Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How to get GitOps right with infrastructure as code security

Blog post from GitLab

Post Details
Company
Date Published
Author
Ulrica de Fort-Menares
Word Count
682
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

In the digital age, organizations must embrace digital transformation to remain competitive, often transitioning to a DevOps model to enhance development and infrastructure processes. While development has long benefited from DevOps practices, infrastructure has lagged behind, particularly in speed, but the use of Infrastructure as Code (IaC) and GitOps is changing this by enabling infrastructure teams to apply application code management disciplines to deliver products faster and more predictably. Security, however, can be a bottleneck, especially when testing is tacked on at the end of the delivery cycle. To address this, the integration of Indeni Cloudrail with GitLab CI/CD allows for IaC security checks to be shifted left, integrating security controls early in the development lifecycle and automating infrastructure compliance. This shift-left approach minimizes the disruption caused by noisy security tools, as Indeni Cloudrail uses context-based analysis to reduce false positives, ensuring only critical security concerns are flagged. By combining their strengths, Indeni and GitLab support organizations' digital transformation efforts by streamlining IaC security within the familiar GitOps framework, promoting faster and more reliable deployments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.