DevOps'ish 176
Next week’s DevOps’ish (177) will be the last DevOps’ish for a while. I’m going to be putting DevOps’ish on a COVID-19 hiatus. A large part of making this newsletter is reading the news every day. Even with very heavy-handed filtering, the amount of data I read about the ongoing pandemic is far higher than one should be consuming. I’m pausing DevOps’ish because the news is hard to read these days. I’ll still be around. I’ve got something I’m pretty excited about in the works. Stay tuned on Twitter and chrishort.net for more info on that. People Sawfish phishing campaign targets GitHub users “Over the last week, GitHub has received reports related to a phishing campaign targeting our customers. We’re publishing this blog to increase awareness of this ongoing threat.” DevOps Chats: DevSecOps and OpenShift, with Red Hat When Kirsten Newcomer speaks, I listen. “We’re seeing that shift left a lot, but then there’s all these other range of things that you should be doing and can be doing to build security into the platform. And so, when we saw pod security policies in Kubernetes, for example, that’s a way that the Kube admin can take advantage of the Linux features that enable container isolation at the Kubernetes layer and enforce things like ensure that a container doesn’t run with unnecessary privileges.” ...