The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 8: Security and safe-change basics · Lab

Narrow an Over-privileged Service User and Rotate Its Secret

45 min hands-on · Core

A local Linux user or service account with fixture files and fixture credentials under /tmp/dlab-m08-01.

Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.

Objectives

  • Scope the identity to the minimum paths and commands its job needs
  • Rotate the fixture credential with the correct response order
  • Prove the job works and the old reach is denied
  1. Step 1

    Map the excess reach

    Document the identity's current reach (files, commands, credentials) against its actual job. Name the grants to remove and the theft scenario each one enables today.

  2. Step 2

    Narrow and rotate

    Scope the identity to the job's minimum (paths, groups, sudo rules if any), move the fixture credential to the narrow channel, and rotate it following the fixed order: rotate, audit, purge, prevent.

  3. Step 3

    Prove both directions

    Run the job green as the narrowed identity, then show the old reach denied (a read or write outside the new scope failing). Record both proofs.

How to confirm it worked

  • Excess reach mapped with a theft scenario per removed grant
  • Identity narrowed with the fixture credential rotated in order
  • Job runs green as the narrowed identity, quoted
  • Old reach demonstrably denied, quoted