A proposed four-day workshop on defensive mechanisms
Participants need workload and permissions foundations. The supported attack-and-defense customization uses isolated examples and synthetic resources, with the selected access path kept explicit throughout.
Day 1
Workload privileges and expected behavior
Explain container settings, host interaction, service accounts, and the application's required operations. Compare the intended configuration with the effective workload.
Hands-on exercises
- Identify an unnecessary capability in a prepared example.
- Record the required and unwanted actions used to evaluate a correction.
Day 2
Templates, architecture, and permissions
Connect rendered resources, control-plane authorization, admission, and node responsibilities. Inspect how a seemingly narrow permission can enable a broader operation.
Hands-on exercises
- Trace the identity and permission behind a bounded access path.
- Compare declared restrictions with the settings admitted by the cluster.
Day 3
Network and dependency boundaries
Examine service exposure, network policy, and the distinction between connectivity and authorization. Keep the example scoped to the infrastructure and workloads that provide its path.
Hands-on exercises
- Verify intended and unintended connections in the isolated setup.
- Diagnose a control that does not apply to the expected workload.
Day 4
Correct, verify, and record
Review secrets, data access, resource constraints, and defensive changes. Verify one correction while preserving the legitimate operation the application needs.
Hands-on exercises
- Repeat the prepared scenario after a targeted control change.
- Write the mechanism, evidence, and remaining limits into a reusable review record.
Your workload configurations, defensive questions, and platform responsibilities can shape the agenda. Get in touch to tailor the workshop to your team's work.