Weaveworks 2022.03 release featuring Magalix PaC | Learn more
Balance innovation and agility with security and compliance
risks using a 3-step process across all cloud infrastructure.
Step up business agility without compromising
security or compliance
Everything you need to become a Kubernetes expert.
Always for free!
Everything you need to know about Magalix
culture and much more
In January of this year, Magalix joined forces with Weaveworks, the GitOps company, to enable trusted application delivery, and to strengthen customers’ ability to securely deploy Kubernetes applications. Magalix's powerful policy as code capabilities will extend the GitOps pipeline with governance, verification, and security.
In this blog, we will briefly describe what Trusted Application Delivery is, how it can secure the GItOps pipeline, and share some relevant resources on the topic.
Trusted application delivery is the practice of embedding policy as code into the software delivery pipelines. These policies can be anything from company policies, to security best practices to industry-mandated compliance standards. Otherwise known as developer guardrails, these policies will detect any vulnerabilities or defects and prevent any new code from being deployed.
The automated and built-in guardrails enable DevOps teams to speedily deploy applications, securely and confidently. Any vulnerabilities or defects are caught early on in the development lifecycle.
Policies can be classified into 3 types:
Trusted application delivery solution is available now through Weave GitOps, the full-stack GitOps platform. Using the OPA-based (Open Policy Agent) policies enables policy-driven deployment and operation automation. With Trusted delivery, misconfigurations are automatically detected, alerts sents, and the deployment halted.
The solution includes Weave Policy Library: a curated libary of hundreds of policies covering security, resilience, and coding standards, all of which are stored in Git.
Policy checks can be automatically triggered at various points in the CI/CD pipeline:
Resources:
Read our latest whitepaper “Trusted Delivery with GitOps and Policy as Code” to learn more about automating security and compliance checks using policy as code. For more information about Weave GitOps, visit the Weave GitOps product page or contact us for a demo now.
Empower developers to delivery secure and compliant software with trusted application delivery and policy as code. Learn more.
Automate your deployments with continuous application delivery and GitOps. Read this blog to learn more.
This article explains the differences between hybrid and multi-cloud model and how GitOps is an effective way of managing these approaches. Learn more.
Implement the proper governance and operational excellence in your Kubernetes clusters.
Comments and Responses