DEV Community

William Rodriguez
William Rodriguez

Posted on

Automated DevSecOps: Nmap, Fail2Ban & Hash verification steps.

Automated DevSecOps: Nmap, Fail2Ban & Hash verification steps.

DevSecOps shouldn't mean writing brittle shell scripts that grep nmap output. wpipe-steps provides native security steps for port scanning, IP ban checks, and cryptographic hashing.

Here is how you use Nmap, Fail2Ban & Hash Generator Steps in a production pipeline with wpipe-steps:

from wpipe import Pipeline
from wpipe_steps.security import NmapScanStep, Fail2BanCheckStep, HashGeneratorStep

pipeline = Pipeline(pipeline_name="infra_security_audit")

pipeline.set_steps([
    # 1. Verify target IP is not banned
    Fail2BanCheckStep.as_step(
        name="check_reputation",
        ip="192.168.1.50",
        response_key="ban_status"
    ),
    # 2. Audit open services
    NmapScanStep.as_step(
        name="scan_ports",
        target="192.168.1.50",
        arguments="-sT -p 80,443,22",
        response_key="scan_results"
    ),
    # 3. Checksum security artifact
    HashGeneratorStep.as_step(
        name="checksum_report",
        algorithm="sha256",
        file_path="/var/log/audit.log",
        response_key="log_checksum"
    )
])

result = pipeline.run({})
print("Audit complete:", result["scan_results"])
Enter fullscreen mode Exit fullscreen mode

Why developers love wpipe-steps:

  • 196 cataloged steps covering Redis, ClickHouse, MySQL, WAF, S3, Docker, and local HuggingFace AI.
  • Lazy-loading imports for instant sub-100ms startup times.
  • Clean .as_step() factory interface.

Check out the full repository on GitHub!

Top comments (0)