply chain attack via Pulumi library?</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about</p>
<p>- what is Pulumi is?</p>
<p>- understand the difference between Pulumi vs. Terraform (and if we should compare them at all)</p>
<p>- What is hard about Pulumi?</p>
<p>- What people ask the most? What are the common confusions?</p>
<p>- Cross-language infra libraries? How is it even possible?!</p>
<p>- Is there a possibility of a supply chain attack via Pulumi library?</p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/98r5mr/podcast-27.mp3" length="46185709" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about
- what is Pulumi is?
- understand the difference between Pulumi vs. Terraform (and if we should compare them at all)
- What is hard about Pulumi?
- What people ask the most? What are the common confusions?
- Cross-language infra libraries? How is it even possible?!
- Is there a possibility of a supply chain attack via Pulumi library?
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3298</itunes:duration>
                <itunes:episode>25</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #24 - Ways To Protect Yourself From Data Breaches And Mitigate Consequences</title>
        <itunes:title>DEVSECOPS Talks #24 - Ways To Protect Yourself From Data Breaches And Mitigate Consequences</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-24-ways-to-protect-yourself-from-data-breaches-and-mitigate-consequences/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-24-ways-to-protect-yourself-from-data-breaches-and-mitigate-consequences/#comments</comments>        <pubDate>Mon, 22 Feb 2021 17:34:35 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/03a96709-8951-3fb2-9a7e-84fd95653aa5</guid>
                                    <description><![CDATA[<p>Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).</p>
<p> </p>
<p>Connect with us on LinkedIn or Twitter <a href='https://devsecops.fm/about/'>https://devsecops.fm/about/</a> and tell us about your questions, and we will answer them in the show.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x257qr/podcast-26-proetct-you-online-ready-for-publish.mp3" length="30256368" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).
 
Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the show.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2161</itunes:duration>
                <itunes:episode>24</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #23 - How Do We Run Kubernetes In The Cloud?</title>
        <itunes:title>DEVSECOPS Talks #23 - How Do We Run Kubernetes In The Cloud?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-23-how-do-we-run-kubernetes-in-the-cloud/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-23-how-do-we-run-kubernetes-in-the-cloud/#comments</comments>        <pubDate>Fri, 05 Feb 2021 05:55:05 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/0d243da8-019b-386c-9d17-a786be94fa5e</guid>
                                    <description><![CDATA[<p>How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings?
We go through the list of things you might be missing out on if not yet using a managed solution.
Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings?<br>
We go through the list of things you might be missing out on if not yet using a managed solution.<br>
Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/5bgi6q/podcast-process-25.mp3" length="31080246" type="audio/mpeg"/>
        <itunes:summary><![CDATA[How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings?We go through the list of things you might be missing out on if not yet using a managed solution.Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2219</itunes:duration>
                <itunes:episode>23</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #22 - Who are Mattias, Julien and Andrey?</title>
        <itunes:title>DEVSECOPS Talks #22 - Who are Mattias, Julien and Andrey?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-22-who-are-mattias-julien-and-andrey/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-22-who-are-mattias-julien-and-andrey/#comments</comments>        <pubDate>Fri, 22 Jan 2021 08:41:33 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/dde3b54f-b841-3030-b10a-3f53f24745de</guid>
                                    <description><![CDATA[<p>It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wxarjw/podcast24.mp3" length="24798773" type="audio/mpeg"/>
        <itunes:summary><![CDATA[It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1771</itunes:duration>
                <itunes:episode>22</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #21 - Surviving AWS Outage</title>
        <itunes:title>DEVSECOPS Talks #21 - Surviving AWS Outage</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-21-surviving-aws-outage/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-21-surviving-aws-outage/#comments</comments>        <pubDate>Tue, 05 Jan 2021 07:23:16 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/a670d920-ca43-3e3d-a3c5-38c2b53d7cec</guid>
                                    <description><![CDATA[<p>AWS had a severe incident at the end of November. Kinesis in us-east-1 went dark for quite some time, and a ripple effect caused degradation of other services like CloudWatch, ECS, and others.
As a Cloud Engineering practitioner, how do you get yourself and your organization ready for a such turn of events?</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>AWS had a severe incident at the end of November. Kinesis in us-east-1 went dark for quite some time, and a ripple effect caused degradation of other services like CloudWatch, ECS, and others.<br>
As a Cloud Engineering practitioner, how do you get yourself and your organization ready for a such turn of events?</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pj3bt8/podcast23.mp3" length="83076756" type="audio/mpeg"/>
        <itunes:summary><![CDATA[AWS had a severe incident at the end of November. Kinesis in us-east-1 went dark for quite some time, and a ripple effect caused degradation of other services like CloudWatch, ECS, and others.As a Cloud Engineering practitioner, how do you get yourself and your organization ready for a such turn of events?
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2076</itunes:duration>
                <itunes:episode>21</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #20-2020 - Monitoring Done Wrong or Dreaming For A Better Monitoring</title>
        <itunes:title>DEVSECOPS Talks #20-2020 - Monitoring Done Wrong or Dreaming For A Better Monitoring</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-20-2020-dreaming-for-a-better-monitoring/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-20-2020-dreaming-for-a-better-monitoring/#comments</comments>        <pubDate>Mon, 07 Dec 2020 10:25:49 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/88f54e11-7639-3807-927e-a7ea2e8a5d0a</guid>
                                    <description><![CDATA[<p>Andrey wants monitoring to be more magical, or does he want a wrong thing? What are the sane defaults? And why do we have to set up boilerplate monitoring again and again?
  
Mattias shares what he does for monitoring security events.
  
Julien explains why using logs to debug in a microservices architecture is costly and inefficient. </p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Andrey wants monitoring to be more magical, or does he want a wrong thing? What are the sane defaults? And why do we have to set up boilerplate monitoring again and again?<br>
  <br>
Mattias shares what he does for monitoring security events.<br>
  <br>
Julien explains why using logs to debug in a microservices architecture is costly and inefficient. </p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/62i3iv/podcast19_processed.mp3" length="26069225" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey wants monitoring to be more magical, or does he want a wrong thing? What are the sane defaults? And why do we have to set up boilerplate monitoring again and again?  Mattias shares what he does for monitoring security events.  Julien explains why using logs to debug in a microservices architecture is costly and inefficient. 
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1862</itunes:duration>
                <itunes:episode>20</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #19-2020 - Deleting Resources In The Cloud</title>
        <itunes:title>DEVSECOPS Talks #19-2020 - Deleting Resources In The Cloud</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-19-2020-deleting-resources-in-the-cloud/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-19-2020-deleting-resources-in-the-cloud/#comments</comments>        <pubDate>Mon, 23 Nov 2020 16:19:45 -0400</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/a9ada73a-f126-3491-ad13-8cc0c889a225</guid>
                                    <description><![CDATA[<p>How to decommission resources from your cloud environment to keep it clean?</p>
<p>What to do when a resource is created without being in the infrastructure code?</p>
<p>Andrey is going through a checklist he uses to delete resources and the utility serverless functions he wrote.</p>
<p>ArgoCD is a project that does GitOps and automatically delete resources in Kubernetes namespaces if they are not defined.</p>
<p>We talked about the different layers of abstraction for infrastructure as code and where it makes sense to have a terraform controller in a Kubernetes cluster to manage the application dependencies.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>How to decommission resources from your cloud environment to keep it clean?</p>
<p>What to do when a resource is created without being in the infrastructure code?</p>
<p>Andrey is going through a checklist he uses to delete resources and the utility serverless functions he wrote.</p>
<p>ArgoCD is a project that does GitOps and automatically delete resources in Kubernetes namespaces if they are not defined.</p>
<p>We talked about the different layers of abstraction for infrastructure as code and where it makes sense to have a terraform controller in a Kubernetes cluster to manage the application dependencies.</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ufscma/episode_19_deleting_things.mp3" length="26069225" type="audio/mpeg"/>
        <itunes:summary><![CDATA[How to decommission resources from your cloud environment to keep it clean?
What to do when a resource is created without being in the infrastructure code?
Andrey is going through a checklist he uses to delete resources and the utility serverless functions he wrote.
ArgoCD is a project that does GitOps and automatically delete resources in Kubernetes namespaces if they are not defined.
We talked about the different layers of abstraction for infrastructure as code and where it makes sense to have a terraform controller in a Kubernetes cluster to manage the application dependencies.
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1862</itunes:duration>
                <itunes:episode>19</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #18-2020 - HashiConf Special</title>
        <itunes:title>DEVSECOPS Talks #18-2020 - HashiConf Special</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-18-2020-hashiconf-special/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-18-2020-hashiconf-special/#comments</comments>        <pubDate>Mon, 26 Oct 2020 12:42:30 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/429ee250-8aa8-3975-9270-f55d7da65ba2</guid>
                                    <description><![CDATA[<p>Initially, we planned this episode as a discussion about HashiCorp Nomad and invited Jacob Lärfors. He recently published a great article about his experience working with Nomad (see link in the show notes). However, because of a few postponements, and with HashiConf that happened just a week ago, we decided to extend the podcast’s scope to go over all of the announcements that they did during the conference. So here it is - HashiConf special: all you need to know about everything that HashiCorp announced during the conference plus a discussion about Nomad!</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Initially, we planned this episode as a discussion about HashiCorp Nomad and invited Jacob Lärfors. He recently published a great article about his experience working with Nomad (see link in the show notes). However, because of a few postponements, and with HashiConf that happened just a week ago, we decided to extend the podcast’s scope to go over all of the announcements that they did during the conference. So here it is - HashiConf special: all you need to know about everything that HashiCorp announced during the conference plus a discussion about Nomad!</p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ixug5p/podcast20_processed.mp3" length="41662916" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Initially, we planned this episode as a discussion about HashiCorp Nomad and invited Jacob Lärfors. He recently published a great article about his experience working with Nomad (see link in the show notes). However, because of a few postponements, and with HashiConf that happened just a week ago, we decided to extend the podcast’s scope to go over all of the announcements that they did during the conference. So here it is - HashiConf special: all you need to know about everything that HashiCorp announced during the conference plus a discussion about Nomad!
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2975</itunes:duration>
                <itunes:episode>18</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #17-2020 - Best Practices for Building Docker Images</title>
        <itunes:title>DEVSECOPS Talks #17-2020 - Best Practices for Building Docker Images</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-17-2020-best-practices-for-building-docker-images/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-17-2020-best-practices-for-building-docker-images/#comments</comments>        <pubDate>Tue, 13 Oct 2020 12:50:12 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d2c5bfa5-c03a-3d7c-8087-fe1d204b9d46</guid>
                                    <description><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">This is the first episode in the new format - 30 minutes short and crisp episodes, i.e., less water and side discussions, focusing on the topic, duration under (well, almost under) 30 minutes. We hope you like it!</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">The topic of this episode is building docker images - automation, security, best practices.</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">In this episode, we discuss:</p>
<ul style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"><li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Saving money with T3a family</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Building Docker images locally and in CI</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Setting up deamonless Docker builds for CI and k8s</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Using multistage builds to keep your images nice and clean as well as encapsulate the build environment and make it portable</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Passing secrets to Docker build and inspecting image layers for secrets (ssh-agent and many more)</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Keeping Docker images updated with dependencies and updates</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Scanning Docker images for vulnerabilities</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Docker image layers caching - doing it right</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">DockerHub is to delete old images stored for free, and GitHub is ready to host them for you</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Docker image naming so you can find all you need to debug quickly</li>
</ul>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">In some of the information overlaps with episode #3 but greatly extends information provided before <a href='https://devsecops.fm/episodes/docker-secure-build/'>https://devsecops.fm/episodes/docker-secure-build/</a></p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">This is the first episode in the new format - 30 minutes short and crisp episodes, i.e., less water and side discussions, focusing on the topic, duration under (well, almost under) 30 minutes. We hope you like it!</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">The topic of this episode is building docker images - automation, security, best practices.</p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">In this episode, we discuss:</p>
<ul style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"><li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Saving money with T3a family</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Building Docker images locally and in CI</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Setting up deamonless Docker builds for CI and k8s</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Using multistage builds to keep your images nice and clean as well as encapsulate the build environment and make it portable</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Passing secrets to Docker build and inspecting image layers for secrets (ssh-agent and many more)</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Keeping Docker images updated with dependencies and updates</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Scanning Docker images for vulnerabilities</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Docker image layers caching - doing it right</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">DockerHub is to delete old images stored for free, and GitHub is ready to host them for you</li>
<li style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;list-style-type:disc;">Docker image naming so you can find all you need to debug quickly</li>
</ul>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;">In some of the information overlaps with episode #3 but greatly extends information provided before <a href='https://devsecops.fm/episodes/docker-secure-build/'>https://devsecops.fm/episodes/docker-secure-build/</a></p>
<p style="color:#0e101a;background:transparent;margin-top:0pt;margin-bottom:0pt;"> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4mzqv6/devsec-ops-episode17-processed.mp3" length="28119829" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is the first episode in the new format - 30 minutes short and crisp episodes, i.e., less water and side discussions, focusing on the topic, duration under (well, almost under) 30 minutes. We hope you like it!
 
The topic of this episode is building docker images - automation, security, best practices.
 
In this episode, we discuss:
Saving money with T3a family
Building Docker images locally and in CI
Setting up deamonless Docker builds for CI and k8s
Using multistage builds to keep your images nice and clean as well as encapsulate the build environment and make it portable
Passing secrets to Docker build and inspecting image layers for secrets (ssh-agent and many more)
Keeping Docker images updated with dependencies and updates
Scanning Docker images for vulnerabilities
Docker image layers caching - doing it right
DockerHub is to delete old images stored for free, and GitHub is ready to host them for you
Docker image naming so you can find all you need to debug quickly
 
In some of the information overlaps with episode #3 but greatly extends information provided before https://devsecops.fm/episodes/docker-secure-build/
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2008</itunes:duration>
                <itunes:episode>17</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #16-2020 - Do you need a staging environment?</title>
        <itunes:title>DEVSECOPS Talks #16-2020 - Do you need a staging environment?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-16-2020-do-you-need-stage/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-16-2020-do-you-need-stage/#comments</comments>        <pubDate>Tue, 29 Sep 2020 08:47:48 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/b93b9097-481a-35cf-845d-6b3354197062</guid>
                                    <description><![CDATA[<p>In this episode, we discuss options for splitting your deployment stages.
We hear people coming up with all possible type of environments - dev, test/QA, integration, stage, prod, etc
How many do you actually need? What is the reason for having all those stages?
Maybe do you need less? Why not deploy directly to production using some fancy technique?</p>
<p>Put it simply - stage or not to stage?</p>
<p> </p>
<p>Visit <a href='https://devsecops.fm'>https://devsecops.fm</a> to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, we discuss options for splitting your deployment stages.<br>
We hear people coming up with all possible type of environments - dev, test/QA, integration, stage, prod, etc<br>
How many do you actually need? What is the reason for having all those stages?<br>
Maybe do you need less? Why not deploy directly to production using some fancy technique?</p>
<p>Put it simply - stage or not to stage?</p>
<p> </p>
<p>Visit <a href='https://devsecops.fm'>https://devsecops.fm</a> to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wnqp68/episode16_do_you_need_stage.mp3" length="41432894" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, we discuss options for splitting your deployment stages.We hear people coming up with all possible type of environments - dev, test/QA, integration, stage, prod, etcHow many do you actually need? What is the reason for having all those stages?Maybe do you need less? Why not deploy directly to production using some fancy technique?
Put it simply - stage or not to stage?
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2959</itunes:duration>
                <itunes:episode>16</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #15-2020 - Remote Work Security</title>
        <itunes:title>DEVSECOPS Talks #15-2020 - Remote Work Security</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-15-2020-remote-work-security/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-15-2020-remote-work-security/#comments</comments>        <pubDate>Thu, 17 Sep 2020 09:50:57 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/31b7f9be-5506-3396-aab9-66f2a30b8827</guid>
                                    <description><![CDATA[<p>Let's talk about security in the era of remote work. Most of us have experienced a flaky VPN connection.
What are the alternatives? SSH certificates? Yubikey?</p>
<p>We discussed various topics around security inside a cluster and outside.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Let's talk about security in the era of remote work. Most of us have experienced a flaky VPN connection.<br>
What are the alternatives? SSH certificates? Yubikey?</p>
<p>We discussed various topics around security inside a cluster and outside.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/687466/episode15_remote_work_security.mp3" length="42357408" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Let's talk about security in the era of remote work. Most of us have experienced a flaky VPN connection.What are the alternatives? SSH certificates? Yubikey?
We discussed various topics around security inside a cluster and outside.
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3025</itunes:duration>
                <itunes:episode>15</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #14-2020 - Theory of constraint</title>
        <itunes:title>DEVSECOPS Talks #14-2020 - Theory of constraint</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-14-2020-theory-of-constraint/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-14-2020-theory-of-constraint/#comments</comments>        <pubDate>Mon, 31 Aug 2020 06:30:31 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/baa40975-7c5b-3893-a1b4-a427fca31da7</guid>
                                    <description><![CDATA[<p>This time, we are joined by Henrik Høegh who shares his unique perspective on applying the theory of constraint to IT transformation as well as how it applies in the world of Cloud Native. We go back to the origin of DevOps, discussing the various problems companies are facing when transforming their organizations and adopting cultural changes.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This time, we are joined by Henrik Høegh who shares his unique perspective on applying the theory of constraint to IT transformation as well as how it applies in the world of Cloud Native. We go back to the origin of DevOps, discussing the various problems companies are facing when transforming their organizations and adopting cultural changes.</p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/522wir/episode14_theory_of_constraint.mp3" length="49843579" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time, we are joined by Henrik Høegh who shares his unique perspective on applying the theory of constraint to IT transformation as well as how it applies in the world of Cloud Native. We go back to the origin of DevOps, discussing the various problems companies are facing when transforming their organizations and adopting cultural changes.
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3560</itunes:duration>
                <itunes:episode>14</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #13-2020 - All you need to know about setting up HashiCorp Vault</title>
        <itunes:title>DEVSECOPS Talks #13-2020 - All you need to know about setting up HashiCorp Vault</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-13-2020-setting-up-hashicorp-vault/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-13-2020-setting-up-hashicorp-vault/#comments</comments>        <pubDate>Tue, 18 Aug 2020 04:57:49 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/227f0309-efd0-3d1e-ae6d-a3d7dead389c</guid>
                                    <description><![CDATA[<p>Mattias wants to setup HashiCorp Vault and quizzes Andrey how to do that.</p>
<p>We cover a lot of ground - from basic Vault concepts to setting it up and hardening.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Mattias wants to setup HashiCorp Vault and quizzes Andrey how to do that.</p>
<p>We cover a lot of ground - from basic Vault concepts to setting it up and hardening.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ceyaiq/episode13_setting_up_vault.mp3" length="43742793" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Mattias wants to setup HashiCorp Vault and quizzes Andrey how to do that.
We cover a lot of ground - from basic Vault concepts to setting it up and hardening.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3124</itunes:duration>
                <itunes:episode>13</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #12-2020 - Scale and Scaling</title>
        <itunes:title>DEVSECOPS Talks #12-2020 - Scale and Scaling</itunes:title>
        <link>https://devsecops.podbean.com/e/scale-and-scaling/</link>
                    <comments>https://devsecops.podbean.com/e/scale-and-scaling/#comments</comments>        <pubDate>Mon, 03 Aug 2020 05:02:47 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d344e1d8-c2c8-3d62-8ce9-efd5497fdc58</guid>
                                    <description><![CDATA[<p>Julien and Andrey got together to define the scale and ways to automate the scaling of your infrastructure in response to changes in load patterns.
What are the prerequisites implementing scaling? What is cooling down, warm up, horizontal and vertical scaling, scale-up, and scale in? What are the metrics that could be useful for making scaling decisions?
And last but not least, the very unexpected spin that Julien gives to the conversation. </p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Julien and Andrey got together to define the scale and ways to automate the scaling of your infrastructure in response to changes in load patterns.<br>
What are the prerequisites implementing scaling? What is cooling down, warm up, horizontal and vertical scaling, scale-up, and scale in? What are the metrics that could be useful for making scaling decisions?<br>
And last but not least, the very unexpected spin that Julien gives to the conversation. </p>
<p> </p>
<p>Visit https://devsecops.fm to see show notes and <a href='https://gitter.im/devsecopstalks/community'>https://gitter.im/devsecopstalks/community</a> to join a discussion</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zewnc6/episode12_scale_and_scaling.mp3" length="46194546" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Julien and Andrey got together to define the scale and ways to automate the scaling of your infrastructure in response to changes in load patterns.What are the prerequisites implementing scaling? What is cooling down, warm up, horizontal and vertical scaling, scale-up, and scale in? What are the metrics that could be useful for making scaling decisions?And last but not least, the very unexpected spin that Julien gives to the conversation. 
 
Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3299</itunes:duration>
                <itunes:episode>12</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #11-2020 - AWS Security Maturity Roadmap 2020</title>
        <itunes:title>DEVSECOPS Talks #11-2020 - AWS Security Maturity Roadmap 2020</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-11-2020-aws-security-maturity-roadmap-2020/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-11-2020-aws-security-maturity-roadmap-2020/#comments</comments>        <pubDate>Fri, 10 Jul 2020 03:55:45 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/7f8b1dd8-1dc1-5c84-8fc6-262bfe0d1cdc</guid>
                                    <description><![CDATA[<p>This time we are discussing the white paper by Summit Route - AWS Security Maturity Roadmap 2020. Tune in to learn more about the white paper and recommendations that we pile up on top of it.
To view show notes visit https://devsecops.fm
Chat with hosts and suggest topics for upcoming episodes at our Gitter channel https://gitter.im/devsecopstalks/community</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This time we are discussing the white paper by Summit Route - AWS Security Maturity Roadmap 2020. Tune in to learn more about the white paper and recommendations that we pile up on top of it.<br>
To view show notes visit https://devsecops.fm<br>
Chat with hosts and suggest topics for upcoming episodes at our Gitter channel https://gitter.im/devsecopstalks/community</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rkmx4i/episode11-aws-security-maturity-roadmap.mp3" length="47155976" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time we are discussing the white paper by Summit Route - AWS Security Maturity Roadmap 2020. Tune in to learn more about the white paper and recommendations that we pile up on top of it.To view show notes visit https://devsecops.fmChat with hosts and suggest topics for upcoming episodes at our Gitter channel https://gitter.im/devsecopstalks/community]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3368</itunes:duration>
                <itunes:episode>11</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #10-2020 - Are we wrong about Terragrunt?</title>
        <itunes:title>DEVSECOPS Talks #10-2020 - Are we wrong about Terragrunt?</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-10-2020-are-we-wrong-about-terragrunt/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-10-2020-are-we-wrong-about-terragrunt/#comments</comments>        <pubDate>Fri, 26 Jun 2020 11:44:31 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/6431c5c2-c3f2-5b0e-be13-6138277b11f6</guid>
                                    <description><![CDATA[<p>Our guest speaker is <a href='https://www.linkedin.com/in/antonbabenko/'>Anton Babenko</a>
he is DevSecOps Talks podcast fan, AWS Community Hero, Terraform fanatic, HashiCorp Ambassador and a prolific open source contributor.
After listening to episode <a href='https://devsecops.fm/episodes/terraform-in-ci/'>#9 Terraform in CI</a> and <a href='https://devsecops.fm/episodes/infrastructure-as-code/'>#1 Infrastructure as code</a>,
Anton decided that enough is enough and volunteered to give his point of view on <a href='https://terragrunt.gruntwork.io/'>Terragrunt</a> since he though that we are missing a few important points.
In this episode, we are discussing the use cases of <a href='https://terragrunt.gruntwork.io/'>Terragrunt</a>,
a wrapper around Terraform for working with multiple environment and modules.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Our guest speaker is <a href='https://www.linkedin.com/in/antonbabenko/'>Anton Babenko</a><br>
he is DevSecOps Talks podcast fan, AWS Community Hero, Terraform fanatic, HashiCorp Ambassador and a prolific open source contributor.<br>
After listening to episode <a href='https://devsecops.fm/episodes/terraform-in-ci/'>#9 Terraform in CI</a> and <a href='https://devsecops.fm/episodes/infrastructure-as-code/'>#1 Infrastructure as code</a>,<br>
Anton decided that enough is enough and volunteered to give his point of view on <a href='https://terragrunt.gruntwork.io/'>Terragrunt</a> since he though that we are missing a few important points.<br>
In this episode, we are discussing the use cases of <a href='https://terragrunt.gruntwork.io/'>Terragrunt</a>,<br>
a wrapper around Terraform for working with multiple environment and modules.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/viae3d/episode10-terragrant-process.mp3" length="44034320" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Our guest speaker is Anton Babenkohe is DevSecOps Talks podcast fan, AWS Community Hero, Terraform fanatic, HashiCorp Ambassador and a prolific open source contributor.After listening to episode #9 Terraform in CI and #1 Infrastructure as code,Anton decided that enough is enough and volunteered to give his point of view on Terragrunt since he though that we are missing a few important points.In this episode, we are discussing the use cases of Terragrunt,a wrapper around Terraform for working with multiple environment and modules.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3145</itunes:duration>
                <itunes:episode>10</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #9-2020 - Terraform in CI</title>
        <itunes:title>DEVSECOPS Talks #9-2020 - Terraform in CI</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-9-2020-terraform-in-ci/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-9-2020-terraform-in-ci/#comments</comments>        <pubDate>Sat, 06 Jun 2020 10:13:42 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/d1c13a70-03b6-57a6-a8a2-70efc659b4ec</guid>
                                    <description><![CDATA[<p>How do you start to implement a CI pipeline when dealing with infrastructure as code implemented via Terraform? What are the security concerns when the credentials to the whole kingdom are used in an automated process? In this episode, we discuss the various security and feasibility aspects of using Terraform in a CI pipeline.</p>
<p>We start the episode by catching up with what we’ve been working on. Feel free to skip to 11:52 if you want to go directly to the topic. Having an automated process to deploy and manage infrastructure has advantages such as fast feedback and collaboration. The code for the infrastructure is treated like an application that is versioned, tested, and deployed.</p>
<p>Show notes are available at https://devsecops.fm/episodes/terraform-in-ci/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>How do you start to implement a CI pipeline when dealing with infrastructure as code implemented via Terraform? What are the security concerns when the credentials to the whole kingdom are used in an automated process? In this episode, we discuss the various security and feasibility aspects of using Terraform in a CI pipeline.</p>
<p>We start the episode by catching up with what we’ve been working on. Feel free to skip to 11:52 if you want to go directly to the topic. Having an automated process to deploy and manage infrastructure has advantages such as fast feedback and collaboration. The code for the infrastructure is treated like an application that is versioned, tested, and deployed.</p>
<p>Show notes are available at https://devsecops.fm/episodes/terraform-in-ci/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9ju293/episode9-terraform-ci.mp3" length="21441213" type="audio/mpeg"/>
        <itunes:summary>How do you start to implement a CI pipeline when dealing with infrastructure as code ?
What are the security concerns when the credentials to the whole kingdom are used in an automated process ?
In this episode, we discuss the various security and feasibility aspects of using terraform in a CI pipeline.</itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3065</itunes:duration>
                <itunes:episode>9</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #8-2020 - DevOps What</title>
        <itunes:title>DEVSECOPS Talks #8-2020 - DevOps What</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-8-2020-devops-what/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-8-2020-devops-what/#comments</comments>        <pubDate>Mon, 25 May 2020 05:12:56 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/690df5c8-329e-5550-8e80-e5436c975d5c</guid>
                                    <description><![CDATA[<p>Andrey tells us the story of how DevOps came into existence and took over the market. We discuss the marketing around it, its relationship with DevSecOps. We tried to shed a light on what is marketing strategy versus implementing DevOps in an organization. We also compared DevOps to SRE (Site Reliability Engineering)</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Andrey tells us the story of how DevOps came into existence and took over the market. We discuss the marketing around it, its relationship with DevSecOps. We tried to shed a light on what is marketing strategy versus implementing DevOps in an organization. We also compared DevOps to SRE (Site Reliability Engineering)</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/alh13o/episode8.mp3" length="20696925" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Andrey tells us the story of how DevOps came into existence and took over the market. We discuss the marketing around it, its relationship with DevSecOps. We tried to shed a light on what is marketing strategy versus implementing DevOps in an organization. We also compared DevOps to SRE (Site Reliability Engineering)]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3188</itunes:duration>
                <itunes:episode>8</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #7-2020 - How do we learn</title>
        <itunes:title>DEVSECOPS Talks #7-2020 - How do we learn</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-7-2020-how-do-we-learn/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-7-2020-how-do-we-learn/#comments</comments>        <pubDate>Wed, 06 May 2020 17:09:08 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/88f8b2d7-fce8-5db7-87aa-9d5205619789</guid>
                                    <description><![CDATA[<p>In this episode, Mattias, Julien, and Andrey share tips and tricks on how to stay on top of what is going on in the industry, resources they use for continuous learning. Make sure to visit devsecops.fm to check out show notes that contain references to resources mentioned during discussion and more</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, Mattias, Julien, and Andrey share tips and tricks on how to stay on top of what is going on in the industry, resources they use for continuous learning. Make sure to visit devsecops.fm to check out show notes that contain references to resources mentioned during discussion and more</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jmjv8h/episode7-learning.mp3" length="17592501" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, Mattias, Julien, and Andrey share tips and tricks on how to stay on top of what is going on in the industry, resources they use for continuous learning. Make sure to visit devsecops.fm to check out show notes that contain references to resources mentioned during discussion and more]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2808</itunes:duration>
                <itunes:episode>7</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #6-2020 - SemVer or not to SemVer</title>
        <itunes:title>DEVSECOPS Talks #6-2020 - SemVer or not to SemVer</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-6-2020-semver-or-not-to-semver/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-6-2020-semver-or-not-to-semver/#comments</comments>        <pubDate>Wed, 06 May 2020 17:08:55 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/37cc7c5d-2105-5baa-83e6-8fb09ccb7528</guid>
                                    <description><![CDATA[<p>This time <a href='https://twitter.com/randomsort'>Johan Abildskov</a>, a Senior Consultant with <a href='https://www.praqma.com'>Praqma/Eficode</a>, joins us to talk about SemVer (Semantic Versioning), and we finally get to hear what Julien has to say about it. We get to explore different options regarding versioning and how it helps humans communicate. At the end of the podcast, everyone gets to share their approach and recommendations for versioning things.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This time <a href='https://twitter.com/randomsort'>Johan Abildskov</a>, a Senior Consultant with <a href='https://www.praqma.com'>Praqma/Eficode</a>, joins us to talk about SemVer (Semantic Versioning), and we finally get to hear what Julien has to say about it. We get to explore different options regarding versioning and how it helps humans communicate. At the end of the podcast, everyone gets to share their approach and recommendations for versioning things.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pur8yn/episode6-semver.mp3" length="24180213" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This time Johan Abildskov, a Senior Consultant with Praqma/Eficode, joins us to talk about SemVer (Semantic Versioning), and we finally get to hear what Julien has to say about it. We get to explore different options regarding versioning and how it helps humans communicate. At the end of the podcast, everyone gets to share their approach and recommendations for versioning things.]]></itunes:summary>
        <itunes:author>Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3689</itunes:duration>
                <itunes:episode>6</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #5-2020 - What we have been working on</title>
        <itunes:title>DEVSECOPS Talks #5-2020 - What we have been working on</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-5-2020-what-we-have-bean-working-on/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-5-2020-what-we-have-bean-working-on/#comments</comments>        <pubDate>Tue, 07 Apr 2020 07:36:03 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/ebdbb688-dd12-5c1e-80cc-2f7d53b4c117</guid>
                                    <description><![CDATA[<p>We had a couple of possible topics for this episode but before getting started with them we decided to discuss what technological problems we were solving during the last two weeks. Well, turns out there was quite a lot to discuss. Tune in for tips on ssh session logging on the ssh server, preventing downloads from AWS S3 even if you got read access, credentials in Git repository 🤦, why you should (or should not) do K8S and more.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We had a couple of possible topics for this episode but before getting started with them we decided to discuss what technological problems we were solving during the last two weeks. Well, turns out there was quite a lot to discuss. Tune in for tips on ssh session logging on the ssh server, preventing downloads from AWS S3 even if you got read access, credentials in Git repository 🤦, why you should (or should not) do K8S and more.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/22si2h/episode5-what-we-have-bean-working-on.mp3" length="25417014" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We had a couple of possible topics for this episode but before getting started with them we decided to discuss what technological problems we were solving during the last two weeks. Well, turns out there was quite a lot to discuss. Tune in for tips on ssh session logging on the ssh server, preventing downloads from AWS S3 even if you got read access, credentials in Git repository 🤦, why you should (or should not) do K8S and more.]]></itunes:summary>
        <itunes:author>devsecops</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3633</itunes:duration>
                <itunes:episode>5</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #4-2020 - Is docker more secure then VM</title>
        <itunes:title>DEVSECOPS Talks #4-2020 - Is docker more secure then VM</itunes:title>
        <link>https://devsecops.podbean.com/e/is-docker-more-secure-then-vm/</link>
                    <comments>https://devsecops.podbean.com/e/is-docker-more-secure-then-vm/#comments</comments>        <pubDate>Thu, 26 Mar 2020 10:14:19 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/236a1d88-09e2-5231-9da3-bb614acfbfd3</guid>
                                    <description><![CDATA[<p>In this episode Mattias is trying to convince that running docker in k8s is more security then VM. Did he success ? listen and find out.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode Mattias is trying to convince that running docker in k8s is more security then VM. Did he success ? listen and find out.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/25y532/episode1-docker-vs-vm-security.mp3" length="22699758" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode Mattias is trying to convince that running docker in k8s is more security then VM. Did he success ? listen and find out.]]></itunes:summary>
        <itunes:author>devsecops</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3330</itunes:duration>
                <itunes:episode>4</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #3-2020 - Docker securing builds</title>
        <itunes:title>DEVSECOPS Talks #3-2020 - Docker securing builds</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-talks-3-2020-docker-securing-builds/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-talks-3-2020-docker-securing-builds/#comments</comments>        <pubDate>Fri, 20 Mar 2020 04:45:44 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/2d8d3583-2556-5c04-a873-6d86e3a3dceb</guid>
                                    <description><![CDATA[<p>Your docker images and build are be coming the base for our platform. But are they secure? In this episode we talk about how you can secure your docker images.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Your docker images and build are be coming the base for our platform. But are they secure? In this episode we talk about how you can secure your docker images.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/i58bsz/episode3-docker-security-build.mp3" length="15684174" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Your docker images and build are be coming the base for our platform. But are they secure? In this episode we talk about how you can secure your docker images.]]></itunes:summary>
        <itunes:author>devsecops</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2272</itunes:duration>
                <itunes:episode>3</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #2-2020 - GitOps</title>
        <itunes:title>DEVSECOPS Talks #2-2020 - GitOps</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-1-2020-gitops/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-1-2020-gitops/#comments</comments>        <pubDate>Fri, 20 Mar 2020 03:44:04 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/9ca8d72d-1656-55a3-ae8a-81d14859cf7f</guid>
                                    <description><![CDATA[<p>Gitops a new concept on devops. Whats is it and how can you use it when deploy and setup your k8s cluster. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Gitops a new concept on devops. Whats is it and how can you use it when deploy and setup your k8s cluster. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9nn44e/episode2-gitops.mp3" length="11010048" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Gitops a new concept on devops. Whats is it and how can you use it when deploy and setup your k8s cluster. ]]></itunes:summary>
        <itunes:author>devsecops</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1091</itunes:duration>
                <itunes:episode>2</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>DEVSECOPS Talks #1-2020 - Infra as code</title>
        <itunes:title>DEVSECOPS Talks #1-2020 - Infra as code</itunes:title>
        <link>https://devsecops.podbean.com/e/devsecops-1-2020-infra-as-code/</link>
                    <comments>https://devsecops.podbean.com/e/devsecops-1-2020-infra-as-code/#comments</comments>        <pubDate>Thu, 19 Mar 2020 18:34:32 -0300</pubDate>
        <guid isPermaLink="false">devsecops.podbean.com/6120c241-aeda-5f90-baf5-121aee0430b1</guid>
                                    <description><![CDATA[<p>Are infra as code always the best way to go and if not when and where should you use it. Here we are trying to better understand when its god to use and when its not. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Are infra as code always the best way to go and if not when and where should you use it. Here we are trying to better understand when its god to use and when its not. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hkbcqv/episode1-infra-as-code.mp3" length="19445214" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Are infra as code always the best way to go and if not when and where should you use it. Here we are trying to better understand when its god to use and when its not. ]]></itunes:summary>
        <itunes:author>devsecops</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3006</itunes:duration>
                <itunes:episode>1</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
</channel>
</rss>
