DevOps Tools Landscape: A Beginner's Map of the Toolchain
DevOps Tools Landscape: A Beginner's Map of the Toolchain
Understand the major DevOps tool categories — version control, CI/CD, containers, IaC, monitoring, and security — and how they fit together in a real delivery pipeline.
Difficulty: Beginner Estimated Reading Time: 12 minutes Last Updated: 2026-02-15
Table of Contents
- How the Toolchain Fits Together
- Version Control
- CI/CD Pipelines
- Containers and Orchestration
- Infrastructure as Code
- Configuration Management
- Monitoring and Observability
- Security Tooling
- Choosing Tools
- A Realistic Starter Stack
How the Toolchain Fits Together
A DevOps pipeline moves code from a developer's machine to production. Each stage has a category of tooling:
Code ──> Build ──> Test ──> Scan ──> Package ──> Deploy ──> Monitor
│ │ │ │ │ │ │
Git CI Test Security Container K8s/IaC Metrics/
tools runners scanners registry Helm logs/traces
Nobody learns every tool. Learn the categories, pick one tool per category, and go deep.
Version Control
Everything starts here. Version control tracks every change and enables collaboration.
| Tool | Model | Notes |
|---|---|---|
| Git | Distributed | The industry standard — learn this first |
| GitHub | Git hosting + CI/CD | Repos, PRs, Actions, secret scanning |
| GitLab | Git hosting + full DevOps | Built-in CI/CD, package registry |
| Azure Repos | Git hosting | Part of Azure DevOps suite |
| Bitbucket | Git hosting | Atlassian ecosystem (Jira integration) |
Learn: clone, branch, commit, push, pull request, merge, rebase (later), .gitignore.
CI/CD Pipelines
CI (Continuous Integration) builds and tests every change. CD (Continuous Delivery/Deployment) ships it.
| Tool | Type | Best for |
|---|---|---|
| Jenkins | Self-hosted | Maximum flexibility, huge plugin ecosystem |
| GitHub Actions | Cloud-native | Teams already on GitHub |
| Azure Pipelines | Cloud | Azure-centric organisations |
| GitLab CI | Built into GitLab | All-in-one platform users |
| CircleCI | Cloud | Fast parallel builds |
| ArgoCD | Kubernetes-native | GitOps deployments |
Key concept: pipelines-as-code — your build definition is a YAML file in the repo, reviewed like any code.
Containers and Orchestration
| Tool | Role |
|---|---|
| Docker | Builds and runs containers — package once, run anywhere |
| containerd | Lower-level container runtime (what Kubernetes actually uses) |
| Kubernetes (K8s) | Orchestrates containers at scale — scheduling, healing, scaling |
| Helm | Package manager for Kubernetes — templated deployments |
| Kind / Minikube / k3d | Local Kubernetes for development and testing |
Learning path: Docker first → docker run, Dockerfile, Compose → then Kubernetes: Pods, Deployments, Services.
Infrastructure as Code
Provision infrastructure with code instead of clicking through consoles.
| Tool | Approach | Scope |
|---|---|---|
| Terraform | Declarative, HCL | Multi-cloud — the default choice |
| Pulumi | Real languages (TypeScript, Python, Go) | Multi-cloud |
| Bicep | Declarative | Azure-only |
| AWS CloudFormation / CDK | Declarative | AWS-only |
| Crossplane | Kubernetes-based | Control-plane style provisioning |
Terraform skills to learn first: init, plan, apply, state files, variables, modules.
Configuration Management
Configures what's inside machines — packages, files, services — after provisioning.
| Tool | Style | Agent needed? |
|---|---|---|
| Ansible | YAML playbooks, push-based | No — SSH only |
| Puppet | Declarative manifests, pull-based | Yes |
| Chef | Ruby DSL, pull-based | Yes |
| Salt | Event-driven | Optional |
Ansible is the common starting point — agentless, readable YAML, ansible-playbook runs over SSH. Containers and immutable images have reduced the need for config management of long-lived servers, but Ansible remains valuable for bootstrapping and ad-hoc operations.
Monitoring and Observability
Three pillars: metrics, logs, traces.
| Category | Tools |
|---|---|
| Metrics | Prometheus (Kubernetes-native standard), Grafana (dashboards), Datadog |
| Logs | ELK stack (Elasticsearch, Logstash, Kibana), Loki, Fluentd |
| Tracing | Jaeger, Tempo, OpenTelemetry (the instrumentation standard) |
| Alerting | Prometheus Alertmanager, PagerDuty, Opsgenie |
| All-in-one SaaS | Datadog, New Relic, Dynatrace |
Kubernetes standard: Prometheus scrapes metrics → Grafana visualises → Alertmanager pages. Start there.
Security Tooling
Security woven into the pipeline rather than bolted on after:
| Stage | Tools |
|---|---|
| Secrets detection | Gitleaks, TruffleHog |
| Dependency scanning | Dependabot, Renovate, Snyk, npm audit |
| Static analysis (SAST) | SonarQube, Semgrep, CodeQL |
| Container/image scanning | Trivy, Grype |
| IaC scanning | Checkov, tfsec, Terrascan |
| Runtime protection | Falco, admission controllers (Kyverno, OPA Gatekeeper) |
Minimum viable security: Gitleaks for secrets + Trivy for images + Dependabot for dependencies. Three tools cover the most common breach vectors.
Choosing Tools
Guidance for picking:
- Start where your code lives — on GitHub? Actions is the path of least resistance. GitLab? Its built-in CI.
- Managed beats self-hosted early on — Jenkins is powerful but you maintain it; GitHub Actions just runs.
- Cloud alignment matters — Azure shop? Azure DevOps + AKS + Bicep/Terraform. AWS? CodePipeline or external CI + EKS + Terraform.
- Learn concepts, not buttons — a pipeline is a pipeline; skills transfer between tools.
- Avoid tool sprawl — every additional tool is something the team must maintain.
A Realistic Starter Stack
For a small team deploying containerised apps to Kubernetes:
| Need | Pick | Why |
|---|---|---|
| Version control | Git + GitHub | Universal, free tier, integrated everything |
| CI/CD | GitHub Actions | Zero setup, in the same place as the code |
| Containers | Docker | The standard |
| Orchestration | Kubernetes (AKS/EKS/GKE managed) | Managed = no control-plane maintenance |
| Packaging | Helm | Reusable, versioned K8s deployments |
| Infrastructure | Terraform | Multi-cloud, huge module ecosystem |
| Monitoring | Prometheus + Grafana | Kubernetes-native, free |
| Security | Gitleaks + Trivy + Dependabot | Covers secrets, images, dependencies |
That stack takes a small team from git push to a monitored production deployment — and every tool in it has a substantial free tier.