|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/ultimate_devsecops_bootcamp/
课程评论:没有评论
课程名称:终极DevSecOps训练营(Ultimate DevSecOps Bootcamp)- 由School of Devops提供 课程概述:本课程面向在Kubernetes上构建或部署应用的人员,尤其是DevOps工程师、平台工程师或AI/ML工程师。安全再也不是一个可有可无的考虑。这一实践性的DevSecOps训练营将帮助您使用开源工具和行业最佳实践构建安全、可上线的CI/CD管道。您将学习如何在软件开发生命周期中整合安全,确保您的应用在设计之初就具备安全性。 课程将通过逐步实验室,结合Jenkins、Kubernetes、ArgoCD、Vault、Trivy、Falco、OWASP ZAP等现代DevSecOps工作流程中必不可少的工具,引导您完成学习。该课程非常适合构建云原生应用、AI/ML模型或任何需要安全大规模部署的容器化工作负载的团队。 您将学习的内容包括: - 核心DevSecOps原则以及安全软件交付生命周期 - 在Kubernetes上使用Jenkins构建CI/CD管道 - 使用OWASP Dependency-Check、Pyraider和Dependency-Track进行软件组成分析(SCA) - 使用slscan和OWASP ZAP进行静态和动态应用安全测试(SAST & DAST) - 使用Trivy、Dockle和多阶段Dockerfile确保容器镜像安全 - 使用InSpec和Ansible强制合规性作为代码 - 使用HashiCorp Vault和Kubernetes RBAC进行秘密管理 - 使用Falco和自动响应管道进行运行时安全监控 - 使用ArgoCD和Kubernetes进行安全部署工作流程 在本课程中,您将使用的工具和技术包括:Jenkins、Helm、Kubernetes (GKE)、ArgoCD、Trivy、Dockle、OWASP ZAP、slscan、Pyraider、Vault、InSpec、Ansible、Falco、Argo Workflows、Docker、Kubernetes RBAC、GitHub、GitOps。 适合人群: - 希望将安全原则融入工具集的DevOps和云工程师 - 在Kubernetes上部署模型和服务的AI/ML工程师 - 管理现代微服务平台的工程师 - 转型为DevSecOps实践的安全工程师 - 为生产环境构建容器化应用的开发人员 本课程不是理论课程,而是聚焦于真实世界的实验室和项目,模拟现代工程团队在生产环境中保护软件管道的实践。无论您是在部署机器学习模型、微服务还是SaaS产品,这门课程都将帮助您确保您的部署是安全、可扩展且合规的。
Are you building or deploying applications on Kubernetes? Whether you're a DevOps Engineer, Platform Engineer, or AI/ML Engineer, security can no longer be an afterthought.This hands-on DevSecOps Bootcamp will help you build secure, production-ready CI/CD pipelines using open-source tools and industry best practices. Learn how to integrate security across the software development lifecycle and ensure your applications are secure by design.We will walk you through step-by-step labs that combine Jenkins, Kubernetes, ArgoCD, Vault, Trivy, Falco, OWASP ZAP, and other essential tools used in modern DevSecOps workflows.This course is ideal for teams building cloud-native applications, AI/ML models, or any containerized workload that needs to be deployed securely at scale.What You Will Learn:Core DevSecOps principles and the secure software delivery lifecycleHow to build a CI/CD pipeline with Jenkins on KubernetesSoftware Composition Analysis (SCA) using OWASP Dependency-Check, Pyraider, and Dependency-TrackStatic and Dynamic Application Security Testing (SAST & DAST) using slscan and OWASP ZAPSecuring container images using Trivy, Dockle, and multi-stage DockerfilesEnforcing compliance as code using InSpec and AnsibleSecrets management using HashiCorp Vault and Kubernetes RBACRuntime security monitoring using Falco with automated response pipelinesSecure deployment workflows with GitOps using ArgoCD and KubernetesTools and Technologies You Will Use:Jenkins, Helm, Kubernetes (GKE), ArgoCDTrivy, Dockle, OWASP ZAP, slscan, PyraiderVault, InSpec, Ansible, Falco, Argo WorkflowsDocker, Kubernetes RBAC, GitHub, GitOpsWho Should Take This Course:DevOps and Cloud Engineers who want to add security to their toolbeltAI/ML Engineers deploying models and services on KubernetesPlatform Engineers managing modern microservices at scaleSecurity Engineers transitioning to DevSecOps practicesDevelopers building containerized applications for productionThis is not a theoretical course. You will be working on real-world labs and projects that simulate what modern engineering teams do to secure their software pipelines in production environments.Whether you're deploying a machine learning model, a microservice, or a SaaS product - this course will help you ensure that your deployments are secure, scalable, and compliant.