301 Labs Overview

Table of Contents

Overview

These advanced labs are the enterprise scale-up of the 201-11 STRIDE map: RHACM PolicySet, GitOps of a Red Hat catalog Python image, AdminNetworkPolicy, ACS runtime enforce, Splunk+ACS IR, supply-chain admission, encryption inventory, and SPIFFE workload identity.

Topics covered:

  • Platform-wide security governance (STRIDE PolicySet)

  • GitOps of a digest-pinned UBI Python image (Red Hat Images)

  • Multi-tenant zero-trust with AdminNetworkPolicy

  • RHACS runtime policies that kill violating processes

  • Incident response with Splunk audit + RHACS

  • Supply-chain digest admission for catalog images

  • Encryption inventory (etcd, TLS, no secret-as-env)

  • Zero-trust workload identity (SPIFFE)

Application Developer has no Advanced labs in the framework—complete Intermediate, then continue with DevSecOps or Architect.

Audience and prerequisites:

  • OpenShift cluster with cluster-admin (or delegated) access for most labs

  • Deep OpenShift networking, security, and architecture familiarity

  • Follow a role track for the labs your role owns

Advanced Labs Index

Lab Title Roles

301-01

STRIDE PolicySet (RHACM governance)

Platform, Architect

301-02

GitOps UBI Python (digest-pinned catalog image)

DevSecOps, Architect

301-03

AdminNetworkPolicy zero-trust east-west

Architect, Network

301-04

RHACS runtime enforce (kill violating actions)

DevSecOps

301-05

Splunk audit + RHACS incident timeline

Architect

301-06

Catalog image provenance and digest admission

DevSecOps, Architect

301-07

Prove etcd encryption, TLS, no secret-as-env

DevSecOps, Architect, Network

301-08

Zero-Trust Workload Identity (SPIFFE/ZTWIM)

DevSecOps, Architect, Network

Role abbreviations: App Dev = Application Developer; Platform = Platform Operator; DevSecOps = DevSecOps Engineer; Architect = Security Architect; Network = Network & Infrastructure Engineer.