A proposed four-day workshop on credential evidence
Participants need workload, identity, and TLS foundations. We use non-production credentials and a selected integration to distinguish the lifecycle responsibilities of each component.
Day 1
Workload configuration and credential consumers
Explain how an application receives and uses its configuration and credentials. Compare startup behavior with its ability to adopt a later value.
Hands-on exercises
- Map the example credential from its source to the consuming process.
- Identify whether replacement, reload, or another application action is required.
Day 2
Controllers, templates, and synchronization
Connect resource configuration, ownership, refresh behavior, and observed conditions. Distinguish a failed source fetch from a successful update the application has not consumed.
Hands-on exercises
- Trace a bounded renewal or refresh through controller status.
- Diagnose an access or configuration fault in the selected synchronization path.
Day 3
Identity, TLS, and trust boundaries
Examine workload identity, service connections, certificate chains, and trust distribution. Separate possession of a certificate from acceptance by the intended peer.
Hands-on exercises
- Compare a credential-consumption failure with a trust failure.
- Verify the effect of a controlled certificate change on representative client connections.
Day 4
Rotation, recovery, and operating records
Review state, rollout, permissions, and observability during lifecycle changes. Record the non-secret evidence needed to accept or investigate a renewal.
Hands-on exercises
- Rehearse a bounded credential change and verify the application's behavior.
- Document the source, controller, consumer, and trust checks for repetition.
Your credential integrations, lifecycle questions, and team responsibilities can shape the agenda. Get in touch to tailor the workshop to your team's work.