<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: DKFM</title>
    <description>The latest articles on DEV Community by DKFM (@dkfm).</description>
    <link>https://dev.to/dkfm</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3644%2F64f7fec7-eb87-43a9-92c8-de0b6d16c79d.png</url>
      <title>DEV Community: DKFM</title>
      <link>https://dev.to/dkfm</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/dkfm"/>
    <language>en</language>
    <item>
      <title>We are DKFM - Making DevOps things that make DevOps things easier</title>
      <dc:creator>DJ Schleen</dc:creator>
      <pubDate>Sat, 29 May 2021 14:25:33 +0000</pubDate>
      <link>https://dev.to/dfkm/we-are-dkfm-making-devops-things-that-make-devops-things-easier-8o8</link>
      <guid>https://dev.to/dfkm/we-are-dkfm-making-devops-things-that-make-devops-things-easier-8o8</guid>
      <description>&lt;p&gt;DevOps, DevSecOps, Rainbow Monkey Unicorn Pony, it really doesn't matter what you call it but one thing is certain - every one of these practices relies on innovative tooling to shift quality issues left to developers. Innovation is something I needed to turn to as a Security Architect many years ago as I built and deployed DevSecOps practices to a few Fortune 10 healthcare organizations.&lt;/p&gt;

&lt;p&gt;When I met Julio Jimenez &lt;a class="mentioned-user" href="https://dev.to/juliojimenez"&gt;@juliojimenez&lt;/a&gt;
 we struck up a great friendship built on a shared vision of developing tools that would blur the line between Security and DevOps. We became &lt;a href="https://www.amazon.com/Essentialism-Disciplined-Pursuit-Greg-McKeown/dp/0804137382"&gt;Essentialists&lt;/a&gt; and adopted the mantra that security is just an attribute of quality. With that, we focused on developing tools that improve the quality of the code we built.&lt;/p&gt;

&lt;p&gt;After Dan Walsh joined DKFM we had our core team and our Open Source collective started gaining industry attention from the tools we were building. Dan brought the business savvy, leadership, product direction, and more Essentialism to our team.&lt;/p&gt;

&lt;h2&gt;
  
  
  Dropping the Code Hammer
&lt;/h2&gt;

&lt;p&gt;Now that our core team was put together,Julio and I migrated a number of personal repositories we had been working on for the past few years to our new GitHub organization we named &lt;a href="https://github.com/devops-kung-fu"&gt;DKFM&lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;The first project we worked on together as DKFM was &lt;a href="https://github.com/devops-kung-fu/shs"&gt;SHS&lt;/a&gt;, which is a tool that calculates a risk score based on vulnerabilities in source code and infrastructure and presents in the format of a credit score.&lt;/p&gt;

&lt;p&gt;Our second project was &lt;a href="https://github.com/devops-kung-fu/domi"&gt;domi&lt;/a&gt;. domi is one of our flagship codebases. It is a policy-as-code enforcer that analyzes infrastructure as code and configuration for policy violations. It integrates with GitHub and uses &lt;a href="https://www.openpolicyagent.org/"&gt;Open Policy Agent&lt;/a&gt; and &lt;a href="https://github.com/open-policy-agent/conftest"&gt;conftest&lt;/a&gt; to validate code on a Pull Request.&lt;/p&gt;

&lt;p&gt;Other projects followed such as &lt;a href="https://github.com/devops-kung-fu/gardener"&gt;gardener&lt;/a&gt; which generates images in markdown from &lt;a href="https://plantuml.com"&gt;PlantUML&lt;/a&gt; diagrams, &lt;a href="https://github.com/devops-kung-fu/hookz"&gt;Hookz&lt;/a&gt; which generates local action pipelines as git hooks that execute when interacting with the git command, and &lt;a href="https://github.com/devops-kung-fu/hinge"&gt;Hinge&lt;/a&gt; that builds dependabot.yaml files for any codebase that is used by GitHub's Dependabot supply chain scanning product. We've started or are working actively on many other projects. All to make DevOps things that make DevOps easier.&lt;/p&gt;

&lt;h2&gt;
  
  
  Join the Movement
&lt;/h2&gt;

&lt;p&gt;As an open source collective &lt;strong&gt;anyone&lt;/strong&gt; can join DKFM. All you need to do is contribute to any of our &lt;a href="https://github.com/devops-kung-fu"&gt;DKFM&lt;/a&gt; projects on GitHub. &lt;/p&gt;

&lt;p&gt;Come and help us make tools that shift left, integrate security as an attribute of quality, and lead by example with  Essentialism and innovation.&lt;/p&gt;

</description>
      <category>devops</category>
      <category>automation</category>
      <category>tools</category>
      <category>cicd</category>
    </item>
  </channel>
</rss>
