An honest treatment of secrets inside a Kubernetes cluster for the platform owner who cannot review any of it personally, including the uncomfortable parts. You will work through how the built in Secret object is really stored, what encryption at rest protects and what it does not, the three routes to a secret's plaintext, delivery as environment variables against mounted files, service account tokens and image pull credentials, external secret managers and their integration patterns, and rotation as the restart problem that stalls almost every programme. It closes with blast radius, detection and a practical sequence for an estate that currently keeps credentials in configuration files.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.