Skip to content

docs: restructure Layered Zero Trust documentation - #720

Open
p-rog wants to merge 5 commits into
validatedpatterns:mainfrom
p-rog:ztvp-docs-update
Open

docs: restructure Layered Zero Trust documentation#720
p-rog wants to merge 5 commits into
validatedpatterns:mainfrom
p-rog:ztvp-docs-update

Conversation

@p-rog

@p-rog p-rog commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Restructure the Layered Zero Trust documentation with a customer-first, value-driven approach
  • Add GUI installation as the primary path with 9 screenshots and an installation video
  • Create three new pages: Architecture, Data Protection, and Security Monitoring
  • Rewrite the landing page to lead with problems and outcomes instead of technical abstractions

New site structure

Tab Description
About (rewritten) Value proposition, problem statement, capability grid
Architecture (new) Layered model, component tables, sidecar pattern, deployment variants
Getting Started (rewritten) GUI-first with screenshots/video, CLI as advanced option
Data Protection (new) qtodo Zero Trust walkthrough — accessible for demos and field engineers
Security Monitoring (new) ACS custom policies, network policy monitoring, runtime threat response
Secure Multitiered Apps Existing (updated weight + cross-ref to Data Protection)
Secure Supply Chain Existing (updated weight)
Automated Supply Chain Existing (unchanged)

Key changes

  • Landing page leads with static defense and data protection problems before CVEs
  • Vault highlighted beyond secret storage — includes JWT auth for workload identity
  • GUI installation marked as "batteries included" baseline; CLI for advanced feature sets
  • "Argo CD" spelling corrected throughout; proper instance navigation documented
  • Keycloak credentials retrieval updated — keycloak-users Secret removed, credentials now in Vault only
  • Security monitoring policies wording updated to "Projects/Namespaces should have..."
  • ACS policies deployment location referenced (charts/acs-policies)
  • Both Data Protection and Security Monitoring note they are part of the default installation

Test plan

  • Verify all cross-references resolve correctly when the site builds
  • Verify screenshots render properly
  • Verify video embed works (may need format conversion for Hugo)
  • Review content accuracy with team

Made with Cursor

Rewrite the ZTVP documentation with a customer-first, value-driven
approach. GUI installation becomes the primary path, technical deep
dives move to dedicated tabs, and new use case pages make the pattern
accessible to non-engineering audiences.

New pages:
- Architecture: layered model, sidecar pattern, deployment variants
- Data Protection: qtodo ZT walkthrough for demos and field engineers
- Security Monitoring: ACS as the Zero Trust brain with custom policies

Updated pages:
- About (landing): value proposition, problem statement, capability grid
- Getting Started: GUI-first with screenshots and video, CLI as advanced
- Existing pages: updated weights and cross-references

Assets: 9 GUI installation screenshots + 1 installation video

Signed-off-by: Przemyslaw Roguski <proguski@redhat.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Hi @p-rog. Thanks for your PR.

I'm waiting for a validatedpatterns member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the size/XL label Aug 5, 2026
@p-rog

p-rog commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

@sabre1041 @mlorenzofr Please review this update. I tried to cover everything we discussed.

Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-architecture.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-architecture.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-architecture.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-data-protection.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-data-protection.adoc Outdated
Co-authored-by: Cursor <cursoragent@cursor.com>
@p-rog
p-rog requested a review from mlorenzofr August 6, 2026 10:55

@sabre1041 sabre1041 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few requested changes. The images were not liking properly

Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
Comment thread content/patterns/layered-zero-trust/_index.adoc Outdated
@@ -2,7 +2,7 @@
title: Layered Zero Trust

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We probably should continue to align on the baseline VP structure for the overview. The rest of the pages we should have the ability to customize as we want

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We probably should continue to align on the baseline VP structure for the overview. The rest of the pages we should have the ability to customize as we want

I adjusted the layout to make it more aligned with the baseline VP structure with keeping the current content to not lose the story we want to say here.

Comment thread content/patterns/layered-zero-trust/lzt-getting-started.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-getting-started.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-data-protection.adoc Outdated
Comment thread content/patterns/layered-zero-trust/lzt-security-monitoring.adoc
Comment thread content/patterns/layered-zero-trust/lzt-getting-started.adoc
|===

[id="try-it-yourself"]
== Try it yourself

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does this section overlap with the content of the Secure Multitiered Applications page?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now when I read the Secure multitiered applications page indeed there is a big overlapping. Maybe we should archive "Secure multitiered applications" in favor of Data Protection page?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like the content that is in the "Secure multitiered applications". Lets indeed combine the pages

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This section needs to be updated to utilize Vault

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that maybe we should archive this page in favor of Data Protection one. I will add only hints about the credentials location and Data Protection page will have full story.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

… baseline structure

Co-authored-by: Cursor <cursoragent@cursor.com>
@p-rog
p-rog requested a review from sabre1041 August 7, 2026 09:38
Co-authored-by: Cursor <cursoragent@cursor.com>
@p-rog

p-rog commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

@sabre1041 I've addressed all your suggestions. The only thing we have to decide is the "Secure Multitiered Applications" page. IMHO right now the "Secure Multitiered Applications" page is not needed. Everything is already covered in the "Data Protection" page. Are you OK to remove that page?

@sabre1041

Copy link
Copy Markdown
Contributor

@sabre1041 I've addressed all your suggestions. The only thing we have to decide is the "Secure Multitiered Applications" page. IMHO right now the "Secure Multitiered Applications" page is not needed. Everything is already covered in the "Data Protection" page. Are you OK to remove that page?

Yup lets go ahead and combine the contents of the two pages into a single "Data Protection" page

Co-authored-by: Cursor <cursoragent@cursor.com>
@p-rog

p-rog commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

@sabre1041 I've addressed all your suggestions. The only thing we have to decide is the "Secure Multitiered Applications" page. IMHO right now the "Secure Multitiered Applications" page is not needed. Everything is already covered in the "Data Protection" page. Are you OK to remove that page?

Yup lets go ahead and combine the contents of the two pages into a single "Data Protection" page

OK, done:

  • Confirmed that all content from the "Secure Multitiered Applications" is covered in the "Data Protection" page
  • Deleted lzt-secure-multitier.adoc
  • Added its alias to lzt-data-protection.adoc so old URLs redirect

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants