BSidesLuxembourg 2026

Andoni Alonso

Building Open Cloud Security at Prowler.

I started as a sysadmin, was a Site Reliability Engineer until a few years ago when I moved to the dark side... Security. I've been hooked to CTFs and anything with a scoreboard for a long time.

Starting the unicrons.cloud project to share knowledge about cloud security with the community.


Sessions

05-06
14:00
240min
Level Up Your CI/CD: Building a secure pipeline with OSS
Andoni Alonso, Paco Sanchez

What does the "perfect" CI/CD pipeline look like, especially one built with security at its core? This hands-on workshop explores that ideal using readily available open-source tools. We'll dissect the essential stages of a modern pipeline, demonstrating how to integrate security seamlessly throughout the development lifecycle (DevSecOps).

Through practical, step-by-step guidance, we'll implement key security checks like Static Application Security Testing (SAST), Software Composition Analysis (SCA), infrastructure vulnerability scanning, and secrets detection using popular OSS tools within a functional pipeline. While we'll showcase specific tools and configurations, the goal is not just replication, but understanding how and why these security controls work.

Discover the underlying principles of secure pipeline design and leave with actionable techniques to start building your own hardened, practical CI/CD pipeline.

IFEN room 3 Workshops and AI Security Village (Building D)
05-07
10:35
40min
Level Up Your CI/CD: Building a secure pipeline with OSS
Andoni Alonso, Paco Sanchez

What does the "perfect" CI/CD pipeline look like, especially one built with security at its core? In this talk, we'll explore that ideal using readily available open-source tools. We'll walk through the essential stages of a modern secure pipeline, demonstrating how to integrate security seamlessly throughout the development lifecycle (DevSecOps).

We'll cover seven key security stages: pipeline security scanning, code security analysis (SAST and SCA), secrets detection, container scanning, Infrastructure as Code scanning and runtime infrastructure scanning. You'll learn not just which tools to use, but why these security controls matter and how they work together.

Leave with a clear understanding of secure pipeline design principles and actionable techniques to start building your own hardened CI/CD pipeline.

Main Stage