• Home
  • Workshops
  • Services
  • Contact
Mont-Cenis-Straße 399, Herne 44627, Germany
+49 (0) 221 9865099 0
hello@devninjas.io

Workshops

  • Docker Fundamentals
  • Kubernetes Introduction
  • CKAD Exam Prep
  • CKA Exam Prep
  • All Workshops

Services

  • Shogun · Platform Consulting
  • Mamori · Managed Retainer
  • Kensho · Platform Audit

Company

  • Contact
  • Sitemap
2026 • Coded with by DevNinjas
  • Imprint
  • Privacy
  • GTC

Introduction to OPA Gatekeeper and Rego

Which Kubernetes resources may enter the cluster, and how do you find violations before a rule blocks deployments? Over three days, you develop testable Kubernetes policies with OPA Gatekeeper and Rego. You build reusable ConstraintTemplates and constraints, audit existing resources, and move rules from dryrun through warn to deny. No previous Rego experience is required.

Share via email
  • Workshop levelIntermediate
  • Satisfied participants2340+
  • Days3
  • LanguageGerman & English
  • Workshop codeDW31

Workshop Details

What makes this workshop stand out

🎯

What you will learn and take away

You develop one small, coherent Gatekeeper policy repository and verify every change through visible results:

  • Turn Rego v1 into reusable constraints: You write and test violation rules, build a structural ConstraintTemplate with a parameter schema, and apply it to Kubernetes resources through constraints with different scopes
  • Check policies before they block requests: opa test, Regal, and gator cover logic, style, and integration errors. Admission responses, audit results, and metrics show the effect in the cluster; dryrun, warn, and deny form the rollout path
  • Assess mutation and operations safely: You configure Gatekeeper's separate mutator resources and compare two decision paths: Rego- and CEL-based validation with native ValidatingAdmissionPolicies, and Gatekeeper mutators with native MutatingAdmissionPolicies. In an isolated lab failure, you diagnose webhook, TLS, and reachability problems and rehearse a documented emergency and restart procedure

The repository contains policies, parameters, fixtures, tests, CI checks, a rollout checklist, and a recovery runbook. It gives you a reviewable starting point for your own platform. For the required Kubernetes operations experience, take the Kubernetes Advanced Training first.

💼

Why the investment pays off

A Kubernetes policy affects development, platform operations, and security at the same time. When requirements, tests, and exceptions are maintained separately, it is difficult to see which applications a rollout will actually affect. The workshop establishes one shared workflow:

  • Review controls together: Policy, parameters, test resources, and expected results live in the same repository and can be evaluated in one review
  • Introduce blocking rules in stages: Audit results, defined scope, and success criteria determine the move from dryrun through warn to deny. Git and CI make the owner, expiry date, and removal of an exception reviewable
  • Choose the appropriate tool: Gatekeeper, Kyverno, and native Kubernetes admission policies are compared by policy complexity, data needs, team skills, and operational ownership

Groups are limited to eight participants, leaving room for policy reviews and architecture questions. In corporate training, your team's policies, responsibilities, and CI structure can inform the exercises.

📋

Prerequisites

The workshop requires hands-on Kubernetes experience, but no policy-language background.

Required:

  • Confidence using kubectl and Kubernetes YAML
  • Hands-on experience with Pods, Deployments, Namespaces, labels, and selectors
  • Basic knowledge of RBAC and the difference between namespaced and cluster-scoped resources
  • Basic experience with Git branches, simple CI jobs, and structured command output

Not required:

  • Previous experience with Rego, OPA, Gatekeeper, or CEL
  • Programming knowledge in a particular language
  • A Kubernetes certification

This is not a Kubernetes introduction. If you do not yet have the required operations foundation, we recommend taking the Kubernetes Advanced Training first.

Workshop Agenda

Your Agenda at a Glance

Hands-on and structured. Every participant works in their own cloud environment. The agenda shows you what to expect each day.

Day 1: Understand Rego and build a first Gatekeeper policy

5 topics
09:00–10:00💬 Introduction Round

OPA makes decisions, Rego describes the rules, and Gatekeeper connects both to Kubernetes. You send two sample workloads through the API server and follow when the admission webhook evaluates them and when the audit controller checks resources already stored. An architecture map connects the request path, Gatekeeper components, ConstraintTemplate, and constraint into one understandable model.

kubernetesKubernetesopaOPA Gatekeeper

Rego describes desired results rather than an imperative sequence of steps. You read a Kubernetes object through input, use if and contains to create a clear violation rule, and test an allowed, violating, and malformed case. opa fmt, opa check --strict, and opa test --fail-on-empty provide immediate, verifiable feedback.

opaOPA Gatekeeper
12:00–13:00🥪 Lunch Break

Kubernetes manifests contain nested objects and lists that a single condition rarely covers completely. You extend your rule with iteration, sets, negation, and a helper rule. Test resources with present, missing, and irrelevant fields expose the difference between false, undefined, and an evaluation error. A result table records the expected and actual decision side by side.

A ConstraintTemplate turns tested Rego logic into a reusable Kubernetes policy type. You transfer your rule into the explicit Rego v1 engine, define a structural OpenAPI parameter schema, and apply the template to the cluster. Ingestion status and the generated CRD show whether code and schema were accepted. One deliberately invalid parameter proves that the API server checks its type.

opaOPA Gatekeeper

A constraint applies the same template with concrete parameters and a defined scope. You create two constraints for different teams and limit kinds, scope, namespaces, exclusions, and selectors. Allowed, violating, and deliberately unmatched workloads reveal whether the rule targets the right resources. The comparison exposes the separation between reusable logic and cluster-specific configuration.

16:00–16:30💭 Questions & Answers

Day 2: Test policies, review violations, and roll out in stages

5 topics
09:00–10:00💭 Questions & Answers

Admission evaluates new changes, while audit finds violations in resources already stored. You apply the same policy to one new and one existing workload and compare the admission response, constraint status, logs, and metrics. This reveals when a request can be blocked, which information audit does not have, and why constraint status is not a complete violation history.

opaOPA Gatekeeper

Some rules must compare a new object with resources already in the cluster, such as detecting duplicate Ingress hosts. You synchronise only the required data into Gatekeeper's inventory and extend the policy with that comparison. A delayed data state exposes the effects of eventual consistency. You then document data scope, permissions, and the risk of deciding from a stale view.

12:00–13:00🥪 Lunch Break

An exception that is too broad can make a correct policy ineffective. You bound a break-glass case through matching and exclusion and record its owner, approval, expiry date, and removal test in the repository. The same rule then moves through dryrun, warn, and deny. Requests inside and outside the exception plus a rollback show whether scope and rollout behave as intended.

Different tools expose different policy errors. opa test checks the Rego logic, Regal reports style and quality issues, and gator evaluates the template, constraint, resources, and inventory together. You build a version-pinned suite with allowed, violating, malformed, and unmatched cases. One deliberately incorrect expectation must fail before the suite counts as effective.

opaOPA Gatekeeper

A policy change must be reviewable in a pull request without a spoken explanation. You organise the requirement, template, constraints, fixtures, tests, exception, and rollback in the repository and let the CI pipeline evaluate the change. You then create a deliberate live deviation. The GitOps diff, review, and pipeline result show how desired state is restored and a faulty policy is reversed.

16:00–16:30💭 Questions & Answers

Day 3: Secure Gatekeeper mutation and recover from failures

5 topics
09:00–10:00💭 Questions & Answers

Gatekeeper validates with Rego or CEL constraints but mutates through separate CRDs. You map the stable v1 resources AssignMetadata, Assign, and ModifySet to suitable tasks while explicitly treating AssignImage as a v1alpha1 API. Across sample objects, you define operations, applyTo, scope, and paths so that existing values are respected and repeated evaluation converges.

opaOPA Gatekeeper

You now use the stable mutators to implement three bounded changes: a new annotation, a non-destructive default, and a list extension. Workloads with existing values reveal what Gatekeeper preserves. A second mutator then creates a deliberate conflict. Repeated evaluation, status, and logs help you distinguish schema, convergence, and conflicting policy intent and correct the relevant cause.

12:00–13:00🥪 Lunch Break

Two separate comparisons prevent false equivalence. For validation, you implement the same object-local requirement as Rego and CEL ConstraintTemplates and as a native ValidatingAdmissionPolicy. For mutation, you compare Gatekeeper's stable mutator resources with the CEL-based MutatingAdmissionPolicy. A decision matrix contrasts policy language, enforcement point, audit, data access, testing, and operational effort.

kubernetesKubernetesopaOPA Gatekeeper

External Data includes information beyond the admission request; ExpansionTemplate can bring generated workload resources such as Pods into validation. For each capability, you inspect one successful and one failing path and assess the provider, TLS, timeout, cache, failure policy, and coverage. The outcome is a reasoned adoption decision, not a complete provider or production implementation.

Gatekeeper operates fail-open by default; only a failurePolicy deliberately set to Fail can block matching API requests when the webhook is unreachable. In an isolated failure, you inspect endpoints, certificates, logs, and metrics. You then disable the affected webhook configuration through the Kubernetes API, fix the cause, and enable it again. Smoke requests and a runbook demonstrate a safe restart.

16:00–16:30💭 Questions & Answers

Our Benefits

All from one hand!

With our high-quality trainings and workshops, you can bring yourself and your team up to date. All this with many benefits that you get from us.

👨‍💻High Practical Content
70% hands-on, 30% theory. You work continuously with real scenarios and take working code home with you. No PowerPoint battles, but directly applicable knowledge for your projects.
☁️Cloud Learning Environment
DevNinjas Dojo: Your own Kubernetes clusters and VMs for each participant in the browser. No installation, works despite VPN/proxy/firewalls. You work with dedicated resources, not in shared environments.
🥷Experienced Trainers
Full-time DevOps engineers and consultants from DevNinjas lead the workshops. Not external trainers, but specialized employees actively working on client projects and sharing real-world experience.
👥Small Groups
Maximum 8 participants per workshop. Everyone gets individual support from the trainer. Your specific questions and use cases get answered, not passed over in anonymous crowds.
🏗️Real-World Scenarios
No toy examples or hello-world demos. You work with production-grade setups: multi-container applications, CI/CD pipelines, monitoring stacks. Directly transferable to your production environments.
🎓Certification
You receive an official certificate of attendance as PDF and a verified LinkedIn badge. Document your professional development for your employer, HR, and recruiters professionally.

Testimonials

How participants experience our trainings

4.9/ 5

1047+ participant reviews · unfiltered

across all DevNinjas trainings

Trainer
5.0
Content
4.8
Hands-on
4.8

DevNinjas overall: over 1,384 participants · 207 companies · 241 workshops

Including BMW, Bundeswehr, Deutsche Bahn and many more.

"My colleagues specifically looked for a sysadmin course for Docker with another provider and had an instructor who only set up an IDE for them and then only worked on a task sheet with development tasks. I had a course with lots of background information, an instructor who had a really extensive knowledge of the whole subject matter beyond the slides, and I feel optimally informed."

Default avatar picture of DevNinjas
Johannes Bernstein
@TRIMET Gelsenkirchen SE

"The advanced Kubernetes workshop at DevNinjas really helped me grow professionally. The content was practical and excellently prepared, so even complex topics like RBAC, network policies and Ingress were conveyed in an understandable and directly applicable way. The deep expertise of the trainer was especially impressive and noticeable in every session. I can recommend this workshop to anyone who wants to use Kubernetes in production!"

Default avatar picture of DevNinjas
Marius Büttner
@Siemens AG

"From my perspective, the workshop had the right speed and an appropriate level of challenge. The subject matter was explained clearly by the instructor and practically consolidated with well-distributed exercises. Adjusting the workshop focus to the participants wishes was not a problem. Valuable practical experiences were shared, and even more specific questions were gladly answered. The instructor's professional expertise and extensive practical experience on the subject gave this workshop a special quality."

Default avatar picture of DevNinjas
S. Kaiser
@forcont business technology GmbH

"The seminar gave a very good overview of Docker administration, with a look at Kubernetes and how this knowledge simplifies everyday work. Many small, easy-to-follow examples with hands-on exercises and a focus on best practice consolidated what we learned. The instructor had an answer to every question, and for very specific questions he came back with a fitting example. The alternation between introductions and exercises was very well organised."

Default avatar picture of DevNinjas
Sebastian A.
@DMI GmbH & Co. KG

"The workshop was very informative and I could immediately spot the mistakes I had made in past Docker projects. Before, I lacked the theory and the fundamentals, so I had only been acting on best practice. Now I can write stable Dockerfiles and Docker Compose setups and secure them properly. A very good workshop that was also a lot of fun!"

Default avatar picture of DevNinjas
Timon Strangfeld

"In the workshop the most important Docker and Kubernetes topics were put together, prepared and explained superbly. The exercises fit precisely and were very well chosen in terms of difficulty. I am very satisfied with how much I learned in the five days and feel well prepared for upcoming tasks at work. Sure, you can teach yourself a lot on your own with AI tools, but without the workshop I would not have gained this overview or worked through so many exercises independently."

Default avatar picture of DevNinjas
Christine L.

"Nico is a very friendly and technically skilled instructor. He answered all questions well. You quickly notice that he combines academic expertise with many years of professional practice."

Default avatar picture of DevNinjas
Philipp van Wickevoort Crommelin
@parcIT GmbH

"The workshop gave me a very good insight into Kubernetes and made working with containers much clearer. Nico delivered the content in a practical and well-structured way, so I could quickly find my way around. The hands-on exercises in particular helped me apply what I learned directly. For anyone looking for a solid introduction to Kubernetes, this workshop is definitely recommended."

Default avatar picture of DevNinjas
Daniel Hagen
@DKB Service GmbH

"I really enjoyed the Docker & Kubernetes workshop at DevNinjas. Nico explained the complex topics around containers and orchestration in a very understandable and practical way. The mix of theory and hands-on exercises was perfect for being able to apply everything directly. I was able to take a lot away for my everyday work and now feel significantly more confident working with Docker and Kubernetes."

Default avatar picture of DevNinjas
Dominik Kneissl
@Siemens Healthineers

"The Docker workshop at DevNinjas was an all-round success. The content was clearly structured and practically delivered, including meaningful hands-on exercises. I took away a lot and feel significantly more confident working with Docker. Even more complex topics like multi-stage builds and networking were explained in an understandable way. A clear recommendation for anyone who really wants to understand Docker!"

Default avatar picture of DevNinjas
Daniel Müller
@Siemens Healthineers

"I really enjoyed the Docker workshop at DevNinjas! The content was well structured and clearly explained, even for beginners like me. The mix of theory and hands-on exercises was especially helpful for trying Docker directly. By the end, I was able to build my own images, configure containers and set up networks. Absolutely recommended for anyone who wants to learn Docker!"

Default avatar picture of DevNinjas
Pascal Schunk
@OEDIV

"The "Docker & Kubernetes Bundle" training provided me with solid, practical knowledge for everyday work and enabled me to handle Docker and Kubernetes professionally. The excellently structured material offers real added value, even beyond the workshop. The combination of technical depth and interactive delivery by the trainer rounded off the whole experience. An experience that continues to help me even after the training."

Default avatar picture of DevNinjas
Swen Strangfeld
@Bundesdruckerei GmbH

"It was fun and I learned a lot that I can actually apply directly in my company. The trainer's approach was very hands-on, and he repeatedly brought in real-world examples."

Default avatar picture of DevNinjas
Felix R.
@Dirk Rossmann GmbH

"I can recommend the Docker workshop at DevNinjas without reservation! The training was excellently structured: theory and practice complemented each other perfectly. The trainer always answered questions competently and clearly, making even more complex topics easily accessible. I was especially impressed by the professionally designed workshop materials, which are very useful as a reference even after the course. Overall, a thoroughly successful learning experience!"

Default avatar picture of DevNinjas
Lukas Graf
@Bundeswehr

"The seminar was superbly prepared, the group pleasantly small and the materials first-class. An excellent instructor who knows the subject inside out, takes time for the participants and answers questions in detail. The learning material alternated in a balanced way between theory and hands-on exercises that were timed excellently."

Default avatar picture of DevNinjas
Kevin H.
@Oest Holding GmbH

"Competent instructor. Individual approach to problems and topics. Interesting structure. Highly recommended to get an in-depth insight into the Docker world. The workshop was definitely worth it. Thanks!"

Default avatar picture of DevNinjas
H. Hillebrand
@PFSt NRW

Continue Learning

Related Workshops for You

Foundation
Kubernetes Advanced Workshop
Intermediate

Kubernetes Advanced

Two-day Kubernetes Advanced Training for production-ready deployments. You'll learn StatefulSets for databases, RBAC for security, HPA and VPA for auto-scaling, and Prometheus and Grafana for monitoring. Perfect after the introductory course or with comparable Kubernetes experience. Live online in groups of up to 8 participants.
2 Days€1,110.00
Alternative
Introduction to Kyverno Workshop
Intermediate

Introduction to Kyverno

Which workloads may enter the cluster, which images are trusted, and which standards should apply automatically? Over three days, you turn these requirements into testable Kubernetes policies with Kyverno. You write rules in CEL, check their impact before rollout, and introduce them in stages: observe first, then block deliberately. No previous Kyverno or CEL experience is required.
3 Days€1,665.00
Certification
Preparation for the Kubernetes and Cloud Native Security Associate (KCSA) Exam Workshop
Intermediate

Preparation for the Kubernetes and Cloud Native Security Associate (KCSA) Exam

In three days, you prepare specifically for the KCSA certification: all six exam domains, from Cloud Native Security fundamentals to cluster hardening and compliance frameworks. You work hands-on with Falco, OPA Gatekeeper, and Trivy in your own cloud environment.
3 Days€1,665.00
Vincent Sturm - DevNinjas

Your Contact

Vincent Sturm

Key Account Manager

Looking for the right Kubernetes or DevOps training for your team? Vincent personally advises you on open workshops, certification prep and customized in-house training. He can also connect you with our consulting services. Get in touch with him directly.

vincent@devninjas.io
+49 221 9865099-4
WhatsApp Chat

Frequently asked questions

No. Rego, OPA, Gatekeeper, and CEL are introduced from the beginning. You do need practical Kubernetes experience because the course does not explain what Pods, Deployments, or namespaces are. You should be able to edit resources with kubectl and YAML, apply labels and selectors, and understand basic RBAC.

Familiarity with simple Git and CI workflows is also useful. A particular programming language or Kubernetes certification is not required. If you lack the Kubernetes operations foundation, take the Kubernetes Advanced Training first.

OPA is the policy engine, Rego is its declarative policy language, and OPA Gatekeeper is the Kubernetes integration for admission validation, mutation, and audit. Gatekeeper packages validation logic in reusable ConstraintTemplates. Constraints add parameters, scope, and an enforcement action and apply that logic to Kubernetes resources.

ConstraintTemplates can use Rego or CEL for validation. Mutation is not authored in Rego or CEL; it follows a separate model with dedicated mutator resources. The workshop focuses on Gatekeeper for Kubernetes; general OPA authorisation for applications, APIs, or infrastructure code is outside its scope.

Choose OPA Gatekeeper when your team operates Gatekeeper or needs Rego, reusable constraints, and policies that compare admission requests with cluster data. This workshop covers ConstraintTemplates, audit, gator, separate mutators, and Gatekeeper operations.

The Kyverno Training is the better fit when Kubernetes-native policy automation for validation, mutation, generation, deletion, and image verification is central. Both tools use CEL in parts of their validation models, but Gatekeeper mutation runs through dedicated mutator CRDs. The deciding factors are your actual controls, team skills, required capabilities, and which system the team wants to operate over time.

No, but the native Kubernetes option can be sufficient for object-local validation rules. ValidatingAdmissionPolicy evaluates CEL inside the API server and needs no additional validating webhook. Gatekeeper adds reusable constraints, audit of existing resources, Rego, referential policies, gator, and its own policy and operational lifecycle.

In the workshop, you implement the same validation requirement as Rego and CEL ConstraintTemplates and as a native VAP. Separately, you compare Gatekeeper's stable mutator resources with the CEL-based MutatingAdmissionPolicy. Rego is not part of Gatekeeper mutation. A decision matrix exposes which option fits your team's required expressiveness, data access, testing, and operating model.

You test both logic and cluster behaviour before moving to deny, and enable rules in reviewable stages. opa test checks Rego, Regal supports style and quality, and gator evaluates the template, constraint, and test resources together. Admission and audit then expose the actual effect in the cluster.

A rule starts with a narrow scope in dryrun, moves to warn after the results have been reviewed, and only then reaches deny. Exceptions use matching or exclusions; the repository records their owner, approval, expiry date, and removal test. Every blocking change retains a documented rollback.

Every technical module ends with a policy, test, cluster result, or documented decision. You write Rego v1, build a ConstraintTemplate, parameterise constraints, evaluate admission and audit, and test with OPA, Regal, and gator. You then configure stable mutator resources and compare the separate validation and mutation paths with native admission policies.

By the end, your versioned repository contains policies, fixtures, tests, CI checks, a rollout checklist, and a recovery runbook. Your personal lab cluster can be reset and keeps failures away from production environments. External data and expansion are assessed through clear success and failure cases rather than built as a complete provider implementation.

No. The OPA Gatekeeper training does not prepare you for CKA, CKS, or KCSA. It concentrates on Rego, ConstraintTemplates, constraints, audit, testing, rollout, mutation, and Gatekeeper operations. Exam blueprints, practice questions, and test strategy are not part of the agenda.

General OPA authorisation, production installation, high availability, performance tuning, fleet architectures, advanced Rego optimisation, and a complete external-data provider implementation also remain outside. For a certification path, the KCSA Exam Preparation is the appropriate starting point; DW31 is the technical Gatekeeper deep dive.

Our trainings usually take place from 9:00 to 16:00, both on-site and for public remote trainings.

For corporate trainings, other time models are flexible and can be worked out together.

We recommend a maximum of 8 participants per training to ensure individual attention for each participant. For corporate trainings, arrangements for larger groups are possible.

Yes, upon completion you will receive an official certificate of attendance from DevNinjas as PDF. This confirms your successful participation and the topics covered. The certificate is perfect for conversations with your employer and your personnel file.

Additionally, you will receive a verified digital badge that you can directly embed in your LinkedIn profile (section "Licenses & Certifications"). The badge follows the Open Badges 2.0 standard and is verifiable via QR code at any time. This way you showcase your qualification and position yourself with recruiters.

Workshop Dates

Workshop dates

Choose a suitable date and book directly online. All dates are guaranteed to run.

😢 Sorry, there are no workshops available at the moment

We regularly plan new workshops. Please check back later or contact us for a custom workshop.

Delivery available in German or English: dates on request.

Request offer