Course Overview
- Course Title: Ultimate DevSecOps Bootcamp by School of DevOps
- Instructor: Gourav J. Shah (Premium Udemy Instructor, 200,000+ students)
- Target Audience:
- DevOps/Cloud Engineers integrating security into pipelines
- AI/ML Engineers deploying models on Kubernetes
- Platform Engineers managing microservices at scale
- Security Engineers transitioning to DevSecOps
- Developers building containerized applications for production
- Prerequisites:
- Familiarity with DevOps concepts and basic CI/CD workflows (recommended)
- Prior experience with Docker and Kubernetes (helpful but not mandatory)
- Access to a GCP account (or any cloud environment for labs)
- No deep security knowledge required
Curriculum Highlights
- Key Topics Covered:
- DevSecOps principles and secure software delivery lifecycle
- CI/CD pipeline with Jenkins, Helm, and Kubernetes (GKE)
- Software Composition Analysis (SCA) using OWASP Dependency-Check, Pyraider, Dependency-Track
- Static Application Security Testing (SAST) with slscan
- Dynamic Application Security Testing (DAST) using OWASP ZAP
- Container hardening with Trivy, Dockle, and multi-stage Dockerfiles
- Secrets management via HashiCorp Vault and Kubernetes RBAC
- Compliance-as-Code with InSpec and Ansible
- Runtime security monitoring using Falco and Argo Workflows
- GitOps deployment with ArgoCD
- Software Bill of Materials (SBOM) integration
- End-to-end secure pipeline from code to production
- Key Skills Learned:
- Design secure CI/CD pipelines for cloud-native applications
- Automate security testing (SAST/DAST/SCA) in pipelines
- Harden containers, Kubernetes workloads, and infrastructure
- Implement secrets management and compliance automation
- Deploy AI/ML models and microservices securely using GitOps
- Monitor runtime anomalies and enforce automated remediation
Course Format
- Duration: 8 hours on-demand video
- Format: Self-paced online course (lifetime access)
- Resources:
- 61 articles
- 8 downloadable resources (labs, configurations, scripts)
- Mobile and TV access
- Certificate of completion
Tools & Technologies
- CI/CD & Orchestration: Jenkins, Helm, Kubernetes (GKE), ArgoCD
- Security Testing: Trivy, Dockle, OWASP ZAP, slscan, Pyraider
- Secrets & Compliance: HashiCorp Vault, InSpec, Ansible, Kubernetes RBAC
- Runtime Security: Falco, Argo Workflows
- Containerization: Docker, Multi-stage builds
- Version Control: GitHub, GitOps


