Security

Application and infrastructure security – container and Kubernetes security, supply-chain security, API security and DevSecOps.

Broad introduction to several DevSecOps related tools. Nice hands on experience with easy to use lap environment.
Andreas Andreas
Software Engineer
More testimonials →

Application & Infrastructure Security

Secure systems, data and identities – from API and app security to Kubernetes and supply-chain hardening.

API Security

Two-day course on developing and operating APIs securely: spot vulnerabilities from the OWASP API Security Top 10, ward off attacks, and apply security best practices.

View course →

Container Supply Chain Security: The Practitioner's Journey

Step-by-step securing of the container supply chain: From chaos to cryptographically verifiable trust in four practical levels.

View course →

DevSecOps

Build security straight into your CI/CD pipelines: static code analysis, container scanning, SBOM generation and Kubernetes policy management following the shift-left approach.

View course →

Hands-On Security Lab

This two-day course sensitises participants to cyber security threats by giving them hands-on experience of penetration testing techniques in a comprehensive lab environment.

View course →

Harbor for Supply Chain Security

Implement and automate Harbor as a central building block for secure container registry infrastructures, software distribution, and supply chain security.

View course →

HashiCorp Vault

Professional secrets management with HashiCorp Vault in Kubernetes environments. From integration to application development.

View course →

Container & Kubernetes Security

Intensive Introduction to Security Aspects of Kubernetes and Container Environments, including Best Practices and Overview of Potential Threats.

View course →

Secrets Management with OpenBao

Two days hands-on with OpenBao for developers and DevOps engineers: authenticate, write policies, use KV, database, PKI and Transit secrets engines, inject secrets in Kubernetes and fetch dynamic secrets in GitLab CI/CD - without vendor lock-in.

View course →

OpenBao Operations & Architecture

Introduce and run OpenBao as a central secrets platform: architecture, storage and high availability, auto-unseal, namespaces and governance, audit and monitoring, backup and DR, upgrades, hardening and migration from HashiCorp Vault.

View course →

Spring Security

Secure Spring Security 6 and 7 in modern Spring Boot architectures – from classic web apps to SPA + Backend-for-Frontend (BFF), with OAuth 2.0, OpenID Connect and Keycloak.

View course →

What participants say

Broad introduction to several DevSecOps related tools. Nice hands on experience with easy to use lap environment.
Andreas Andreas
Software Engineer
This course helped me to better understand how everything comes together in a Kubernetes environment in terms of security.
Simon Simon
Bedag
Outstanding course for starting the K8s and container security learning journey.
Christian Christian
Site Reliability Engineer, CSS
Nice start into K8s security themes after passing CKA exam.
Marco Marco
Schmucki ICT
Excellent course. Many thanks to Jonas for this outstanding session.
Roland
RVolk Consult
Nice overview about risk and issues related to k8s-security with some handy examples. It requires already some knowledge about k8s / docker / linux.
Juerg
Worldline

More testimonials →