SlideShare a Scribd company logo
t
Track Overview:
Security
19 - 21 October
San Diego
A Year in Open Source Automated
Compliance With Puppet
This session will provide the attendee with a look at what the SIMP
project has achieved since its debut at PuppetConf 2015. Topic
covered will include a brief overview of the SIMP project, the
creation of a public community, new features, the automated CI
process, code level attestation of Puppet parameters to Policy,
lessons learned, and a glimpse of the future.
2
Thursday, October 20 | 1:30 pm
Trevor Vaughan
VP Engineering, Onyx Point, Inc.
Security
Security Roadmap: How We Are
Helping You When Everything is
Burning
This talk will be a walk thru of the puppet security roadmap, where
Puppet fits in the world of Security and the world of Compliance.
Including, identifying what is burning, how to catch things before
they burn, and why these features fit in with defining and aligning
security with a DevOps approach. Additionally, we will do a demo
and walk thru of what we have done to date. This will span things
like our Corrective Change feature to PQL.
3
Thursday, October 20 | 2:30 pm
Verne Lindner
Beth Cornils
Sr. Product Manager, Puppet
UX Designer, Puppet
Security
Nice and Secure: Good OpSec
Hygiene With Puppet!
Puppet is a great first step to making your environment more
secure. Evolving your system setup into infrastructure as code
allows a clear audit trail and more inspection of your current state,
allowing you to shine a light on any problem areas in your estate.
But how do we make sure our Puppet setup doesn't make things
less secure whilst making it easier to automate? We're going to talk
about:
4
Thursday, October 20 | 4:45 pm
Professional Services Engineer, Puppet
Peter Souter
Security
● Making sure security is part of your workflow, rather than
an afterthought.
● Best practise with hardening your Puppet architecture.
● Secrets management with the Puppet toolchain.
● Keeping your code clear of plaintext passwords.
Using HashiCorp's Vault With
Puppet
One common challenge organizations often face when adopting secret
management solutions like Vault into their infrastructure is how to fetch
secrets from Vault using a configuration management tool like Puppet.
In addition to providing a high-level overview of Vault and Vault's
architecture, this example-driven talk details a few techniques for
retrieving secrets from Vault using Puppet by bridging the gap
between runtime and build time data. Join me on an adventure as we
move our secrets from Hiera to Vault.
5
Friday, October 21 | 11:15 am
Seth Vargo
Director of Evangelism, HashiCorp
Security
Puppet as Security Tooling
As a Puppet user, you know the value of Puppet for configuration
management, deployment, and delivery of your applications. What you
may not know is that it is also a powerful tool for securing your
environment and for meeting your compliance and auditing needs. In
this session you’ll see how Puppet can provide policy enforcement,
help monitor compliance requirements, and help with fast response to
security issues. I’ll speak about my experience running a small security
program using Puppet and provide you guidance about where to look
to make wins for your organization.
6
Friday, October 21 | 2:30 pm
Bill Weiss
Manager of SysOps, Puppet
Security
How You Actually Get Hacked
One common challenge organizations often face when adopting secret
management solutions like Vault into their infrastructure is how to fetch
secrets from Vault using a configuration management tool like Puppet.
In addition to providing a high-level overview of Vault and Vault's
architecture, this example-driven talk details a few techniques for
retrieving secrets from Vault using Puppet by bridging the gap
between runtime and build time data. Join me on an adventure as we
move our secrets from Hiera to Vault.
7
Friday, October 21 | 3:45 pm
Ben Hughes
Security Engineer, Etsy
Security
Want to explore more PuppetConf
sessions?
View our full agenda and other tracks at
puppet.com/puppetconf
t
Security:
Speakers
19 - 21 October
San Diego
Trevor Vaughan
VP Engineering, Onyx Point, Inc.
Trevor is a co-founder of Onyx Point, Inc. and has been using
Puppet since 0.24 to automate pretty much everything. He is
the organizer of the Baltimore Puppet Users Group and a
voracious Open Source supporter. He is also the technical lead
for the SIMP project, released by the National Security Agency,
to improve the availability of compliant managed platforms to
the systems management industry.
Beth Cornils
Sr. Product Manager, Puppet
Beth Cornils is a product manager for Insights and Visibility,
Security, and PuppetDB. She's spent the last 2 years at
Puppet learning about why sysadmins and security people
do what they do. Turns out, Developers, Operations, and
Security people have different motivators. Who knew! Most
important lesson learned from Ops this year, no one cares
about my feature the way I do. They only care how much
glue is needed to make it work. Opservations, they keep me
honest.
Verne Lindner
UX Designer, Puppet
Verne Lindner is part of the user experience team at Puppet.
As part of her team, she has designed change reporting tools
for PE's graphical user interface, as well as the GUI's node
graph. She is currently working on aggregate and historical
reporting tools for Puppet-managed systems.
Peter Souter
Professional Services Engineer, Puppet
Peter is a Professional Services Engineer at Puppet, and has
been helping people on their first steps on their DevOps
journey for over 5 years. He's been tinkering with Puppet
since 2.7, and finds that listening to Bonobo increases his
work output 50%.
Seth Vargo
Director of Evangelism, HashiCorp
Seth Vargo is the Director of Evangelism at HashiCorp.
Previously, Seth worked at Chef (Opscode), CustomInk, and
a few Pittsburgh-based startups. He the author of Learning
Chef and is passionate about reducing inequality in
technology. When he is not writing, working on open source,
or speaking at conferences, Seth enjoys spending time with
his friends and advising non-profits. He loves all things
bacon.
Bill Weiss
Manager of SysOps, Puppet
As a red-and-blue-team member turned sysadmin herder, Bill
Weiss had an early introduction to automation in security,
and he's spent the rest of his career trying to bring that idea
to more places. He started out working in the .gov, moved to
Chicago to spend several years at a financial services SaaS,
and finally made it to Portland in 2015 to join Puppet as the
Manager of SysOps, which he thinks is a way better term
than “sysadmin.”
Ben Hughes
Security Engineer, Etsy
"Don't call it a comeback, I've been here for years" Ben
maintains he's an information security professional with over
15 long hard years and tens of shell accounts of experience.
He's previously worked as an operations engineer for Puppet
Labs, (yes that long ago, hence the comeback). He's also
worked at global Fortune 500 companies, down to small
startups on key areas of security, networking and
infrastructure. He's spoken all over the world, in any city that
has good third wave coffee, on topics relating to DevOps and
all it entails, intrusion detection, buzzword conscious Docker,
and why curl piped to sudo bash is the worst. He also does a
mean She-Ra impersonation.
t
Get on the path
to a better future
Join us 19-21 October in San Diego
Register now
Summer Savings:
Save $240 until 15 September
puppetconf.com

More Related Content

What's hot

(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
DevOpsDays Tel Aviv
 
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
XebiaLabs
 
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
VMware Tanzu
 
Securing the Pipeline
Securing the PipelineSecuring the Pipeline
Securing the Pipeline
Thoughtworks
 
Going Cloud Native
Going Cloud NativeGoing Cloud Native
Going Cloud Native
David Schmitz
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineThe DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD Pipeline
James Wickett
 
Intro to DevOps 4 undergraduates
Intro to DevOps 4 undergraduates Intro to DevOps 4 undergraduates
Intro to DevOps 4 undergraduates
Liran Levy
 
Working Without Wires
Working Without WiresWorking Without Wires
Working Without Wires
Kinoma
 
Lean Engineering. Applying Lean Principles to Building Experiences
Lean Engineering. Applying Lean Principles to Building ExperiencesLean Engineering. Applying Lean Principles to Building Experiences
Lean Engineering. Applying Lean Principles to Building Experiences
Bill Scott
 
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
Puppet
 
Application Security Epistemology in a Continuous Delivery World
Application Security Epistemology in a Continuous Delivery WorldApplication Security Epistemology in a Continuous Delivery World
Application Security Epistemology in a Continuous Delivery World
James Wickett
 
Building a DevSecOps Pipeline Around Your Spring Boot Application
Building a DevSecOps Pipeline Around Your Spring Boot ApplicationBuilding a DevSecOps Pipeline Around Your Spring Boot Application
Building a DevSecOps Pipeline Around Your Spring Boot Application
VMware Tanzu
 
Marko Berković
Marko BerkovićMarko Berković
Marko Berković
CodeFest
 
My web application in 20 minutes with Telosys
My web application in 20 minutes with Telosys My web application in 20 minutes with Telosys
My web application in 20 minutes with Telosys
Laurent Guérin
 
Eclipse Vs Netbeans
Eclipse Vs NetbeansEclipse Vs Netbeans
Eclipse Vs Netbeans
SiliconExpert Technologies
 
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
Sonatype
 
Deploying your SaaS stack OnPrem
Deploying your SaaS stack OnPremDeploying your SaaS stack OnPrem
Deploying your SaaS stack OnPrem
Kris Buytaert
 
The Seven Habits of the Highly Effective DevSecOp
The Seven Habits of the Highly Effective DevSecOpThe Seven Habits of the Highly Effective DevSecOp
The Seven Habits of the Highly Effective DevSecOp
James Wickett
 
Why sending patches back is so important
Why sending patches back is so importantWhy sending patches back is so important
Why sending patches back is so important
Macpaul Lin
 
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
DevSecCon
 

What's hot (20)

(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
(Ignite) OPEN SOURCE - OPEN CHOICE: HOW TO CHOOSE AN OPEN-SOURCE PROJECT, HIL...
 
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
Losing Sight of DevOps in an Automation Forest - devopsdays Atlanta 2013
 
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
Iterating For Success: A Case Study in Remote Paired Programming, The Evoluti...
 
Securing the Pipeline
Securing the PipelineSecuring the Pipeline
Securing the Pipeline
 
Going Cloud Native
Going Cloud NativeGoing Cloud Native
Going Cloud Native
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineThe DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD Pipeline
 
Intro to DevOps 4 undergraduates
Intro to DevOps 4 undergraduates Intro to DevOps 4 undergraduates
Intro to DevOps 4 undergraduates
 
Working Without Wires
Working Without WiresWorking Without Wires
Working Without Wires
 
Lean Engineering. Applying Lean Principles to Building Experiences
Lean Engineering. Applying Lean Principles to Building ExperiencesLean Engineering. Applying Lean Principles to Building Experiences
Lean Engineering. Applying Lean Principles to Building Experiences
 
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
Keynote: The Phoenix Project: Lessons Learned - PuppetConf 2014
 
Application Security Epistemology in a Continuous Delivery World
Application Security Epistemology in a Continuous Delivery WorldApplication Security Epistemology in a Continuous Delivery World
Application Security Epistemology in a Continuous Delivery World
 
Building a DevSecOps Pipeline Around Your Spring Boot Application
Building a DevSecOps Pipeline Around Your Spring Boot ApplicationBuilding a DevSecOps Pipeline Around Your Spring Boot Application
Building a DevSecOps Pipeline Around Your Spring Boot Application
 
Marko Berković
Marko BerkovićMarko Berković
Marko Berković
 
My web application in 20 minutes with Telosys
My web application in 20 minutes with Telosys My web application in 20 minutes with Telosys
My web application in 20 minutes with Telosys
 
Eclipse Vs Netbeans
Eclipse Vs NetbeansEclipse Vs Netbeans
Eclipse Vs Netbeans
 
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
 
Deploying your SaaS stack OnPrem
Deploying your SaaS stack OnPremDeploying your SaaS stack OnPrem
Deploying your SaaS stack OnPrem
 
The Seven Habits of the Highly Effective DevSecOp
The Seven Habits of the Highly Effective DevSecOpThe Seven Habits of the Highly Effective DevSecOp
The Seven Habits of the Highly Effective DevSecOp
 
Why sending patches back is so important
Why sending patches back is so importantWhy sending patches back is so important
Why sending patches back is so important
 
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
DevSecCon Boston 2018: Securing the Automated Pipeline: A Tale of Navigating ...
 

Viewers also liked

Seminario 3
Seminario 3Seminario 3
Seminario 3
paularuizvargas
 
English mtsn 2016 03 time and activities test
English mtsn 2016 03 time and activities testEnglish mtsn 2016 03 time and activities test
English mtsn 2016 03 time and activities test
Winarno Ganteng
 
Agenda II Encuentro Sumak Kawsay 2016
Agenda II Encuentro Sumak Kawsay 2016Agenda II Encuentro Sumak Kawsay 2016
Agenda II Encuentro Sumak Kawsay 2016
Jorge Cano
 
News 4 2016 print2
News 4 2016 print2News 4 2016 print2
News 4 2016 print2
Ethika the place of living
 
Bizyhood overview - November 2016
Bizyhood overview - November 2016Bizyhood overview - November 2016
Bizyhood overview - November 2016
bizyscott
 
13 passos
13 passos13 passos
TED Talk
TED Talk TED Talk
Ecymk
EcymkEcymk
Psiquiatria - Conclusão drogas
Psiquiatria - Conclusão drogasPsiquiatria - Conclusão drogas
Psiquiatria - Conclusão drogas
Adriana Bonadia dos Santos
 
Apostila portugues
Apostila portuguesApostila portugues
Apostila portugues
resolvidos
 
Polo tecnologico di Pavia
Polo tecnologico di PaviaPolo tecnologico di Pavia
Polo tecnologico di Pavia
echo_artecomunicazione
 
Puppet for Security Compliance - GOSCON 2010
Puppet for Security Compliance - GOSCON 2010Puppet for Security Compliance - GOSCON 2010
Puppet for Security Compliance - GOSCON 2010
Puppet
 
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
Adriana Bonadia dos Santos
 
EDUARDO H. PARE WORK CERTIFICATE_RASCO1
EDUARDO H. PARE WORK CERTIFICATE_RASCO1EDUARDO H. PARE WORK CERTIFICATE_RASCO1
EDUARDO H. PARE WORK CERTIFICATE_RASCO1
Eduardo H. Pare
 
PuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
PuppetConf 2016: Keynote - Luke Kanies, Puppet FounderPuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
PuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
Puppet
 
Psicologia - A Importância do toque.
Psicologia - A Importância do toque.Psicologia - A Importância do toque.
Psicologia - A Importância do toque.
Adriana Bonadia dos Santos
 
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, PuppetPuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
Puppet
 

Viewers also liked (20)

my academic record
my academic recordmy academic record
my academic record
 
Seminario 3
Seminario 3Seminario 3
Seminario 3
 
English mtsn 2016 03 time and activities test
English mtsn 2016 03 time and activities testEnglish mtsn 2016 03 time and activities test
English mtsn 2016 03 time and activities test
 
Agenda II Encuentro Sumak Kawsay 2016
Agenda II Encuentro Sumak Kawsay 2016Agenda II Encuentro Sumak Kawsay 2016
Agenda II Encuentro Sumak Kawsay 2016
 
News 4 2016 print2
News 4 2016 print2News 4 2016 print2
News 4 2016 print2
 
lean black belt cert
lean black belt certlean black belt cert
lean black belt cert
 
Bizyhood overview - November 2016
Bizyhood overview - November 2016Bizyhood overview - November 2016
Bizyhood overview - November 2016
 
13 passos
13 passos13 passos
13 passos
 
TED Talk
TED Talk TED Talk
TED Talk
 
Ecymk
EcymkEcymk
Ecymk
 
8
 8 8
8
 
Psiquiatria - Conclusão drogas
Psiquiatria - Conclusão drogasPsiquiatria - Conclusão drogas
Psiquiatria - Conclusão drogas
 
Apostila portugues
Apostila portuguesApostila portugues
Apostila portugues
 
Polo tecnologico di Pavia
Polo tecnologico di PaviaPolo tecnologico di Pavia
Polo tecnologico di Pavia
 
Puppet for Security Compliance - GOSCON 2010
Puppet for Security Compliance - GOSCON 2010Puppet for Security Compliance - GOSCON 2010
Puppet for Security Compliance - GOSCON 2010
 
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
Ortopedia - Hérnia do Núcleo Pulposo (Hérnia de disco)
 
EDUARDO H. PARE WORK CERTIFICATE_RASCO1
EDUARDO H. PARE WORK CERTIFICATE_RASCO1EDUARDO H. PARE WORK CERTIFICATE_RASCO1
EDUARDO H. PARE WORK CERTIFICATE_RASCO1
 
PuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
PuppetConf 2016: Keynote - Luke Kanies, Puppet FounderPuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
PuppetConf 2016: Keynote - Luke Kanies, Puppet Founder
 
Psicologia - A Importância do toque.
Psicologia - A Importância do toque.Psicologia - A Importância do toque.
Psicologia - A Importância do toque.
 
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, PuppetPuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
PuppetConf 2016: Puppet as Security Tooling – Bill Weiss, Puppet
 

Similar to PuppetConf track overview: Security

PuppetConf track overview: Puppet 4
PuppetConf track overview: Puppet 4PuppetConf track overview: Puppet 4
PuppetConf track overview: Puppet 4
Puppet
 
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
DevOps Indonesia
 
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
André Goliath
 
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
Puppet
 
The OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
The OpenSIPS security audit - OpenSIPS Summit - Sandro GauciThe OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
The OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
Sandro Gauci
 
PuppetConf track overview: Modern Infrastructure
PuppetConf track overview: Modern InfrastructurePuppetConf track overview: Modern Infrastructure
PuppetConf track overview: Modern Infrastructure
Puppet
 
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
Claire Priester Papas
 
DevSecOps in 2031: How robots and humans will secure apps together Log
DevSecOps in 2031: How robots and humans will secure apps together LogDevSecOps in 2031: How robots and humans will secure apps together Log
DevSecOps in 2031: How robots and humans will secure apps together Log
Stefan Streichsbier
 
Securing a great DX - DevSecOps Days Singapore 2018
Securing a great DX - DevSecOps Days Singapore 2018Securing a great DX - DevSecOps Days Singapore 2018
Securing a great DX - DevSecOps Days Singapore 2018
Stefan Streichsbier
 
DevOps for Defenders in the Enterprise
DevOps for Defenders in the EnterpriseDevOps for Defenders in the Enterprise
DevOps for Defenders in the Enterprise
James Wickett
 
Butler
ButlerButler
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOps
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOpsShift Left: Puppet + CloudPassage = New Approach to Securing DevOps
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOps
Claire Priester Papas
 
Butler
ButlerButler
Allegory of the cave(1)
Allegory of the cave(1)Allegory of the cave(1)
Allegory of the cave(1)
setuid0
 
Maturing DevSecOps: From Easy to High Impact
Maturing DevSecOps: From Easy to High ImpactMaturing DevSecOps: From Easy to High Impact
Maturing DevSecOps: From Easy to High Impact
SBWebinars
 
Kali linux cookbook
Kali linux cookbookKali linux cookbook
Kali linux cookbook
Jules Krdenas
 
Sydney mule soft meetup 30 april 2020
Sydney mule soft meetup   30 april 2020Sydney mule soft meetup   30 april 2020
Sydney mule soft meetup 30 april 2020
Royston Lobo
 
Intro to Puppet Enterprise 06.28.2017
Intro to Puppet Enterprise 06.28.2017Intro to Puppet Enterprise 06.28.2017
Intro to Puppet Enterprise 06.28.2017
Puppet
 
From 🤦 to 🐿️
From 🤦 to 🐿️From 🤦 to 🐿️
From 🤦 to 🐿️
Ori Pekelman
 
TechDayConf Edition 1 - 2020
TechDayConf Edition 1 -  2020TechDayConf Edition 1 -  2020
TechDayConf Edition 1 - 2020
Hamida Rebai Trabelsi
 

Similar to PuppetConf track overview: Security (20)

PuppetConf track overview: Puppet 4
PuppetConf track overview: Puppet 4PuppetConf track overview: Puppet 4
PuppetConf track overview: Puppet 4
 
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
Securing a Great Developer Experience - DevOps Indonesia Meetup by Stefan Str...
 
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
 
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
PuppetConf 2016: Security Roadmap: How We Are Helping You When Everything is ...
 
The OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
The OpenSIPS security audit - OpenSIPS Summit - Sandro GauciThe OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
The OpenSIPS security audit - OpenSIPS Summit - Sandro Gauci
 
PuppetConf track overview: Modern Infrastructure
PuppetConf track overview: Modern InfrastructurePuppetConf track overview: Modern Infrastructure
PuppetConf track overview: Modern Infrastructure
 
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
Delivering Infrastructure and Security Policy as Code with Puppet and CyberAr...
 
DevSecOps in 2031: How robots and humans will secure apps together Log
DevSecOps in 2031: How robots and humans will secure apps together LogDevSecOps in 2031: How robots and humans will secure apps together Log
DevSecOps in 2031: How robots and humans will secure apps together Log
 
Securing a great DX - DevSecOps Days Singapore 2018
Securing a great DX - DevSecOps Days Singapore 2018Securing a great DX - DevSecOps Days Singapore 2018
Securing a great DX - DevSecOps Days Singapore 2018
 
DevOps for Defenders in the Enterprise
DevOps for Defenders in the EnterpriseDevOps for Defenders in the Enterprise
DevOps for Defenders in the Enterprise
 
Butler
ButlerButler
Butler
 
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOps
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOpsShift Left: Puppet + CloudPassage = New Approach to Securing DevOps
Shift Left: Puppet + CloudPassage = New Approach to Securing DevOps
 
Butler
ButlerButler
Butler
 
Allegory of the cave(1)
Allegory of the cave(1)Allegory of the cave(1)
Allegory of the cave(1)
 
Maturing DevSecOps: From Easy to High Impact
Maturing DevSecOps: From Easy to High ImpactMaturing DevSecOps: From Easy to High Impact
Maturing DevSecOps: From Easy to High Impact
 
Kali linux cookbook
Kali linux cookbookKali linux cookbook
Kali linux cookbook
 
Sydney mule soft meetup 30 april 2020
Sydney mule soft meetup   30 april 2020Sydney mule soft meetup   30 april 2020
Sydney mule soft meetup 30 april 2020
 
Intro to Puppet Enterprise 06.28.2017
Intro to Puppet Enterprise 06.28.2017Intro to Puppet Enterprise 06.28.2017
Intro to Puppet Enterprise 06.28.2017
 
From 🤦 to 🐿️
From 🤦 to 🐿️From 🤦 to 🐿️
From 🤦 to 🐿️
 
TechDayConf Edition 1 - 2020
TechDayConf Edition 1 -  2020TechDayConf Edition 1 -  2020
TechDayConf Edition 1 - 2020
 

More from Puppet

Puppet camp2021 testing modules and controlrepo
Puppet camp2021 testing modules and controlrepoPuppet camp2021 testing modules and controlrepo
Puppet camp2021 testing modules and controlrepo
Puppet
 
Puppetcamp r10kyaml
Puppetcamp r10kyamlPuppetcamp r10kyaml
Puppetcamp r10kyaml
Puppet
 
2021 04-15 operational verification (with notes)
2021 04-15 operational verification (with notes)2021 04-15 operational verification (with notes)
2021 04-15 operational verification (with notes)
Puppet
 
Puppet camp vscode
Puppet camp vscodePuppet camp vscode
Puppet camp vscode
Puppet
 
Modules of the twenties
Modules of the twentiesModules of the twenties
Modules of the twenties
Puppet
 
Applying Roles and Profiles method to compliance code
Applying Roles and Profiles method to compliance codeApplying Roles and Profiles method to compliance code
Applying Roles and Profiles method to compliance code
Puppet
 
KGI compliance as-code approach
KGI compliance as-code approachKGI compliance as-code approach
KGI compliance as-code approach
Puppet
 
Enforce compliance policy with model-driven automation
Enforce compliance policy with model-driven automationEnforce compliance policy with model-driven automation
Enforce compliance policy with model-driven automation
Puppet
 
Keynote: Puppet camp compliance
Keynote: Puppet camp complianceKeynote: Puppet camp compliance
Keynote: Puppet camp compliance
Puppet
 
Automating it management with Puppet + ServiceNow
Automating it management with Puppet + ServiceNowAutomating it management with Puppet + ServiceNow
Automating it management with Puppet + ServiceNow
Puppet
 
Puppet: The best way to harden Windows
Puppet: The best way to harden WindowsPuppet: The best way to harden Windows
Puppet: The best way to harden Windows
Puppet
 
Simplified Patch Management with Puppet - Oct. 2020
Simplified Patch Management with Puppet - Oct. 2020Simplified Patch Management with Puppet - Oct. 2020
Simplified Patch Management with Puppet - Oct. 2020
Puppet
 
Accelerating azure adoption with puppet
Accelerating azure adoption with puppetAccelerating azure adoption with puppet
Accelerating azure adoption with puppet
Puppet
 
Puppet catalog Diff; Raphael Pinson
Puppet catalog Diff; Raphael PinsonPuppet catalog Diff; Raphael Pinson
Puppet catalog Diff; Raphael Pinson
Puppet
 
ServiceNow and Puppet- better together, Kevin Reeuwijk
ServiceNow and Puppet- better together, Kevin ReeuwijkServiceNow and Puppet- better together, Kevin Reeuwijk
ServiceNow and Puppet- better together, Kevin Reeuwijk
Puppet
 
Take control of your dev ops dumping ground
Take control of your  dev ops dumping groundTake control of your  dev ops dumping ground
Take control of your dev ops dumping ground
Puppet
 
100% Puppet Cloud Deployment of Legacy Software
100% Puppet Cloud Deployment of Legacy Software100% Puppet Cloud Deployment of Legacy Software
100% Puppet Cloud Deployment of Legacy Software
Puppet
 
Puppet User Group
Puppet User GroupPuppet User Group
Puppet User Group
Puppet
 
Continuous Compliance and DevSecOps
Continuous Compliance and DevSecOpsContinuous Compliance and DevSecOps
Continuous Compliance and DevSecOps
Puppet
 
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick MaludyThe Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
Puppet
 

More from Puppet (20)

Puppet camp2021 testing modules and controlrepo
Puppet camp2021 testing modules and controlrepoPuppet camp2021 testing modules and controlrepo
Puppet camp2021 testing modules and controlrepo
 
Puppetcamp r10kyaml
Puppetcamp r10kyamlPuppetcamp r10kyaml
Puppetcamp r10kyaml
 
2021 04-15 operational verification (with notes)
2021 04-15 operational verification (with notes)2021 04-15 operational verification (with notes)
2021 04-15 operational verification (with notes)
 
Puppet camp vscode
Puppet camp vscodePuppet camp vscode
Puppet camp vscode
 
Modules of the twenties
Modules of the twentiesModules of the twenties
Modules of the twenties
 
Applying Roles and Profiles method to compliance code
Applying Roles and Profiles method to compliance codeApplying Roles and Profiles method to compliance code
Applying Roles and Profiles method to compliance code
 
KGI compliance as-code approach
KGI compliance as-code approachKGI compliance as-code approach
KGI compliance as-code approach
 
Enforce compliance policy with model-driven automation
Enforce compliance policy with model-driven automationEnforce compliance policy with model-driven automation
Enforce compliance policy with model-driven automation
 
Keynote: Puppet camp compliance
Keynote: Puppet camp complianceKeynote: Puppet camp compliance
Keynote: Puppet camp compliance
 
Automating it management with Puppet + ServiceNow
Automating it management with Puppet + ServiceNowAutomating it management with Puppet + ServiceNow
Automating it management with Puppet + ServiceNow
 
Puppet: The best way to harden Windows
Puppet: The best way to harden WindowsPuppet: The best way to harden Windows
Puppet: The best way to harden Windows
 
Simplified Patch Management with Puppet - Oct. 2020
Simplified Patch Management with Puppet - Oct. 2020Simplified Patch Management with Puppet - Oct. 2020
Simplified Patch Management with Puppet - Oct. 2020
 
Accelerating azure adoption with puppet
Accelerating azure adoption with puppetAccelerating azure adoption with puppet
Accelerating azure adoption with puppet
 
Puppet catalog Diff; Raphael Pinson
Puppet catalog Diff; Raphael PinsonPuppet catalog Diff; Raphael Pinson
Puppet catalog Diff; Raphael Pinson
 
ServiceNow and Puppet- better together, Kevin Reeuwijk
ServiceNow and Puppet- better together, Kevin ReeuwijkServiceNow and Puppet- better together, Kevin Reeuwijk
ServiceNow and Puppet- better together, Kevin Reeuwijk
 
Take control of your dev ops dumping ground
Take control of your  dev ops dumping groundTake control of your  dev ops dumping ground
Take control of your dev ops dumping ground
 
100% Puppet Cloud Deployment of Legacy Software
100% Puppet Cloud Deployment of Legacy Software100% Puppet Cloud Deployment of Legacy Software
100% Puppet Cloud Deployment of Legacy Software
 
Puppet User Group
Puppet User GroupPuppet User Group
Puppet User Group
 
Continuous Compliance and DevSecOps
Continuous Compliance and DevSecOpsContinuous Compliance and DevSecOps
Continuous Compliance and DevSecOps
 
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick MaludyThe Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
The Dynamic Duo of Puppet and Vault tame SSL Certificates, Nick Maludy
 

Recently uploaded

Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
Deuglo Infosystem Pvt Ltd
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
NYGGS Automation Suite
 
Using Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional SafetyUsing Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional Safety
Ayan Halder
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Crescat
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
Fermin Galan
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
Philip Schwarz
 
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI AppAI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
Google
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Undress Baby
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Neo4j
 
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
mz5nrf0n
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
rickgrimesss22
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
Green Software Development
 
DDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systemsDDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systems
Gerardo Pardo-Castellote
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate
 
Transform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR SolutionsTransform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR Solutions
TheSMSPoint
 
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
kalichargn70th171
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
Neo4j
 
Fundamentals of Programming and Language Processors
Fundamentals of Programming and Language ProcessorsFundamentals of Programming and Language Processors
Fundamentals of Programming and Language Processors
Rakesh Kumar R
 

Recently uploaded (20)

Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
 
Using Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional SafetyUsing Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional Safety
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
 
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI AppAI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
 
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
原版定制美国纽约州立大学奥尔巴尼分校毕业证学位证书原版一模一样
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
 
DDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systemsDDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systems
 
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
 
Transform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR SolutionsTransform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR Solutions
 
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
Why Mobile App Regression Testing is Critical for Sustained Success_ A Detail...
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
 
Fundamentals of Programming and Language Processors
Fundamentals of Programming and Language ProcessorsFundamentals of Programming and Language Processors
Fundamentals of Programming and Language Processors
 

PuppetConf track overview: Security

  • 1. t Track Overview: Security 19 - 21 October San Diego
  • 2. A Year in Open Source Automated Compliance With Puppet This session will provide the attendee with a look at what the SIMP project has achieved since its debut at PuppetConf 2015. Topic covered will include a brief overview of the SIMP project, the creation of a public community, new features, the automated CI process, code level attestation of Puppet parameters to Policy, lessons learned, and a glimpse of the future. 2 Thursday, October 20 | 1:30 pm Trevor Vaughan VP Engineering, Onyx Point, Inc. Security
  • 3. Security Roadmap: How We Are Helping You When Everything is Burning This talk will be a walk thru of the puppet security roadmap, where Puppet fits in the world of Security and the world of Compliance. Including, identifying what is burning, how to catch things before they burn, and why these features fit in with defining and aligning security with a DevOps approach. Additionally, we will do a demo and walk thru of what we have done to date. This will span things like our Corrective Change feature to PQL. 3 Thursday, October 20 | 2:30 pm Verne Lindner Beth Cornils Sr. Product Manager, Puppet UX Designer, Puppet Security
  • 4. Nice and Secure: Good OpSec Hygiene With Puppet! Puppet is a great first step to making your environment more secure. Evolving your system setup into infrastructure as code allows a clear audit trail and more inspection of your current state, allowing you to shine a light on any problem areas in your estate. But how do we make sure our Puppet setup doesn't make things less secure whilst making it easier to automate? We're going to talk about: 4 Thursday, October 20 | 4:45 pm Professional Services Engineer, Puppet Peter Souter Security ● Making sure security is part of your workflow, rather than an afterthought. ● Best practise with hardening your Puppet architecture. ● Secrets management with the Puppet toolchain. ● Keeping your code clear of plaintext passwords.
  • 5. Using HashiCorp's Vault With Puppet One common challenge organizations often face when adopting secret management solutions like Vault into their infrastructure is how to fetch secrets from Vault using a configuration management tool like Puppet. In addition to providing a high-level overview of Vault and Vault's architecture, this example-driven talk details a few techniques for retrieving secrets from Vault using Puppet by bridging the gap between runtime and build time data. Join me on an adventure as we move our secrets from Hiera to Vault. 5 Friday, October 21 | 11:15 am Seth Vargo Director of Evangelism, HashiCorp Security
  • 6. Puppet as Security Tooling As a Puppet user, you know the value of Puppet for configuration management, deployment, and delivery of your applications. What you may not know is that it is also a powerful tool for securing your environment and for meeting your compliance and auditing needs. In this session you’ll see how Puppet can provide policy enforcement, help monitor compliance requirements, and help with fast response to security issues. I’ll speak about my experience running a small security program using Puppet and provide you guidance about where to look to make wins for your organization. 6 Friday, October 21 | 2:30 pm Bill Weiss Manager of SysOps, Puppet Security
  • 7. How You Actually Get Hacked One common challenge organizations often face when adopting secret management solutions like Vault into their infrastructure is how to fetch secrets from Vault using a configuration management tool like Puppet. In addition to providing a high-level overview of Vault and Vault's architecture, this example-driven talk details a few techniques for retrieving secrets from Vault using Puppet by bridging the gap between runtime and build time data. Join me on an adventure as we move our secrets from Hiera to Vault. 7 Friday, October 21 | 3:45 pm Ben Hughes Security Engineer, Etsy Security
  • 8. Want to explore more PuppetConf sessions? View our full agenda and other tracks at puppet.com/puppetconf
  • 9. t Security: Speakers 19 - 21 October San Diego
  • 10. Trevor Vaughan VP Engineering, Onyx Point, Inc. Trevor is a co-founder of Onyx Point, Inc. and has been using Puppet since 0.24 to automate pretty much everything. He is the organizer of the Baltimore Puppet Users Group and a voracious Open Source supporter. He is also the technical lead for the SIMP project, released by the National Security Agency, to improve the availability of compliant managed platforms to the systems management industry.
  • 11. Beth Cornils Sr. Product Manager, Puppet Beth Cornils is a product manager for Insights and Visibility, Security, and PuppetDB. She's spent the last 2 years at Puppet learning about why sysadmins and security people do what they do. Turns out, Developers, Operations, and Security people have different motivators. Who knew! Most important lesson learned from Ops this year, no one cares about my feature the way I do. They only care how much glue is needed to make it work. Opservations, they keep me honest.
  • 12. Verne Lindner UX Designer, Puppet Verne Lindner is part of the user experience team at Puppet. As part of her team, she has designed change reporting tools for PE's graphical user interface, as well as the GUI's node graph. She is currently working on aggregate and historical reporting tools for Puppet-managed systems.
  • 13. Peter Souter Professional Services Engineer, Puppet Peter is a Professional Services Engineer at Puppet, and has been helping people on their first steps on their DevOps journey for over 5 years. He's been tinkering with Puppet since 2.7, and finds that listening to Bonobo increases his work output 50%.
  • 14. Seth Vargo Director of Evangelism, HashiCorp Seth Vargo is the Director of Evangelism at HashiCorp. Previously, Seth worked at Chef (Opscode), CustomInk, and a few Pittsburgh-based startups. He the author of Learning Chef and is passionate about reducing inequality in technology. When he is not writing, working on open source, or speaking at conferences, Seth enjoys spending time with his friends and advising non-profits. He loves all things bacon.
  • 15. Bill Weiss Manager of SysOps, Puppet As a red-and-blue-team member turned sysadmin herder, Bill Weiss had an early introduction to automation in security, and he's spent the rest of his career trying to bring that idea to more places. He started out working in the .gov, moved to Chicago to spend several years at a financial services SaaS, and finally made it to Portland in 2015 to join Puppet as the Manager of SysOps, which he thinks is a way better term than “sysadmin.”
  • 16. Ben Hughes Security Engineer, Etsy "Don't call it a comeback, I've been here for years" Ben maintains he's an information security professional with over 15 long hard years and tens of shell accounts of experience. He's previously worked as an operations engineer for Puppet Labs, (yes that long ago, hence the comeback). He's also worked at global Fortune 500 companies, down to small startups on key areas of security, networking and infrastructure. He's spoken all over the world, in any city that has good third wave coffee, on topics relating to DevOps and all it entails, intrusion detection, buzzword conscious Docker, and why curl piped to sudo bash is the worst. He also does a mean She-Ra impersonation.
  • 17. t Get on the path to a better future Join us 19-21 October in San Diego Register now Summer Savings: Save $240 until 15 September puppetconf.com