Skip to content

DevOps · DevSecOps · SRE · Platform Engineering

The DevSecOps Handbook#

An opinionated, actionable reference that works in production — not a conference slide deck, but a reference that earns its keep on-call. Every section runs what → how → why, and ends with an anti-pattern table and a production checklist. Written in Turkish, with deep TR/EU regulatory coverage.

21topics
134deep-dives
9cheatsheets
19templates
85K+lines

Why this handbook

What makes it different#

  • Actionable


    Every section follows "what / how / why". Not a buzzword list — steps you can apply today and commands that run.

  • Placeholder-safe


    No real IPs/credentials. The <TARGET_IP>, <NAMESPACE> convention — enforced automatically in CI.

  • 2026 stack


    CloudNativePG, Karpenter, OpenTofu, Cilium ambient, Gateway API, vLLM. No stale advice.

  • TR-specific


    KVKK, BDDK, Wazuh, Iyzico stack notes. Not just an English translation — local engineering.

Starting from scratch?#

Not a reading list but a curriculum: read → build → verify → go back if you fail → move on if you pass. 6 blocks, 29 modules, labs + "broken labs" + certification gates. It never leaves you asking "what now?".

Enter the Learning Path Study method


Use cases

What brought you here?#


Knowledge base · 21 topics · 134 deep-dives

Categories#

Culture & People#

Sustainable teams, blameless culture, on-call health.

Build & Ship#

From source to production: version, pipeline, infra, containers, orchestration.

Run & Observe#

Run, see, protect: observability, security, networking, data, SRE.

Optimize & Evolve#

Cost, platform, sustainability and AI/LLMOps.

In Your Back Pocket#

Quick reference: cheatsheets, copy-paste templates, career.

Compliance controls and raw field notes from real deployments.


Author

About#

Halil İbrahim Dürmüş

Halil İbrahim Dürmüş#

DevSecOps Engineer

I don't trust pipelines that leave security for last. A default config that "works" means "not broken yet" to me — I build both Kubernetes and the supply chain tight from day one, I don't patch them later. This handbook is my flagship, distilling what I've learned in production into something actionable.

Kubernetes Docker Helm Kustomize Terraform OpenTofu ArgoCD Flux GitHub Actions GitLab CI AWS Cilium / eBPF Gateway API Prometheus Grafana OpenTelemetry Loki / Tempo PostgreSQL Patroni Vault / ESO Trivy Cosign / SLSA Kyverno / OPA Falco Wazuh SIEM Ansible Python Bash KVKK / GDPR vLLM / RAG

Open source · GitHub

Projects#

Alongside the knowledge base, open-source tools I've written for production:

  • databases-stack


    A self-hosted MariaDB + PostgreSQL + MongoDB + Redis stack with a single docker compose up: admin panels, Prometheus exporters, 15-minute backup automation, Google Drive sync.

    Repo

  • file-crypter


    File/folder encryption with AES-256-CBC + PBKDF2 — a single command from the terminal. Lightweight, no dependencies.

    Repo

  • wakapi-admin


    Self-hosted Wakapi stack + custom admin panel: real-time active users, domain tag system, AI editor detection.

    Repo

  • api-sentinel


    Schema-change detection for third-party APIs — plugin-based, severity-aware monitoring. It catches breaking changes before you do.

    Repo

  • cheat-sheet


    Offensive security command reference — 2000+ pentest commands, OSCP/OSWE/OSEP prep.

    Repo

  • More


    All my open-source work lives on my GitHub profile.

    github.com/halilibrahimd27


Get in touch#

Got an idea, a collaboration, or a question? Don't be shy — reach out.

s.ibrahimdrms@gmail.com LinkedIn GitHub