Browse the full catalog of hands-on environments.
Break out of a deliberately misconfigured container to reach the host, then apply the runtime and admission controls that make the same escape fail.
Take a bloated application image that runs as root and rebuild it as a minimal, non-root, reproducible image, measuring the vulnerability count at every step.