DevSecOps in Cloud‐Based Container Platform

Abbas Kudrati, Sina Manavi, Muhammed Aizuddin Zali · 2025

DevSecOps is an evolution of DevOps that integrates security practices into the entire software development lifecycle. This chapter explores the intersection of DevSecOps and cloud-based containers. It discusses the key principles and practices of DevSecOps and how they can be applied to secure containerized applications running on Azure, GCP, and AWS. The chapter delves into topics such as integrating security into cloud continuous integration/continuous delivery (CI/CD) pipelines, performing static application security testing (SAST) and dependency analysis, securing infrastructure as code, managing secrets, implementing continuous monitoring and alerts, and leveraging cloud-based DevSecOps tools and frameworks. CI/CD pipelines are a fundamental aspect of DevOps practices. The chapter provides some key practices for integrating security into cloud CI/CD pipelines. SAST and dependency analysis are two critical practices in the DevSecOps approach to securing containerized applications in cloud environments.

Read the paper · More papers on PaperTik