Book Image

Learning DevOps - Second Edition

By : Mikael Krief
Book Image

Learning DevOps - Second Edition

By: Mikael Krief

Overview of this book

In the implementation of DevOps processes, the choice of tools is crucial to the sustainability of projects and collaboration between developers and ops. This book presents the different patterns and tools for provisioning and configuring an infrastructure in the cloud, covering mostly open source tools with a large community contribution, such as Terraform, Ansible, and Packer, which are assets for automation. This DevOps book will show you how to containerize your applications with Docker and Kubernetes and walk you through the construction of DevOps pipelines in Jenkins as well as Azure pipelines before covering the tools and importance of testing. You'll find a complete chapter on DevOps practices and tooling for open source projects before getting to grips with security integration in DevOps using Inspec, Hashicorp Vault, and Azure Secure DevOps kit. You'll also learn about the reduction of downtime with blue-green deployment and feature flags techniques before finally covering common DevOps best practices for all your projects. By the end of this book, you'll have built a solid foundation in DevOps and developed the skills necessary to enhance a traditional software delivery process using modern software delivery tools and techniques.
Table of Contents (25 chapters)
1
Section 1: DevOps and Infrastructure as Code
7
Section 2: DevOps CI/CD Pipeline
11
Section 3: Containerized Microservices with Docker and Kubernetes
14
Section 4: Testing Your Application
18
Section 5: Taking DevOps Further/More on DevOps

Exploring SonarQube

SonarQube is an open source tool from SonarSource (https://www.sonarsource.com/) that's written in Java. It allows us to perform static code analysis to verify the quality and security of an application's code.

SonarQube is designed for developer teams and provides them with a dashboard and reports that are customizable so that they can present the quality of the code in their applications.

It allows for the analysis of static code in a multitude of languages (over 25), such as PHP: Hypertext Preprocessor (PHP), Java, .NET, JavaScript, Python, and so on. A complete list can be found at https://www.sonarqube.org/features/multi-languages/.

In addition, apart from code analysis with security issues, code smell, and code duplication, SonarQube also provides code coverage for unit tests. For more details about these issue concepts, read the documentation here: https://docs.sonarqube.org/latest/user-guide/concepts/.

Finally, SonarQube integrates...