DevOps Foundations · Module 8: Security and safe-change basics · Lab
Narrow an Over-privileged Service User and Rotate Its Secret
45 min hands-on · Core
A local Linux user or service account with fixture files and fixture credentials under /tmp/dlab-m08-01.
Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.
Objectives
- Scope the identity to the minimum paths and commands its job needs
- Rotate the fixture credential with the correct response order
- Prove the job works and the old reach is denied
Step 1
Map the excess reach
Document the identity's current reach (files, commands, credentials) against its actual job. Name the grants to remove and the theft scenario each one enables today.
Step 2
Narrow and rotate
Scope the identity to the job's minimum (paths, groups, sudo rules if any), move the fixture credential to the narrow channel, and rotate it following the fixed order: rotate, audit, purge, prevent.
Step 3
Prove both directions
Run the job green as the narrowed identity, then show the old reach denied (a read or write outside the new scope failing). Record both proofs.
How to confirm it worked
- Excess reach mapped with a theft scenario per removed grant
- Identity narrowed with the fixture credential rotated in order
- Job runs green as the narrowed identity, quoted
- Old reach demonstrably denied, quoted