101 Labs Overview
Start from a role: * Application Developer * Platform Operator *DevSecOps * Security Architect * Network & Infrastructure
Overview
These basic labs introduce OpenShift’s secure-by-default posture. Align workloads to built-in guardrails instead of bypassing them.
Topics covered:
-
Container security fundamentals (projects and namespaces)
-
Default OpenShift platform security layers
-
Basic RBAC
-
Workload guardrails (SCC/PSA, quotas, limits)
-
Least privilege (non-root, minimal capabilities)
-
NetworkPolicies
-
Secrets basics
-
Trusted images and vulnerability awareness
-
Encryption in transit and at rest
-
Audit and cluster logs
-
Security extension operators (awareness)
Audience: any of the five framework roles. Prefer a role track so you only take the labs your role owns (for example, Application Developer skips audit logging and compliance add-ons).
Basic Labs Index
| Lab | Title | Roles |
|---|---|---|
Default Secure Behavior |
App Dev, Platform, DevSecOps, Architect, Network |
|
Projects & Namespaces as Security Boundaries |
App Dev, Platform, DevSecOps, Architect, Network |
|
Role-Based Access Control Basics |
App Dev, Platform, DevSecOps, Architect |
|
SCC Limits, Resource Guardrails & Pod Security |
App Dev, Platform, DevSecOps, Architect, Network |
|
NetworkPolicy Basics |
App Dev, Platform, DevSecOps, Architect, Network |
|
Secrets Management |
App Dev, Platform, DevSecOps, Architect |
|
Image Provenance Guardrails |
App Dev, Platform, DevSecOps, Architect |
|
Etcd Encryption at Rest & Control Plane Hardening |
App Dev, Platform, DevSecOps, Architect, Network |
|
Audit Logging & Exec Events |
Platform, DevSecOps, Architect, Network |
|
Security & Compliance Add-Ons Overview |
Platform, Architect |
|
Rebuilding & Hardening Images |
App Dev, DevSecOps (Platform secondary) |
|
Enforcing TLS on Routes |
App Dev, Platform, DevSecOps, Architect, Network |