Skip to main content
RunBook Academy

Secrets, PKI & Certificates · Curriculum

Curriculum

120 lessons across 25 parts. Lessons build on each other; later parts assume familiarity with earlier material.

Part I

Secrets and Identity Foundations

What counts as a secret, the configuration/secret boundary, human versus machine versus workload identity, a credential taxonomy, blast radius, and where credentials actually leak.

6 lessons
  1. 01What actually counts as a secretFoundations · foundation · ~22 min
  2. 02The six questions that govern every credentialFoundations · foundation · ~24 min
  3. 03Human identity, machine identity and workload identityFoundations · foundation · ~24 min
  4. 04A working taxonomy of infrastructure credentialsFoundations · foundation · ~25 min
  5. 05Blast radius: what one credential unlocksFoundations · intermediate · ~25 min
  6. 06Where credentials really leakFoundations · intermediate · ~24 min

Part II

The Secret Lifecycle

Generate, distribute, use, store, rotate, revoke and destroy; safe generation and entropy; distribution without proliferation; and the storage anti-patterns that dominate real incidents.

6 lessons
  1. 01The secret lifecycle - seven stages and seven ownersLifecycle · foundation · ~21 min
  2. 02Generating secrets safely - entropy, strength and the folkloreLifecycle · foundation · ~22 min
  3. 03Distribution without proliferation - counting the copiesLifecycle · foundation · ~23 min
  4. 04Storage anti-patterns I - repositories, images, state and inventoriesLifecycle · intermediate · ~24 min
  5. 05Storage anti-patterns II - logs, the environment, the process table and peopleLifecycle · intermediate · ~24 min
  6. 06Ownership, expiry and destruction - closing the lifecycleLifecycle · intermediate · ~23 min

Part III

Cryptography for Infrastructure Engineers

Symmetric and asymmetric cryptography, hashes, MACs, digital signatures, entropy and key derivation, and envelope encryption - to operator depth, never implementation depth.

7 lessons
  1. 01What "encrypted" actually promises, and the vocabulary that carries itCryptography · foundation · ~20 min
  2. 02Symmetric encryption in infrastructure, and why AEAD is the only sane defaultCryptography · foundation · ~22 min
  3. 03Key pairs, signing and key agreement: what a public key is actually forCryptography · foundation · ~22 min
  4. 04Hashes, MACs and HMAC: integrity is not authenticityCryptography · intermediate · ~24 min
  5. 05Digital signatures end to end: what is signed, by which key, and what a verifier learnsCryptography · intermediate · ~24 min
  6. 06Entropy, random number generation and key derivation on modern LinuxCryptography · intermediate · ~22 min
  7. 07Envelope encryption and the key hierarchy: why KEK and DEK are everywhereCryptography · intermediate · ~26 min

Part IV

PKI Foundations

Trust anchors, root and intermediate and leaf, path building and validation, public Web PKI versus internal PKI, offline root operations, and intermediate CA design for blast-radius control.

7 lessons
  1. 01What a public key infrastructure is actually forPKI · intermediate · ~22 min
  2. 02Trust anchors: where a client's trust physically livesPKI · intermediate · ~22 min
  3. 03Root, intermediate and leaf: why the middle layer existsPKI · intermediate · ~23 min
  4. 04Certification path building and path validationPKI · intermediate · ~25 min
  5. 05Public Web PKI and internal PKI: two different problemsPKI · intermediate · ~24 min
  6. 06Operating a root CA: offline keys, ceremony and honest trade-offsPKI · intermediate · ~23 min
  7. 07Designing an intermediate CA layout for blast-radius controlPKI · intermediate · ~24 minLab

Part V

X.509 Certificates in Depth

The fields operators use, the extensions that decide behaviour, Subject Alternative Name and the end of Common Name matching, CSRs and what they prove, and key-to-certificate correspondence.

6 lessons
  1. 01Reading a certificate: the fields an operator actually usesX509 · intermediate · ~22 minLab
  2. 02Extensions that decide behaviour: basicConstraints, keyUsage and extendedKeyUsageX509 · intermediate · ~23 min
  3. 03Subject Alternative Name and the end of Common Name matchingX509 · intermediate · ~24 min
  4. 04Serial numbers, validity windows, signature algorithms and fingerprintsX509 · intermediate · ~22 min
  5. 05Certificate signing requests: what a CSR proves and what it does notX509 · intermediate · ~23 minLab
  6. 06Proving a private key matches a certificateX509 · intermediate · ~22 min

Part VI

Chains and Trust Stores

How a chain is assembled and presented, the missing intermediate, OS and language and container trust stores, distributing a private trust anchor, and diagnosing client-specific trust failures.

6 lessons
  1. 01How a certificate chain is assembled, and who supplies which certificateTrustStores · intermediate · ~21 min
  2. 02The missing intermediate, the most common TLS failure in productionTrustStores · intermediate · ~24 minLab
  3. 03Operating system trust stores on Linux, and how they are updatedTrustStores · intermediate · ~22 min
  4. 04Application and language trust stores: Java, Python, Node.js, Go and containersTrustStores · intermediate · ~24 min
  5. 05Distributing a private trust anchor across a fleet, and the ordering ruleTrustStores · intermediate · ~23 minLab
  6. 06Diagnosing works on my machine but fails in the clusterTrustStores · intermediate · ~22 min

Part VII

TLS for Operators

What TLS actually provides, the TLS 1.3 handshake, how TLS 1.2 differs, certificate validation as the client performs it, version and cipher policy, and mutual TLS.

6 lessons
  1. 01What TLS actually provides, and what a certificate really doesTLS · intermediate · ~20 min
  2. 02The TLS 1.3 handshake, message by messageTLS · intermediate · ~24 minLab
  3. 03TLS 1.2 versus TLS 1.3, and why the difference reaches your configurationTLS · advanced · ~22 min
  4. 04Certificate validation as the client performs itTLS · intermediate · ~24 min
  5. 05Protocol versions, cipher suites and configuration policy in 2026TLS · advanced · ~22 min
  6. 06Mutual TLS: authenticating the client as well as the serverTLS · advanced · ~24 minLab

Part VIII

TLS Troubleshooting

Evidence-first methodology, openssl s_client and curl as instruments, the classic failure signatures, clock skew, and why disabling verification is never the fix.

6 lessons
  1. 01Identify the layer before you touch the configurationTroubleshooting · intermediate · ~22 min
  2. 02Reading openssl s_client: the five flags that decide what you learnTroubleshooting · intermediate · ~24 min
  3. 03curl exit 60 and the three different failures behind itTroubleshooting · intermediate · ~22 min
  4. 04The classic failures and their exact signaturesTroubleshooting · advanced · ~26 minLab
  5. 05Clock skew, validity windows and why a correct certificate fails on one hostTroubleshooting · intermediate · ~22 min
  6. 06Why disabling verification is not a fixTroubleshooting · advanced · ~24 min

Part IX

Certificate Lifecycle and Revocation

Expiry as an availability incident, renewal windows and overlap, deployment and reload, key rotation versus renewal, CRL and OCSP mechanics, and what revocation really achieves.

7 lessons
  1. 01Certificate expiry is an availability incidentLifecycle · intermediate · ~20 min
  2. 02Renewal windows, overlapping validity and safe deliveryLifecycle · intermediate · ~22 min
  3. 03Deployment and reload: the step that actually breaksLifecycle · intermediate · ~24 minLab
  4. 04Rotating a private key versus renewing a certificateLifecycle · advanced · ~22 min
  5. 05Revocation mechanics: CRL and OCSPLifecycle · advanced · ~26 min
  6. 06What revocation actually achieves in the Web PKILifecycle · advanced · ~24 min
  7. 07Revocation inside a private PKILifecycle · advanced · ~24 min

Part X

ACME and Certificate Automation

The ACME order flow, HTTP-01 and DNS-01 and TLS-ALPN-01, Let's Encrypt staging and rate limits, internal ACME from a private CA, and renewal automation you can trust.

6 lessons
  1. 01Why manual certificate issuance fails at scaleAutomation · intermediate · ~22 min
  2. 02The ACME protocol — accounts, orders, authorizations and the two keysAutomation · intermediate · ~24 min
  3. 03HTTP-01, DNS-01 and TLS-ALPN-01 — how each one is actually validatedAutomation · intermediate · ~24 min
  4. 04Let's Encrypt in production — staging, profiles, rate limits and ARIAutomation · advanced · ~26 minLab
  5. 05Internal ACME — automating issuance from a private certificate authorityAutomation · advanced · ~23 min
  6. 06Designing renewal automation you can trustAutomation · advanced · ~25 min

Part XI

SSH Keys, Host Trust and SSH CAs

Public-key authentication, host keys and trust on first use, investigating a changed host key, the agent and forwarding risks, and SSH certificate authorities with principals and revocation.

6 lessons
  1. 01SSH public-key authentication — what actually proves identitySSH · intermediate · ~22 minLab
  2. 02Host keys and trust on first use — what TOFU guaranteesSSH · intermediate · ~21 min
  3. 03REMOTE HOST IDENTIFICATION HAS CHANGED — investigate before you deleteSSH · intermediate · ~23 min
  4. 04The SSH agent, forwarding, and what a bastion can borrowSSH · intermediate · ~21 min
  5. 05SSH certificate authorities — trusting one key instead of thousandsSSH · advanced · ~24 minLab
  6. 06Issuing, constraining and revoking SSH certificatesSSH · advanced · ~25 minLab

Part XII

Secret Management Platforms

Secret-manager architecture before any product, storage and barrier and seal, static secrets, least-privilege policy, tokens and authentication methods, and audit that does not leak.

6 lessons
  1. 01The architecture of a secret manager, before any productSecretManagers · intermediate · ~22 min
  2. 02OpenBao concretely: storage, the barrier, and the unseal ceremonySecretManagers · advanced · ~26 minLab
  3. 03Static secrets, and why central storage does not solve rotationSecretManagers · intermediate · ~22 min
  4. 04Policies and least privilege: path rules, capabilities and the KV v2 splitSecretManagers · advanced · ~26 minLab
  5. 05Tokens, authentication methods and identitySecretManagers · advanced · ~24 min
  6. 06Audit without leaking: what to record and what must never be recordedSecretManagers · advanced · ~24 min

Part XIII

Dynamic Credentials and Workload Identity

Credentials created on demand, leases and TTL trade-offs, machine authentication methods, the secret-zero problem, platform-attested workload identity, and SPIFFE/SPIRE scope and cost.

6 lessons
  1. 01Dynamic credentials: a database login that did not exist a minute agoDynamicCredentials · advanced · ~22 minLab
  2. 02Leases and TTLs: choosing an exposure window you can actually operateDynamicCredentials · advanced · ~22 min
  3. 03Authenticating machines: AppRole, Kubernetes, JWT and client certificatesDynamicCredentials · advanced · ~24 minLab
  4. 04The secret-zero problem: how a machine gets the credential that gets its credentialsDynamicCredentials · advanced · ~26 min
  5. 05Workload identity: exchanging a platform-issued token for a short-lived credentialDynamicCredentials · advanced · ~22 min
  6. 06SPIFFE and SPIRE: a universal identity namespace and what it costs to run oneDynamicCredentials · advanced · ~24 min

Part XIV

Platform Integration

Kubernetes secrets and cluster PKI and certificate incidents, container build secrets and image layers, Terraform state exposure, Ansible vault and no_log limits, CI/CD OIDC federation, and database and network-device patterns.

7 lessons
  1. 01Kubernetes Secrets and the cluster PKIPlatformIntegration · advanced · ~24 min
  2. 02Kubernetes workload identity and certificate incidentsPlatformIntegration · advanced · ~24 min
  3. 03Container build secrets, image layers and runtime injectionPlatformIntegration · advanced · ~22 min
  4. 04Terraform state, sensitive values and provider credentialsPlatformIntegration · advanced · ~23 min
  5. 05Ansible Vault, no_log and external secret lookupsPlatformIntegration · advanced · ~22 min
  6. 06CI/CD credentials: OIDC federation, log masking and runner compromisePlatformIntegration · advanced · ~24 min
  7. 07Databases and network devices: identity, rotation and connection poolsPlatformIntegration · advanced · ~22 min

Part XV

KMS, HSM and Key Protection

The operations you delegate to a KMS, envelope encryption in practice, non-exportable keys in hardware, what KMS key rotation actually changes, key backup, and quorum-controlled root key recovery.

6 lessons
  1. 01Key management services: what you delegate and what it costsKeyProtection · advanced · ~20 min
  2. 02Envelope encryption in practice: key-wrapping keys and data keysKeyProtection · advanced · ~21 min
  3. 03Hardware security modules and what non-exportable really meansKeyProtection · advanced · ~23 min
  4. 04Key rotation in a KMS: what it does and what it definitely does notKeyProtection · advanced · ~22 min
  5. 05Backing up key material, and when a key must not be recoverableKeyProtection · advanced · ~20 min
  6. 06Root key recovery, quorum and break-glassKeyProtection · advanced · ~22 min

Part XVI

Rotation Without Outage

Why instant replacement causes outages, the dual-credential pattern, zero-downtime database password rotation, fleet certificate and key rotation, intermediate CA rotation, and trust-anchor migration.

6 lessons
  1. 01Why instant credential replacement causes outagesRotation · advanced · ~22 min
  2. 02The dual-credential rotation pattern in detailRotation · advanced · ~23 min
  3. 03Rotating a database password with no downtimeRotation · advanced · ~24 minLab
  4. 04Rotating certificates and private keys across a fleetRotation · advanced · ~23 min
  5. 05Rotating an intermediate CARotation · advanced · ~24 min
  6. 06Root and trust anchor migrationRotation · advanced · ~25 min

Part XVII

Inventory, Discovery and Monitoring

You cannot rotate what you do not know exists: building a credential inventory, discovering certificates across an estate, expiry monitoring, secret-manager observability, and alert design.

6 lessons
  1. 01You cannot rotate what you do not know existsInventory · intermediate · ~21 min
  2. 02Building a credential inventory that stays trueInventory · intermediate · ~22 min
  3. 03Discovering certificates across an estateInventory · advanced · ~24 min
  4. 04Monitoring certificate expiry so it actually catches itInventory · advanced · ~24 minLab
  5. 05Monitoring a secret manager: availability, denials and leasesInventory · advanced · ~23 min
  6. 06Alert design for credential and certificate riskInventory · advanced · ~22 min

Part XVIII

Incidents and Recovery

The first hour after exposure, private key compromise, CA compromise as a different class of incident, compromised CI and cloud and SSH credentials, secret-manager outage, and backup and disaster recovery.

7 lessons
  1. 01A secret is exposed: the first hourIncidentResponse · advanced · ~22 min
  2. 02Private key compromise: TLS server keysIncidentResponse · advanced · ~22 min
  3. 03CA compromise: the incident that is different in kindIncidentResponse · advanced · ~25 min
  4. 04Compromised CI, cloud and SSH credentialsIncidentResponse · advanced · ~23 min
  5. 05Secret manager outage and its failure modesIncidentResponse · advanced · ~22 minLab
  6. 06Backup and disaster recovery for PKI and secret stateIncidentResponse · advanced · ~23 min
  7. 07Break-glass access, and testing it before you need itIncidentResponse · advanced · ~21 min

Part XIX

Production Architecture

Trust boundaries, least privilege for retrieving a secret versus using a key, what belongs in Git, and reference architectures for internal PKI, workload secrets, and delivery-pipeline identity.

6 lessons
  1. 01Trust boundaries: drawing the diagram that mattersArchitecture · advanced · ~22 min
  2. 02Least privilege in two dimensions: retrieving a secret and using a keyArchitecture · advanced · ~22 min
  3. 03What belongs in Git, and what never doesArchitecture · advanced · ~22 min
  4. 04Reference architecture: internal PKIArchitecture · advanced · ~22 min
  5. 05Reference architecture: workload secretsArchitecture · advanced · ~21 min
  6. 06Reference architecture: delivery-pipeline identityArchitecture · advanced · ~23 min

Part Labs

Labs

Hands-on disposable-environment labs covering certificate inspection and issuance, CA construction, TLS and mutual TLS, chain and trust-store diagnosis, ACME automation, SSH certificate authorities, secret-manager operation, dynamic credentials, rotation, monitoring and recovery.

0 lessons

No lessons published in this part yet. The full curriculum is planned in docs/courses/secrets-pki/curriculum.md on GitHub.

Part Runbooks

Runbooks

Operational procedures for certificate expiry and renewal, TLS and chain and mutual-TLS troubleshooting, key and credential rotation, revocation, leaked-secret and compromised-key response, secret-manager recovery, and PKI restoration.

0 lessons

Part Checklists

Checklists

Production readiness reviews for secret management, internal PKI, TLS services, certificate issuance and renewal, ACME automation, SSH trust, rotation, CA security, KMS and HSM, platform integration, and disaster recovery.

0 lessons

Part Breakfix

Break/Fix Scenarios

Evidence-first diagnosis of certificate, chain, trust-store, TLS, ACME, SSH, secret-manager, dynamic-credential, leakage and compromise failure modes, each reproduced against real software.

0 lessons

Part Capstone

Production Capstone

Design and build a complete secrets and PKI architecture: trust hierarchy, automated issuance, SSH identity, least-privilege secret management, short-lived credentials, workload identity, monitoring, rotation, compromise response and proven recovery.

1 lesson
  1. 01Capstone — build and defend a production secrets and PKI architectureCapstone · expert · ~240 min

Part Final

Final Assessment

Final theory assessment plus final practical assessment of an inherited estate with realistic credential, certificate and trust defects.

0 lessons

No lessons published in this part yet. The full curriculum is planned in docs/courses/secrets-pki/curriculum.md on GitHub.