Course Outline
Overview of DevSecOps Framework
- Strategic value of embedding security controls within the software development lifecycle
- Fundamental tenets and operational practices of DevSecOps
Security Controls for Continuous Integration (CI)
- Hardening code repository access (GitLab integration with Jenkins)
- Deployment of automated code quality assurance and vulnerability assessment via SonarQube
- Incorporation of static application security testing (SAST) into the Jenkins CI workflow
Docker Container Security Protocols
- Construction of hardened Docker container images
- Administration of container image registries using Harbor
- Adoption of industry-standard vulnerability scanning and version control methodologies
Establishment of Secure CI/CD Workflows
- Configuration of Jenkins for robust security integration
- Execution of comprehensive SonarQube security assessments
- Generation and protection of Docker container images
Kubernetes-Based Deployment Security
- Security standards for Kubernetes orchestration environments
- Function of the Kubernetes Orchestrator in facilitating secure, progressive deployments
- Implementation of Role-Based Access Control (RBAC) and encryption for service-to-service communication
Integration of RabbitMQ, PostgreSQL, and MongoDB
- Maintenance of encrypted communication channels between microservices
- Security protocols for data at rest in PostgreSQL and MongoDB environments
- Hardenng RabbitMQ configurations to ensure secure message queuing
Identity and Access Management via Keycloak
- Configuration of Keycloak for centralized authentication and authorization services
- Management of digital identities across Kubernetes cluster infrastructure
Kubernetes Security Implementation Strategies
- Secure deployment methodologies for applications within Kubernetes environments
- Integration of Keycloak with Docker and Kubernetes ecosystems for unified identity governance
DevSecOps Monitoring and Audit Compliance
- Deployment of continuous monitoring technologies and operational techniques
- Audit procedures for deployment activities and adherence to regulatory compliance standards
- Operational guidance for automating system rollback procedures in response to security incidents
Conclusion and Future Actions
Requirements
- Demonstrated proficiency in DevOps methodologies
- Fundamental expertise in Docker containerization and Kubernetes orchestration frameworks
Target Audience
- DevOps practitioners seeking resources designed for government
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer