🔐DevSecOps & Security Hardening
Security at every stage. Scan images in CI. Enforce policies at admission time. Detect runtime anomalies. Encrypt secrets. Implement zero-trust networking.
Architecture & How It Works 10.1
Defense-in-depth layers: code scanning → image scanning → admission control → runtime detection → network segmentation → access control. Shift left reduces blast radius.
Core Components 10.2
| Tool | Role | Primary Command |
|---|---|---|
| Trivy | Vulnerability scanner | trivy image |
| Falco | Runtime threat detection | falco -r custom-rules.yaml |
| Gatekeeper / OPA | Admission webhook policies | kubectl apply -f constraint.yaml |
| SOPS + age | Secret encryption | sops --encrypt |
| NetworkPolicy | Pod traffic control | kubectl apply -f netpol.yaml |
WSL Hands-On Lab 10.3
Trivy → Falco on kind → OPA Constraint → SOPS → NetworkPolicy
$ trivy image --severity CRITICAL myapp:latest $ helm repo add falcosecurity https://falcosecurity.github.io/charts $ helm install falco falcosecurity/falco -n falco --create-namespace $ sops --encrypt --in-place secrets/production.yaml
- Scan a deliberately vulnerable image and fix findings
- Deploy Falco and trigger a runtime rule
- Create and test OPA Gatekeeper constraint denying privileged pods
- Encrypt a Helm values file using SOPS + age
- Apply a NetworkPolicy that isolates a namespace
Real-World Project 10.4
Trivy scan step inside GitHub Actions
OPA policies + NetworkPolicies + encrypted secrets with SOPS
Falco + SIEM integration + Cosign image signing + SLSA provenance + SOC2 controls
Troubleshooting 10.5
Create exceptions or custom rules that match your legitimate workloads.
Start with dryRun: true mode. Review audit logs before switching to deny.
Always test with a wide allow policy first. Use namespace selectors carefully.
30-Day Roadmap 10.6
- Trivy / Grype workflows
- Distroless images
- Fixing CVEs fast
- RBAC least privilege
- Pod Security Standards
- NetworkPolicy
- Falco rules
- OPA Gatekeeper
- Admission controllers
- Cosign signing
- SLSA + SBOM
- Compliance automation
Deep Dive: Supply Chain Security 10.7
Cosign + SLSA
Sign every image in CI. Verify signatures in admission controller or at deploy time. Generate SBOMs and attach them. Meet SLSA level 2+ for high-trust environments.
Runtime + Admission Synergy
Falco catches what static analysis misses. OPA prevents bad configurations from ever reaching the cluster. Together they provide full defense in depth.