Defend, Contain, Comply

Welcome to the Defend, Contain, Comply workshop — a hands-on Ansible Automation Platform experience focused on vulnerability management.

What you will learn

In this 120-150 minutes workshop you will manage a complete vulnerability lifecycle on a RHEL system using AAP:

  • Module 1 — DEFEND: Detect a critical CVE and automate containment when no patch exists

  • Module 2 — CONTAIN: Apply a policy-gated patching workflow once an errata is published

  • Module 3 — COMPLY: Validate compliance, apply CIS hardening, generate evidence, and deliver a hardened container

Workshop environment

Your lab provides:

  • AAP Controller — orchestrates all automation workflows

  • EDA Controller — receives Splunk webhook alerts and triggers responses

  • RHEL 9 application server — runs a customer-facing httpd instance

  • Local container registry — for supply chain delivery in Module 3

How to use this guide

Each module follows a progressive narrative. Commands marked with the execute role can be run directly from the terminal tab.

Complete the modules in order — each builds on the previous one.

Ready?

Start with the Workshop Overview to understand your mission.