<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DevOps - STEP Software</title>
	<atom:link href="https://www.stepsoftware.com/tag/devops/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.stepsoftware.com</link>
	<description>Custom Software Development</description>
	<lastBuildDate>Fri, 03 May 2024 16:22:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.stepsoftware.com/wp-content/uploads/2025/02/FaviconFoxOnDark_512-150x150.png</url>
	<title>DevOps - STEP Software</title>
	<link>https://www.stepsoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Luna-25 and Chandrayaan-3 tell two very different stories for developers</title>
		<link>https://www.stepsoftware.com/luna-25-and-chandrayaan-3-tell-two-very-different-stories-for-developers/</link>
					<comments>https://www.stepsoftware.com/luna-25-and-chandrayaan-3-tell-two-very-different-stories-for-developers/#respond</comments>
		
		<dc:creator><![CDATA[Carmi Levy]]></dc:creator>
		<pubDate>Fri, 25 Aug 2023 19:44:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[chandrayaan3]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[luna25]]></category>
		<category><![CDATA[moon]]></category>
		<category><![CDATA[software development]]></category>
		<category><![CDATA[space]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1512</guid>

					<description><![CDATA[<p>As space missions go, Russia’s Luna-25 and India’s Chandrayaan-3 couldn’t have been more different.</p>
<p>Russian space officials said their lunar probe “moved into an unpredictable orbit and ceased to exist as a result of a collision with the surface of the Moon” as it attempted a soft landing on August 19. India’s mission, however, successfully soft-landed on the Moon’s south pole four days later, a milestone Prime Minister Narendra Modi said, “belongs to all humanity.”</p>
<p>As dramatic as both missions were and are, they hold critical lessons for software developers in terms of what to do – and not to do – when planning and executing a project.</p>
<p>The post <a href="https://www.stepsoftware.com/luna-25-and-chandrayaan-3-tell-two-very-different-stories-for-developers/">Luna-25 and Chandrayaan-3 tell two very different stories for developers</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">UNDERSTANDING THE WHY</h3>



<p class="wp-block-paragraph">It could be months before investigators figure out what happened to Russia’s robotic probe in the critical moments as it maneuvered above the lunar surface.</p>



<p class="wp-block-paragraph">Yuri Borisov, Director General of Russia’s space agency, Roscosmos,&nbsp;<a href="https://apnews.com/article/russia-moon-crash-luna-25-roscosmos-space-228fc0caf6f84b4a2c7c8484cfd337be" target="_blank" rel="noreferrer noopener">blamed a botched engine burn</a>&nbsp;for the disaster. He said a planned 84-second engine burn that was supposed to put the probe into a “pre-landing orbit”, instead ran for 127 seconds.&nbsp;</p>



<p class="wp-block-paragraph">The mission was Russia’s first since 1976, when the Soviet Union lofted&nbsp;<a href="https://nssdc.gsfc.nasa.gov/nmc/spacecraft/display.action?id=1976-081A" target="_blank" rel="noreferrer noopener">Luna-24</a>&nbsp;toward Earth’s nearest neighbour. Borisov said failure to carry forward institutional knowledge from the earlier mission contributed to the Luna-25 outcome.</p>



<p class="wp-block-paragraph">“The negative experience of interrupting the lunar program for almost 50 years is the main reason for the failures,” he said. “The priceless experience that our predecessors earned in the 1960-70s was effectively lost. The link between generations has been cut.”</p>



<p class="wp-block-paragraph">Given the Russian government’s traditionally fraught relationship with truth and transparency, we may never learn the actual cause.</p>



<h3 class="wp-block-heading">THE INVASION RIPPLE EFFECT</h3>



<p class="wp-block-paragraph">Truthiness in Vladimir Putin’s Russia notwithstanding, even a cursory examination of the mission highlights clear issues with development timelines and resourcing. Global sanctions imposed on Russia following its February 2022 invasion of Ukraine severely hampered mission planners as they finalized and ground-tested the vehicle.&nbsp;<a href="https://apnews.com/article/russia-moon-luna25-spacecraft-mission-33c9884c907998f06bf9562be6d47445" target="_blank" rel="noreferrer noopener">Component shortages hampered progress</a>&nbsp;as engineers scrambled to implement workarounds.</p>



<p class="wp-block-paragraph">The original design of Luna-25 was supposed to include a landing camera from the European Space Agency (ESA). But the ESA ended its partnership with Roscosmos after the invasion and ordered the Russians to delete their equipment from the vehicle. Technology transfer restrictions imposed on Russia also prevented it from buying a critical navigation unit from Airbus, forcing Roscosmos to develop a homegrown unit twice as heavy as the original.</p>



<p class="wp-block-paragraph">Tight timelines didn’t help. Natan Eismont, a researcher with the Institute for State Research in Moscow,&nbsp;<a href="https://www.cbncompass.ca/a-failed-lunar-mission-dents-russian-pride-and-reflects-deeper-problems-in-moscows-space-industry/" target="_blank" rel="noreferrer noopener">told the state RIA Novosti agency</a>&nbsp;despite equipment problems that dogged the project all along, Roscosmos refused to delay the launch.&nbsp;<a href="https://www.youtube.com/watch?v=WgNBKqI94qk" target="_blank" rel="noreferrer noopener">Russian space blogger Vitaly Egorov</a>&nbsp;said Russia wanted to land before Chandrayaan-3.</p>



<p class="wp-block-paragraph">“It looks like things weren’t going according to plan,” he said, “but they decided not to change the schedule to prevent the Indians from coming in first,”</p>



<p class="wp-block-paragraph">Luna-25’s failure echoed that of the ill-starred&nbsp;<a href="https://solarsystem.nasa.gov/missions/phobos-grunt/in-depth/" target="_blank" rel="noreferrer noopener">Phobos-Grunt</a>&nbsp;sample return mission in 2011 that was supposed to explore the Mars moon Phobos. Instead, the earlier mission failed to execute a critical burn in Earth orbit and crashed back into the Pacific. Investigators blamed the use of off-the-shelf microchips that couldn’t stand up to the radiation and heat extremes of space.</p>



<h3 class="wp-block-heading">KEY TAKEAWAYS FOR DEVELOPERS</h3>



<p class="wp-block-paragraph">Russian opaqueness and troubling history notwithstanding, the Luna-25 narrative is already informing developers both inside – and far beyond – the space industry. Developers in particular might want to keep the following critical lessons in mind:</p>



<ol class="wp-block-list">
<li><strong>Be flexible on timing.</strong>&nbsp;On-time delivery of complex projects is always a challenge, and rigid adherence to a timeline is decidedly not always the way to go. By forcing engineers to stick to the original schedule despite ongoing component shortages and redesigns, Luna-25’s leadership forced compromises that resulted in a flawed vehicle that was unfit for the mission. Extra time might have allowed these gaps to be addressed, but we’ll never know now.</li>



<li><strong>Don’t skimp on testing.</strong>&nbsp;Whatever scenario Luna-25 encountered that caused its engine to fire for 50% longer than planned, it’s clear the in-development testing regime failed to account for everything that could happen in flight. It may seem like a quick way to prevent the timeline from slipping to the right, but skimping on testing and simulation adds huge risk to any project. This applies not only in the harsh environment of space, but even within the most mundane software development projects.</li>



<li><strong>Focus on error handling.</strong>&nbsp;As systems become increasingly automated, their ability to autonomously – and gracefully – recover from unexpected events becomes ever more critical to successful final outcomes. Robust, clean, elegant code sets the stage for systems that adapt to uncertainty – both in-orbit and back on Earth.</li>



<li><strong>Document in parallel.</strong>&nbsp;The admission by Roscosmos’s leader that they didn’t learn from earlier missions is a troubling one that fails to honour Russia’s storied space history. Proper documentation – performed in lockstep with project execution – can go a long way toward preserving institutional knowledge and ensuring it remains accessible to developers for future projects.</li>



<li><strong>Learn from every mistake.</strong>&nbsp;Chandrayaan-3’s successful landing comes less than 4 years since the Vikram lander separated from the Chandrayaan-2 orbiter and crashed into the Moon while attempting to land on the south pole. The Indian Space Research Organization (ISRO) launched a public inquiry, and folded learnings directly into the Chandrayaan-3 mission.</li>
</ol>



<h3 class="wp-block-heading">THE BOTTOM LINE</h3>



<p class="wp-block-paragraph">Every project now depends to a certain degree on software – and this is just as true down here on terra firma as it is in outer space. Whether you’re a space-nerd or not, the lessons from Luna-25’s failure and Chandrayaan-3’s success should give you cause to reflect on your own development experiences.</p>



<p class="wp-block-paragraph">In the meantime, we’re working on an exciting new platform that will also help inform your future development experiences. We call it the StringNetwork, and you can&nbsp;<a href="https://www.stringnetwork.com/" target="_blank" rel="noreferrer noopener">sign up here to learn more</a>.</p><p>The post <a href="https://www.stepsoftware.com/luna-25-and-chandrayaan-3-tell-two-very-different-stories-for-developers/">Luna-25 and Chandrayaan-3 tell two very different stories for developers</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/luna-25-and-chandrayaan-3-tell-two-very-different-stories-for-developers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DevSecOps: Why It&#8217;s Important and How To Achieve It</title>
		<link>https://www.stepsoftware.com/devsecops-why-its-important-and-how-to-achieve-it/</link>
					<comments>https://www.stepsoftware.com/devsecops-why-its-important-and-how-to-achieve-it/#respond</comments>
		
		<dc:creator><![CDATA[STEP Software]]></dc:creator>
		<pubDate>Thu, 07 Nov 2019 20:06:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software development]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1843</guid>

					<description><![CDATA[<p>DevOps is a cultural movement that has taken software development by storm over the last decade. The idea of DevOps is to encourage increased collaboration between software developers and IT operations through automation, tools, and best practices. The core aim of DevOps is to shorten software development cycles, leading to more frequent software releases.</p>
<p>An important flaw in the original DevOps movement is that software security remains an afterthought. This article overviews an updated approach--DevSecOps--in which security is embedded throughout the software development process. You will also find some useful best practices on how to effectively embed security in DevOps teams.</p>
<p>The post <a href="https://www.stepsoftware.com/devsecops-why-its-important-and-how-to-achieve-it/">DevSecOps: Why It’s Important and How To Achieve It</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">What Is DevSecOps?</h3>



<p class="wp-block-paragraph">In essence, DevSecOps is a refinement of the original DevOps concept that puts more emphasis on the importance of application security. Many cybersecurity incidents are the result of security flaws in an application&#8217;s code. There is a strong argument that the DevOps movement&#8217;s focus on faster software deployment acts as a barrier to developing secure software.</p>



<p class="wp-block-paragraph">Software security teams are tasked with ensuring that vulnerable code is not released into production. Traditionally, security teams implement rigorous testing to verify the integrity and security of applications. However, security testing takes up valuable time, and time is of the essence in DevOps teams. There is a clear conflict between the goals of security teams and the ideals of the DevOps movement.</p>



<p class="wp-block-paragraph">Security tests and checks are carried out at the end of development cycles in DevOps, however, there is often simply not enough time to properly audit code. The DevSecOps movement advocates embedding security practices and tools in the design of an application. In DevSecOps, security requirements are considered from the outset, which helps to better ensure watertight software security.</p>



<h3 class="wp-block-heading">DevSecOps Best Practices</h3>



<p class="wp-block-paragraph">There are several opportunities to ingrain security into the workflows of DevOps teams. The general goal is that software security requirements should be met without compromising the fluidity and speed inherent in DevOps development cycles. Consider the following best practices for achieving alignment with a DevSecOps mindset.</p>



<p class="wp-block-paragraph"><strong>Security Test Automation</strong></p>



<p class="wp-block-paragraph">Automation is a vital aspect of the DevOps philosophy because it speeds up development by automating repetitive tasks. Security teams can speed up their testing through increased automation, and it is prudent to introduce these tests as early as possible in each development cycle.</p>



<p class="wp-block-paragraph"><strong>Emphasize Supply Chain Security</strong>&nbsp;</p>



<p class="wp-block-paragraph">A number of high-profile cybersecurity incidents in recent years have arisen due to open source vulnerabilities. Developers often use libraries and frameworks from open source projects as part of the development of applications. The infamous Equifax data breach occurred as a result of using a vulnerable version of the open-source Apache Struts web framework.</p>



<p class="wp-block-paragraph">Security teams must create policies that emphasize software supply chain security. Developers need to be encouraged to properly source the libraries and frameworks they use. Patches should be applied as soon as possible, and build automation tools can provide visibility into vulnerable software components that require patching.</p>



<p class="wp-block-paragraph"><strong>Facilitate Speed and Precision</strong></p>



<p class="wp-block-paragraph">Security teams need to remember that heir tests and checks must be completed both quickly and accurately. Security tools suited for DevOps teams would ideally be able to identify vulnerable code as it is being written because this facilitates immediate action to rectify those vulnerabilities.</p>



<p class="wp-block-paragraph"><strong>Train Developers in Application Security</strong></p>



<p class="wp-block-paragraph">A surprisingly high number of developers are never taught how to securely code software. Third-level computer science courses typically emphasize the logistics of programming and instruct developers on how to build functional code.</p>



<p class="wp-block-paragraph">Infosec teams need to convince stakeholders at organizations to invest in training for developers on application security. Security teams could run these courses, and they would equip developers with a level of knowledge that would lead to long-term benefits in achieving a secure DevOps culture.</p>



<h3 class="wp-block-heading">The Time for DevSecOps is Now</h3>



<p class="wp-block-paragraph">DevSecOps is a crucial evolution in the DevOps movement. Make sure everyone at your organization understands the costs and risks of releasing vulnerable software into production. Make changes to embed security into DevOps teams and leverage some of the aforementioned best practices.</p><p>The post <a href="https://www.stepsoftware.com/devsecops-why-its-important-and-how-to-achieve-it/">DevSecOps: Why It’s Important and How To Achieve It</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/devsecops-why-its-important-and-how-to-achieve-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
