Get in Touch

Course Outline

**Establishing Sovereign DevSecOps Capabilities with GitLab** * **Deployment Models and Governance:** Comparison of Feature Control in GitLab Community Edition versus Enterprise Edition; analysis of self-hosted Omnibus architecture and Kubernetes Helm deployments; assessment of Software-as-a-Service (SaaS) dependency risks and adherence to data residency mandates for government applications. * **System Architecture and Deployment:** Configuration of Omnibus installations on Ubuntu with PostgreSQL and Redis services; implementation of GitLab via Helm charts on Kubernetes with persistent volume management; integration of external infrastructure components including object storage, Simple Mail Transfer Protocol (SMTP), and Lightweight Directory Access Protocol (LDAP); establishment of Geographic replication for multi-region disaster recovery readiness. **Repository Governance and Project Coordination** * **Organizational Structure:** Management of hierarchical relationships among groups, subgroups, and individual projects. * **Collaboration Workflows:** Execution of merge request processes, peer code review procedures, and enforcement of approval authorities. * **Agile Planning Tools:** Utilization of issue boards, epics, and milestones for structured project tracking. * **Documentation and Release Control:** Management of wiki repositories, code snippets, and formal release lifecycles. **Continuous Integration and Deployment Pipeline Engineering** * **Pipeline Configuration:** Definition of `.gitlab-ci.yml` structures, execution stages, and job dependency mappings. * **Runner Infrastructure:** Deployment of shared, group-scoped, and instance-specific runners; configuration of Docker and Kubernetes executors with autoscaling capabilities. * **Resource Management:** Implementation of artifact caching mechanisms, container registry publishing, and automated deployment stages for government systems. **Security Assessment and Compliance** * **Automated Scanning:** Execution of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), dependency vulnerability scanning, and container image analysis. * **Risk Mitigation:** Detection of sensitive secrets and verification of software license compliance for government use cases. * **Threat Management:** Monitoring of vulnerability dashboards and tracking of remediation activities to ensure operational security. **Identity Management and Access Control** * **Single Sign-On (SSO) Integration:** Configuration of LDAP, SAML, and OpenID Connect protocols for unified authentication. * **Enhanced Security Measures:** Enforcement of two-factor authentication (2FA) and management of personal access tokens. * **Network and Audit Controls:** Implementation of IP allowlisting policies and maintenance of comprehensive audit event logs for accountability. **Artifact Registry and Package Distribution** * **Container Management:** Configuration of container registry authentication, lifecycle cleanup policies, and image replication strategies. * **Package Repositories:** Support for Maven, npm, PyPI, and Conan package formats to facilitate standardized software delivery for government agencies. * **Internal Artifact Storage:** Enablement of generic package uploads to secure internal development assets. **Operational Monitoring and Infrastructure Scaling** * **Performance Telemetry:** Collection of GitLab Exporter metrics and visualization via Grafana dashboards for operational oversight. * **Database Optimization:** Tuning of PostgreSQL performance and implementation of PgBouncer connection pooling to enhance scalability. * **System Scalability:** Horizontal expansion of web servers, API nodes, and Sidekiq workers to meet varying workload demands. * **Disaster Recovery Protocols:** Execution of backup strategies using rake tasks and object storage, with rigorous verification of restore capabilities to ensure data integrity for government operations.

Requirements

  • Demonstrated proficiency in advanced Linux system administration, alongside foundational knowledge of Ruby and Go programming languages.
  • Comprehensive understanding of continuous integration and delivery (CI/CD) pipelines, container orchestration methodologies, and Git version control workflows.
  • Proven experience managing PostgreSQL and Redis database systems at an enterprise scale.

Intended Audience

  • Enterprise DevOps units seeking to migrate away from commercial platforms such as GitLab.com or GitHub Enterprise.
  • Organizations prioritizing complete sovereignty over their DevSecOps toolchains through independent infrastructure management.
  • Sectors with stringent regulatory compliance requirements that mandate on-premise CI/CD environments and artifact registries for government
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories