DevOpsArk Security

Security engineering, DevOpsArk

The DevOpsArk security engineering group writes about DevSecOps practice, container and Kubernetes security, vulnerability prioritisation and the parts of compliance that actually change how systems are built.

DevSecOpsContainer securityVulnerability managementCloud security posture
7 articles

Written by DevOpsArk Security

7 min read

Compliance readiness vs compliance certification: what auditors actually ask for

"Compliance ready" and "certified" get used interchangeably, but auditors treat them very differently. What the difference is, and what audit evidence actually looks like.

7 min read

DevOps audit trails: why full event history is your cheapest incident tool

Most audit trails are built for a compliance reviewer and used, months later, by an on-call engineer at 2am. What a useful trail captures and how to make it serve both jobs.

7 min read

Secrets management: getting credentials out of your repositories

How to centralise credentials, replace long-lived secrets with short-lived ones, rotate without breaking consumers, and respond when a secret leaks.

8 min read

Vulnerability management: turning a report into a work queue

How to make a twelve-thousand-row vulnerability report actionable: deduplication, exposure-based ranking, ownership and verified closure.

10 min read

Kubernetes security: the controls that matter most

A prioritised guide to securing Kubernetes (RBAC, pod security, network policy, secrets and supply chain) ordered by risk reduced rather than by chapter number.

9 min read

Container security: the practices that actually reduce risk

Build-time hardening, runtime restriction and supply chain controls for containers, ordered by how much risk each one removes rather than by how often it is mentioned.

8 min read

What is DevSecOps? Beyond "shift left"

What DevSecOps means in practice, why shifting left fails when the feedback is not actionable, and the practices that actually change security outcomes.

Questions about any of this?

The people who write here also take the demo calls.