In traditional network models, a firewall protects the edge, and anything “inside” is implicitly trusted — a system that critically fails when attackers breach the perimeter, insiders go rogue, or workloads span distributed clouds. Zero Trust flips this model, dictating that every single request — whether from a person, an application, or an automation job — must prove it should be allowed through strong identity management, explicit policy enforcement, and continuous verification.
This workshop provides hands-on experience building a NIST SP 800-207 compliant environment where Red Hat Ansible Automation Platform sits at the center of the architecture. By integrating various infrastructure and security tools — such as Open Policy Agent (OPA) for policy decisions, HashiCorp Vault for secrets, and Splunk for threat signaling — Ansible Automation Platform acts as the unified gateway, ensuring that every operational change passes through identity checks, policy gates, and audit trails.
Key themes explored in the workshop:
| Resource | Link |
|---|---|
| Workshop content and exercises | 🖥️ Google Slides |
| Post-event survey | 📋 Post-event survey |
| Registration page & promotional email copy | 📝 Registration page & promotional email copy |
| Event banners | 🎨 Adobe Express banners |
| Option | Link | Description |
|---|---|---|
| Launch on RHDP | 🚀 Launch Lab | Provision a full lab environment on the Red Hat Demo Platform |
| View Instructions | 📖 View Showroom | Browse the lab instructions and exercises |
This lab environment is available via the Red Hat Demo Platform under the Implementing Zero Trust with Ansible Automation Platform catalog item.
| Activity | Link |
|---|---|
| Slides: Introduction + Workshop Brief | 🖥️ Google Slides |
| Exercise 1 — Verify ZTA Components and AAP Integration | 🚀 Launch Exercise |
| Exercise 2 — Deploy application with short-lived credentials | 🚀 Launch Exercise |
| Exercise 3 — AAP Policy as Code: platform-gated patching | 🚀 Launch Exercise |
| Exercise 4 — SPIFFE-verified network VLAN management | 🚀 Launch Exercise |
| Exercise 5 — Automated incident response with Splunk and EDA | 🚀 Launch Exercise |
| *Extended security workshop option | |
| Exercise 6 — SSH lockdown and break-glass | 🚀 Launch Exercise |
| Exercise 7 — Wazuh SIEM (optional) | 🚀 Launch Exercise |
This is an official Ansible Workshop
This workshop is maintained by the Red Hat Ansible Technical Marketing Team. Please open an issues on Github
