301 Labs Overview
Overview
These advanced labs are the enterprise scale-up of the 201-11 STRIDE map: RHACM PolicySet, GitOps of a Red Hat catalog Python image, AdminNetworkPolicy, ACS runtime enforce, Splunk+ACS IR, supply-chain admission, encryption inventory, and SPIFFE workload identity.
Topics covered:
-
Platform-wide security governance (STRIDE PolicySet)
-
GitOps of a digest-pinned UBI Python image (Red Hat Images)
-
Multi-tenant zero-trust with AdminNetworkPolicy
-
RHACS runtime policies that kill violating processes
-
Incident response with Splunk audit + RHACS
-
Supply-chain digest admission for catalog images
-
Encryption inventory (etcd, TLS, no secret-as-env)
-
Zero-trust workload identity (SPIFFE)
Application Developer has no Advanced labs in the framework—complete Intermediate, then continue with DevSecOps or Architect.
Audience and prerequisites:
-
OpenShift cluster with cluster-admin (or delegated) access for most labs
-
Deep OpenShift networking, security, and architecture familiarity
-
Follow a role track for the labs your role owns
Advanced Labs Index
| Lab | Title | Roles |
|---|---|---|
STRIDE PolicySet (RHACM governance) |
Platform, Architect |
|
GitOps UBI Python (digest-pinned catalog image) |
DevSecOps, Architect |
|
AdminNetworkPolicy zero-trust east-west |
Architect, Network |
|
RHACS runtime enforce (kill violating actions) |
DevSecOps |
|
Splunk audit + RHACS incident timeline |
Architect |
|
Catalog image provenance and digest admission |
DevSecOps, Architect |
|
Prove etcd encryption, TLS, no secret-as-env |
DevSecOps, Architect, Network |
|
Zero-Trust Workload Identity (SPIFFE/ZTWIM) |
DevSecOps, Architect, Network |
Role abbreviations: App Dev = Application Developer; Platform = Platform Operator; DevSecOps = DevSecOps Engineer; Architect = Security Architect; Network = Network & Infrastructure Engineer.