Linux Security for DevSecOps

A hands-on Linux security course for DevSecOps learners focused on service exposure, web hardening, file permissions, sudo, secrets, root-run automation, service identity, runtime configuration, logs, scripts, and access policy cleanup. You will investigate real host state, apply targeted fixes, and verify that systems stay usable after hardening.

LinuxDevSecOps

Introduction

Linux hardening is strongest when it begins with observed host state and ends with both an allowed-path and denied-path test. This challenge-only course applies that method across 20 focused scenarios involving network exposure, local permissions, service identity, privileged automation, secrets, scripts, and application policy.

You will inspect sockets, processes, /proc, ownership, modes, sudoers, Cron definitions, HTTP responses, and helper scripts before making narrowly scoped changes. Every remediation must preserve the intended site, health check, service write path, approved command, or backup workflow while closing the unsafe path.

What You Will Learn

  • Classify live TCP bindings, restrict an admin listener to loopback, and remove an unnecessary legacy port
  • Disable directory indexes, relocate a public backup archive, close diagnostics, and remove debug or incident-only responses
  • Tighten secret files, environment files, upload directories, and application logs while preserving intended user or group access
  • Replace broad sudo authority with one command-specific rule and harden a root-run Cron execution directory against untrusted writes
  • Move hardcoded and process-environment credentials into protected files and verify secrets disappear from scripts or /proc exposure
  • Run a local service as its dedicated non-root account and retain its health and log-append behavior
  • Restore token-gated application policy by removing temporary allow-all or bypass settings and test both denied and authorized requests
  • Pin script command resolution to trusted system paths and reject normalized backup inputs that escape the approved data directory

Who This Course Is For

This course is for DevSecOps practitioners, Linux administrators, and platform learners who want to harden existing host services through evidence-driven challenges.

Prerequisites: Confident Linux terminal use, ss, process inspection, users and groups, ownership and permission modes, sudoers and visudo, Cron, shell scripts, environment files, HTTP testing, and basic path normalization; this is not a beginner walkthrough.

Learning environment: A browser-accessible Linux host with sudo, prepared local users, services, scripts, files, and loopback HTTP endpoints; each challenge strictly limits the paths, ports, identities, and behavior you may change.

Frequently Asked Questions

Is this a guided Linux fundamentals course?

No. Each challenge supplies a current situation, strict scope, acceptance criteria, and hints, but you must inspect live evidence, choose the smallest safe fix, restart through the provided path, and test the result.

Do the secret challenges use Vault or another production secret manager?

No. They focus on removing literals and process-environment exposure by using prepared files with modes such as 600 or 640. Rotation, encryption, central secret stores, and credential issuance are outside scope.

Does the course configure a host firewall, SELinux, or AppArmor?

No. Network exercises change application listeners and routes, while access exercises use Unix permissions, service users, sudoers, configuration, and script validation. Kernel MAC policy and firewall administration are not covered.

How does the course prove a fix did not break operations?

Acceptance criteria pair the new denial with preserved behavior—for example, an admin route rejects missing tokens but accepts the approved token, an unrelated user cannot read a log while the service can append, or an outside backup path fails while an in-bounds backup succeeds.

Teacher

labby
Labby
Labby is the LabEx teacher.