If you're interested in application security and DevSecOps, but don't spend all day writing code, hands-on labs are one of the best ways to close that gap.
I recently refreshed a DevSecOps workshop to make it fully functional with current GitHub and Azure security capabilities.
- Workshop repo: github.com/vitalsecurity/AKS-DevSecOps-Workshop
- Workshop guide: vitalsecurity.notion.site/aks-devsecops-workshop
What it covers
- Core DevSecOps concepts, common vulnerabilities, and best practices
- How security integrates into modern CI/CD pipelines
- Using GitHub and Azure features to shift security left
- Capabilities such as CodeQL, dependency scanning, cloud security tooling, and developer integrations
The documentation was updated with expanded explanations, additional screenshots, PowerShell-based commands, and a clean-up module to restore environments after completing the lab.
H/T to the repo's authors and contributors for open sourcing this workshop: azure.github.io/AKS-DevSecOps-Workshop
Feedback is always welcome, and I hope others find this useful.