Stratpoint Engineering

DevSecOps Engineering Bootcamp

Sign in with your Stratpoint Google account to continue.

DevSecOps Engineering
DevSecOps Engineering Bootcamp
Chapter 5

Project Details

Continuing From Phase 1

You keep working in the same GitLab repository from Phase 1 — Phase 2 is not a new clone. Pull the Phase 2 guides from the devsecops branch of the training repo into your existing project:

git clone -b devsecops https://github.com/stratpoint-engineering/devops-capstone-3tier-app.git devsecops-guides
cp devsecops-guides/docs/1*.md <your-gitlab-project>/docs/

Project Focus

Secure the same 3-tier app pipeline from Phase 1: add security scanning to GitLab CI, replace hardcoded secrets with ESO and Vault, scan and fix your Helm chart with Checkov, enforce policy cluster-wide with Kyverno, sign and attest images with Cosign and Syft, and monitor runtime threats with Falco.

Repository Structure

docs/                              # Phase 2 implementation guides
|-- 10-devsecops-intro.md
|-- 11-sast-sca-scanning.md
|-- 12-secrets-management.md
|-- 13-manifest-security.md
|-- 14-admission-control.md
|-- 15-supply-chain-security.md
|-- 16-runtime-security.md
+-- devsecops-capstone-requirements.md

policies/
|-- kyverno/                       # ClusterPolicy YAMLs
+-- falco/custom-rules.yaml        # Custom Falco rules

secrets/
|-- secretstore.yaml               # ESO SecretStore
+-- externalsecret-db.yaml         # ExternalSecret for DB creds

Implementation Order

  • Read the intro — docs/10-devsecops-intro.md — before writing any config
  • Add pipeline scanning — docs/11-sast-sca-scanning.md — Gitleaks + Semgrep + Trivy in GitLab CI
  • Migrate secrets — docs/12-secrets-management.md — ESO + Vault, remove all hardcoded credentials
  • Scan manifests — docs/13-manifest-security.md — Checkov on Helm charts, fix HIGH/CRITICAL findings
  • Enforce policies — docs/14-admission-control.md — Kyverno with 4 core policies, Audit then Enforce
  • Secure the supply chain — docs/15-supply-chain-security.md — Syft SBOM + Cosign signing
  • Add runtime security — docs/16-runtime-security.md — Falco + Grafana security dashboard

Deliverables (20% each)

RequirementWeightWhat to Show
Pipeline Security20%Updated .gitlab-ci.yml with all four scanning jobs · screenshot of a passing run · screenshot of a run that failed on a finding, then fixed
Secrets Management20%secretstore.yaml and externalsecret-db.yaml · kubectl describe externalsecret showing SecretSynced · backend pod running with ESO-injected secrets
Manifest Security20%Checkov scan showing 0 HIGH/CRITICAL findings · updated Helm chart with security contexts · manifest-scan job in .gitlab-ci.yml
Admission Control20%4+ Kyverno policies in policies/kyverno/ · kubectl get clusterpolicy all READY · a blocked kubectl run attempt · ArgoCD still syncing
Supply Chain + Runtime Security20%generate-sbom and sign-images CI jobs · SBOM artifact · Kyverno signature-verification policy · custom Falco rules · Grafana security dashboard · Falco detecting a shell spawn

Deliverable Checklist

  • Updated .gitlab-ci.yml with Gitleaks, Semgrep, Trivy, Checkov, Syft, and Cosign stages
  • secretstore.yaml and externalsecret-db.yaml committed to the repo
  • Helm chart updated: non-root, resource limits, no latest tag, no plaintext secrets
  • policies/kyverno/ with 4+ ClusterPolicy YAMLs, all READY
  • policies/falco/custom-rules.yaml with 2+ custom rules for your app
  • SBOM (.json) artifact from a recent pipeline run, attached to the image in the registry
  • Grafana security dashboard showing Falco events, with an alert rule for CRITICAL events
  • No secrets in Git history, verified with Gitleaks

Evaluation Criteria

TierRequirements
Basic (70-79%)Pipeline has 2+ scanning jobs · ESO installed with 1+ secret managed externally · Checkov run locally with some findings fixed · Kyverno with 2+ policies · Falco installed with default rules
Proficient (80-89%)All 4 scanning jobs in CI · all DB credentials via ESO · Checkov in CI with 0 HIGH/CRITICAL findings · all 4 Kyverno policies enforced · images signed and verified · Falco alerts visible in Grafana
Advanced (90-100%)All of Proficient, plus: a real finding caught and documented before/after · custom Falco rules for your app · SBOM attached in the registry · Grafana dashboard with alert rules · full commit-to-detect demo

Optional Bonus Points

BonusPointsWhat to Do
DAST+5%Add an OWASP ZAP scan against your running staging environment
Network Policies+5%Implement Kubernetes NetworkPolicy to restrict pod-to-pod traffic
CIS Benchmark+5%Run kube-bench against your cluster and remediate findings

Final Presentation

Duration: 30 minutes (20 minutes presentation + 10 minutes Q&A)

RequirementWeightWhat to show
Technical Demo100%Live pipeline run with all security stages · a scan finding caught and fixed · Kyverno enforcing policy at deploy time · a Falco alert in Grafana · SBOM attached to an image in the registry