DevSecOps Engineering Bootcamp
Chapter 5
Project Details
Continuing From Phase 1
You keep working in the same GitLab repository from Phase 1 — Phase 2 is not a new clone. Pull the Phase 2 guides from the devsecops branch of the training repo into your existing project:
git clone -b devsecops https://github.com/stratpoint-engineering/devops-capstone-3tier-app.git devsecops-guides cp devsecops-guides/docs/1*.md <your-gitlab-project>/docs/
Project Focus
Secure the same 3-tier app pipeline from Phase 1: add security scanning to GitLab CI, replace hardcoded secrets with ESO and Vault, scan and fix your Helm chart with Checkov, enforce policy cluster-wide with Kyverno, sign and attest images with Cosign and Syft, and monitor runtime threats with Falco.
Repository Structure
docs/ # Phase 2 implementation guides |-- 10-devsecops-intro.md |-- 11-sast-sca-scanning.md |-- 12-secrets-management.md |-- 13-manifest-security.md |-- 14-admission-control.md |-- 15-supply-chain-security.md |-- 16-runtime-security.md +-- devsecops-capstone-requirements.md policies/ |-- kyverno/ # ClusterPolicy YAMLs +-- falco/custom-rules.yaml # Custom Falco rules secrets/ |-- secretstore.yaml # ESO SecretStore +-- externalsecret-db.yaml # ExternalSecret for DB creds
Implementation Order
- Read the intro — docs/10-devsecops-intro.md — before writing any config
- Add pipeline scanning — docs/11-sast-sca-scanning.md — Gitleaks + Semgrep + Trivy in GitLab CI
- Migrate secrets — docs/12-secrets-management.md — ESO + Vault, remove all hardcoded credentials
- Scan manifests — docs/13-manifest-security.md — Checkov on Helm charts, fix HIGH/CRITICAL findings
- Enforce policies — docs/14-admission-control.md — Kyverno with 4 core policies, Audit then Enforce
- Secure the supply chain — docs/15-supply-chain-security.md — Syft SBOM + Cosign signing
- Add runtime security — docs/16-runtime-security.md — Falco + Grafana security dashboard
Deliverables (20% each)
| Requirement | Weight | What to Show |
|---|---|---|
| Pipeline Security | 20% | Updated .gitlab-ci.yml with all four scanning jobs · screenshot of a passing run · screenshot of a run that failed on a finding, then fixed |
| Secrets Management | 20% | secretstore.yaml and externalsecret-db.yaml · kubectl describe externalsecret showing SecretSynced · backend pod running with ESO-injected secrets |
| Manifest Security | 20% | Checkov scan showing 0 HIGH/CRITICAL findings · updated Helm chart with security contexts · manifest-scan job in .gitlab-ci.yml |
| Admission Control | 20% | 4+ Kyverno policies in policies/kyverno/ · kubectl get clusterpolicy all READY · a blocked kubectl run attempt · ArgoCD still syncing |
| Supply Chain + Runtime Security | 20% | generate-sbom and sign-images CI jobs · SBOM artifact · Kyverno signature-verification policy · custom Falco rules · Grafana security dashboard · Falco detecting a shell spawn |
Deliverable Checklist
- Updated .gitlab-ci.yml with Gitleaks, Semgrep, Trivy, Checkov, Syft, and Cosign stages
- secretstore.yaml and externalsecret-db.yaml committed to the repo
- Helm chart updated: non-root, resource limits, no latest tag, no plaintext secrets
- policies/kyverno/ with 4+ ClusterPolicy YAMLs, all READY
- policies/falco/custom-rules.yaml with 2+ custom rules for your app
- SBOM (.json) artifact from a recent pipeline run, attached to the image in the registry
- Grafana security dashboard showing Falco events, with an alert rule for CRITICAL events
- No secrets in Git history, verified with Gitleaks
Evaluation Criteria
| Tier | Requirements |
|---|---|
| Basic (70-79%) | Pipeline has 2+ scanning jobs · ESO installed with 1+ secret managed externally · Checkov run locally with some findings fixed · Kyverno with 2+ policies · Falco installed with default rules |
| Proficient (80-89%) | All 4 scanning jobs in CI · all DB credentials via ESO · Checkov in CI with 0 HIGH/CRITICAL findings · all 4 Kyverno policies enforced · images signed and verified · Falco alerts visible in Grafana |
| Advanced (90-100%) | All of Proficient, plus: a real finding caught and documented before/after · custom Falco rules for your app · SBOM attached in the registry · Grafana dashboard with alert rules · full commit-to-detect demo |
Optional Bonus Points
| Bonus | Points | What to Do |
|---|---|---|
| DAST | +5% | Add an OWASP ZAP scan against your running staging environment |
| Network Policies | +5% | Implement Kubernetes NetworkPolicy to restrict pod-to-pod traffic |
| CIS Benchmark | +5% | Run kube-bench against your cluster and remediate findings |
Final Presentation
Duration: 30 minutes (20 minutes presentation + 10 minutes Q&A)
| Requirement | Weight | What to show |
|---|---|---|
| Technical Demo | 100% | Live pipeline run with all security stages · a scan finding caught and fixed · Kyverno enforcing policy at deploy time · a Falco alert in Grafana · SBOM attached to an image in the registry |