7 ms·
Difference between DevOps, SecOps and DevSecOps
- cyberpunk 5y agoUnfortunately here in Germany the majority of “devops” is just a bunch of operations people who maintain terraform and ansible markup, no real dev involved. DevSecOps seems to just be plugging sonarqube into ci pipelines and installing siem/wafs. Is it really better anywhere else?
- gonzo41 5y agoNope, we just use Jfrog Xray.
- allendoerfer 5y agoCan confirm and have a suspicion that OP is sitting right next to me.
- jstx1 5y agoWhat's bad about it? Apart from the name mismatch and that it could have been just "Ops".
- allendoerfer 5y agoAt least in my organization, these Ops people did not get the whole point about DevOps. They are basically just administering servers and using Ansible to do it. E.g. if a services does not start after running a playbook, they are logging in and restarting it, instead of fixing the playbook. Ansible runs on a weekly schedule instead of provisioning based on application needs. They have their own playbooks for standard systems and doing custom modifications through SSH, if you have special needs. I could go on. They just totally missed the point of DevOps, it's just Ops with DevOps tools. You can compare it with how we/they are doing agile.
- skywhopper 5y agoI would say your approach of blaming “them” for missing the point, misses the point. Think about your own responsibility. DevOps is not a single role in an org, but a way of doing business and collaborating between dev and ops teams. If your ops support is not sufficient for the devs’ needs, then the devs should be working with ops to fix it. If the devs are saying “oh, ops is no good at DevOps, so that’s why our deployment process sucks” then it’s as much the devs’ fault as the ops team.
- allendoerfer 5y agoAnd I am trying to do so every day. This is not some small operation, where I can just go over to a different desk and talk about just doing it differently. I am talking about an organization with hundreds of thousands of employees. In this case Ops is literally a different legal entity. I have no say whatsoever over "them". If you want to change something, it's more about constantly begging and nagging. It is a very fine line, you risk to become difficult to work with. After all, sometimes you actually need "them" to do something for you. It also costs a lot of energy. At some point most people just stop trying and focus on more important things in life.
- temp0826 5y agoMy last couple devops roles were somewhat this, involving mostly infra-type stuff. It's really a catch-all term for someone who keeps the "10000 foot view" of the product so the "real" devs can focus on their own little cog in the wheel. I usually absorbed all of the testing automation, centralized logging/metrics, "IT" (directory/ldap, backups), sane security and networking etc etc and ensured their was a coherent story soup-to-nuts. Wrote a lot of python/glue and "business"-oriented infrastructure management tools along the way. Had to be the point person for anything in the aws console, from dbs to vpns to docker containers to cdns etc etc and dealt with integrations to other saas/products as well
- q3k 5y agoIt is, but it's difficult to introduce. Just hiring 'devops' people for your ops team, or giving developers access to AWS is missing the whole damn point. It requires reorganizing work in a way that makes a lot of people angry, as they now have to do things that so far they've just tossed over the wall to another team and then complained loudly when that didn't work. You have to convince developers that they're responsible for making software easy to deploy and debug, and get them to carry pagers during work hours. You have to convince them to make the product internals clear for everyone, including to operations people, and get them to do knowledge exchange with them. You have to enable them by providing insight into production deployments and providing a platform that unifies production/development as much as possible without tons of boilerplate required per project (common database interfaces, common logging interfaces, common CI, common release procedures, common development environment). You have to convince operations teams to write programs in something other than bash, and to generally follow good software engineering practices, to write operations-level code that is as testable as the application itself. You have to enable them by giving them the means to build a company-wide production platform where complexity is decimated by moving every product team onto the simplest possible setup. You have to let them build bespoke tooling and accept that these lines of code are as important as the application code itself. With all of this implemented well, the differences between ops and dev roles will begin to blur, people with different backgrounds will mingle within and across teams, and you will end up with a more platform/product split between teams rather than a development/operations split.
- chazu 5y agoThis person gets it. Which is rare - do you want a job? :) But seriously, you hit upon something which is important, but very hard to communicate/admit - a big part of making the "DevOps Transformation" happen - which is a cheesy term but it conveys something better than just DevOps - is saying _no_ to devs and traditional SysAdmins and giving them a better alternative. Unfortunately this means that SysAdmin skillsets need to be supplemented or even supplanted by SWE skillsets. But the TL;DR is yes, doing DevOps often means putting the brakes on fun.
- tupac_speedrap 5y agoIt's the opposite where I work. We are "DevOps Engineers" but we spend most of our time writing Java and we get by using Kubernetes, Docker and Ansible but I always feel like we are scratching the surface a bit.
- raesene9 5y agoTo me, DevSecOps is mostly about seeing what tests can be done whilst not getting in the way of the development/deployment process too much. That's not a bad thing and there's meaningful security testing that can be done with that strategy, but it's hard to cover all aspects of security testing in a fully automated DevSecOps pipeline.
- trabant00 5y agoThis is getting more and more ridiculous. I even heard about GitOps (ops that use git). What is next? CliOps? Thank you for all the buzzwords without which poor sysadmin old me would've never heard of coding, automation, security, version control and so on. /s
- gls2ro 5y agoI think we miss some other Ops: ProdBizSupportUxGitDevSecOps - one person doing everything (or maybe I am msising some other Ops) On a more serious note I think there is a trend to ask a lot of deep knowledge from one single person in too many areas.
- skywhopper 5y agoGitOps does have a meaning beyond just “use git”. But you aren’t wrong that the strength of the meaning is rapidly fading as does any phrase that catches on with product marketing.
- hkt 5y agoI think this is an important point: startups hawking product are a strong source of entropy, undoing the work of practitioners who are trying to say coherent things to their intended audience of peers. It'd be nice to have a safe space away from those people, even if it was closed to the world at large.
- gls2ro 5y agoI like Git and probably GitOps does mean something. But I really don't like that has the name of a specific technology. What if someone is using Mercurial shoult it call themselves MercurialOps. I also find the definition odd: "GitOps is a way of implementing Continuous Deployment for cloud native applications" [0] At least DevOps is more generic and not JavaOps or DotNetOps or PythonOps. Also I would have nothing against naming things like this except that along with naming things like this a bunch of hiring people starts asking for this very specific skills as it is like basic literacy that everyone should know or (a little bit worse) suddently appearing 1000 courses and materials from 0 to XOps in 29 minutes and suddently Github and Twitter is flooded with small projects copying at infinitum the same exercise without being able to actually teach people the hard skills of solving problems and then translating solutions into a specific technology(ies). [0] https://www.gitops.tech/ https://www.gitops.tech/
- bovermyer 5y agoAll the *Ops words are just attempts by people to name things. None of these attempts are particularly helpful, except perhaps as conversation starters. I am not a "DevOps" engineer. I am a digital platform engineer, with specialization in writing code to connect things to other things. When I talk to people outside of tech, I just tell them I'm a software engineer. It's close enough.
- zikduruqe 5y agohttps://i.imgur.com/oNqfbL4.jpg https://i.imgur.com/oNqfbL4.jpg
- notwedtm 5y agoThe missing link here is that "Ops" should no longer be the traditional imperative, reactive approach to systems design and maintenance. Ops in all three of these becomes the modifier. This is why most practitioners today will tell you that DevOps/DevSecOps/SecOps are less individual titles and more a cultural way of thinking and operating and that the philosophy is executed by engineers of all types. It's important to remember the origins as well. Prior to DevOps, developers and operations teams were siloed in ways that hindered healthy growth in todays distributed systems and cloud environments. These "*Ops" terms were born of the necessity to impress upon people the importance of interoperability between traditionally isolated and independent departments. *Ops is the natural progression of Conway's Law into modern engineering organizations.
- dijit 5y agoHonestly I super hate the word “DevOps”. It doesn’t tell me anything about what you do; and it implies that sysadmins never used to code either. There are people pushing “devops tools” but those tools used to be called deployment or build tools. The word is pointless ambiguity. Additionally: the “title” was coined as the name of a conference to include developers. The actual intended job title (and original conference name) was “agile systems administrator” according to the person who invented the word (Patrick Dubois). http://blog.dijit.sh/devops-confusion-and-frustration http://blog.dijit.sh/devops-confusion-and-frustration
- nix23 5y ago>Honestly I super hate the word “DevOps”. Absolutely, i call myself adaptable Administrator ;)
- deleted 5y ago[deleted]
- Chyzwar 5y agoIn some companies, DevOps mean: developers do everything poorly, including ops. No dedicated Ops or security teams in company or applicable training for developers. In others companies it means separate siloed DevOps teams and people, You need to raise request to do anything on your servers. Sometimes deployment mean getting DevOps team approval in process. I also dislike DevOps terms because it is not specific enough on how you should organize Dev and Ops concerns.
- chazu 5y agoThis is why I like the 'platform engineering' meme - much better way to frame the value proposition. See: Thoughtworks' blogs and podcasts on platform-engineering-centric topics.
- aniou 5y agoToo often "DevOps" emerged as a way to walk around system administrators and their "blabling" about security, resource management, upgrades and long-term maintainability. I'm always upset when I see a installations that are created with pattern: "we need it to run and we doesn't care where system will be in next two years" (in trashcan, usually - or it will act as a jumphost for another scam/DDoS). And I see such systems everyday. And that dramas, when I ask a simple question like: "how it will be upgraded"? "What is your plan about dealing with manually-installed python modules that overwrites files from system-installed ones when system upgrade will be performed?" and so on, and so on... Fortunately a separate "devops" team that really cares about infrastructure reliability usually evolves into a normal sysadmins in no-time and their priorities are usually different that rest of "dev-teams".
- sparcpile 5y agoDevOps = sysadmin SecOps = sysadmin has to apply the CIS/SCAP/whatever security template to the machine DevSecOps = developer also has to apply the CIS/SCAP/whatever security template to their machine It all ends up becoming marketing jargon for suits looking to follow the next big trend.
- chazu 5y agoThis is absolutely wrong - DevOps is not a job title. At least it shouldn't be, as anyone in the sector will tell you. The conflation of DevOps responsibilities and specializations with SysAdmin work is the reason why the vast majority of "DevOps" teams are...vastly unqualified.
- drran 5y agoDevOps is a Developer which does Operational Support by writing code instead of performing operations manually. Sysadmin is a System Administrator, which performs operations manually.
- aniou 5y agoNot at all. Things like CFEengine (1993) and even Puppet predates a spread of "devops" term. Not mentioning tools for automated system installations, embedded in distributions like RedHat or Debian. Creating a tools, that allows us doing a simple, repeatable and - usually - automated tasks, always was an important part of sysadm role. Of course, there were ones that did everything manually and wasn't able to write own code: we called them "operators". From my point of view: "devop is that hasty one, that doesn't care about long-term support of underlying infrastructure".
- drran 5y ago> Not at all. Things like CFEengine (1993) and even Puppet predates a spread of "devops" term. Not mentioning tools for automated system installations, embedded in distributions like RedHat or Debian. Yep. > Creating a tools, that allows us doing a simple, repeatable and - usually - automated tasks, always was an important part of sysadm role. Of course, there were ones that did everything manually and wasn't able to write own code: we called them "operators". Yep. > From my point of view: "devop is that hasty one, that doesn't care about long-term support of underlying infrastructure". Nope. https://en.wikipedia.org/wiki/DevOps https://en.wikipedia.org/wiki/DevOps
- polotics 5y agoArgh, one particularly clueless mgr once went on about DevSecOps vs. SecDevOps and the cringe factor was so high I almost resigned on the spot.
- aaccount 5y agoThese are temporary job titles since most of the IT work these days comprise of gluing things together. I think these types of jobs will vanish with in the decade due to platforms like Microsoft's power platform or dynamics 365.
- CrazyPyroLinux 5y agoI'm sure this is redundant, but since no one has mentioned yet: "The Phoenix Project" and "The Unicorn Project" are awesome books for this, and I recommend them both in audiobook.