Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin

The DevSecOps Talks Podcast

This is the show by and for DevSecOps practitioners who are trying to survive information overload, get through marketing nonsense, do right technology bets, help their organizations to deliver value and last but not the least to have some fun. Tune in for talks about technology, ways of working and news from DevSecOps. This show is not sponsored by any technology vendor and trying to be as unbiased as possible. We talk like no one is listening! For good or bad :) For more info, show notes, and discussion of past and upcoming episodes visit devsecops.fm

Author

Mattias Hemmingsson, Julien Bisconti and Andrey Devyatkin

Category

Technology

Podcast website

devsecops.fm

Latest episode

Jun 14, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DEVSECOPS Talks #28 - Scaling Security 04.05.2021

The real cloud lock-in is security! Every service/cloud provider has its own levels of granularity regarding resources. Cloud engineering is mainly about compute, storage, and networking and how to make them scale. Scaling security is often left out as it is hard to measure on so many levels. We think that it is a myth and that we can measure how many steps it takes to add, modify or remove access...

DEVSECOPS Talks #27 - AWS Bottlerocket - Open Source Contrainer OS from AWS. Explained 12.04.2021

AWS released AWS Bottlerocket OS in March of 2020, and version 1.0.0 got released in August 2020. What is it? Should you be using it? What are the benefits? Is it ready for prime time? We answer all of those questions during this episode of DevSecOps Talks. Tune in!   Connect with us on LinkedIn or Twitter https://devsecops.fm/about/ and tell us about your questions, and we will answer them in the...

DEVSECOPS Talks #26 - Git Branching Strategies. Do's and Don'ts 29.03.2021

Johan Abildskov (@RandomSort, see episode 6) is back, and we are talking branching strategies! In particular, why you shouldn't be doing git-flow, and what are other options out there. This conversation takes us down memory lane to a more broad discussion about version control systems, mono-repositories, continuous integration, and delivery. We hope you will like it! Connect with us on LinkedIn or...

DEVSECOPS Talks #25 -All The Things You Wanted To Know About Pulumi. Explained 12.03.2021

This time we are joined by Paul Stack (@stack72, Pulumi developer, former Terraform developer) and podcast friend Jacob Lärfors to talk about - what is Pulumi is? - understand the difference between Pulumi vs. Terraform (and if we should compare them at all) - What is hard about Pulumi? - What people ask the most? What are the common confusions? - Cross-language infra libraries? How is it even pos...

DEVSECOPS Talks #24 - Ways To Protect Yourself From Data Breaches And Mitigate Consequences 22.02.2021

Last week (week 6, 2021), seven data breaches were announced. In this episode, we discuss the possible scenarios for preventing attackers from getting a hold of your data, whether private or company data. And tips on how to mitigate the consequences of data leaks in cases when you have no control over data management (think of breach of 3rd party service).   Connect with us on LinkedIn or Twitter...

DEVSECOPS Talks #23 - How Do We Run Kubernetes In The Cloud? 05.02.2021

How do you run Kubernetes in the cloud? Still using Kops? Or is it time to jump to the managed offerings? We go through the list of things you might be missing out on if not yet using a managed solution. Also, in this episode - what do you always configure in the k8s cluster? CNI, Ingress, IAM, and even more!   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/commu...

DEVSECOPS Talks #22 - Who are Mattias, Julien and Andrey? 22.01.2021

It's been almost a year since we started the podcast, but we never took time to explain who we are and what problems we solve for our customers/employers. So in this episode, you will find more details about us and, as usual, references to useful tools, talks, and techniques.   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion

DEVSECOPS Talks #21 - Surviving AWS Outage 05.01.2021

AWS had a severe incident at the end of November. Kinesis in us-east-1 went dark for quite some time, and a ripple effect caused degradation of other services like CloudWatch, ECS, and others. As a Cloud Engineering practitioner, how do you get yourself and your organization ready for a such turn of events?   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/communi...

DEVSECOPS Talks #20-2020 - Monitoring Done Wrong or Dreaming For A Better Monitoring 07.12.2020

Andrey wants monitoring to be more magical, or does he want a wrong thing? What are the sane defaults? And why do we have to set up boilerplate monitoring again and again?    Mattias shares what he does for monitoring security events.    Julien explains why using logs to debug in a microservices architecture is costly and inefficient.    Visit https://devsecops.fm to see show notes and https://git...

DEVSECOPS Talks #19-2020 - Deleting Resources In The Cloud 23.11.2020

How to decommission resources from your cloud environment to keep it clean? What to do when a resource is created without being in the infrastructure code? Andrey is going through a checklist he uses to delete resources and the utility serverless functions he wrote. ArgoCD is a project that does GitOps and automatically delete resources in Kubernetes namespaces if they are not defined. We talked a...

DEVSECOPS Talks #18-2020 - HashiConf Special 26.10.2020

Initially, we planned this episode as a discussion about HashiCorp Nomad and invited Jacob Lärfors. He recently published a great article about his experience working with Nomad (see link in the show notes). However, because of a few postponements, and with HashiConf that happened just a week ago, we decided to extend the podcast’s scope to go over all of the announcements that they did during the...

DEVSECOPS Talks #17-2020 - Best Practices for Building Docker Images 13.10.2020

This is the first episode in the new format - 30 minutes short and crisp episodes, i.e., less water and side discussions, focusing on the topic, duration under (well, almost under) 30 minutes. We hope you like it!   The topic of this episode is building docker images - automation, security, best practices.   In this episode, we discuss: Saving money with T3a family Building Docker images locally a...

DEVSECOPS Talks #16-2020 - Do you need a staging environment? 29.09.2020

In this episode, we discuss options for splitting your deployment stages. We hear people coming up with all possible type of environments - dev, test/QA, integration, stage, prod, etc How many do you actually need? What is the reason for having all those stages? Maybe do you need less? Why not deploy directly to production using some fancy technique? Put it simply - stage or not to stage?   Visit...

DEVSECOPS Talks #15-2020 - Remote Work Security 17.09.2020

Let's talk about security in the era of remote work. Most of us have experienced a flaky VPN connection. What are the alternatives? SSH certificates? Yubikey? We discussed various topics around security inside a cluster and outside.   Visit https://devsecops.fm to see show notes and https://gitter.im/devsecopstalks/community to join a discussion

DEVSECOPS Talks #14-2020 - Theory of constraint 31.08.2020

This time, we are joined by Henrik Høegh who shares his unique perspective on applying the theory of constraint to IT transformation as well as how it applies in the world of Cloud Native. We go back to the origin of DevOps, discussing the various problems companies are facing when transforming their organizations and adopting cultural changes.   Visit https://devsecops.fm to see show notes and ht...

DEVSECOPS Talks #13-2020 - All you need to know about setting up HashiCorp Vault 18.08.2020

Mattias wants to setup HashiCorp Vault and quizzes Andrey how to do that. We cover a lot of ground - from basic Vault concepts to setting it up and hardening.

DEVSECOPS Talks #12-2020 - Scale and Scaling 03.08.2020

Julien and Andrey got together to define the scale and ways to automate the scaling of your infrastructure in response to changes in load patterns. What are the prerequisites implementing scaling? What is cooling down, warm up, horizontal and vertical scaling, scale-up, and scale in? What are the metrics that could be useful for making scaling decisions? And last but not least, the very unexpected...

DEVSECOPS Talks #11-2020 - AWS Security Maturity Roadmap 2020 10.07.2020

This time we are discussing the white paper by Summit Route - AWS Security Maturity Roadmap 2020. Tune in to learn more about the white paper and recommendations that we pile up on top of it. To view show notes visit https://devsecops.fm Chat with hosts and suggest topics for upcoming episodes at our Gitter channel https://gitter.im/devsecopstalks/community

DEVSECOPS Talks #10-2020 - Are we wrong about Terragrunt? 26.06.2020

Our guest speaker is Anton Babenko he is DevSecOps Talks podcast fan, AWS Community Hero, Terraform fanatic, HashiCorp Ambassador and a prolific open source contributor. After listening to episode #9 Terraform in CI  and #1 Infrastructure as code , Anton decided that enough is enough and volunteered to give his point of view on Terragrunt since he though that we are missing a few important points....

DEVSECOPS Talks #9-2020 - Terraform in CI 06.06.2020

How do you start to implement a CI pipeline when dealing with infrastructure as code implemented via Terraform? What are the security concerns when the credentials to the whole kingdom are used in an automated process? In this episode, we discuss the various security and feasibility aspects of using Terraform in a CI pipeline. We start the episode by catching up with what we’ve been working on. Fe...

DEVSECOPS Talks #8-2020 - DevOps What 25.05.2020

Andrey tells us the story of how DevOps came into existence and took over the market. We discuss the marketing around it, its relationship with DevSecOps. We tried to shed a light on what is marketing strategy versus implementing DevOps in an organization. We also compared DevOps to SRE (Site Reliability Engineering)

DEVSECOPS Talks #7-2020 - How do we learn 06.05.2020

In this episode, Mattias, Julien, and Andrey share tips and tricks on how to stay on top of what is going on in the industry, resources they use for continuous learning. Make sure to visit devsecops.fm to check out show notes that contain references to resources mentioned during discussion and more

DEVSECOPS Talks #6-2020 - SemVer or not to SemVer 06.05.2020

This time Johan Abildskov , a Senior Consultant with Praqma/Eficode , joins us to talk about SemVer (Semantic Versioning), and we finally get to hear what Julien has to say about it. We get to explore different options regarding versioning and how it helps humans communicate. At the end of the podcast, everyone gets to share their approach and recommendations for versioning things.

DEVSECOPS Talks #5-2020 - What we have been working on 07.04.2020

We had a couple of possible topics for this episode but before getting started with them we decided to discuss what technological problems we were solving during the last two weeks. Well, turns out there was quite a lot to discuss. Tune in for tips on ssh session logging on the ssh server, preventing downloads from AWS S3 even if you got read access, credentials in Git repository 🤦, why you shoul...

DEVSECOPS Talks #4-2020 - Is docker more secure then VM 26.03.2020

In this episode Mattias is trying to convince that running docker in k8s is more security then VM. Did he success ? listen and find out. Summary Mattias makes a bold claim: Docker containers are more secure than virtual machines. Andrey and Julien push back hard — and by the end, the three hosts explicitly agree to disagree. Along the way, they dig into why container breakouts are harder than peop...

Listen to the The DevSecOps Talks Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.