Docker Masters! From CI/CD to DevSecOps Automation Security Practice!

This course systematically teaches practical Docker skills (installation→operation→automation→security) and comprehensively covers the latest security threats and countermeasures in each section. It features a hands-on approach where you learn by following along with practical exercises. This curriculum is highly recommended for DevOps engineers, infrastructure engineers, and security practitioners who want to experience the latest container/cloud environments in real-world scenarios.

(4.9) 23 reviews

351 learners

Level Beginner

Course period Unlimited

Docker
Docker
Kubernetes
Kubernetes
CI/CD
CI/CD
devsecops
devsecops
security training
security training
Docker
Docker
Kubernetes
Kubernetes
CI/CD
CI/CD
devsecops
devsecops
security training
security training

Reviews from Early Learners

4.9

5.0

성준 유

48% enrolled

The explanations are broken down so well that even non-majors can easily understand them, and I really like the curriculum. I think it's a great course for self-study and thinking for yourself because there are practice problems provided throughout to ensure you don't forget what you've learned.

5.0

YSH

100% enrolled

Starting from the basics of Docker and building a practical CI/CD pipeline, I gained a clear understanding of the point where development and operations converge. Beyond simple deployment automation, I was able to learn from a practical perspective how to integrate security into each stage of the pipeline from a DevSecOps standpoint. Through the process of optimizing container images, managing environment-specific configurations, and automating vulnerability scanning, I learned how to build more robust systems. I was able to develop a balanced set of technical skills necessary for managing infrastructure as code and releasing services reliably.

5.0

solitarius

77% enrolled

It was beneficial to be able to explore container-based automation and security while encountering CI/CD and DevSecOps for the first time. The explanations were well-organized step by step, so setting up the practice environment wasn't difficult, and I'd like to try using it once in actual work.

What you will gain after the course

  • Docker Containers and DevSecOps-Based Infrastructure Automation and Security Practice

  • CI/CD (Continuous Integration/Deployment) Pipeline Construction and Latest Security Threat Response Methods

  • Integrating CI Security Testing with SonarQube, Trivy, and OWASP Zap

실전으로 배우는 도커와 DevSecOps: 인프라 자동화·클라우드 보안 완전정복


배울 수 있는 것

  • Docker와 컨테이너 실습을 통한 인프라 환경 구축 및 관리

  • CI/CD 파이프라인 자동화, devsecops 보안 원리 실전 적용

  • 실제 클라우드·기업 환경에 맞춘 공급망 위협 대응법 및 최신 보안 베스트프랙티스 활용


주로 사용되는 분야

  • 클라우드 인프라 운영

  • DevOps 및 자동화 배포 업무

  • IT서비스 개발, 시스템/보안 실무


참고할 수 있는 자료

  • 도커와 컨테이너 구조(아키텍처)

  • CI/CD 파이프라인 자동화 흐름도

  • 공급망 공격 및 취약점 진단 예시

  • DevSecOps 실전 적용 사례, MITRE ATT&CK 매트릭스 보안 교육
    (강의 내 실습 이미지, 구성도, 보안 도구 적용 결과 리포트 등 제공)



1. 컨테이너와 도커의 이해

핵심 키워드: 도커, 리눅스 네임스페이스, cgroup, 이미지, 컨테이너

  • 컨테이너와 가상화의 차이점

  • 도커 아키텍처와 이미지/컨테이너 라이프사이클

  • 실습: 도커 명령어로 이미지 다운로드/컨테이너 실행/삭제

  • 예시 이미지: 도커 구조도, 컨테이너 생성 단계별 변화

    2. 인프라와 네트워크 구성

    핵심 키워드: 네트워크, 볼륨, 브릿지, Overlay, 마운트

    • 컨테이너 네트워크 격리 및 구성 방법

    • 데이터 저장(마운트/볼륨), 컨테이너 간 통신 예제

    • 실습: 웹 서버(Nginx, WordPress) 컨테이너 직접 구축

    • 예시 도표: 브릿지 네트워크 및 실제 인프라 레이아웃

3. CI/CD 자동화 파이프라인

핵심 키워드: Jenkins, ArgoCD, GitHub Actions, 자동배포

  • CI/CD 기본 개념과 역할

  • 도커와 연동한 자동 빌드, 테스트, 배포 설정

  • 실습: Jenkins & Argo 파이프라인 직접 구축(스크린샷 포함)

  • 예시 이미지: 파이프라인 내 데이터/이미지 흐름도



4. DevSecOps와 실전 보안

핵심 키워드: SCA, SAST, DAST, 취약점 진단, 시크릿, 보안 베스트프랙티스

  • 실시간 취약점 점검(Security Scan) 도구 활용법

  • 컨테이너, 네트워크, 공급망 보안 원리(OWASP·MITRE 사례)

  • 실습: 이미지 취약점 자동 진단, 시크릿 관리,Kubernetes 환경에서 system call 탐지 등

  • 예시 자료: 보안 위협 매트릭스(MITRE ATT&CK), 실제 진단 결과 리포트


수강 전 참고 사항

실습 환경

  • 운영 체제 및 버전(OS): Windows 10 이상

  • 사용 도구: VirtualBox, Vagrant를 활용한 빠른 환경 구성, Docker, docker-compose, docker swarm, kuberntes 등

  • PC 사양:

    • CPU: 4코어 이상 (i5/i7, Ryzen 5 이상)

    • 메모리: 16GB 이상(32GB 권장)

    • 디스크: 200GB 이상의 여유 저장공간


학습 자료

  • PDF 교재

  • Notion 실습 노트


선수 지식 및 유의사항

  • 리눅스 기본 명령어, Git 사용법을 미리 알아두면 도움이 됩니다.

  • 강의와 함께 실습을 병행하면 효과가 큽니다.

  • 질문은 Q&A 게시판 등에서 자유롭게 할 수 있으며, 강의 자료는 지속적으로 업데이트될 수 있습니다.

  • 강의 자료와 영상은 본인 학습 목적 외 무단 복제·배포가 금지됩니다.

Recommended for
these people

Who is this course right for?

  • Infrastructure engineer aspirant who wants to directly operate services in a cloud environment

  • Developers who have no hands-on experience with Docker and orchestration, or who want to learn construction and deployment processes close to actual enterprise environments

  • Security practitioners who want to experience DevSecOps and container security principles

  • Startup CTOs and development team leaders who are deeply concerned about code deployment automation and supply chain security

Need to know before starting?

  • Linux Basic Commands and File Structure

  • Network Fundamentals

Hello
This is CLOUD SECURITY LAB

Career Verified

627

Learners

38

Reviews

315

Answers

4.9

Rating

3

Courses

CEO Il-sun Choi

ilsunchoi@cloudsecuritylab.co.kr

Cloud and IT Security Expert | Kubernetes, DevOps, and Cloud Security Instructor | Consulting and Practical Experience

Cloud Security Lab possesses over 10 years of practical experience and teaching expertise in the fields of cloud and IT security. Based on a deep understanding of security and infrastructure construction across various cloud environments such as AWS, Azure, OpenStack, VMware, Kubernetes, and Docker, we provide customized training and consulting for corporate professionals and students.

Key Experience and Areas of Expertise

  • I have been responsible for providing hands-on training for professionals at companies such as the Financial Security Institute, Samsung SDS, Samsung Integrated Security, LG CNS, Nexon, KT, Hana Financial IT, and Hyundai Motor Company, covering Kubernetes security, AWS, Azure, Terraform, Ansible cloud, security, and monitoring. I have also consistently delivered lectures on infrastructure construction and security principles for DevSecOps.

  • Private Cloud Lectures: Conducted OpenStack lectures for private clouds at SDS, and provided training on building security infrastructure using VMware vSphere and open source on Inflearn.

  • Malware Analysis and Cybersecurity: I conduct practical lectures on malware analysis and security forensics at organizations such as the Korean National Police Agency, Samsung Integrated Security, the Ministry of National Defense, SK Shieldus, and KISIA, sharing knowledge on the latest trends in cybersecurity and their practical applications.

  • Books and Certifications: I am sharing knowledge on IT security and programming through the publication of numerous books, including 'Complete Practice of Web Penetration Testing Using the Bee-Box Environment' and 'Python with Minecraft'. Additionally, I have enhanced my expertise by obtaining various global certifications, such as AWS Solution Architect Professional, CKA/CKS (Kubernetes certifications), and Azure Solutions Architect Expert.

Major Teaching History

  • Nexon: Docker and Kubernetes for DevOps, Ansible infrastructure management automation, Terraform AWS infrastructure automation content planning and training

  • Financial Security Institute: Kubernetes Security, AWS/Azure Cloud Security Training for Practitioners

  • Multicampus: DevOps training using Docker and Kubernetes, infrastructure automation, and cloud security training

  • Samsung SDS: Cloud Native, Kubernetes, Docker, OpenStack training

  • LGCNS: AWS security infrastructure, EKS monitoring using OpenSearch, and EKS monitoring training using Prometheus and Grafana

  • National Police Agency, Ministry of National Defense, KISIA, Hana Financial Group, Samsung Integrated Security Center: Cloud adoption and security training, penetration testing, malware analysis, DevSecOps, CI/CD training, etc.

EKS Monitoring Training National Police Agency, Ministry of National Defense, KISIA, Hana Financial Group, Samsung Integrated Security Center: Cloud adoption and security training, penetration testing, malware analysis, DevSecOps, CI/CD training, etc.

I am constantly striving to provide practical and impactful training that keeps pace with the latest technology trends and industry demands. With my passion and expertise in technical education and consulting, I am committed to supporting growth in the cloud and security sectors.

More

Curriculum

All

114 lectures ∙ (21hr 37min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

All

23 reviews

4.9

23 reviews

  • wndudwns00283062님의 프로필 이미지
    wndudwns00283062

    Reviews 3

    Average Rating 5.0

    5

    58% enrolled

    I had heard about Harbor and Trivy and simply knew what kind of technologies they were, but I was wondering how to study them when I came across this course. Although I had some knowledge of Docker and existing CI/CD, I'm enjoying the course as I'm studying the concepts again and using Docker Swarm and Docker Compose once more. I'm now learning Harbor, but I'll continue studying consistently until I complete the course. Thank you for creating such a beneficial course.

    • Hello, Juyeongjun! Thank you so much for taking your precious time to leave such a thoughtful course review. It's a huge source of strength for me! I will also cheer you on until the end. If you have any questions or get stuck while studying, please feel free to ask anytime! Once again, I sincerely thank you.

  • k10235425927님의 프로필 이미지
    k10235425927

    Reviews 1

    Average Rating 5.0

    5

    31% enrolled

    It is well-explained and easy to understand.

    • auddbs21310님의 프로필 이미지
      auddbs21310

      Reviews 1

      Average Rating 5.0

      5

      48% enrolled

      The explanations are broken down so well that even non-majors can easily understand them, and I really like the curriculum. I think it's a great course for self-study and thinking for yourself because there are practice problems provided throughout to ensure you don't forget what you've learned.

      • jnkim01170028님의 프로필 이미지
        jnkim01170028

        Reviews 1

        Average Rating 5.0

        5

        31% enrolled

        The learning content is great.

        • dbstkdgus12116395님의 프로필 이미지
          dbstkdgus12116395

          Reviews 2

          Average Rating 5.0

          Edited

          5

          100% enrolled

          Starting from the basics of Docker and building a practical CI/CD pipeline, I gained a clear understanding of the point where development and operations converge. Beyond simple deployment automation, I was able to learn from a practical perspective how to integrate security into each stage of the pipeline from a DevSecOps standpoint. Through the process of optimizing container images, managing environment-specific configurations, and automating vulnerability scanning, I learned how to build more robust systems. I was able to develop a balanced set of technical skills necessary for managing infrastructure as code and releasing services reliably.

          Similar courses

          Explore other courses in the same field!