Skip to content
Beta

TM1: Security Big Picture

Last updated on

1. Motivation: Why Cloud Security is Different

Section titled “1. Motivation: Why Cloud Security is Different”

Unlike traditional on-premise environments (“Boundary Security”), the cloud operates on the Shared Responsibility Model:

  • STACKIT Responsibility: Security of the Cloud (Data centers, Hardware, Host OS).
  • User Responsibility: Security in the Cloud (Network config, Encryption, App Security, Data).

2. The Security Big Picture (Lines of Defense)

Section titled “2. The Security Big Picture (Lines of Defense)”

Code & Supply Chain Security * 4-Eye-Principle: Mandatory reviews for every Pull Request. * Vulnerability Scanning: Using Snyk to identify vulnerabilities in libraries.


Security is defined as code and rolled out automatically:

  1. Templates: Integration of pre-built security modules in the CI/CD pipeline.
  2. Secrets Manager: Secure credential retrieval via Hashicorp Vault. 3. Automated Guardrails: Temporary opening and automatic resealing of ACLs during deployment.

Asset historyActive 6 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
Maintainers
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172??Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.Contributed in Open Contributors
Show full history (9 more)