Puppet may be already working on this, however, it would be helpful if they made the product agent-less or making an option for agent-less. They may offer that in Puppet Bolt. I haven't explored that much. The compliance side needs work. Puppet doesn't have much in terms of dealing with compliance. Chef has inSpec. On Red Hat, we are getting Insight so that we can run some standard templates for compliance, like CIS or DSR, PCI, or something of that nature. We can use those templates to harden the environments and perform a security checklist within those environments. There's a lot of scope for enhancement on the DevSecOps side. They should definitely include features for compliance, for both the Linux and Windows side of the devices, as well as for network devices. Compliance is something they need to work on. It would be great if there was integration with some InfoSec tools like Lenovo. The pricing of the solution is a bit high. View full review »
