Stratpoint Engineering

DevSecOps Engineering Bootcamp

Sign in with your Stratpoint Google account to continue.

DevSecOps Engineering
DevSecOps Engineering Bootcamp
Chapter 3

Video Resources

1. SAST, SCA & Secrets Scanning — Week 1, Days 1-2 Implementation Guide

Gitleaks — secrets detection, step by step

Semgrep (SAST): https://www.youtube.com/watch?v=Ip6knn_8NDw — adding a Semgrep SAST job and custom rules to GitLab CI

Trivy (SCA + image scan): https://www.youtube.com/watch?v=OiRzHiCehII — container vulnerability scanning

Watch Out

Three tools, one stage — Gitleaks blocks on secrets, Semgrep blocks on critical SAST findings, Trivy blocks on HIGH/CRITICAL CVEs. All three run before the build stage, in that order.

2. Secrets Management — Week 1, Days 3-4 Implementation Guide

External Secrets Operator Tutorial for Kubernetes Secret Management

3. Manifest Security — Week 1, Day 5 Implementation Guide

Checkov — scanning Helm charts for misconfigurations

4. Admission Control — Week 2, Days 1-2 Implementation Guide

Kyverno — enforcing Kubernetes security policies, complete walkthrough

5. Supply Chain Security — Week 2, Days 3-4 Implementation Guide

Cosign signatures, attestation, Trivy reports and Kyverno policies together

Syft (SBOM generation): https://www.youtube.com/watch?v=9oj3BC3vOtc — generating an SBOM from a container image

6. Runtime Security — Week 2, Days 3-4 Implementation Guide

Falco for Kubernetes runtime security — eBPF, rules, tuning and alerts