DevSecOps Engineering Bootcamp
Chapter 2
Prerequisites
Required Accounts
GitLab Account — the same account and repository you used for Phase 1. Phase 2 is not a fresh project; it builds directly on top of it.
Verify Phase 1 Is Working
Watch Out
Phase 2 builds directly on Phase 1 — don't start here until your cluster, Helm chart, GitLab CI pipeline, and ArgoCD sync are all working end-to-end.
- Kubernetes cluster running
- ArgoCD installed and syncing
- GitLab CI pipeline passing on the main branch
kubectl get nodes kubectl get pods -n argocd # then check your GitLab project > CI/CD > Pipelines
Local Tooling
| Tool | Install | Used For |
|---|---|---|
| Python 3 + pip | pip install checkov semgrep | Manifest and code scanning, run locally before pushing |
| Cosign | See Sigstore install docs | Signing and verifying container images |
| Syft | See Anchore install docs | Generating SBOMs from container images |
Add the Helm repos you'll need this phase:
helm repo add external-secrets https://charts.external-secrets.io helm repo add kyverno https://kyverno.github.io/kyverno/ helm repo add falcosecurity https://falcosecurity.github.io/charts helm repo add hashicorp https://helm.releases.hashicorp.com helm repo update