Modern DevSecOps Foundations
Build repeatable, secure delivery as one team — development, security, and operations sharing one pipeline instead of three silos: governed templates with the gates built in, IaC wrapper libraries, policy gates, testing and release discipline, artifact integrity, and delivery you can measure.
6 modules · 22 lessons · ~6.4 hours · Software engineers, platform teams, security engineers, tech leads
Chapter 3 in the Meridian sequence · 9 live so far · builds on Cloud Modernization Patterns and Zero Trust Implementation · continues in Secure Software Delivery for Federal Environments
A year of modernization left the fictional Meridian Utilities with something new: a platform team — and a mandate to make delivery repeatable for everyone else. The name says DevSecOps on purpose: the hardest idea in this training for leadership is that development, security, and operations are no longer three teams handing work across fences — they are one delivery system, with security built into the pipeline templates everyone extends and operations running the platform delivery happens on. Every lesson here is that idea made concrete. Grounded in the 2026 evidence (DORA's amplifier findings, the settled trunk-based consensus, the post-mandate supply-chain reality), this training builds the delivery system pattern by pattern: governed pipeline templates, an IaC wrapper library with inherited compliance, policy gates, honest testing and release discipline, artifact integrity, and metrics that survive skeptics. Azure DevOps is the reference stack, with GitHub equivalents called out throughout. Every lesson uses AI CLI tools to do the real work. No prior Meridian knowledge needed — Lesson 1.1 catches you up in two minutes.
The Curriculum
The Operating Picture
Foundations matter more now
What good delivery looks like under the 2026 evidence, trunk-based work as actually practiced, and routing workloads before building them
Pipelines as a Product
Templates, governance, and the agents
Pipeline-as-code foundations, the three-tier template model, templates managed like software, and the AI change flow every platform converged on
IaC Foundations
Wrappers, inheritance, and gates
The wrapper library over verified modules, environments by inheritance, the IaC supply chain, and policy gates from scanner to scan matrix
Test and Release
Fast, honest, reversible
Test shapes chosen from failure data, flake discipline, deploy decoupled from release, and database changes that pick their school deliberately
Artifacts and Evidence
Trust what you promote
Hash-verified dependency-aware promotion, provenance and SBOM after the mandate shuffle, and evidence pushed as code
The Platform Team
Productize, measure, migrate
Golden paths run as a product, delivery measured instead of vibed, and the migration story that ends where behavioral parity begins
New to AI CLI tools?
This training assumes you can drive an AI CLI (Claude Code, Codex CLI, Antigravity CLI, or Copilot CLI). If that's new, these modules from our AI-Powered Development training are the fastest preparation — most students need only the first one: