Learn DevSecOps
The controls that reduce the most risk, in the order worth doing them.
What does the Learn DevSecOps track cover?
This track covers building security verification into delivery, hardening containers and clusters, making a large vulnerability backlog tractable, and getting credentials out of repositories.
The route, in order
Beyond shift-left, and why moving a check earlier is not sufficient on its own.
Non-root, minimal images, digest pinning and the runtime controls that go with them.
Pod security standards, network policy, RBAC and admission control, prioritised.
Deduplication, exposure ranking and verified closure.
Short-lived credentials, coordinated rotation and what to do when one leaks.
Why an SBOM turns the next disclosure into a query.
What you should be able to do afterwards
- Explain why exposure ranking beats sorting by CVSS
- Harden a container image and its pod specification together
- Prioritise Kubernetes security controls by risk reduced per unit of effort
- Respond correctly to a credential committed to a repository
Where this shows up in the product
Questions about this track
Both. The material assumes infrastructure familiarity rather than a security background, which is deliberate: most of these controls are applied by platform teams.
Only where they change technical practice. The focus is on controls that reduce risk rather than on framework mapping.
Where to go next
Learn DevOps
Start here if DevOps is a word you use more confidently than you would like.
Learn Kubernetes
For people who have to run Kubernetes, not just deploy to it.
Learn observability
What each signal is for, how to make them join, and how to keep the bill sane.
Learn AI and agentic DevOps
Where agents genuinely help, where they are oversold, and how to introduce them safely.
Learn cloud operations
Running infrastructure across providers without three of everything.
See it working rather than reading about it
Connect a cluster read-only during a demo call and look at the concepts in your own environment.