Online workshop

Zero Trust Architecture with Ansible Automation Platform workshop

Jump to section

In traditional network models, a firewall protects the edge, and anything "inside" is implicitly trusted—a system that critically fails when attackers breach the perimeter, insiders go rogue, or workloads span distributed clouds. Zero Trust flips this model, dictating that every single request—whether from a person, an application, or an automation job—must prove it should be allowed through strong identity management, explicit policy enforcement, and continuous verification.

This workshop provides hands-on experience building a NIST SP 800-207 compliant environment where Red Hat Ansible Automation Platform sits at the center of the architecture. By integrating various infrastructure and security tools—such as Open Policy Agent (OPA) for policy decisions, HashiCorp Vault for secrets, and Splunk for threat signaling—Ansible Automation Platform acts as the unified gateway, ensuring that every operational change passes through identity checks, policy gates, and audit trails.

WHAT YOU'LL LEARN

  • Verify ZTA components and configure LDAP authentication
  • Deploy applications utilizing short-lived credentials from HashiCorp Vault
  • Enforce platform-gating with AAP Policy as Code using Open Policy Agent (OPA)

WHO SHOULD ATTEND

  • Security operations, engineers and architects 
  • System admins and ITOps 
  • Network architects and operations
  • Cloud architects and operations 
  • IT architects 
  • Platform engineers

PRE-REQUISITES

  • Student has one (1) of the following
    • Student has completed the Ansible Red Hat Enterprise Linux Workshop 
    • Student has completed the Write your first playbook interactive lab
    • Student has completed the Red Hat training course Ansible Basics: Automation Technical Overview
  • A basic understanding of working with Linux systems
  • A basic understanding of Visual Studio Code. [Available for MacOS, Windows and Linux]
  • Attendees must bring/use a laptop with ADMIN rights and the ability to SSH to a lab environment hosted in a public cloud.
  • Must use a laptop with Chrome 73+, Firefox 60+, Edge 40+, or Safari 12+installed.