Listen "How to Secure DevOps"
Episode Synopsis
Dan “Pop” Papandrea (@danpopnyc, Field CTO @Sysdig Host @PopcastPop) talks about securing DevOps, how to secure containers and runtimes, and the cultural challenges of security in an agile world. SHOW: 460SHOW SPONSOR LINKS:Datadog Security Monitoring Homepage - Modern Monitoring and AnalyticsTry Datadog yourself by starting a free, 14-day trial today. Listeners of this podcast will also receive a free Datadog T-shirtstrongDM HomepageStart your free 14 day trial today at: strongdm.com/cloudcastCLOUD NEWS OF THE WEEK - http://bit.ly/cloudcast-cnotwPodCTL Podcast is Back (Enterprise Kubernetes) - http://podctl.comSHOW NOTES:Sysdig HomepageThePOPcast with Dan POP HomepageEscape 2019 talk Webinar on the top 5 Pipeline considerations we did with Booz Allen Topic 1 - Welcome to the show. I first got to know you through your podcast The POPcast, but you’re been around this evolution of the cloud for quite a while. Tell us a bit about your background. Topic 2 - There’s a concept that’s now been around a couple years called “DevSecOps”. Originally it was “Sec” being jammed in there because it had been excluded from the early days of DevOps (at least in practice). Where are we with DevSecOps today? Topic 3 - Let’s talk about DevSecOps in the context of containers. We now have things like Container Scanning, Container Signing, and Immutable Infrastructure and yet security still concerns people. Isn’t the “software supply chain” supposed to weed out the vulnerabilities before they get into the production systems?Topic 4 - One of the challenges that companies have in adopting containers is that they were used to having root access to hosts, and containers live in the user space. How can security tools fit into a container world? Topic 5 - As you talk to lots of companies, how are they dealing with the cultural challenges that go along with implementing DevSecOps? Topic 6 - Any tips or suggestions you can share to help people avoid common DevSecOps mistakes, or accelerate best practices and wider adoption?FEEDBACK?Email: show at thecloudcast dot netTwitter: @thecloudcastnet
More episodes of the podcast The Cloudcast
RAG That Survives Production
14/01/2026
20 Years of OSS Databases
07/01/2026
AI & Cloud Trends for December 2025
04/01/2026
Cloud and AI Predictions for 2026
31/12/2025
The Craziest Year (so far) comes to a close
28/12/2025
The 2025 State of AI in Review
24/12/2025
How AGI will change Everything, Everywhere
21/12/2025
The 2025 State of Cloud in Review
17/12/2025
Will there be a market for expert AI agents?
14/12/2025
How AI is evolving Enterprise Infrastructure
10/12/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.