Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereign Architecture Design
- Threat modeling: Identifying cloud dependencies and data egress points.
- Network topology: Structuring DMZ, internal zones, and management networks.
- Hardware selection: Choosing appropriate servers, storage, networking, and UPS units.
- Configuring disaster recovery sites and air-gap requirements.
Identity and Access Foundation
- Deploying Authentik to enable SSO across all services.
- Designing LDAP directories and group policies.
- Implementing Step CA for service-to-service mTLS.
- Enrolling YubiKeys and hardware tokens.
Communication and Collaboration Hub
- Setting up Synapse/Element for chat and federation.
- Configuring Jitsi Meet for video conferencing.
- Deploying Roundcube/Nextcloud Mail for email services.
- Utilizing Nextcloud for file synchronization, calendars, and contacts.
- Integrating OnlyOffice for document editing.
Development and Operations Platform
- Using Gitea for source code management and CI/CD.
- Implementing Woodpecker CI for automated builds.
- Configuring Nexus or Harbor for artifact and container registries.
- Deploying Wazuh for security monitoring and compliance.
- Setting up Uptime Kuma for service health dashboards.
AI and Knowledge Management
- Deploying Ollama with local LLM serving capabilities.
- Configuring LibreChat for internal AI assistant access.
- Using Obsidian or Logseq for personal knowledge bases.
- Preserving web content with Hoarder/ArchiveBox.
Security and Perimeter
- Deploying pfSense or OPNsense firewalls.
- Configuring Suricata IDS/IPS with custom rules.
- Setting up WireGuard/OpenVPN for secure remote access.
- Implementing Pi-hole for DNS filtering and local resolution.
- Managing team passwords with Vaultwarden.
Backup, DR, and Operations
- Creating a central BorgBackup repository for all services.
- Automating database dumps and off-site replication.
- Documenting runbooks and incident response procedures.
- Planning capacity and defining scaling triggers.
- Conducting quarterly sovereignty audits and dependency reviews.
Capstone Project
- Presenting the fully operational sovereign stack.
- Undergoing peer review of architectural decisions and trade-offs.
- Performing load testing and failure injection.
- Completing documentation handoff and operational readiness assessments.
Requirements
- Advanced proficiency in Linux, networking, and container orchestration.
- Completion of at least two other Data Sovereignty courses or equivalent practical experience.
- Solid understanding of DNS, TLS, firewall, and backup concepts.
Target Audience
- Senior infrastructure architects building sovereign organizational structures.
- CTOs and CISOs developing digital independence roadmaps.
- Digital transformation teams within government and defense sectors.
35 Hours
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer