CIS/Iron Bank-aligned container hardening with OPA/Kyverno policies, Cosign signing, SBOM generation, and Falco runtime detection.
-
Updated
Aug 9, 2026 - Open Policy Agent
CIS/Iron Bank-aligned container hardening with OPA/Kyverno policies, Cosign signing, SBOM generation, and Falco runtime detection.
Composable, secure-by-default AWS Terraform modules with a full authoring toolchain — terraform-docs, native tests, tflint, semver.
Production-grade Kubernetes platform bootstrap from Kind to EKS — GitOps, observability, and runtime security managed declaratively.
SRE observability lab — SLO-based alerting, burn-rate math, chaos engineering, runbooks, and Grafana dashboards as code
Production-grade MLOps deployment pipeline — container hardening, CI/CD, GitOps, observability, and Kyverno policy enforcement around a HuggingFace model.
A deliberately simple Go app with a deliberately thorough deployment lifecycle — migrations, container hardening, GitOps, and observability.
Agent workload on tenant-controlled, security-hardened Kubernetes. Phase 1 (runtime evaluation) in progress.
Policy-as-code static analysis for Terraform against the CIS AWS Foundations Benchmark using tfsec, Trivy, and OPA/Rego.
Add a description, image, and links to the devsecops-labs topic page so that developers can more easily learn about it.
To associate your repository with the devsecops-labs topic, visit your repo's landing page and select "manage topics."