[{"data":1,"prerenderedAt":35},["ShallowReactive",2],{"blog-tag-en-devsecops":3},[4,16,25],{"path":5,"title":6,"description":7,"date":8,"tags":9},"\u002Fblog\u002Fen\u002Fgitlab-auto-devops-k3s-admission-controller-gate","Why GitLab Auto DevOps' 'It Just Works' CI Is the Closest Threat to Your Production K3s Cluster","GitLab Auto DevOps runs SAST\u002FDAST automatically the moment you turn it on. But a scan 'running' and a vulnerable image never reaching your production K3s cluster are two completely different things. Here's how to build an audit gate between CI\u002FCD and the cluster.","2026-08-17",[10,11,12,13,14,15],"k3s","kubernetes","gitlab","ci-cd","devsecops","admission-controller",{"path":17,"title":18,"description":19,"date":20,"tags":21},"\u002Fblog\u002Fen\u002Fcicd-pipeline-security-devsecops","ci-cd Pipeline Security: A Practical DevSecOps Guide","A practical guide to ci-cd pipeline security from a DevSecOps perspective. Covers SAST\u002FDAST, supply chain protection, the SLSA framework, and Policy as Code.","2026-05-27",[14,13,22,23,24,11],"security","supply-chain","slsa",{"path":26,"title":27,"description":28,"date":20,"tags":29},"\u002Fblog\u002Fen\u002Fdocker-security-scanning-best-practices","Docker Container Security: Scanning and Vulnerability Management","A practical guide to integrating vulnerability scanning into your container ci-cd pipeline. Compare Trivy, Snyk, and Grype, implement shift-left security, and build defense-in-depth with Harbor.",[30,22,31,32,33,34,14],"docker","vulnerability-scanning","trivy","snyk","container-security",1787649525966]