OPA and Gatekeeper
Workshop

Platform and security teams usually know their requirements: approved registries only, mandatory labels, or clearly bounded resources. The difficult part is expressing them so that a team can understand and test the rule, introduce it in stages, and reverse it when something goes wrong. OPA is the policy engine, Rego is its declarative language, and Gatekeeper is the Kubernetes integration for admission validation, mutation, and audit. A ConstraintTemplate contains reusable validation logic and its parameter schema. A constraint applies that logic to the cluster with concrete values and a defi

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for OPA and Gatekeeper.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Understand Rego and build a first Gatekeeper policy

  • Understand How OPA, Rego, and Gatekeeper Fit Together
  • Write and Test a First Rego Rule
  • Extend Rego for Kubernetes Objects
  • Build a ConstraintTemplate from Rego
  • Parameterize and Scope Constraints
Day 1

Day 2: Test policies, review violations, and roll out in stages

  • Evaluate Admission and Audit Together
  • Use Cluster Data in Policies
  • Manage Exceptions and Enforcement Safely
  • Test Policies with OPA and gator
  • Embed Policy Tests in CI and GitOps
Day 2

Day 3: Secure Gatekeeper mutation and recover from failures

  • Design Gatekeeper Mutation Correctly
  • Apply Mutators and Detect Conflicts
  • Compare Validation and Mutation
  • Evaluate External Data and Expansion
  • Recover Safely from a Fail-closed Failure
Day 3

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.

Introduction to Kyverno

  • Duration: 3 days