A working engineer's devops and devsecops reference — notes, snippets, configs, and templates for vulnerability scanning, secret detection, supply chain security, runtime security, policy engines, and infrastructure automation.
New here? Start at the learning path. It walks you from first-contact to confident in a sensible order — read that before the table below.
A working DevSecOps engineer's quick-reference for Trivy, Semgrep, Checkov, Grype, TruffleHog, Syft, Cosign, OPA, Falco, and HashiCorp Vault. Use it as a shelf you grab from, not a tutorial site. It deliberately does not try to replace each tool's official docs.
A curated collection of notes, scripts, snippets, and templates covering vulnerability scanning, secret detection, supply chain security, runtime security, policy engines, and secrets management. Every entry is scenario-grounded and designed to be adapted for real infrastructure work.
The kit spans tools including Trivy, Semgrep, Checkov, Grype, CodeQL, Snyk, Terrascan, TruffleHog, GitGuardian, Syft, Cosign, Dependabot, Falco, Tetragon, OPA, Vault, ZAP, DefectDojo, SonarQube, Docker, Kubernetes, Helm, Kustomize, ArgoCD, GitHub Actions, Terraform, OpenTofu, Git, Prometheus, Grafana, and observability — with CVE-specific remediation guidance, Linux system administration, and CI/CD pipeline toolkits.
- Secrets access management practice exercises — Python exercises for secret handling and access management
- Version control with Git practice exercises — Hands-on Git exercises for branching, merging, and collaboration
- Infrastructure as Code practice exercises — HCL exercises for Terraform resource composition
- Linux & Shell practice exercises — Shell scripting and command-line exercises
- Supply chain security practice exercises — SBOM and dependency verification exercises
00_index/— Navigation: topic index, quick links, glossary, learning pathassets/— Architecture diagrams and workflow illustrationsargocd/— ArgoCD GitOps delivery notes, manifests, and first-app deploymentscheckov//semgrep//trivy//trufflehog//syft/— Security scanner notes, scripts, configsgrype//codeql//zap//snyk//gitguardian//falco//cosign//tetragon/— Vulnerability scanner and runtime security tool contentterrascan//opa/— IaC compliance and policy engine primersdefectdojo/— Vulnerability management platform notesdependabot/— Dependency update configs and alertsvault/— HashiCorp Vault primers, configs, and scriptsgit/— Git primers, branching, and version controldocker/— Docker image authoring, CLI, and container securitygithub-actions/— GitHub Actions CI/CD workflows and runnershelm//kubernetes//kustomize/— Kubernetes ecosystem noteslinux/— Linux fundamentals, CLI, system administration, and security hardeningsonarqube//opentofu/— Static analysis and IaC tool primersgrafana//observability//prometheus/— Metrics, logs, traces, dashboardsdocs/— How-to guides, concepts, reference, runbooks, security docs, troubleshooting, setup guidesenvironments/— Terraform environment configs (dev / staging / prod)lab/— Mini-projects and sandboxesscripts/— Shell scripts organised by tool (bash toolkit directories)snippets/— Copy-paste ready one-liners and cheatsheetstemplates/— Starter configs for Kubernetes, Terraform, Linux, Jenkins, Logstash, syslog-ngterraform/— Terraform primers, configs, scripts, and EventBridge Lambda modules.github/— GitHub templates (PR template, CODEOWNERS)CHANGELOG.md— Release history and version trackingCONTRIBUTING.md— Contribution guidelines and workflow
Coverage table
| Tool | Notes | Scripts | Configs | Snippets | Docs | Manifests | Templates | Notebooks | Dockerfiles | Policies | Total |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Trivy | 3 | 5 | 2 | 1 | 3 | 2 | 6 | 2 | 1 | — | 25 |
| TruffleHog | 3 | 3 | 2 | 2 | 2 | 1 | 21 | 2 | 1 | — | 37 |
| ZAP | 5 | 2 | 2 | 4 | 3 | — | 16 | — | 1 | — | 33 |
| Checkov | 4 | 2 | 2 | 4 | 5 | 2 | 10 | 2 | — | 1 | 32 |
| Syft | 4 | 3 | 1 | 1 | 5 | — | 7 | 1 | 1 | — | 23 |
| Grype | 4 | 8 | 1 | 2 | 1 | 2 | — | 1 | 1 | — | 20 |
| Semgrep | 3 | 3 | 1 | 2 | 4 | 2 | — | 1 | 2 | — | 18 |
| Terraform | 2 | 3 | 1 | 1 | — | — | — | — | — | — | 7 |
| Falco | 4 | 3 | 3 | 1 | 2 | — | — | — | — | — | 13 |
| CodeQL | 3 | 1 | 1 | 4 | 1 | 1 | — | — | 1 | — | 12 |
| GitGuardian | 4 | 2 | 2 | 2 | 1 | — | — | — | — | — | 11 |
| Vault | 3 | 2 | 2 | 1 | 2 | — | — | — | 1 | — | 11 |
| Snyk | 4 | 1 | 2 | 1 | 1 | — | — | — | 1 | — | 10 |
| OPA | 3 | 1 | 1 | 3 | 1 | — | — | — | — | — | 9 |
| Cosign | 4 | 2 | 1 | 1 | — | 1 | — | — | — | — | 9 |
| Terrascan | 5 | 1 | 1 | 2 | — | — | — | — | — | — | 9 |
| Dependabot | 6 | — | 3 | — | — | — | — | — | — | — | 9 |
| Git | 3 | 2 | — | 1 | — | — | — | — | — | — | 6 |
| Docker | 2 | 1 | — | — | — | — | — | — | 2 | — | 5 |
| ArgoCD | 2 | — | — | — | — | 1 | — | — | — | — | 3 |
| Helm | 2 | — | — | — | — | 1 | — | — | — | — | 3 |
| Kubernetes | 2 | — | — | — | — | 1 | — | — | — | — | 3 |
| Kustomize | 2 | — | 1 | — | — | — | — | — | — | — | 3 |
| GitHub Actions | 2 | — | 1 | — | — | — | — | — | — | — | 3 |
| SonarQube | 2 | — | — | 1 | — | — | — | — | — | — | 3 |
| Tetragon | 2 | — | 1 | — | — | — | — | — | — | — | 3 |
| OpenTofu | 2 | — | 1 | — | — | — | — | — | — | — | 3 |
| DefectDojo | 1 | — | — | 1 | — | — | — | — | — | — | 2 |
| Grafana | 1 | — | — | — | — | — | — | — | — | — | 1 |
| Observability | 1 | — | — | — | — | — | — | — | — | — | 1 |
| Prometheus | 1 | — | — | — | — | — | — | — | — | — | 1 |
| Linux | 1 | — | — | — | — | — | — | — | — | — | 1 |
Currently expanding tool coverage with foundational concept primers for secrets management, version control, infrastructure as code, and Linux/shell fundamentals; practice exercises across multiple domains; and ongoing CVE remediation guides for the security toolchain.
Last updated: 2026-07-25