Video Resources
1. SAST, SCA & Secrets Scanning — Week 1, Days 1-2 Implementation Guide
Gitleaks — secrets detection, step by step
Semgrep (SAST): https://www.youtube.com/watch?v=Ip6knn_8NDw — adding a Semgrep SAST job and custom rules to GitLab CI
Trivy (SCA + image scan): https://www.youtube.com/watch?v=OiRzHiCehII — container vulnerability scanning
Watch Out
Three tools, one stage — Gitleaks blocks on secrets, Semgrep blocks on critical SAST findings, Trivy blocks on HIGH/CRITICAL CVEs. All three run before the build stage, in that order.
2. Secrets Management — Week 1, Days 3-4 Implementation Guide
External Secrets Operator Tutorial for Kubernetes Secret Management
3. Manifest Security — Week 1, Day 5 Implementation Guide
Checkov — scanning Helm charts for misconfigurations
4. Admission Control — Week 2, Days 1-2 Implementation Guide
Kyverno — enforcing Kubernetes security policies, complete walkthrough
5. Supply Chain Security — Week 2, Days 3-4 Implementation Guide
Cosign signatures, attestation, Trivy reports and Kyverno policies together
Syft (SBOM generation): https://www.youtube.com/watch?v=9oj3BC3vOtc — generating an SBOM from a container image
6. Runtime Security — Week 2, Days 3-4 Implementation Guide
Falco for Kubernetes runtime security — eBPF, rules, tuning and alerts