This Project is part of the S4CP Training accessible at https://rohitsalecha.com/s4cp/
- Testing OPA Runtime
- Integrating OPA in GHA
- Introduction to OPA
- Install SCPs (Service Control Policies)
- Installing Network Security Policy
- Installing Calico
- Installing Kyverno
- Testing Violations
- Secrets Management in EKS with AWS SM
- Encrypting K8s Secrets with AWS KMS
- Implementing EKS RBAC
- Creating K8s IAM Roles
- Setting Up Prod K8s
- Trivy Integration
- Semgrep Rules for Scanning Dockerfiles
- Docker Image Build and Push GHA (docker-prod.yaml,docker-dev.yaml)
- Create IAM Role for Github OIDC
- Create ECR Registry
- Integrating GitLeaks in GHA (secrets.yaml)
- Running True Positive Scenario
- Creating Custom GitLeaks Configuration
- Erasing Git History
- Integrating Dependency-checker in GHA (sca.yaml)
- Running Github Actions
- Fixing Dependency Issue
- GHA for running Semgrep (sast.yaml)
- Deploy the Semgrep Rules via GHA
- Test Violations
- Fix the vulnerability
- Rule for Command Injection
- Rule for SQL Injection
- AWS Multi-Account CI/CD Flow
- Creating AWS IAM Users
- Creating AWS IAM Roles and Groups
- Activating AWS Organisations
- Creating AWS Accounts and OUs
- Terraform State Storage Creation
- Spin up The App with complete AWS Infrastructure
- Threat Model the entire scenario