DevSecOps Engineering Bootcamp
Chapter 1
Course Overview
Hands-on training in DevSecOps practices through project-based learning. You've already built a working DevOps pipeline in Phase 1 — now you'll secure it, adding security controls at every stage: pipeline, cluster, and runtime.
Pro Tip
A failed security scan is good news — it means you caught something before production. Implement controls in order; each one builds on the last, so don't skip ahead.
What You'll Implement
| # | Control | Tools |
|---|---|---|
| 1 | Pipeline Security | Gitleaks · Semgrep · Trivy |
| 2 | Secrets Management | External Secrets Operator · HashiCorp Vault |
| 3 | Manifest Security | Checkov |
| 4 | Admission Control | Kyverno |
| 5 | Supply Chain Security | Syft · Cosign |
| 6 | Runtime Security | Falco |
Security Controls: P0 vs P1
| Tier | Controls |
|---|---|
| P0 — Non-negotiable | Secrets never in code or env vars · images scanned before deploy · manifests checked for misconfigurations · signed images verified before running |
| P1 — High value | SBOM generated for every build · runtime threat detection (Falco) · admission controllers blocking non-compliant workloads · dynamic application security testing (DAST) |
This training implements all P0 controls and most P1 controls.