Development, testing and production.
WHAT ENVIRONMENTS ARE NEEDED
Local development A shared testing environment Production
WHAT TO KEEP IDENTICAL
Configuration mechanism Dependency versions Security settings
WHY SECURITY SETTINGS SPECIFICALLY
Relaxing them for convenience hides the problems that appear on release.
WHAT TO NEVER DO
Use production data in testing without anonymising.
WHY
Test environments are less protected, and this is a common cause of breaches.
WHAT TO NEVER SHARE
Credentials between environments.
WHY
A compromise of the least protected then reaches production.
WHAT TO MAKE OBVIOUS
Which environment you are looking at.
HOW
A visible banner, coloured differently.
WHY
Actions taken in production believing it to be testing are a recurring and serious mistake.
WHAT TO PROTECT PRODUCTION WITH
Restricted access Confirmation for destructive actions Logging of everything administrative
WHAT TO AUTOMATE
Creation of environments, so they are consistent.
WHAT TO DISABLE OUTSIDE PRODUCTION
Real email sending Real payment processing Notifications to customers
WHY
Test messages reaching customers cause immediate damage.
WHAT TO ROUTE THEM TO
A capture service.