hardFreedevsecops
Course

Introduction to DevSecOps

A complete DevSecOps curriculum, taught from both sides: how to build the pipeline and how to break it. It begins with the discipline itself - shift-left, security as code, the pipeline, threat modelling - then works through application security (SAST, SCA, secrets management, DAST/IAST/RASP), conta

34
Modules
38
Lectures
14
Hands-on labs
23h
Of material

About this course

A complete DevSecOps curriculum, taught from both sides: how to build the pipeline and how to break it. It begins with the discipline itself - shift-left, security as code, the pipeline, threat modelling - then works through application security (SAST, SCA, secrets management, DAST/IAST/RASP), containers and images (with Dive), the whole of Kubernetes security, infrastructure as code and Ansible, cloud IAM and object storage, the pipeline and delivery layer (CI/CD security, software supply chain, GitOps), and finishes with vulnerability management, compliance as code, and a capstone that chains a real breach end to end.

Thirteen hands-on labs, every one a real machine rather than a simulation, run without --privileged: the container labs run their own Docker engine, the Kubernetes labs a real k3s cluster with kubectl and k9s, the cloud labs MinIO and LocalStack speaking the genuine S3 and IAM APIs, the CI/CD lab a real Gitea with a self-hosted Actions runner, and the GitOps lab real Flux image automation. You perform the socket escape, the registry poisoning, the RBAC escalation, the poisoned pipeline and the registry-to-cluster GitOps attack yourself, and break nothing. Every challenge ends by asking which single change would have stopped you - that write-up, not the flag, is the point.

It closes with a playground rather than another test: Kubernetes Goat, Madhu Akula's deliberately vulnerable cluster, deployed in full and scored not at all. Twenty-odd scenarios side by side, nothing to capture, and no single way through - somewhere to go once the modules have taught you what you are looking at.

Syllabus

34 modules, 38 lectures, 33 quizzes and 14 hands-on challenges.

  1. DevSecOps Foundations and Shift Left

    What DevSecOps is, why the old security-gate model fails, shift-left, the three ways, security as code, the pipeline, and the metrics that show it working.

    • What DevSecOps Actually Is

    1 quiz

  2. DevOps Foundations: How Software Is Built and Shipped

    The build-and-ship machinery - version control, CI, CD, IaC, config management, artifacts, environments - taught so every later attack has a place to land.

    • How Software Is Built and Shipped

    1 quiz

  3. Threat Modelling

    The furthest-left control: the four questions, data flow diagrams and trust boundaries, STRIDE, attack trees, and threat-modelling as code.

    • Threat Modelling, Done Properly

    1 quiz

  4. SAST: Static Application Security Testing

    Reading code for bugs without running it: pattern matching, taint analysis, the tools, false positives and negatives, and gating on the diff.

    • SAST: Reading Code for Bugs Without Running It

    1 quiz

  5. SCA: Software Composition Analysis

    Your dependencies are your code: the transitive tree, known CVEs, dependency confusion and typosquatting, SBOMs, and reachability-based prioritisation.

    • SCA: Your Dependencies Are Your Code

    1 quiz

  6. Secrets Management

    Getting credentials out of code and delivering them without a human: detection, Vault and dynamic secrets, the bootstrap problem, and the CSI pattern.

    • Secrets Management: Getting Credentials Out of Your Code

    1 quiz

  7. DAST, IAST and RASP

    Working with the running app: attacking it from outside (DAST), watching from inside (IAST), defending in real time (RASP), and fuzzing.

    • DAST, IAST and RASP: Testing and Protecting the Running App

    1 quiz

  8. Containers From First Principles

    What a container actually is - namespaces, cgroups, capabilities, the union filesystem - and how to check every claim from the inside.

    • What a Container Actually Is
    • Seeing It From the Inside

    1 quiz 1 hands-on challenge

  9. Images, the Build, and Dive

    An image is tarballs and JSON. Layers, the cache, build secrets, digests, why deleting does not remove - and Dive to see every layer.

    • Layers, the Cache, and What Ends Up in an Image
    • Dive: Reading an Image Layer by Layer

    1 quiz 1 hands-on challenge

  10. Dockerfile and Runtime Security

    The privilege ladder from a plain container to privileged, and the one sentence worth memorising: the Docker socket is the machine.

    • The Privilege Ladder
    • The Docker Socket Is the Machine

    1 quiz 1 hands-on challenge

  11. Docker Compose

    Compose read the way an attacker does: the seven lines that matter, and the flat-network default that connects your third-party container to your database.

    • Compose as a Security Surface

    1 quiz 1 hands-on challenge

  12. Docker Swarm

    The orchestrator in the engine, kept for one reason: a secrets model stricter by default than most Kubernetes practice.

    • Swarm, and the Secrets Model Everyone Should Copy

    1 quiz

  13. Kubernetes Fundamentals

    The API is the system and RBAC is the security model. The objects that matter, and a pod as a security context.

    • The Objects That Matter

    1 quiz 1 hands-on challenge

  14. Workloads and Config

    Where most real credential exposure happens: a ConfigMap that should be a Secret, a Secret as an env var, an etcd with no encryption.

    • Config, Secrets, and Where They Leak

    1 quiz

  15. RBAC

    The Kubernetes security model, read as an escalation surface. The verbs that are not what they look like.

    • RBAC, and How It Is Escalated

    1 quiz 1 hands-on challenge

  16. Pod Security and Admission Control

    RBAC decides who may create a pod. Admission control decides what that pod is allowed to be.

    • Admission Control and Pod Security

    1 quiz 1 hands-on challenge

  17. Networking

    The default network is flat: every pod reaches every pod. Segmentation is your job, and egress is the half people skip.

    • NetworkPolicy and the Flat Default

    1 quiz

  18. Attacking Kubernetes

    Attackers think in paths, not resources. The attack graph, and computing it with KubeHound.

    • The Attack Graph

    1 quiz

  19. Runtime Detection

    The earlier layers are static and preventive. Falco watches what a workload actually does, live.

    • Falco, and Seeing Behaviour at Runtime

    1 quiz

  20. Auditing and Benchmarks

    The standing-audit layer: kube-bench, kubeaudit, kubescape, and the audit trail - run on a schedule, not once.

    • Benchmarks and Auditors

    1 quiz

  21. Image Registries and the Supply Chain

    How a registry works - blobs are content, tags are pointers - and the consequence: pulling by tag trusts whoever can write the tag.

    • How Registries Work, and How They Are Abused

    1 quiz 1 hands-on challenge

  22. Image Scanning and SBOM

    Scanning is a join between an inventory and a database. Make its output small enough to act on, and understand what it cannot see.

    • Scanning That Earns Its Noise
    • Syft: An Inventory You Can Keep
    • Grype: Scanning the Inventory

    1 quiz 1 hands-on challenge

  23. Infrastructure as Code: Terraform

    IaC moves the mistake into a file you can review - and introduces the state file, the least-guarded crown jewel.

    • Terraform, and the State File Nobody Guards

    1 quiz

  24. IaC Scanning and Policy as Code

    Catch the misconfiguration before the resource exists. Checkov, Terrascan, and making the secure configuration the automatic one.

    • Checkov, Terrascan, and Policy as Code

    1 quiz

  25. Ansible and Configuration Management Security

    Terraform creates the machines; Ansible configures them - with a security surface of its own and fleet-wide root at stake.

    • Ansible: Configuration Management, and How It Is Abused

    1 quiz

  26. Cloud IAM

    Every escape in the cloud ends at the node's identity. How it works, how it is stolen, and how to make the theft worthless.

    • Cloud IAM, the Metadata Service, and Assumed Roles

    1 quiz 1 hands-on challenge

  27. Object Storage

    The most common source of cloud data breaches, and not because of exotic attacks. Practised safely with MinIO and LocalStack.

    • Buckets, Policies, and the Public Default

    1 quiz 1 hands-on challenge

  28. CI/CD Security and Poisoned Pipelines

    The under-defended crown jewel: how a fork PR runs on a self-hosted runner, with a Gitea lab you exploit end to end.

    • Poisoned Pipelines and the Runner That Trusts Too Much

    1 quiz 1 hands-on challenge

  29. Software Supply Chain: Provenance and Signing

    Make the whole chain verifiable end to end: in-toto provenance, SLSA levels, cosign keyless signing, and enforcement at admission.

    • The Software Supply Chain: Provenance, Signing, and SLSA

    1 quiz

  30. GitOps and Flux

    GitOps flips the deploy model - and a registry that can trigger a deployment becomes a compromised cluster, with a Flux lab you exploit.

    • GitOps, Flux, and the Registry That Deploys Itself

    1 quiz 1 hands-on challenge

  31. Vulnerability Management

    From findings to fixed: deduplicate, prioritise by KEV/EPSS and reachability, VEX, route, SLA, verify - spending finite capacity on what matters.

    • Vulnerability Management: From Findings to Fixed

    1 quiz

  32. Compliance as Code

    Make the control a piece of code enforced continuously that produces its own evidence, so an audit is a report the pipeline already generates.

    • Compliance as Code

    1 quiz

  33. Capstone: The Whole Chain

    Real incidents are a path through several controls, each a small oversight. Walk one end to end, and name the single change that breaks each link.

    • The Whole Chain

    1 quiz

  34. Playgrounds: Somewhere to Wander

    Deliberately vulnerable environments with nothing to capture. The challenges teach one thing each and have one way through; these are whole broken systems to explore once you know what you are looking at.

    1 hands-on challenge

34 modules about 23 hoursOpened from your Arena account

Take Introduction to DevSecOps

Create an account to open the lectures and launch this course's labs in the browser.

Create a free account