Free · ungated · runnable

Cloud security training you can actually run.

Most of it is slides against an account you never touch. Every lesson here runs against one deliberately broken AWS account you clone and keep.

66 LESSONS
0 PAYWALLS
1 LAB ACCOUNT

DevSecOps — the whole path

27 steps · 25 written

  1. Build

    6 steps

    Prevent known-bad from ever shipping.

  2. Run

    11 steps

    Detect the unknown in the live account, then respond automatically.

  3. Prove

    10 steps

    Your pipeline output is the audit evidence. Show it.

Begin at step 1, or jump to any of the 25 written lessons.

Every command copy-pasteable. Every lesson re-run before it ships.

Intentionally vulnerable — education only

The Range

Three shared broken artifacts every lesson scans: a vulnerable app, a vulnerable image, and the Terraform that builds the broken AWS account. Run it locally or in a throwaway account with billing alarms — never deployed publicly.

How the Range works

Different job? Read this instead

Responsible for CPS 234 at an APRA-regulated entity?

The control mapping, the evidence an auditor actually accepts, and where most AWS estates fail CPG 234 — without the four-year-stale tooling.

15+ years platform engineering · enterprise data security at MNC scale · AWS Security Specialty, AWS Solutions Architect & CKA certified

  • AWS Certified Security – Specialty
  • AWS Certified Solutions Architect – Associate
  • CNCF Certified Kubernetes Administrator

The free Big Data tools — YARN calculator, HDFS planner, Spark sizer, queue designer — are still here. Use them →

Get the DevSecOps Pipeline Cheatsheet

One page: every gate, the tool that owns it, and what fails the build vs what just reports — plus a heads-up when a tool dies (like tfsec). Free, straight to your inbox.

No spam. Unsubscribe anytime. See our privacy policy.

Prefer to grab it now?Read the cheatsheet → Download PDF