Skip to content
DevOps Architect

    Syllabus / Operations / 10

    STARTUP TO ENTERPRISE
    10 / 14 • SHIFT-LEFT SECURITY

    🔐DevSecOps & Security Hardening

    Security at every stage. Scan images in CI. Enforce policies at admission time. Detect runtime anomalies. Encrypt secrets. Implement zero-trust networking.

    Trivy CI OPA + NetPol Falco + Cosign + SLSA

    Architecture & How It Works 10.1

    Defense-in-depth layers: code scanning → image scanning → admission control → runtime detection → network segmentation → access control. Shift left reduces blast radius.

    graph LR Code[Code Repo] --> Trivy[Trivy Scan] Trivy --> Build[Build Image] Build --> Gate[OPA Gatekeeper] Gate --> Runtime[Falco] Runtime --> Net[NetworkPolicy] Net --> Access[RBAC/IRSA]

    Core Components 10.2

    ToolRolePrimary Command
    TrivyVulnerability scannertrivy image
    FalcoRuntime threat detectionfalco -r custom-rules.yaml
    Gatekeeper / OPAAdmission webhook policieskubectl apply -f constraint.yaml
    SOPS + ageSecret encryptionsops --encrypt
    NetworkPolicyPod traffic controlkubectl apply -f netpol.yaml

    WSL Hands-On Lab 10.3

    Trivy → Falco on kind → OPA Constraint → SOPS → NetworkPolicy

    security commands
    $ trivy image --severity CRITICAL myapp:latest
    $ helm repo add falcosecurity https://falcosecurity.github.io/charts
    $ helm install falco falcosecurity/falco -n falco --create-namespace
    $ sops --encrypt --in-place secrets/production.yaml
    • Scan a deliberately vulnerable image and fix findings
    • Deploy Falco and trigger a runtime rule
    • Create and test OPA Gatekeeper constraint denying privileged pods
    • Encrypt a Helm values file using SOPS + age
    • Apply a NetworkPolicy that isolates a namespace

    Real-World Project 10.4

    Trivy scan step inside GitHub Actions

    OPA policies + NetworkPolicies + encrypted secrets with SOPS

    Falco + SIEM integration + Cosign image signing + SLSA provenance + SOC2 controls

    Troubleshooting 10.5

    Create exceptions or custom rules that match your legitimate workloads.

    Start with dryRun: true mode. Review audit logs before switching to deny.

    Always test with a wide allow policy first. Use namespace selectors carefully.

    30-Day Roadmap 10.6

    WEEK 1
    Image Hardening
    • Trivy / Grype workflows
    • Distroless images
    • Fixing CVEs fast
    WEEK 2
    Kubernetes Security
    • RBAC least privilege
    • Pod Security Standards
    • NetworkPolicy
    WEEK 3
    Runtime Detection
    • Falco rules
    • OPA Gatekeeper
    • Admission controllers
    WEEK 4
    Supply Chain
    • Cosign signing
    • SLSA + SBOM
    • Compliance automation

    Deep Dive: Supply Chain Security 10.7

    Cosign + SLSA

    Sign every image in CI. Verify signatures in admission controller or at deploy time. Generate SBOMs and attach them. Meet SLSA level 2+ for high-trust environments.

    Runtime + Admission Synergy

    Falco catches what static analysis misses. OPA prevents bad configurations from ever reaching the cluster. Together they provide full defense in depth.

    Run: trivy image --severity CRITICAL myapp:latest

    Extra commands from this lesson (3) are kept out of this page. Quizzes were not in the source HTML.