DevSecOps
Container and Kubernetes security, vulnerability management, secrets handling, audit trails and compliance evidence.
What does the DevSecOps cluster cover?
The DevSecOps cluster on the DevOpsArk blog collects 7 articles on container and kubernetes security, vulnerability management, secrets handling, audit trails and compliance evidence.
Everything in DevSecOps
Compliance readiness vs compliance certification: what auditors actually ask for
"Compliance ready" and "certified" get used interchangeably, but auditors treat them very differently. What the difference is, and what audit evidence actually looks like.
DevOps audit trails: why full event history is your cheapest incident tool
Most audit trails are built for a compliance reviewer and used, months later, by an on-call engineer at 2am. What a useful trail captures and how to make it serve both jobs.
Secrets management: getting credentials out of your repositories
How to centralise credentials, replace long-lived secrets with short-lived ones, rotate without breaking consumers, and respond when a secret leaks.
Vulnerability management: turning a report into a work queue
How to make a twelve-thousand-row vulnerability report actionable: deduplication, exposure-based ranking, ownership and verified closure.
Kubernetes security: the controls that matter most
A prioritised guide to securing Kubernetes (RBAC, pod security, network policy, secrets and supply chain) ordered by risk reduced rather than by chapter number.
Container security: the practices that actually reduce risk
Build-time hardening, runtime restriction and supply chain controls for containers, ordered by how much risk each one removes rather than by how often it is mentioned.
What is DevSecOps? Beyond "shift left"
What DevSecOps means in practice, why shifting left fails when the feedback is not actionable, and the practices that actually change security outcomes.
What the platform does about this
360 DITE
Delivery, infrastructure, testing and experience in one score
IAM
Access, roles and approvals
Security
Posture, policy and continuous verification
Log Management
Centralised logs with structure and retention
AI Log Analysis
Find the line that matters
Anomaly Detection
Detection without hand-written thresholds
Secrets
Centralised secrets with rotation
Scanners
Image, code, IaC and secret scanning
Elsewhere on the blog
DevOps
Fundamentals, automation strategy, incident practice and the platform-versus-toolchain question.
Kubernetes
Architecture, monitoring, deployment strategy, multi-cluster operations and troubleshooting.
Observability
Metrics, logs, traces, alerting design and what observability actually means.
AI DevOps
Agentic DevOps, AI log analysis, incident response and where automation should stop.
Cloud and cost
Multi-cloud operations, cost optimisation, infrastructure drift and infrastructure hygiene.
Want a structured route through this?
Learning tracks arrange these articles into an ordered path with the glossary terms they depend on.