Skip to content

vitalsecurity/AKS-DevSecOps-Workshop

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

245 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AKS DevSecOps Workshop

Welcome to the AKS DevSecOps Workshop, a hands-on learning experience designed to help developers, security engineers, and DevOps professionals understand how to integrate security into the Azure Kubernetes Service (AKS) lifecycle. This workshop demonstrates best practices for securing containerized applications, implementing CI/CD pipelines, and applying governance and compliance standards in a cloud-native environment.

Workshop Guide

The full lab guide is hosted on Notion, providing step-by-step instructions, exercises, and references for each module:

Key Topics Covered

  • Setting up an Azure Kubernetes Service (AKS) cluster
  • Integrating security scanning into CI/CD pipelines
  • Implementing DevSecOps practices for containerized applications
  • Using Azure Policy and governance tools for compliance
  • Detecting vulnerabilities and remediating risks in AKS deployments

Resources

For reference, the original workshop repository from Microsoft is available here:

Who Should Use This Workshop

  • Developers looking to build secure applications on Kubernetes
  • DevOps engineers aiming to integrate security into CI/CD pipelines
  • Security professionals exploring practical cloud-native security controls
  • Students or enthusiasts learning modern DevSecOps practices

Getting Started

  1. Review the Notion lab guide to understand the workshop structure and prerequisites.
  2. Clone this repository for access to scripts, templates, and exercise files.
  3. Follow along with the lab modules to build, secure, and deploy applications in AKS while applying DevSecOps practices.

Acknowledgements

H/T to the Contributors of https://github.com/Azure/AKS-DevSecOps-Workshop, including https://github.com/ahmedbham https://github.com/msmarti and others who developed and open sourced this exercise.

About

A repo with labs for implementing a best practice for each phase of DevSecOps lifecycle for AKS

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages

  • Java 82.2%
  • HTML 10.5%
  • Bicep 7.3%