Course Outline
Introduction to DevSecOps
- The critical role of security integration in DevOps.
- Foundational principles and established practices in DevSecOps.
Securing Continuous Integration (CI)
- Protecting code repositories through GitLab and Jenkins integration.
- Performing automated code quality and security assessments with SonarQube.
- Incorporating static code analysis into the Jenkins CI pipeline.
Docker Container Security
- Building secure Docker images from the ground up.
- Administering Docker image repositories using Harbor.
- Applying best practices for vulnerability scanning and image version management.
Constructing Secure CI/CD Pipelines
- Configuring Jenkins to support security integrations.
- Executing SonarQube analyses within the workflow.
- Creating and securing Docker images for deployment.
Kubernetes Deployment Security
- Essential security practices for Kubernetes orchestration.
- The role of the Kubernetes Orchestrator in secure progressive deployment strategies.
- Implementing Role-Based Access Control (RBAC) and securing service-to-service communication.
Secure Integration of RabbitMQ, PostgreSQL, and MongoDB
- Establishing secure communication channels between services.
- Data protection strategies for PostgreSQL and MongoDB environments.
- Hardening RabbitMQ to ensure secure message handling.
Identity and Access Management via Keycloak
- Configuring Keycloak for robust user authentication and authorization.
- Managing identity frameworks within Kubernetes clusters.
Applying Security in Kubernetes Environments
- Securely deploying applications on Kubernetes infrastructure.
- Integrating Keycloak with Docker and Kubernetes for cohesive identity management.
DevSecOps Monitoring and Auditing
- Utilizing continuous monitoring tools and advanced techniques.
- Auditing deployment activities to ensure ongoing compliance.
- A practical approach to automating rollbacks in the event of security failures.
Conclusion and Future Pathways
Requirements
- Familiarity with DevOps workflows and methodologies.
- Fundamental proficiency in Docker containers and Kubernetes orchestration.
Target Audience
- DevOps professionals seeking to integrate security practices.
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer