Appendix: instructor two-day grouping

This page is for instructors running a two-day event. It is not an exercise. Nothing to pass here.

Learners still start at Workshop home and 1.1. Do not brief this grouping as a clock they must beat.

Envelope, not a timer

The catalog envelope is a two-day event. Clock time is not the design constraint. Catalog duration stays unset until a dry run measures it.

  • Do not drop a gated Check to fit a wall clock.

  • Do not add a timer, attempt cap, or instructor reset.

  • Rebalance this page after dry runs. Do not rewrite the seven-track story to make Day 2 shorter.

Day 2 has more Checks (eleven) than Day 1 (seven gated plus the ungated intro). That split is story order (trusted inputs, then build through operate), not an even split of minutes.

Suggested grouping

Instructor two-day grouping: Day 1 tracks 1–3

Day 1 — trusted inputs and source (tracks 1–3)

Orientation plus every Check that pins what the app is allowed to consume.

Page Track Why it belongs on Day 1

Workshop home

Ungated map. No Check. Point at honor system and “what this is not” before 1.1.

1.1 Verify Hummingbird

1

Published digest and Hardened Images key. Arm64 is a callout, not a Check.

1.2 Mirror into the trust boundary

1

Learner-run oc-mirror. Dest digest is what later FROM lines use.

2.1 Enterprise proxy

2

Author settings.xml against in-cluster Nexus. Python / Artifactory are callouts.

2.2 Remediated pin

2

Exact .rhlw-* on a broken pom.xml. Track 7 VEX is this GAV.

3.1 Golden-path source

3

Learner-owned Gitea remotes. Templates stay in workshop-templates.

3.2 Bind base and deps

3

Runtime FROM the dest Hummingbird digest plus Lightwell pins.

3.3 Live Renovate

3

Merge a real renovate-bot PR. Do not leave this for Day 2.

Day 1 exit: 3.3 Check passed (bot PR merged, not a hand-edit). Tracks 4–7 assume those pins and that dest digest.

Day 2 — build through operate (tracks 4–7)

Hermetic build, sign, promote, then prove the pin in TPA.

Page Track Why it belongs on Day 2

4.1 Source forbid-list

4

Strip public FROM / Central / curl from active build files.

4.2 Prefetch (Hermeto mapping)

4

Wire Task prefetch-dependencies. Not hosted Konflux Hermeto.

4.3 Build NetworkPolicy

4

Tighten build-egress on lw-poc-build. App-ns operate is Track 6.

4.4 Build and SBOM

4

OpenShift BuildConfig image plus SBOM. Known-bad Dockerfile still fails.

5.1 Sign (keyless)

5

RHTAS Fulcio / Rekor / TUF on the app digest.

5.2 Attest + Conforma

5

Tighten the weak seed; fail then pass.

5.3 Disconnected verify

5

Second Check: learner TUF root plus --key. Cluster stays networked.

6.1 GitOps + admission

6

Stage GitOps; unsigned deny. VM / canary / blue-green are callouts.

6.2 Promote to prod repo

6

Commit the signed digest to the prod remote. Prod Argo must not still track stage.

7.1 SBOM system of record

7

Ingest the promoted digest into TPA.

7.2 VEX blast radius + ACS

7

Lightwell GAV-bound VEX from Track 2; ACS is not the disabled stub.

Day 2 exit: 7.2 Check passed. Appendices are not a third day.

Overnight

Keep the same claim overnight. Do not reprovision between days.

  • Start Day 2 at 4.1, not at the intro.

  • If 3.3 did not merge, finish it before 4.1. A hand-edited pin fails that Check and poisons Track 4.

  • The Renovate CronJob is default-off. If oc -n renovate get cronjob is empty, the claim never enabled components.renovate — debug the chart; do not fake a PR.

If the room runs short

Coverage first. Do not cut a gated page.

Safe to defer (read later, not a Check):

Not safe to defer: 3.3, 5.3, 6.2, 7.2. Later pages assume those edits landed.

Honor system and debug

Classic Showroom does not lock the next URL. Learners can open 7.2 on day one. Say so once (the intro already does). If they skip a Check, later steps fail for real.

  • There is no Solve — not a Job, not a playbook, not an instructor button. Support debugs by hand.

  • Learners may re-run each Validate Job as often as they need. No quota. No instructor reset.

  • Jobs live in lw-poc-validate. Templates are ConfigMap validate-job-templates. The Job grades cluster/git state and the per-module report token (not a screenshot). Do not invent a lock.

GitHub Dependabot and lab Maven / pip pins

Do not merge Dependabot Maven PRs that bump commons-lang3 (or spring-core) on this GitHub repo. Those versions are the scored affected line (3.14.0 / LW-DEMO-0002). “Upgrade to latest” (3.18.0) is the wrong story; Track 2.2 is the exact .rhlw-* pin.

Do not merge Dependabot pip PRs that bump httpx (or the FastAPI/uvicorn pins) on the Python lab fixtures. httpx==0.27.2 is the Validated demo line.

Lab fixtures on GitHub are pom.xml.example and requirements.txt.example. Gitea seed renames them so learners still see pom.xml / requirements.txt. Keep it that way. Do not rename publishing-house/tools/requirements.txt.

After the workshop

Finishing the claim is not the enablement metric. Score Appendix: internal enablement checklist after the event. It is not a live customer proof-of-value during these two days.

After dry runs

When you have wall-clock notes:

  1. Record minutes per gated page (sticky note or spreadsheet). Do not invent minutes in the catalog spec.

  2. If Day 2 overruns, move a whole track boundary on this page (for example, start Day 2 at 5.1 and finish 4.x on Day 1). Do not delete a Check.

  3. Set catalog duration only after those notes exist.