Skip to content

DevSecOps workshop v0.1.1 - optional workload identity

Pre-release
Pre-release

Choose a tag to compare

@frye frye released this 22 Sep 04:59
· 1 commit to main since this release

Optional workload identity: v0.1.1 prerelease

Learners can now perform a complete self-service GITHUB_TOKEN exercise in their own public repository. One job proves an expected permission denial; a separate job with only issue-write permission creates and closes a labeled training issue as github-actions[bot]. The guide includes failure classification, exact-issue cleanup, cancellation recovery, and a safe non-main negative check.

Lesson 1 now explains the GitHub App installation-token identity and job-scoped permissions. The optional lab's OIDC section links official GitHub, Azure, and AWS guidance. It distinguishes an identity assertion from provider-issued access and warns about immutable ID-bearing subjects in new repositories.

No cloud login or ID-token request is added. The two-file core setup, original Pets application template, 75-minute core, and individual secret exercise are unchanged. This is optional take-home or separately scheduled practice, not another mandatory core outcome.

Start and version integrity

Use Step 0 for v0.1.1 for the original-template and companion-fetch routes. Existing learners can open the optional guide directly; they do not need to reinstall the two core workflows.

The annotated v0.1.1 tag resolves to companion commit:

c3286ff3834c963484f5a586531644d182302826

The ZIP and checksum sidecar are attached. SHA-256 of devsecops-workshop-kit-0.1.1.zip:

40a0fdd572047f9f01caf1cce5fa973490b361ae50c9ede85f5b9bda5be90769

The 51-file archive includes all existing live/take-home materials and the optional identity starter, guide, tests, and recorded evidence. Version v0.1.0 and its assets remain unchanged.

Observed evidence

Rehearsal PR12 passed the existing required checks and CodeQL policy before merge. Main run 35688557307 confirmed the exact non-rate-limited integration HTTP 403, then HTTP 201 with the separate write-scoped job. Training issue 13 was created and closed by the bot; no unrelated issue was modified. Non-main run 35688654756 failed before API access and skipped the allowed job.

All 50 local tests passed, including 17 new permission/error/cleanup cases. Four inert starters passed actionlint. The document validator checked 25 kit Markdown files, 185 local links, and 25 command/config snippets. Two builds produced identical ZIP bytes. Humanizer v3.0.0 File mode was applied from its pinned source to every changed Markdown file; the installed skill loader remains unavailable.

This remains a rehearsal prerelease. The browser-only workflow presentation, fresh independent learner walkthroughs, and human timing remain unverified. OIDC is documentation-only guidance, not a tested cloud integration. See the readiness register for the full evidence and remaining manual gates.