
Pets vs Cattle DevOps: The Security Risk You Inherit
Pets vs Cattle DevOps: The Security Risk You Inherit No CVEs patched. Your attack surface still changes. I have watched teams “modernize” from pet VMs to cattle and accidentally make audits harder and breaches faster. If you do not treat pets vs cattle as a security classification, you will ship unauditable infrastructure and you will not notice until an incident, or a regulator, forces you to. Security impact first: what changes when you move to “cattle” Patch this before your next standup. Not with a hotfix, with controls. Pets fail in slow motion. Cattle fail at scale. If you run cattle without guardrails, a single bad image, a poisoned Terraform module, or a compromised GitOps repo can roll out to 400 nodes before you finish your coffee. Until we see a PoC, the real risk is probably misconfiguration and supply-chain drift, not a Hollywood zero-day. If you keep pets: Long-lived SSH keys and config drift hang around for years. An attacker who lands once can come back later and still
Continue reading on Dev.to DevOps
Opens in a new tab

