A recommended four-day workshop around shared policy decisions
This proposed agenda follows one application and its security requirements. The technical work makes differences between application changes, policy settings, and approval responsibilities visible.
Day 1
Workload behavior and runtime requirements
We connect images, Pods, Deployments, Services, and probes to the application's required behavior. Each role identifies which settings are application needs and which are shared restrictions.
Hands-on exercises
- Compare two workload configurations against the supplied policy intent.
- Explain an application startup problem without assuming that a policy exception is the only correction.
Day 2
Templates, architecture, and control ownership
We examine Helm and Kustomize defaults alongside the API and admission path. Participants distinguish what templates suggest from what the platform actually enforces.
Hands-on exercises
- Trace a security-related value from the template to the admitted workload.
- Compare a warning with a rejected Pod and identify the configuration responsible.
Day 3
Network and placement boundaries
We connect Services, ingress, network policies, and placement to the intended application connections. The group discusses service mesh controls without assuming every environment needs the same implementation.
Hands-on exercises
- Review a permitted application connection from security and application perspectives.
- Compare a workload requirement with the controls and owner needed to support it.
Day 4
State, resources, access, and joint review
We examine secrets, storage, resource settings, scaling, and RBAC as parts of the workload contract. Participants review the application and explain the evidence needed for any justified exception.
Hands-on exercises
- Compare the credentials and data access required by the workload with its configured permissions.
- Present a joint review that separates compatible fixes, missing evidence, and decisions requiring approval.
Your security, platform, and application teams, shared defaults, and review boundaries can shape the agenda. Get in touch to tailor the workshop to how your teams work together.