Course structure available

Stage 09 · DevSecOps & Secrets

Trivy Complete Course

Use Trivy across container images, filesystems, repositories, SBOMs, Kubernetes, IaC, secrets, licenses, CI/CD, VEX, attestations, policies, air-gapped environments, and enterprise DevSecOps workflows.

TRV
39chapters
195lessons
Intermediatestarting level
Hands-onlearning mode
Course stateCurriculum ready

Course brief

A practical Trivy curriculum for vulnerability, misconfiguration, secret, license, SBOM, and supply-chain scanning across modern DevOps pipelines.

This course is organized as a progressive operational curriculum. Lesson files are reserved in the repository structure so future content can be added without changing URLs or navigation.

By the end

You will be able to

  • Scan container images, filesystems, repositories, SBOMs, and Kubernetes environments
  • Interpret vulnerabilities, severities, fix status, packages, and dependency paths
  • Detect IaC misconfigurations, exposed secrets, and license risks
  • Integrate Trivy into CI/CD, registries, admission workflows, and security gates
  • Operate caches, databases, VEX, policies, air-gapped scanning, and large-scale security automation

Complete syllabus

39 chapters in prerequisite order.

The structure goes beyond a command reference and includes architecture, security, reliability, troubleshooting, automation, governance, and production operations.

01

Chapter 1

Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner Types

5 lessons
01
Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner Types: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner Types: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner Types: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner Types: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Trivy Foundations, DevSecOps Use Cases, Architecture, and Scanner TypesReserved in course structure
Planned
02

Chapter 2

Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab Setup

5 lessons
01
Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab Setup: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab Setup: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab Setup: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab Setup: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Installing Trivy 0.72.x, Containers, Packages, Verification, and Lab SetupReserved in course structure
Planned
03

Chapter 3

Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline Considerations

5 lessons
01
Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline Considerations: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline Considerations: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline Considerations: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline Considerations: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Vulnerability Databases, Metadata, Update Lifecycle, Caching, and Offline ConsiderationsReserved in course structure
Planned
04

Chapter 4

Container Image Scanning Fundamentals, Layers, Packages, and Findings

5 lessons
01
Container Image Scanning Fundamentals, Layers, Packages, and Findings: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Container Image Scanning Fundamentals, Layers, Packages, and Findings: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Container Image Scanning Fundamentals, Layers, Packages, and Findings: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Container Image Scanning Fundamentals, Layers, Packages, and Findings: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Container Image Scanning Fundamentals, Layers, Packages, and FindingsReserved in course structure
Planned
05

Chapter 5

OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity Sources

5 lessons
01
OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity Sources: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity Sources: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity Sources: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity Sources: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — OS Package Vulnerabilities, Distribution Advisories, Fix Status, and Severity SourcesReserved in course structure
Planned
06

Chapter 6

Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and More

5 lessons
01
Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and More: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and More: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and More: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and More: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Language Dependency Scanning for npm, pip, Maven, Go, Ruby, .NET, and MoreReserved in course structure
Planned
07

Chapter 7

Filesystem Scanning, Local Projects, Build Outputs, and Host Paths

5 lessons
01
Filesystem Scanning, Local Projects, Build Outputs, and Host Paths: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Filesystem Scanning, Local Projects, Build Outputs, and Host Paths: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Filesystem Scanning, Local Projects, Build Outputs, and Host Paths: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Filesystem Scanning, Local Projects, Build Outputs, and Host Paths: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Filesystem Scanning, Local Projects, Build Outputs, and Host PathsReserved in course structure
Planned
08

Chapter 8

Repository Scanning, Git Sources, Branches, and Pre-Build Security

5 lessons
01
Repository Scanning, Git Sources, Branches, and Pre-Build Security: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Repository Scanning, Git Sources, Branches, and Pre-Build Security: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Repository Scanning, Git Sources, Branches, and Pre-Build Security: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Repository Scanning, Git Sources, Branches, and Pre-Build Security: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Repository Scanning, Git Sources, Branches, and Pre-Build SecurityReserved in course structure
Planned
09

Chapter 9

Root Filesystems, VM Images, and Infrastructure Artifact Scanning

5 lessons
01
Root Filesystems, VM Images, and Infrastructure Artifact Scanning: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Root Filesystems, VM Images, and Infrastructure Artifact Scanning: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Root Filesystems, VM Images, and Infrastructure Artifact Scanning: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Root Filesystems, VM Images, and Infrastructure Artifact Scanning: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Root Filesystems, VM Images, and Infrastructure Artifact ScanningReserved in course structure
Planned
10

Chapter 10

SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and Consumption

5 lessons
01
SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and Consumption: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and Consumption: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and Consumption: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and Consumption: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — SBOM Fundamentals, CycloneDX, SPDX, Generation, Export, and ConsumptionReserved in course structure
Planned
11

Chapter 11

Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security Analysis

5 lessons
01
Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security Analysis: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security Analysis: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security Analysis: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security Analysis: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Scanning Existing SBOMs, Dependency Intelligence, and Decoupled Security AnalysisReserved in course structure
Planned
12

Chapter 12

Secret Scanning, Detectors, Entropy, False Positives, and Secret Hygiene

5 lessons
01
Secret Scanning, Detectors, Entropy, False Positives, and Secret Hygiene: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Secret Scanning, Detectors, Entropy, False Positives, and Secret Hygiene: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Secret Scanning, Detectors, Entropy, False Positives, and Secret Hygiene: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Secret Scanning, Detectors, Entropy, False Positives, and Secret Hygiene: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Secret Scanning, Detectors, Entropy, False Positives, and Secret HygieneReserved in course structure
Planned
13

Chapter 13

Misconfiguration Scanning, IaC Security Model, Checks, and Results

5 lessons
01
Misconfiguration Scanning, IaC Security Model, Checks, and Results: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Misconfiguration Scanning, IaC Security Model, Checks, and Results: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Misconfiguration Scanning, IaC Security Model, Checks, and Results: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Misconfiguration Scanning, IaC Security Model, Checks, and Results: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Misconfiguration Scanning, IaC Security Model, Checks, and ResultsReserved in course structure
Planned
14

Chapter 14

Terraform Scanning, Modules, Plans Awareness, and Cloud Misconfigurations

5 lessons
01
Terraform Scanning, Modules, Plans Awareness, and Cloud Misconfigurations: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Terraform Scanning, Modules, Plans Awareness, and Cloud Misconfigurations: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Terraform Scanning, Modules, Plans Awareness, and Cloud Misconfigurations: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Terraform Scanning, Modules, Plans Awareness, and Cloud Misconfigurations: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Terraform Scanning, Modules, Plans Awareness, and Cloud MisconfigurationsReserved in course structure
Planned
15

Chapter 15

Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration Scanning

5 lessons
01
Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration Scanning: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration Scanning: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration Scanning: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration Scanning: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Kubernetes YAML, Helm, Kustomize, and Manifest Misconfiguration ScanningReserved in course structure
Planned
16

Chapter 16

Dockerfile and Container Configuration Security

5 lessons
01
Dockerfile and Container Configuration Security: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Dockerfile and Container Configuration Security: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Dockerfile and Container Configuration Security: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Dockerfile and Container Configuration Security: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Dockerfile and Container Configuration SecurityReserved in course structure
Planned
17

Chapter 17

CloudFormation and Infrastructure Template Security

5 lessons
01
CloudFormation and Infrastructure Template Security: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
CloudFormation and Infrastructure Template Security: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
CloudFormation and Infrastructure Template Security: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
CloudFormation and Infrastructure Template Security: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — CloudFormation and Infrastructure Template SecurityReserved in course structure
Planned
18

Chapter 18

Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane Findings

5 lessons
01
Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane Findings: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane Findings: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane Findings: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane Findings: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Kubernetes Cluster Scanning, Workloads, RBAC, Nodes, and Control-Plane FindingsReserved in course structure
Planned
19

Chapter 19

Trivy Operator Architecture, Custom Resources, Controllers, and Cluster Automation

5 lessons
01
Trivy Operator Architecture, Custom Resources, Controllers, and Cluster Automation: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Trivy Operator Architecture, Custom Resources, Controllers, and Cluster Automation: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Trivy Operator Architecture, Custom Resources, Controllers, and Cluster Automation: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Trivy Operator Architecture, Custom Resources, Controllers, and Cluster Automation: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Trivy Operator Architecture, Custom Resources, Controllers, and Cluster AutomationReserved in course structure
Planned
20

Chapter 20

License Scanning, Package Licenses, Policy Decisions, and Compliance

5 lessons
01
License Scanning, Package Licenses, Policy Decisions, and Compliance: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
License Scanning, Package Licenses, Policy Decisions, and Compliance: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
License Scanning, Package Licenses, Policy Decisions, and Compliance: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
License Scanning, Package Licenses, Policy Decisions, and Compliance: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — License Scanning, Package Licenses, Policy Decisions, and ComplianceReserved in course structure
Planned
21

Chapter 21

Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and Precedence

5 lessons
01
Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and Precedence: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and Precedence: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and Precedence: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and Precedence: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Configuration Files, trivy.yaml, CLI Flags, Environment Variables, and PrecedenceReserved in course structure
Planned
22

Chapter 22

Filtering Results, Severity, Status, Ignore-Unfixed, and Scope Reduction

5 lessons
01
Filtering Results, Severity, Status, Ignore-Unfixed, and Scope Reduction: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Filtering Results, Severity, Status, Ignore-Unfixed, and Scope Reduction: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Filtering Results, Severity, Status, Ignore-Unfixed, and Scope Reduction: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Filtering Results, Severity, Status, Ignore-Unfixed, and Scope Reduction: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Filtering Results, Severity, Status, Ignore-Unfixed, and Scope ReductionReserved in course structure
Planned
23

Chapter 23

.trivyignore, Ignore Policies, Expiration, Governance, and Exception Management

5 lessons
01
.trivyignore, Ignore Policies, Expiration, Governance, and Exception Management: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
.trivyignore, Ignore Policies, Expiration, Governance, and Exception Management: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
.trivyignore, Ignore Policies, Expiration, Governance, and Exception Management: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
.trivyignore, Ignore Policies, Expiration, Governance, and Exception Management: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — .trivyignore, Ignore Policies, Expiration, Governance, and Exception ManagementReserved in course structure
Planned
24

Chapter 24

Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific Rules

5 lessons
01
Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific Rules: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific Rules: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific Rules: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific Rules: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Custom Checks with Rego, OPA Concepts, Policies, and Organization-Specific RulesReserved in course structure
Planned
25

Chapter 25

Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDX

5 lessons
01
Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDX: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDX: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDX: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDX: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Output Formats: Table, JSON, SARIF, Template, CycloneDX, and SPDXReserved in course structure
Planned
26

Chapter 26

GitHub Actions Integration, SARIF Upload, PR Feedback, and Security Gates

5 lessons
01
GitHub Actions Integration, SARIF Upload, PR Feedback, and Security Gates: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
GitHub Actions Integration, SARIF Upload, PR Feedback, and Security Gates: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
GitHub Actions Integration, SARIF Upload, PR Feedback, and Security Gates: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
GitHub Actions Integration, SARIF Upload, PR Feedback, and Security Gates: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — GitHub Actions Integration, SARIF Upload, PR Feedback, and Security GatesReserved in course structure
Planned
27

Chapter 27

GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD Integration

5 lessons
01
GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD Integration: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD Integration: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD Integration: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD Integration: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — GitLab CI, Jenkins, Azure Pipelines, and Generic CI/CD IntegrationReserved in course structure
Planned
28

Chapter 28

Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private Registries

5 lessons
01
Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private Registries: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private Registries: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private Registries: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private Registries: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Registry Authentication for Docker Hub, GHCR, ECR, ACR, GCR/Artifact Registry, and Private RegistriesReserved in course structure
Planned
29

Chapter 29

Remote Scanning, Trivy Server, Client/Server Architecture, and Shared Databases

5 lessons
01
Remote Scanning, Trivy Server, Client/Server Architecture, and Shared Databases: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Remote Scanning, Trivy Server, Client/Server Architecture, and Shared Databases: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Remote Scanning, Trivy Server, Client/Server Architecture, and Shared Databases: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Remote Scanning, Trivy Server, Client/Server Architecture, and Shared Databases: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Remote Scanning, Trivy Server, Client/Server Architecture, and Shared DatabasesReserved in course structure
Planned
30

Chapter 30

Cache Backends, Persistent Cache, Redis Concepts, and Performance

5 lessons
01
Cache Backends, Persistent Cache, Redis Concepts, and Performance: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Cache Backends, Persistent Cache, Redis Concepts, and Performance: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Cache Backends, Persistent Cache, Redis Concepts, and Performance: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Cache Backends, Persistent Cache, Redis Concepts, and Performance: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Cache Backends, Persistent Cache, Redis Concepts, and PerformanceReserved in course structure
Planned
31

Chapter 31

Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline Scanning

5 lessons
01
Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline Scanning: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline Scanning: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline Scanning: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline Scanning: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Air-Gapped and Restricted Networks, DB Mirroring, OCI Artifacts, and Offline ScanningReserved in course structure
Planned
32

Chapter 32

VEX, OpenVEX, Not-Affected Statements, and Vulnerability Context

5 lessons
01
VEX, OpenVEX, Not-Affected Statements, and Vulnerability Context: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
VEX, OpenVEX, Not-Affected Statements, and Vulnerability Context: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
VEX, OpenVEX, Not-Affected Statements, and Vulnerability Context: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
VEX, OpenVEX, Not-Affected Statements, and Vulnerability Context: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — VEX, OpenVEX, Not-Affected Statements, and Vulnerability ContextReserved in course structure
Planned
33

Chapter 33

Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented Workflows

5 lessons
01
Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented Workflows: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented Workflows: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented Workflows: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented Workflows: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Supply-Chain Security, SBOMs, Provenance, Attestations, and SLSA-Oriented WorkflowsReserved in course structure
Planned
34

Chapter 34

Kubernetes Admission and Policy Integration Patterns

5 lessons
01
Kubernetes Admission and Policy Integration Patterns: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Kubernetes Admission and Policy Integration Patterns: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Kubernetes Admission and Policy Integration Patterns: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Kubernetes Admission and Policy Integration Patterns: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Kubernetes Admission and Policy Integration PatternsReserved in course structure
Planned
35

Chapter 35

Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive Enforcement

5 lessons
01
Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive Enforcement: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive Enforcement: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive Enforcement: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive Enforcement: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Exit Codes, Quality Gates, Baselines, Risk Acceptance, and Progressive EnforcementReserved in course structure
Planned
36

Chapter 36

Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and Monorepos

5 lessons
01
Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and Monorepos: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and Monorepos: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and Monorepos: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and Monorepos: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Performance Tuning, Parallelism, Cache Reuse, Large Repositories, and MonoreposReserved in course structure
Planned
37

Chapter 37

Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner Failures

5 lessons
01
Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner Failures: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner Failures: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner Failures: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner Failures: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Troubleshooting Databases, Registries, Authentication, False Positives, and Scanner FailuresReserved in course structure
Planned
38

Chapter 38

Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least Privilege

5 lessons
01
Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least Privilege: Concepts, Vocabulary, and Mental ModelReserved in course structure
Planned
02
Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least Privilege: Guided Configuration and Hands-On WorkflowReserved in course structure
Planned
03
Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least Privilege: Design Patterns, Trade-Offs, and Production DecisionsReserved in course structure
Planned
04
Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least Privilege: Security, Diagnostics, Failure Modes, and TroubleshootingReserved in course structure
Planned
05
Checkpoint Lab — Security of the Scanner, DB Trust, Binary Verification, Credentials, and Least PrivilegeReserved in course structure
Planned
39

Chapter 39

Production Capstone: Build a Multi-Artifact Trivy Security Pipeline with Governance and Exceptions

5 lessons
01
Capstone Requirements, Architecture, Threat Model, and Success CriteriaReserved in course structure
Planned
02
Build the End-to-End Environment — Build a Multi-Artifact Trivy Security Pipeline with Governance and ExceptionsReserved in course structure
Planned
03
Integrate Automation, Security Controls, Observability, and GovernanceReserved in course structure
Planned
04
Inject Failures, Diagnose Behavior, Recover Safely, and Verify StateReserved in course structure
Planned
05
Final Validation, Runbook, Operational Handoff, and Improvement BacklogReserved in course structure
Planned

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0 Send only Ethereum/ERC-20 compatible assets to this address.