THE KANGL BLOG
Operating AppSec, written down.
Practical guides for the unglamorous layer where security programs succeed or fail: coverage, drift, policy, credentials, audit, and scale — across Azure DevOps estates.
Snyk and Azure DevOps: Integration, Enforcement, and Scale
How to run Snyk in Azure DevOps pipelines, choose between pipeline tasks and centralized injection, protect credentials, and keep coverage from drifting.
Azure DevOps Pipeline Security Checklist: 15 Controls That Matter
A practical Azure DevOps pipeline security checklist covering identities, service connections, branch policies, scanners, gates, drift, and audit evidence.
Azure DevOps Security Best Practices for 2026
A practical checklist for securing Azure DevOps organizations, projects, repositories, service connections, and build pipelines — and how to keep it enforced.
How to Enforce Security Scanning Across Hundreds of Azure DevOps Pipelines
Copy-pasting scan tasks into YAML does not scale. Here is an operating model for rolling out and enforcing security scanning across a large Azure DevOps estate.
Configuration Drift: Why Pipelines Quietly Stop Scanning
Security tasks disappear from CI pipelines without anyone deciding to remove them. Here is why drift happens, why it goes unnoticed, and how to close the loop.
Backend-Authoritative Policy: Why UI Toggles Are Not Governance
If a policy decision is computed in a browser or a YAML file, it is advice. Real enforcement needs one authoritative evaluation point in the backend.
Operating Snyk at Enterprise Scale on Azure DevOps
Snyk finds the vulnerabilities. Operating Snyk across a large Azure DevOps estate — projects, Security Runtime, pipelines, service connections — is its own discipline.
Kangl Pipeline Security Runtime: Coverage Without YAML Sprawl
Pipeline Security Runtime applies security controls across Azure DevOps builds without repetitive YAML edits. Learn how coverage, control, and drift repair work at scale.
YAML vs Classic Pipelines: Closing the Security Coverage Gap
Most estates still run both YAML and classic build pipelines. A security rollout that only handles one of them leaves a permanent blind spot.
Fail the Build or Monitor Only? Designing Thresholds Developers Accept
Blocking every finding halts delivery; blocking nothing is theater. How to design severity thresholds and enforcement modes that survive contact with real teams.
Normalized Security Posture: Comparing Findings Across Different Scanners
Every scanner counts severity differently. Without a normalized read model, 'what is our posture?' has a different answer per vendor console.
AppSec Tool Sprawl: Consolidating Operations Without Replacing Scanners
The answer to five security consoles is rarely a sixth scanner. Consolidate the operating model, keep the engines.
Multi-Tenant AppSec: Governing Many Organizations Without Merging Them
Platform teams, MSPs, and holding companies run security across many Azure DevOps organizations. Central control and tenant isolation must both be true.
Keeping Provider Credentials Out of Pipelines, Queues, and Logs
Scanner tokens are production credentials. The integration architecture decides whether they leak into build logs, queue messages, and variable groups.
Audit Trails for AppSec Operations: What Compliance Actually Needs
Scanner reports show findings. Auditors ask about operations: who changed the policy, who disabled scanning, and when. Most stacks cannot answer.
Service Connections: The Quietest Privilege in Azure DevOps
Service connections hold cloud and vendor credentials behind a friendly UI. Governing them is core AppSec work, not platform housekeeping.
Variable Groups and the Slow Leak of Pipeline Secrets
Variable groups make sharing configuration easy — including configuration that should never have been shared. A field guide to cleaning up.
The Org-Wide Scanner Rollout Playbook: From Pilot to Default
A phased sequence for taking SAST/SCA from one pilot team to organization-wide default — without a developer revolt or a coverage mirage.
The Global Kill Switch: Change Control for Security Automation
When injected security steps misbehave at 2 a.m., you need one governed switch — not a hundred YAML reverts. Why every enforcement system needs an emergency brake.
Provider-Neutral AppSec: Keeping the Freedom to Change Scanners
Scanner switching costs are mostly operational, not contractual. A provider-neutral control layer keeps your estate portable.
Measuring AppSec Coverage: The Metrics That Survive an Audit
Vulnerability counts fluctuate with scanner behavior. Coverage, enforcement, drift, and freshness are the metrics that describe whether your program works.
PR Gates vs Build Gates in Azure DevOps: Where Should Security Decide?
Pull request checks catch issues before merge; build gates catch them before artifacts ship. Mature programs use both — with one policy brain behind them.
Drift Detection and Force Sync: The Reconciliation Loop for Pipeline Security
Infrastructure teams solved drift with reconciliation years ago. Pipeline security configuration deserves the same loop: desired state, observed state, controlled repair.
From Findings to Decisions: The Missing Layer Between Scanners and Builds
Scanners produce findings. Builds need decisions. The translation between them — policy — deserves to be a system, not a convention.
Why Kangl Exists: The Case for an AppSec Control Plane
The origin logic of Kangl: scanners multiplied, Azure DevOps estates grew, and the operating layer between them never got built. So we built it.
Shadow Pipelines: Finding the Builds Your Security Program Forgot
Every estate has pipelines nobody remembers creating — still building, still deploying, never scanned. Here is how they accumulate and how to bring them in.

SECURITY OPERATIONS, UNIFIED
Bring your security tools.
Kangl makes them one platform.
Start with seven days of full plan access — or see it live with our team first.
