Skip to Content
Cloud Native Application Protection Platforms
book

Cloud Native Application Protection Platforms

by Russ Miles, Stephen Giguere, Taylor Smith
September 2024
Intermediate to advanced
206 pages
5h 30m
English
O'Reilly Media, Inc.
Audiobook available
Content preview from Cloud Native Application Protection Platforms

Chapter 6. Continuous Delivery, Continuous Insecurity

An army marches on its stomach.

Napoleon Bonaparte (or Frederick the Great)

You get out what you put in.

Jeanette Jenkins

In the previous chapter, you used a CNAPP to secure your dependencies. This meant the pre-packed boxes of code, libraries, frameworks, and containers that your applications depend upon, packaged and supplied by third parties, were all scanned and free from any known vulnerabilities. While you can’t claim to be vulnerability-free,1 you’ve got a grip on your supply chain and some strong OODA loops back to your developers so they can be aware of and fix problems as they arise across all those dependencies.

You’ve secured the packages, but what about your own packager? What about the processes that you run, whose sole responsibilities are to process and package your own code and then collate your third-party dependencies into the artifacts that can then be deployed and released at runtime? There’s many a slip ‘twixt the cup and the lip or, in our case, there’s many a vulnerability between commit and deploy. Something has to do the building, the packaging, the deploying and releasing. And in all that activity contains a myriad of possibilities for a malicious actor to seize control.

It’s time to secure a new realm of your cloud native application. It’s time to secure the continuous integration and delivery (CI/CD) pipeline.

CI/CD Pipelines: The Arteries of Production

In many respects, we’d done our best. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Cloud Without Compromise

Cloud Without Compromise

Paul Zikopoulos, Christopher Bienko, Chris Backer, Chris Konarski, Sai Vennam
How to Develop a Great Digital Strategy

How to Develop a Great Digital Strategy

Jeanne W. Ross, Cynthia M. Beath, Ina M. Sebastian

Publisher Resources

ISBN: 9781098141691Errata Page