Learning Hub / Delivery & Infrastructure as Code
CI/CD & Software Supply Chain
Practitioner → Advanced8 lessonsAvailable
Real pipelines on self-hosted runners in Kubernetes, with OIDC federation instead of stored secrets, and build → sign → attest → deploy, including an air-gapped variant with Gitea/Forgejo.
You'll meetGitHub ActionsrunnersARCOIDC federationcosignSBOMSLSAJenkinsair-gapped CI
Start lesson 01 →
What you'll be able to do
- Run Actions Runner Controller on your own cluster
- Remove long-lived CI secrets with OIDC federation
- Sign, attest and verify every artifact you ship
Before you start
Git, containers.
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Modules
- 01The execution modelRunners, jobs, contexts, cachingRead →
- 02Real pipelinesMatrix builds, reusable workflowsRead →
- 03Actions Runner ControllerSelf-hosted runners on KubernetesRead →
- 04OIDC federation & secret hygieneNo more static cloud keysRead →
- 05Supply chain: sign, attest, scan, verifycosign, SLSA, SBOMRead →
- 06Hardening the runnerIsolation, ephemeral runnersRead →
- 07The air-gapped portGitea/Forgejo Actions offlineRead →
- 08Jenkins in the real worldPipelines you'll inheritRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 24 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
The CI server is down mid-release
Designing CI that isn't a single point of failure.
The rollback that redeployed the bug
Mutable tags, and how digests save you.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.