301 Labs Overview
Overview
These advanced labs are the enterprise scale-up of the 201-11 STRIDE map: RHACM PolicySet, GitOps of a Red Hat catalog Python image, AdminNetworkPolicy, ACS runtime enforce, Splunk+ACS IR, supply-chain admission, encryption inventory, and SPIFFE workload identity.
Topics covered:
-
Platform-wide security governance (STRIDE PolicySet)
-
GitOps of a digest-pinned UBI Python image (Red Hat Images)
-
Multi-tenant zero-trust with AdminNetworkPolicy
-
RHACS runtime policies that kill violating processes
-
Incident response with Splunk audit + RHACS
-
Supply-chain digest admission for catalog images
-
Encryption inventory (etcd, TLS, no secret-as-env)
-
Zero-trust workload identity (SPIFFE)
Audience and prerequisites:
-
OpenShift cluster with cluster-admin (or delegated) access for most labs
-
Deep OpenShift networking, security, and architecture familiarity
-
Complete 201 Intermediate first, especially 201-11
Advanced Labs Index
| Lab | Title |
|---|---|
STRIDE PolicySet (RHACM governance) |
|
GitOps UBI Python (digest-pinned catalog image) |
|
AdminNetworkPolicy zero-trust east-west |
|
RHACS runtime enforce (kill violating actions) |
|
Splunk audit + RHACS incident timeline |
|
Catalog image provenance and digest admission |
|
Prove etcd encryption, TLS, no secret-as-env |
|
Zero-Trust Workload Identity (SPIFFE/ZTWIM) |