201 Labs Overview
Overview
These intermediate labs move from knowing defaults to integrating and adapting controls: custom RBAC/SCC, shift-left pipelines, external secrets, audit correlation, compliance tailoring, and admission governance. Finish with threat modeling so the control map can use every lab you already ran.
Topics covered:
-
Advanced RBAC and service account hardening
-
Custom workload security controls (SCC/PSA, SELinux, seccomp)
-
Tighter isolation / restriction profiles
-
Advanced network segmentation and egress/ingress controls
-
CI/CD scanning and policy checks
-
Secure, reproducible images with signing/attestation
-
Secret lifecycle (rotation, externalization)
-
Audit/monitoring correlation
-
Automated compliance assessment and remediation
-
Admission and policy controllers
-
Practical threat modeling (capstone — maps the controls above)
Work them in order after 101 Foundations, then continue with 301 Advanced.
Intermediate Labs Index
| Lab | Title |
|---|---|
Custom RBAC & ClusterRoles |
|
Custom SCC, Seccomp, SELinux & User Namespaces |
|
File Integrity Monitoring & Node Hardening |
|
CI/CD Scanning, Image Signing & Cosign/Sigstore |
|
Secret Lifecycle Externalization (Vault, ESO, CSI) |
|
Audit Log Correlation & Anomaly Detection |
|
Advanced Compliance Operator Usage & Tailoring |
|
Certificate Management & mTLS Basics |
|
Sandboxed Containers & Workload Isolation |
|
RHACM Policy Governance (DoD / NIST baseline) |
|
STRIDE control map (capstone → 301) |