The DevOps HandbookDEPLOYMENT PIPELINE i. CD pipelines represent a new attack surface. If not properly secured, credentials could be compromised or malicious code & changes injected. 1. Harden CI/CD servers and ensure they calls from certain types of test code) 4. Ensure every CI process is in an isolated container 5. Make the version control credentials of the CI system read-only 3. Ch. 23 – Protecting the Deployment0 码力 | 9 页 | 25.13 KB | 5 月前3
The DevOps Handbookdue to integrating late in the lifecycle. Downward spiral of pain b. HP LaserJet Firmware –i. Before CI: 2 releases per year. 5% of effort supporting new features, 20% on detailed planning, 25% on porting branches, 10% integrating, 15% manual testing. ii. Implemented Trunk-based development & CI iii. After CI: 40% effort on new features, 40% decrease in development costs, 140% increase in programs under dependency improvements often provide high-payoffs d. ADOPT TRUNK-BASED DEVELOPMENT PRACTICES i. CI and Trunk-based development (TBD) are countermeasures to large batch size ii. TBD enables: 1. Frequent0 码力 | 8 页 | 23.08 KB | 5 月前3
The DevOps Handbookmonitoring 1. Create telemetry in application & environments (to include production, pre-production, and CD pipeline) iii. Ian Malpass, Etsy – “If Engineering at Etsy has a religion, it’s the Church of Graphs identify opportunity costs. d. INTEGRATE A/B TESTING INTO OUR RELEASE i. A/B testing requires fast CD to support ii. Use feature toggles to control experiments, cohort creation, etc. iii. Use telemetry0 码力 | 8 页 | 24.02 KB | 5 月前3
MITRE Defense Agile Acquisition Guide - Mar 2014Requirements Definition Packages (RDPs) to capture a subset of the IS ICD scope and/or Capability Drop (CD) documents for smaller items such as applications (see Figure 13). Services and requirements oversight As illustrated in Figure 14, each RDP captures a set of requirements prioritized for a release. A CD captures the release backlog requirements allocated to a sprint and forms the basis for a sprint backlog ACAT Acquisition Category BCL Business Capability Lifecycle BPA Blanket Purchase Agreement CD Capability Drop CDD Capability Development Document CONOPS Concept of Operations COTS Commercial0 码力 | 74 页 | 3.57 MB | 5 月前3
Open Discussion on Project PlanningRequirements Definition Packages (RDPs) to capture a subset of the IS ICD scope and/or Capability Drop (CD) documents for smaller items such as applications o Replace comprehensive Preliminary Design Reviews0 码力 | 2 页 | 49.30 KB | 5 月前3
共 5 条
- 1













