Appendix: instructor two-day grouping
This page is for instructors running a two-day event. It is not an exercise. Nothing to pass here.
Learners still start at Workshop home and 1.1. Do not brief this grouping as a clock they must beat.
Envelope, not a timer
The catalog envelope is a two-day event. Clock time is not the design constraint. Catalog duration stays unset until a dry run measures it.
-
Do not drop a gated Check to fit a wall clock.
-
Do not add a timer, attempt cap, or instructor reset.
-
Rebalance this page after dry runs. Do not rewrite the seven-track story to make Day 2 shorter.
Day 2 has more Checks (eleven) than Day 1 (seven gated plus the ungated intro). That split is story order (trusted inputs, then build through operate), not an even split of minutes.
Suggested grouping
Day 1 — trusted inputs and source (tracks 1–3)
Orientation plus every Check that pins what the app is allowed to consume.
| Page | Track | Why it belongs on Day 1 |
|---|---|---|
— |
Ungated map. No Check. Point at honor system and “what this is not” before 1.1. |
|
1 |
Published digest and Hardened Images key. Arm64 is a callout, not a Check. |
|
1 |
Learner-run oc-mirror. Dest digest is what later |
|
2 |
Author |
|
2 |
Exact |
|
3 |
Learner-owned Gitea remotes. Templates stay in |
|
3 |
Runtime |
|
3 |
Merge a real |
Day 1 exit: 3.3 Check passed (bot PR merged, not a hand-edit). Tracks 4–7 assume those pins and that dest digest.
Day 2 — build through operate (tracks 4–7)
Hermetic build, sign, promote, then prove the pin in TPA.
| Page | Track | Why it belongs on Day 2 |
|---|---|---|
4 |
Strip public |
|
4 |
Wire Task |
|
4 |
Tighten |
|
4 |
OpenShift BuildConfig image plus SBOM. Known-bad Dockerfile still fails. |
|
5 |
RHTAS Fulcio / Rekor / TUF on the app digest. |
|
5 |
Tighten the weak seed; fail then pass. |
|
5 |
Second Check: learner TUF root plus |
|
6 |
Stage GitOps; unsigned deny. VM / canary / blue-green are callouts. |
|
6 |
Commit the signed digest to the prod remote. Prod Argo must not still track stage. |
|
7 |
Ingest the promoted digest into TPA. |
|
7 |
Lightwell GAV-bound VEX from Track 2; ACS is not the disabled stub. |
Day 2 exit: 7.2 Check passed. Appendices are not a third day.
Overnight
Keep the same claim overnight. Do not reprovision between days.
-
Start Day 2 at 4.1, not at the intro.
-
If 3.3 did not merge, finish it before 4.1. A hand-edited pin fails that Check and poisons Track 4.
-
The Renovate CronJob is default-off. If
oc -n renovate get cronjobis empty, the claim never enabledcomponents.renovate— debug the chart; do not fake a PR.
If the room runs short
Coverage first. Do not cut a gated page.
Safe to defer (read later, not a Check):
Not safe to defer: 3.3, 5.3, 6.2, 7.2. Later pages assume those edits landed.
Honor system and debug
Classic Showroom does not lock the next URL. Learners can open 7.2 on day one. Say so once (the intro already does). If they skip a Check, later steps fail for real.
-
There is no Solve — not a Job, not a playbook, not an instructor button. Support debugs by hand.
-
Learners may re-run each Validate Job as often as they need. No quota. No instructor reset.
-
Jobs live in
lw-poc-validate. Templates are ConfigMapvalidate-job-templates. The Job grades cluster/git state and the per-module report token (not a screenshot). Do not invent a lock.
GitHub Dependabot and lab Maven / pip pins
Do not merge Dependabot Maven PRs that bump commons-lang3 (or spring-core) on this GitHub repo. Those versions are the scored affected line (3.14.0 / LW-DEMO-0002). “Upgrade to latest” (3.18.0) is the wrong story; Track 2.2 is the exact .rhlw-* pin.
Do not merge Dependabot pip PRs that bump httpx (or the FastAPI/uvicorn pins) on the Python lab fixtures. httpx==0.27.2 is the Validated demo line.
Lab fixtures on GitHub are pom.xml.example and requirements.txt.example. Gitea seed renames them so learners still see pom.xml / requirements.txt. Keep it that way. Do not rename publishing-house/tools/requirements.txt.
After the workshop
Finishing the claim is not the enablement metric. Score Appendix: internal enablement checklist after the event. It is not a live customer proof-of-value during these two days.
After dry runs
When you have wall-clock notes:
-
Record minutes per gated page (sticky note or spreadsheet). Do not invent minutes in the catalog spec.
-
If Day 2 overruns, move a whole track boundary on this page (for example, start Day 2 at 5.1 and finish 4.x on Day 1). Do not delete a Check.
-
Set catalog duration only after those notes exist.
Related
-
Workshop home — learner map and honor system
-
Internal enablement checklist — scored after the event, not during
-
Consultant delivery map — engagement activity → track
-
Konflux mapping — names used in client engagements
