201 Labs Overview

Table of Contents

Overview

These intermediate labs move from knowing defaults to integrating and adapting controls: custom RBAC/SCC, shift-left pipelines, external secrets, audit correlation, compliance tailoring, and admission governance. Finish with threat modeling so the control map can use every lab you already ran.

Topics covered:

  • Advanced RBAC and service account hardening

  • Custom workload security controls (SCC/PSA, SELinux, seccomp)

  • Tighter isolation / restriction profiles

  • Advanced network segmentation and egress/ingress controls

  • CI/CD scanning and policy checks

  • Secure, reproducible images with signing/attestation

  • Secret lifecycle (rotation, externalization)

  • Audit/monitoring correlation

  • Automated compliance assessment and remediation

  • Admission and policy controllers

  • Practical threat modeling (capstone — maps the controls above)

Work them in order after 101 Foundations, then continue with 301 Advanced.

Intermediate Labs Index

Lab Title

201-01

Custom RBAC & ClusterRoles

201-02

Custom SCC, Seccomp, SELinux & User Namespaces

201-03

File Integrity Monitoring & Node Hardening

201-04

CI/CD Scanning, Image Signing & Cosign/Sigstore

201-05

Secret Lifecycle Externalization (Vault, ESO, CSI)

201-06

Audit Log Correlation & Anomaly Detection

201-07

Advanced Compliance Operator Usage & Tailoring

201-08

Certificate Management & mTLS Basics

201-09

Sandboxed Containers & Workload Isolation

201-10

RHACM Policy Governance (DoD / NIST baseline)

201-11

STRIDE control map (capstone → 301)