H2-CSDE · Core certification path
DevSecOps and Supply Chain
H2 Certified Secure Delivery Engineer
Ship securely and prove where every artifact came from. No Docker daemon, Chainguard bases, images built with Kaniko, dependencies vendored and verified, a self-hosted forge, and the whole chain signed and attested.
5 courses · 21 lessons · ~36 h of guided work
Assumes Foundation
What you leave with
A pipeline on your own Forgejo that builds distroless images with Kaniko, vendors and verifies every dependency, signs and attests each artifact, and blocks a release that fails policy.
- Forge
- Forgejo + runners
- Build
- Kaniko
- Base images
- Chainguard
- Signing
- Sigstore / cosign / Rekor
- Policy
- Kyverno / OPA
- Scanning
- Bearer / Trivy / Grype
Syllabus
5 courses · every lesson graded · minutes are guided work
Course 01
Building without Docker
Why the local daemon and Docker Hub bases are a liability, and how to build images with Kaniko from Chainguard bases instead: no daemon, no root, no shell in the result.
5 lessons · ~8 h
- 01The case against the daemonWhat the Docker daemon and Docker Hub bases cost you in trust and attack surface.90 min
- 02KanikoBuild in-cluster with no daemon; the SSL_CERT_FILE trap, the DOCR auth path, and the R2 blob source.120 min
- 03Chainguard basesDistroless, minimal-CVE bases; digest-pinned; the diff versus a Hub base, counted.90 min
- 04The self-destruct trapKaniko deleting the runner's own git and node mid-job, and how to survive it.90 min
- 05No shell, no rootAn image with nothing to exploit; proving it with a scan and a failed exec.60 min
Course checkBuild a service image with Kaniko from a Chainguard base; the grader fails it if it contains a shell, a package manager or runs as root.
You leave withA distroless, non-root, shell-free service image built by Kaniko from a digest-pinned Chainguard base, with the traps documented.
Course 02
Dependencies and vendoring
Stop trusting the registry at build time. Vendor dependencies, pin by hash, mirror what you rely on, and verify signatures before anything enters the build.
4 lessons · ~7 h
- 01Why vendorThe registry as a runtime dependency of your build; what a yank or a compromise does.90 min
- 02Pinning and lockfilesHash-pinned dependencies; a build that fails on an unpinned or drifted add.90 min
- 03Private mirrorsMirror the packages and base images you depend on into Forgejo's registry with SHA256 verification.120 min
- 04Verifying provenanceSignature and attestation checks on dependencies before they enter the build.90 min
Course checkIntroduce a dependency that fails verification; the build must refuse it and name why.
You leave withVendored, hash-pinned dependencies for two languages, a private mirror of what you rely on, and a build that verifies signatures before use.
Course 03
Self-hosting the forge
Own the source of truth: Forgejo as the authoritative git host with isolated runners, a mirror for disaster recovery, and CI that never leaks a secret into a log.
4 lessons · ~7 h
- 01Forgejo as authoritativeSelf-hosted git as the source of truth; a mirror to a second host and the DR ordering it creates.120 min
- 02Runners and isolationEphemeral runners in their own VPC with no route to production; what a compromised job can reach.120 min
- 03Secrets in CI, done rightShort-lived tokens, masked outputs, and a scan that fails the build if a URL carries a key.90 min
- 04Build isolationUntrusted builds on their own cluster behind a private, not public, load balancer.90 min
Course checkFrom an empty Forgejo instance to a green pipeline with isolated runners; a scan proves no secret reached a job log.
You leave withA self-hosted Forgejo with ephemeral, network-isolated runners, a push-mirror for DR, and CI whose logs are clean.
Course 04
Signing, SBOM and attestation
Prove what you shipped. Sign artifacts with Sigstore, generate an SBOM, attest the build, and log it all to a transparency log anyone can check.
4 lessons · ~7 h
- 01Signing with cosignKeyless signing, verification in the pipeline, and the trust root behind it.120 min
- 02SBOMGenerate and store an SBOM per build; diff two releases; answer are-we-affected for a new CVE.90 min
- 03Attestation and SLSABuild provenance attestations; the SLSA levels and which one you actually reached.120 min
- 04Transparency logsRekor as an append-only record; verify an artifact's provenance from outside your infrastructure.90 min
Course checkSign and attest a release, publish the SBOM, and verify from the transparency log that a given artifact is the one you built.
You leave withSigned images with an SBOM and build provenance, recorded in a Rekor transparency log, verifiable by a third party.
Course 05
Policy gates and scanning
Fail the build on what matters and let the rest through, or the team turns the scanner off. Admission policy, SAST/DAST/SCA, and CVE triage that is not noise.
4 lessons · ~8 h
- 01Gate the pipeline, not the teamBlock on ERROR severity, report everything else, upload the SARIF either way.120 min
- 02SAST, DAST, SCAEach in the pipeline with a real finding fixed; the difference between them and where each earns its place.120 min
- 03Admission controlKyverno or OPA rejecting unsigned images and disallowed configurations at the cluster door.120 min
- 04CVE triage that is not noiseEPSS and KEV to rank by exploitability; a Chainguard swap that clears a class of findings.90 min
Course checkGiven a pipeline that fails on every finding, rewrite it to block on ERROR only, report the rest, and admit only signed, policy-compliant images.
You leave withA pipeline that gates on severity not volume, an admission controller that rejects unsigned or non-compliant images, and a CVE triage that ranks by exploitability.
Certification course
H2 Certified Secure Delivery Engineer
$499 · one price · courses + 90-day labs + exam
A supply-chain incident: a poisoned dependency and a tampered base image are introduced. Your pipeline must refuse both, and you must prove from attestations exactly what shipped and what did not.
Opens when Foundation is complete and the 5 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.
Create an account to enrol