Implementing Zero Trust with Ansible Automation Platform

In traditional network models, a firewall protects the edge, and anything “inside” is implicitly trusted — a system that critically fails when attackers breach the perimeter, insiders go rogue, or workloads span distributed clouds. Zero Trust flips this model, dictating that every single request — whether from a person, an application, or an automation job — must prove it should be allowed through strong identity management, explicit policy enforcement, and continuous verification.

This workshop provides hands-on experience building a NIST SP 800-207 compliant environment where Red Hat Ansible Automation Platform sits at the center of the architecture. By integrating various infrastructure and security tools — such as Open Policy Agent (OPA) for policy decisions, HashiCorp Vault for secrets, and Splunk for threat signaling — Ansible Automation Platform acts as the unified gateway, ensuring that every operational change passes through identity checks, policy gates, and audit trails.

Key themes explored in the workshop:

Workshop Resources

Resource Link
Workshop content and exercises 🖥️ Google Slides
Post-event survey 📋 Post-event survey
Registration page & promotional email copy 📝 Registration page & promotional email copy
Event banners 🎨 Adobe Express banners

Target Audience

Attendee Prerequisites

Presentation Deck

Lab Options

Option Link Description
Launch on RHDP 🚀 Launch Lab Provision a full lab environment on the Red Hat Demo Platform
View Instructions 📖 View Showroom Browse the lab instructions and exercises

Lab provisioner

This lab environment is available via the Red Hat Demo Platform under the Implementing Zero Trust with Ansible Automation Platform catalog item.

Exercises

Activity Link
Slides: Introduction + Workshop Brief 🖥️ Google Slides
Exercise 1 — Verify ZTA Components and AAP Integration 🚀 Launch Exercise
Exercise 2 — Deploy application with short-lived credentials 🚀 Launch Exercise
Exercise 3 — AAP Policy as Code: platform-gated patching 🚀 Launch Exercise
Exercise 4 — SPIFFE-verified network VLAN management 🚀 Launch Exercise
Exercise 5 — Automated incident response with Splunk and EDA 🚀 Launch Exercise
*Extended security workshop option
Exercise 6 — SSH lockdown and break-glass 🚀 Launch Exercise
Exercise 7 — Wazuh SIEM (optional) 🚀 Launch Exercise

Ansible Workshop

This is an official Ansible Workshop

This workshop is maintained by the Red Hat Ansible Technical Marketing Team. Please open an issues on Github

ansible workshop logo