Skip to main content

Identity and Access Security for DevSecOps

Learn zero trust identity in practice: SSO and MFA for people, federation for workloads, just-in-time access, short-lived certificates, and OAuth flows.

~3.5 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding Identity as the New Perimeter

A reused admin password and no MFA A contractor at acme-shop has an admin account on the company's cloud console.

Securing Human Access with SSO and Phishing-resistant MFA

Why single sign-on beats many passwords With single sign-on (SSO), people sign in once to a central identity provider, and every application trusts...

Designing Least Privilege with Roles and Attributes

RBAC with scoped permissions Role-based access control (RBAC) grants permissions to roles, and people get roles.

Granting Just-in-Time and Privileged Access

Why standing privilege is the problem An admin with always-on privileges is exposed every hour of every week, whether or not they are doing admin...

Federating Workload Identity Without Secrets

The shared OIDC pattern A workload has no password and no fingerprint.

Issuing Short-lived Certificates with Vault PKI

Why short-lived certificates beat revocation A certificate proves the identity of a service.

Skills You'll Master

IDENTITY-SECURITYZERO-TRUSTOIDCWORKLOAD-IDENTITYJIT-ACCESS

Curriculum Index10 topics

1

Understanding Identity as the New Perimeter

A reused admin password and no MFA A contractor at acme-shop has an admin account on the company's cloud console.

2

Securing Human Access with SSO and Phishing-resistant MFA

Why single sign-on beats many passwords With single sign-on (SSO), people sign in once to a central identity provider...

3

Designing Least Privilege with Roles and Attributes

RBAC with scoped permissions Role-based access control (RBAC) grants permissions to roles, and people get roles.

4

Granting Just-in-Time and Privileged Access

Why standing privilege is the problem An admin with always-on privileges is exposed every hour of every week, whether...

5

Federating Workload Identity Without Secrets

The shared OIDC pattern A workload has no password and no fingerprint.

6

Issuing Short-lived Certificates with Vault PKI

Why short-lived certificates beat revocation A certificate proves the identity of a service.

7

Understanding SPIFFE and SPIRE

The secret zero problem Every secret-free design hits one question: how does a workload prove its identity to get its...

8

Choosing the Right OAuth 2.0 Flow

Authorization code with PKCE for users and public clients Apps that cannot keep a secret, such as mobile apps...

9

Hands-on Lab: Workload Identity and Short-lived Certificates

Before you start 📌 Remember: Cost: the main lab runs on your laptop and costs nothing.

10

Quick Reference and Common Mistakes

Quick reference Common mistakes Treating any MFA as good enough leaves admins open to phishing.

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Cloud Security Engineer

    ₹14L - ₹32L a year

    High Demand
  • Security Engineer

    ₹14L - ₹35L a year

    Growing
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

It means no request is trusted because of where it comes from. Every person and workload must prove who it is, is authorised for only what it needs, and is evaluated continuously. Network location alone never grants access.

No. PKCE protects the authorization code flow for user-facing public clients such as mobile apps, single-page apps, and command-line tools. Service-to-service calls use the client credentials flow or, better, workload identity federation.

It is access granted only when needed and removed automatically afterwards. A person requests elevated rights for a specific task, gets them for a short, fixed time with MFA, and the rights expire without anyone remembering to revoke them.

Revocation depends on every client checking a revocation list, and many do not. A certificate valid for hours expires on its own, so a stolen one stops working quickly and there is little to revoke.