Introduction to DevSecOps
A complete DevSecOps curriculum, taught from both sides: how to build the pipeline and how to break it. It begins with the discipline itself - shift-left, security as code, the pipeline, threat modelling - then works through application security (SAST, SCA, secrets management, DAST/IAST/RASP), conta
- 34
- Modules
- 38
- Lectures
- 14
- Hands-on labs
- 23h
- Of material
About this course
A complete DevSecOps curriculum, taught from both sides: how to build the pipeline and how to break it. It begins with the discipline itself - shift-left, security as code, the pipeline, threat modelling - then works through application security (SAST, SCA, secrets management, DAST/IAST/RASP), containers and images (with Dive), the whole of Kubernetes security, infrastructure as code and Ansible, cloud IAM and object storage, the pipeline and delivery layer (CI/CD security, software supply chain, GitOps), and finishes with vulnerability management, compliance as code, and a capstone that chains a real breach end to end.
Thirteen hands-on labs, every one a real machine rather than a simulation, run without --privileged: the container labs run their own Docker engine, the Kubernetes labs a real k3s cluster with kubectl and k9s, the cloud labs MinIO and LocalStack speaking the genuine S3 and IAM APIs, the CI/CD lab a real Gitea with a self-hosted Actions runner, and the GitOps lab real Flux image automation. You perform the socket escape, the registry poisoning, the RBAC escalation, the poisoned pipeline and the registry-to-cluster GitOps attack yourself, and break nothing. Every challenge ends by asking which single change would have stopped you - that write-up, not the flag, is the point.
It closes with a playground rather than another test: Kubernetes Goat, Madhu Akula's deliberately vulnerable cluster, deployed in full and scored not at all. Twenty-odd scenarios side by side, nothing to capture, and no single way through - somewhere to go once the modules have taught you what you are looking at.
Syllabus
34 modules, 38 lectures, 33 quizzes and 14 hands-on challenges.
DevSecOps Foundations and Shift Left
What DevSecOps is, why the old security-gate model fails, shift-left, the three ways, security as code, the pipeline, and the metrics that show it working.
- What DevSecOps Actually Is
1 quiz
DevOps Foundations: How Software Is Built and Shipped
The build-and-ship machinery - version control, CI, CD, IaC, config management, artifacts, environments - taught so every later attack has a place to land.
- How Software Is Built and Shipped
1 quiz
Threat Modelling
The furthest-left control: the four questions, data flow diagrams and trust boundaries, STRIDE, attack trees, and threat-modelling as code.
- Threat Modelling, Done Properly
1 quiz
SAST: Static Application Security Testing
Reading code for bugs without running it: pattern matching, taint analysis, the tools, false positives and negatives, and gating on the diff.
- SAST: Reading Code for Bugs Without Running It
1 quiz
SCA: Software Composition Analysis
Your dependencies are your code: the transitive tree, known CVEs, dependency confusion and typosquatting, SBOMs, and reachability-based prioritisation.
- SCA: Your Dependencies Are Your Code
1 quiz
Secrets Management
Getting credentials out of code and delivering them without a human: detection, Vault and dynamic secrets, the bootstrap problem, and the CSI pattern.
- Secrets Management: Getting Credentials Out of Your Code
1 quiz
DAST, IAST and RASP
Working with the running app: attacking it from outside (DAST), watching from inside (IAST), defending in real time (RASP), and fuzzing.
- DAST, IAST and RASP: Testing and Protecting the Running App
1 quiz
Containers From First Principles
What a container actually is - namespaces, cgroups, capabilities, the union filesystem - and how to check every claim from the inside.
- What a Container Actually Is
- Seeing It From the Inside
1 quiz 1 hands-on challenge
Images, the Build, and Dive
An image is tarballs and JSON. Layers, the cache, build secrets, digests, why deleting does not remove - and Dive to see every layer.
- Layers, the Cache, and What Ends Up in an Image
- Dive: Reading an Image Layer by Layer
1 quiz 1 hands-on challenge
Dockerfile and Runtime Security
The privilege ladder from a plain container to privileged, and the one sentence worth memorising: the Docker socket is the machine.
- The Privilege Ladder
- The Docker Socket Is the Machine
1 quiz 1 hands-on challenge
Docker Compose
Compose read the way an attacker does: the seven lines that matter, and the flat-network default that connects your third-party container to your database.
- Compose as a Security Surface
1 quiz 1 hands-on challenge
Docker Swarm
The orchestrator in the engine, kept for one reason: a secrets model stricter by default than most Kubernetes practice.
- Swarm, and the Secrets Model Everyone Should Copy
1 quiz
Kubernetes Fundamentals
The API is the system and RBAC is the security model. The objects that matter, and a pod as a security context.
- The Objects That Matter
1 quiz 1 hands-on challenge
Workloads and Config
Where most real credential exposure happens: a ConfigMap that should be a Secret, a Secret as an env var, an etcd with no encryption.
- Config, Secrets, and Where They Leak
1 quiz
RBAC
The Kubernetes security model, read as an escalation surface. The verbs that are not what they look like.
- RBAC, and How It Is Escalated
1 quiz 1 hands-on challenge
Pod Security and Admission Control
RBAC decides who may create a pod. Admission control decides what that pod is allowed to be.
- Admission Control and Pod Security
1 quiz 1 hands-on challenge
Networking
The default network is flat: every pod reaches every pod. Segmentation is your job, and egress is the half people skip.
- NetworkPolicy and the Flat Default
1 quiz
Attacking Kubernetes
Attackers think in paths, not resources. The attack graph, and computing it with KubeHound.
- The Attack Graph
1 quiz
Runtime Detection
The earlier layers are static and preventive. Falco watches what a workload actually does, live.
- Falco, and Seeing Behaviour at Runtime
1 quiz
Auditing and Benchmarks
The standing-audit layer: kube-bench, kubeaudit, kubescape, and the audit trail - run on a schedule, not once.
- Benchmarks and Auditors
1 quiz
Image Registries and the Supply Chain
How a registry works - blobs are content, tags are pointers - and the consequence: pulling by tag trusts whoever can write the tag.
- How Registries Work, and How They Are Abused
1 quiz 1 hands-on challenge
Image Scanning and SBOM
Scanning is a join between an inventory and a database. Make its output small enough to act on, and understand what it cannot see.
- Scanning That Earns Its Noise
- Syft: An Inventory You Can Keep
- Grype: Scanning the Inventory
1 quiz 1 hands-on challenge
Infrastructure as Code: Terraform
IaC moves the mistake into a file you can review - and introduces the state file, the least-guarded crown jewel.
- Terraform, and the State File Nobody Guards
1 quiz
IaC Scanning and Policy as Code
Catch the misconfiguration before the resource exists. Checkov, Terrascan, and making the secure configuration the automatic one.
- Checkov, Terrascan, and Policy as Code
1 quiz
Ansible and Configuration Management Security
Terraform creates the machines; Ansible configures them - with a security surface of its own and fleet-wide root at stake.
- Ansible: Configuration Management, and How It Is Abused
1 quiz
Cloud IAM
Every escape in the cloud ends at the node's identity. How it works, how it is stolen, and how to make the theft worthless.
- Cloud IAM, the Metadata Service, and Assumed Roles
1 quiz 1 hands-on challenge
Object Storage
The most common source of cloud data breaches, and not because of exotic attacks. Practised safely with MinIO and LocalStack.
- Buckets, Policies, and the Public Default
1 quiz 1 hands-on challenge
CI/CD Security and Poisoned Pipelines
The under-defended crown jewel: how a fork PR runs on a self-hosted runner, with a Gitea lab you exploit end to end.
- Poisoned Pipelines and the Runner That Trusts Too Much
1 quiz 1 hands-on challenge
Software Supply Chain: Provenance and Signing
Make the whole chain verifiable end to end: in-toto provenance, SLSA levels, cosign keyless signing, and enforcement at admission.
- The Software Supply Chain: Provenance, Signing, and SLSA
1 quiz
GitOps and Flux
GitOps flips the deploy model - and a registry that can trigger a deployment becomes a compromised cluster, with a Flux lab you exploit.
- GitOps, Flux, and the Registry That Deploys Itself
1 quiz 1 hands-on challenge
Vulnerability Management
From findings to fixed: deduplicate, prioritise by KEV/EPSS and reachability, VEX, route, SLA, verify - spending finite capacity on what matters.
- Vulnerability Management: From Findings to Fixed
1 quiz
Compliance as Code
Make the control a piece of code enforced continuously that produces its own evidence, so an audit is a report the pipeline already generates.
- Compliance as Code
1 quiz
Capstone: The Whole Chain
Real incidents are a path through several controls, each a small oversight. Walk one end to end, and name the single change that breaks each link.
- The Whole Chain
1 quiz
Playgrounds: Somewhere to Wander
Deliberately vulnerable environments with nothing to capture. The challenges teach one thing each and have one way through; these are whole broken systems to explore once you know what you are looking at.
1 hands-on challenge
34 modules about 23 hoursOpened from your Arena account
Take Introduction to DevSecOps
Create an account to open the lectures and launch this course's labs in the browser.
Create a free account