Story
Nike Uses Consul for Developer Security
Nike, a consumer discretionary organization in the United States, uses Consul from HashiCorp to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Developers and AppSec work from the same Consul record for developer security |
| Risk and compliance | Developer security can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for developer security |
Story
Inside Nike, secure delivery used to depend on whoever still had the latest file. That pattern is common in consumer discretionary groups working out of the United States. Developers and AppSec needed a system that would still make sense after the original project team moved on.
Nike uses Consul from HashiCorp as the working layer for developer security. HashiCorp (an IBM company) provides infrastructure automation software, including Terraform and Vault, for cloud provisioning and secrets. The practical change is simple: secure delivery has a home, and reviews happen there instead of in a forwarded thread.
Nothing in this writeup invents a savings number. What Nike gets from HashiCorp is a durable place to run secure delivery and a way for developers and AppSec to see the same developer security at the same time.