DevOps · DevSecOps · SRE · Platform Engineering
The DevSecOps Handbook#
An opinionated, actionable reference that works in production — not a conference slide deck, but a reference that earns its keep on-call. Every section runs what → how → why, and ends with an anti-pattern table and a production checklist. Written in Turkish, with deep TR/EU regulatory coverage.
Why this handbook
What makes it different#
-
Actionable
Every section follows "what / how / why". Not a buzzword list — steps you can apply today and commands that run.
-
Placeholder-safe
No real IPs/credentials. The
<TARGET_IP>,<NAMESPACE>convention — enforced automatically in CI. -
2026 stack
CloudNativePG, Karpenter, OpenTofu, Cilium ambient, Gateway API, vLLM. No stale advice.
-
TR-specific
KVKK, BDDK, Wazuh, Iyzico stack notes. Not just an English translation — local engineering.
Starting from scratch?#
Not a reading list but a curriculum: read → build → verify → go back if you fail → move on if you pass. 6 blocks, 29 modules, labs + "broken labs" + certification gates. It never leaves you asking "what now?".
Use cases
What brought you here?#
-
Firefighting
Something blew up in production.
-
Standing up a new service
Containers + K8s + CI/CD.
-
Security review incoming
DevSecOps, hardening, SLSA/SBOM.
-
Cloud bill exploded
Cost allocation, right-sizing, spot.
-
KVKK / GDPR / SOC2
Compliance via engineering controls.
-
Taking Postgres to prod
Patroni HA, zero-downtime migration.
Knowledge base · 21 topics · 134 deep-dives
Categories#
Culture & People#
Sustainable teams, blameless culture, on-call health.
Build & Ship#
From source to production: version, pipeline, infra, containers, orchestration.
Run & Observe#
Run, see, protect: observability, security, networking, data, SRE.
Optimize & Evolve#
Cost, platform, sustainability and AI/LLMOps.
In Your Back Pocket#
Quick reference: cheatsheets, copy-paste templates, career.
Legal & Field#
Compliance controls and raw field notes from real deployments.
Author
About#
Open source · GitHub
Projects#
Alongside the knowledge base, open-source tools I've written for production:
-
databases-stack
A self-hosted MariaDB + PostgreSQL + MongoDB + Redis stack with a single
docker compose up: admin panels, Prometheus exporters, 15-minute backup automation, Google Drive sync. -
file-crypter
File/folder encryption with AES-256-CBC + PBKDF2 — a single command from the terminal. Lightweight, no dependencies.
-
wakapi-admin
Self-hosted Wakapi stack + custom admin panel: real-time active users, domain tag system, AI editor detection.
-
api-sentinel
Schema-change detection for third-party APIs — plugin-based, severity-aware monitoring. It catches breaking changes before you do.
-
cheat-sheet
Offensive security command reference — 2000+ pentest commands, OSCP/OSWE/OSEP prep.
-
More
All my open-source work lives on my GitHub profile.
Get in touch#
Got an idea, a collaboration, or a question? Don't be shy — reach out.