{"id":865,"date":"2026-09-18T11:17:20","date_gmt":"2026-09-18T11:17:20","guid":{"rendered":"https:\/\/datascientists.info\/?p=865"},"modified":"2026-09-18T11:17:21","modified_gmt":"2026-09-18T11:17:21","slug":"devpi-kubernetes-python-package-cache-security","status":"publish","type":"post","link":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/","title":{"rendered":"Automating the Python Package Release Process"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In modern Data Engineering and ML environments, consistently reaching out to the public internet (like PyPI) for every pipeline, test, or notebook spawn is not just a performance bottleneck\u2014it introduces significant supply-chain risks. To address this, our engineering team deploys <strong>DevPi<\/strong> as an internal Python package proxy and caching index directly into our Kubernetes clusters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This post breaks down our high-level architecture, the automated CI\/CD lifecycle for custom packages, and the automated security janitor that actively keeps vulnerabilities out of our execution environments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">High-Level Architecture &amp; Networking<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At its core, our DevPi component provides a cluster-local index for all Python workloads. Instead of reaching external repositories directly, notebooks and pipeline jobs communicate with DevPi, which transparently caches necessary packages and serves locally hosted, custom libraries.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"810\" src=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png\" alt=\"\" class=\"wp-image-866\" srcset=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png 1024w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-300x237.png 300w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-767x607.png 767w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1536x1215.png 1536w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3.png 1837w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Architecture Highlights<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Service Layer:<\/strong> DevPi runs behind a Kubernetes ClusterIP service exposing ports <code>80<\/code> and <code>3141<\/code>.<\/li>\n\n\n\n<li><strong>Storage:<\/strong> Backed by an OBS\/S3 volume (<code>\/devpi\/files<\/code>) for package artifacts and a PersistentVolumeClaim (<code>\/devpi\/server<\/code>) for fast metadata retrieval.<\/li>\n\n\n\n<li><strong>Routing:<\/strong> Managed via an Istio Virtual Service, routing both ports to <code>devpi.kubeflow.svc.cluster.local<\/code> with a 120-second timeout, ensuring seamless in-cluster DNS resolution.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Automating the Release Process<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Publishing internal code to DevPi is highly standardized using a comprehensive GitLab CI\/CD release pipeline. We enforce strict quality and security checks before a package ever reaches the index:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"65\" src=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-1024x65.png\" alt=\"\" class=\"wp-image-867\" srcset=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-1024x65.png 1024w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-300x19.png 300w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-761x48.png 761w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-1536x97.png 1536w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-4-2048x129.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Linting:<\/strong> Fast, static code analysis and formatting checks using <a href=\"https:\/\/github.com\/astral-sh\/ruff\">Ruff<\/a>.<\/li>\n\n\n\n<li><strong>Testing:<\/strong> Building the execution environment and running unit tests against package code via pytest.<\/li>\n\n\n\n<li><strong>Static Security:<\/strong> Scanning third-party dependencies to generate a Software Bill of Materials (SBOM) to track supply chain compliance.<\/li>\n\n\n\n<li><strong>Versioning:<\/strong> Automatic semantic versioning (MAJOR.MINOR.PATCH) calculation based on structured git commit messages.<\/li>\n\n\n\n<li><strong>Build &amp; Publish:<\/strong> Compiling binary wheels (<code>.whl<\/code>) and source distributions (<code>.tar.gz<\/code>) via Python&#8217;s build module, before pushing to DevPi using <code>twine<\/code>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Active Security: The Trivy Janitor<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Having an internal registry is excellent for speed, but hosting vulnerable code is dangerous. We built an automated, multi-tiered security flow centered around Trivy to actively scan and remediate our package cache.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Scheduled Scanning (The Hourly Cron)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A Kubernetes CronJob executes hourly to inspect the OBS-backed package cache. An init-container running Trivy scans the read-only mounted volume, reporting only <code>CRITICAL<\/code> severity vulnerabilities into a shared volume.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"611\" height=\"1024\" src=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-5-611x1024.png\" alt=\"\" class=\"wp-image-868\" srcset=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-5-611x1024.png 611w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-5-179x300.png 179w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-5-768x1287.png 768w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-5.png 877w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2. Event-Driven Scanning (Upload Triggers)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We do not wait for the hourly job if new packages arrive. We integrate <strong>Argo Events<\/strong> to monitor package uploads in real time:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An <code>EventSource<\/code> exposes a webhook listening for OBS uploads on port 12000.<\/li>\n\n\n\n<li>A <code>Sensor<\/code> filters incoming events, reacting only to relevant artifacts ending in <code>.whl<\/code>, <code>.tar.gz<\/code>, or <code>.zip<\/code>.<\/li>\n\n\n\n<li>When a match is found, a one-off Kubernetes Job is triggered to immediately scan the new artifacts with Trivy.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"476\" height=\"1024\" src=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-6-476x1024.png\" alt=\"\" class=\"wp-image-869\" srcset=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-6-476x1024.png 476w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-6-139x300.png 139w, https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-6.png 675w\" sizes=\"auto, (max-width: 476px) 100vw, 476px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">3. Automated Remediation (The Janitor Script)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Scanning is only half the battle. Our custom Python <code>janitor.py<\/code> container takes over right after Trivy finishes. It parses the JSON output looking for vulnerable package names. If critical threats are found, the script automatically:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Applies a strict <strong>NetworkPolicy<\/strong> (<code>isolate-notebooks<\/code>) limiting ingress and egress traffic for the vulnerable environment (e.g., in the <code>kubeflow<\/code> namespace).<\/li>\n\n\n\n<li>Updates the DevPi index configuration via the CLI to whitelist substitute the affected packages, preventing further pulls.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Developer Quickstart: Using DevPi<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For developer environments and CI runners wanting to interact with the cache, environment variables easily point Python tooling to DevPi.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>import os\n\nDEVPI_HOST = \"devpi.kubeflow.svc.cluster.local\"\nDEVPI_PORT = \"3141\"\n\n# Environment configuration for pip and twine\nos.environ&#91;\"PIP_INDEX_URL\"] = f\"http:\/\/{DEVPI_HOST}:{DEVPI_PORT}\/root\/pypi\/+simple\/\"\nos.environ&#91;\"PIP_TRUSTED_HOST\"] = DEVPI_HOST\nos.environ&#91;\"DEVPI_URL\"] = f\"http:\/\/{DEVPI_HOST}:{DEVPI_PORT}\"\nos.environ&#91;\"DEVPI_INDEX_URL\"] = f\"http:\/\/{DEVPI_HOST}:{DEVPI_PORT}\/root\/dev\/\"\nos.environ&#91;\"TWINE_REPOSITORY_URL\"] = f\"http:\/\/{DEVPI_HOST}:{DEVPI_PORT}\/root\/dev\/\"<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Installing Packages<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once configured, you can simply use standard <code>pip<\/code> with the formulated simple index endpoint:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import subprocess\nimport sys\nimport os\n\ndevpi_index_url = os.environ&#91;\"DEVPI_INDEX_URL\"]\ntrusted_host = os.getenv(\"PIP_TRUSTED_HOST\", \"devpi.kubeflow.svc.cluster.local\")\nsimple_index_url = devpi_index_url.rstrip(\"\/\") + \"\/+simple\/\"\n\nsubprocess.run(&#91;\n    sys.executable, \"-m\", \"pip\", \"install\",\n    \"--index-url\", simple_index_url,\n    \"--trusted-host\", trusted_host,\n    \"your-custom-package==0.1.0\"\n], check=True)<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Building a Resilient Python Infrastructure<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Bringing DevPi inside your Kubernetes boundary converts an unpredictable external dependency into a managed, high-speed utility. By pairing cluster-local package caching with an automated remediation loop driven by Trivy and Argo Events, engineering teams eliminate external bandwidth dependencies and active security risks simultaneously. This setup provides data science and engineering teams with the speed of local package management alongside the strict governance required for production enterprise platforms.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In modern Data Engineering and ML environments, consistently reaching out to the public internet (like PyPI) for every pipeline, test, or notebook spawn is not just a performance bottleneck\u2014it introduces significant supply-chain risks. To address this, our engineering team deploys DevPi as an internal Python package proxy and caching index directly into our Kubernetes clusters. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_ppma_block_editor_authors":""},"categories":[125],"tags":[126,66],"ppma_author":[144],"class_list":["post-865","post","type-post","status-publish","format-standard","hentry","category-data-engineering","tag-data-engineering","tag-python","author-marc"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053<\/title>\n<meta name=\"description\" content=\"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053\" \/>\n<meta property=\"og:description\" content=\"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/\" \/>\n<meta property=\"og:site_name\" content=\"DATA DO - \u30c7\u30fc\u30bf \u9053\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/DataScientists\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T11:17:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-18T11:17:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png\" \/>\n<meta name=\"author\" content=\"Marc Matt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Marc Matt\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/\"},\"author\":{\"name\":\"Marc Matt\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/#\\\/schema\\\/person\\\/723078870bf3135121086d46ebb12f19\"},\"headline\":\"Automating the Python Package Release Process\",\"datePublished\":\"2026-09-18T11:17:20+00:00\",\"dateModified\":\"2026-09-18T11:17:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/\"},\"wordCount\":617,\"publisher\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-3-1024x810.png\",\"keywords\":[\"Data Engineering\",\"Python\"],\"articleSection\":[\"Data Engineering\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/\",\"url\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/\",\"name\":\"Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-3-1024x810.png\",\"datePublished\":\"2026-09-18T11:17:20+00:00\",\"dateModified\":\"2026-09-18T11:17:21+00:00\",\"description\":\"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-3.png\",\"contentUrl\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/image-3.png\",\"width\":1837,\"height\":1453},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/index.php\\\/2026\\\/09\\\/18\\\/devpi-kubernetes-python-package-cache-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/datascientists.info\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Automating the Python Package Release Process\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/#website\",\"url\":\"https:\\\/\\\/datascientists.info\\\/\",\"name\":\"Data Scientists\",\"description\":\"Digging data, Big Data, Analysis, Data Mining\",\"publisher\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/datascientists.info\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/#organization\",\"name\":\"DATA DO - \u30c7\u30fc\u30bf \u9053\",\"url\":\"https:\\\/\\\/datascientists.info\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Bildschirmfoto-vom-2026-02-02-08-13-21.png\",\"contentUrl\":\"https:\\\/\\\/datascientists.info\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Bildschirmfoto-vom-2026-02-02-08-13-21.png\",\"width\":250,\"height\":174,\"caption\":\"DATA DO - \u30c7\u30fc\u30bf \u9053\"},\"image\":{\"@id\":\"https:\\\/\\\/datascientists.info\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/DataScientists\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/datascientists.info\\\/#\\\/schema\\\/person\\\/723078870bf3135121086d46ebb12f19\",\"name\":\"Marc Matt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g53b84b5f47a2156ba8b047d71d6d05fc\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g\",\"caption\":\"Marc Matt\"},\"description\":\"Senior Data Architect with 15+ years of experience helping Hamburg's leading enterprises modernize their data infrastructure. I bridge the gap between legacy systems (SAP, Hadoop) and modern AI capabilities. I help clients: Migrate &amp; Modernize: Transitioning on-premise data warehouses to Google Cloud\\\/AWS to reduce costs and increase agility. Implement GenAI: Building secure RAG (Retrieval-Augmented Generation) pipelines to unlock value from internal knowledge bases using LangChain and Vector DBs. Scale MLOps: Operationalizing machine learning models from PoC to production with Kubernetes and Airflow. Proven track record leading engineering teams.\",\"sameAs\":[\"https:\\\/\\\/data-do.de\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053","description":"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/","og_locale":"en_US","og_type":"article","og_title":"Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053","og_description":"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.","og_url":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/","og_site_name":"DATA DO - \u30c7\u30fc\u30bf \u9053","article_publisher":"https:\/\/www.facebook.com\/DataScientists\/","article_published_time":"2026-09-18T11:17:20+00:00","article_modified_time":"2026-09-18T11:17:21+00:00","og_image":[{"url":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png","type":"","width":"","height":""}],"author":"Marc Matt","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Marc Matt","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#article","isPartOf":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/"},"author":{"name":"Marc Matt","@id":"https:\/\/datascientists.info\/#\/schema\/person\/723078870bf3135121086d46ebb12f19"},"headline":"Automating the Python Package Release Process","datePublished":"2026-09-18T11:17:20+00:00","dateModified":"2026-09-18T11:17:21+00:00","mainEntityOfPage":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/"},"wordCount":617,"publisher":{"@id":"https:\/\/datascientists.info\/#organization"},"image":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#primaryimage"},"thumbnailUrl":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png","keywords":["Data Engineering","Python"],"articleSection":["Data Engineering"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/","url":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/","name":"Automating the Python Package Release Process - DATA DO - \u30c7\u30fc\u30bf \u9053","isPartOf":{"@id":"https:\/\/datascientists.info\/#website"},"primaryImageOfPage":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#primaryimage"},"image":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#primaryimage"},"thumbnailUrl":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3-1024x810.png","datePublished":"2026-09-18T11:17:20+00:00","dateModified":"2026-09-18T11:17:21+00:00","description":"Learn how deploying DevPi on Kubernetes speeds up Python pipelines and secures your software supply chain using Trivy automated vulnerability scanning.","breadcrumb":{"@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#primaryimage","url":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3.png","contentUrl":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/08\/image-3.png","width":1837,"height":1453},{"@type":"BreadcrumbList","@id":"https:\/\/datascientists.info\/index.php\/2026\/09\/18\/devpi-kubernetes-python-package-cache-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/datascientists.info\/"},{"@type":"ListItem","position":2,"name":"Automating the Python Package Release Process"}]},{"@type":"WebSite","@id":"https:\/\/datascientists.info\/#website","url":"https:\/\/datascientists.info\/","name":"Data Scientists","description":"Digging data, Big Data, Analysis, Data Mining","publisher":{"@id":"https:\/\/datascientists.info\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/datascientists.info\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/datascientists.info\/#organization","name":"DATA DO - \u30c7\u30fc\u30bf \u9053","url":"https:\/\/datascientists.info\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/datascientists.info\/#\/schema\/logo\/image\/","url":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/02\/Bildschirmfoto-vom-2026-02-02-08-13-21.png","contentUrl":"https:\/\/datascientists.info\/wp-content\/uploads\/2026\/02\/Bildschirmfoto-vom-2026-02-02-08-13-21.png","width":250,"height":174,"caption":"DATA DO - \u30c7\u30fc\u30bf \u9053"},"image":{"@id":"https:\/\/datascientists.info\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/DataScientists\/"]},{"@type":"Person","@id":"https:\/\/datascientists.info\/#\/schema\/person\/723078870bf3135121086d46ebb12f19","name":"Marc Matt","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g53b84b5f47a2156ba8b047d71d6d05fc","url":"https:\/\/secure.gravatar.com\/avatar\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g","caption":"Marc Matt"},"description":"Senior Data Architect with 15+ years of experience helping Hamburg's leading enterprises modernize their data infrastructure. I bridge the gap between legacy systems (SAP, Hadoop) and modern AI capabilities. I help clients: Migrate &amp; Modernize: Transitioning on-premise data warehouses to Google Cloud\/AWS to reduce costs and increase agility. Implement GenAI: Building secure RAG (Retrieval-Augmented Generation) pipelines to unlock value from internal knowledge bases using LangChain and Vector DBs. Scale MLOps: Operationalizing machine learning models from PoC to production with Kubernetes and Airflow. Proven track record leading engineering teams.","sameAs":["https:\/\/data-do.de"]}]}},"authors":[{"term_id":144,"user_id":1,"is_guest":0,"slug":"marc","display_name":"Marc Matt","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/74f48ef754cf04f628f42ed117a3f2b42931feeb41a3cca2313b9714a7d4fdd2?s=96&d=mm&r=g","author_category":"1","first_name":"Marc","last_name":"Matt","user_url":"https:\/\/data-do.de","job_title":"Senior Data Architect | GenAI & RAG Expert | GCP \/ AWS","description":"Senior Data Architect with 15+ years of experience helping Hamburg's leading enterprises modernize their data infrastructure. I bridge the gap between legacy systems (SAP, Hadoop) and modern AI capabilities.\r\n\r\nI help clients:\r\n\r\n \tMigrate &amp; Modernize: Transitioning on-premise data warehouses to Google Cloud\/AWS to reduce costs and increase agility.\r\n\r\n\r\n \tImplement GenAI: Building secure RAG (Retrieval-Augmented Generation) pipelines to unlock value from internal knowledge bases using LangChain and Vector DBs.\r\n \tScale MLOps: Operationalizing machine learning models from PoC to production with Kubernetes and Airflow.\r\n\r\nProven track record leading engineering teams."}],"_links":{"self":[{"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/posts\/865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/comments?post=865"}],"version-history":[{"count":1,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/posts\/865\/revisions"}],"predecessor-version":[{"id":870,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/posts\/865\/revisions\/870"}],"wp:attachment":[{"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/media?parent=865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/categories?post=865"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/tags?post=865"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/datascientists.info\/index.php\/wp-json\/wp\/v2\/ppma_author?post=865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}