Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereign Architecture Design
- Threat modeling: Identifying cloud dependencies and data egress points.
- Network topology: Establishing DMZ, internal zones, and management networks.
- Hardware selection: Selecting servers, storage, networking gear, and UPS units.
- Disaster recovery sites and air-gap requirements.
Identity and Access Foundation
- Deploying Authentik for single sign-on (SSO) across all services.
- Designing LDAP directories and group policies.
- Implementing Step CA for service-to-service mutual TLS (mTLS).
- Enrolling YubiKeys and hardware tokens.
Communication and Collaboration Hub
- Utilizing Synapse/Element for chat and federation capabilities.
- Implementing Jitsi Meet for video conferencing.
- Setting up Roundcube/Nextcloud Mail for email services.
- Leveraging Nextcloud for file synchronization, calendars, and contacts.
- Integrating OnlyOffice for document editing.
Development and Operations Platform
- Using Gitea for source code management and CI/CD pipelines.
- Employing Woodpecker CI for automated builds.
- Utilizing Nexus or Harbor as artifact and container registries.
- Implementing Wazuh for security monitoring and compliance.
- Setting up Uptime Kuma for service health dashboards.
AI and Knowledge Management
- Deploying Ollama with local LLM serving capabilities.
- Providing internal AI assistant access via LibreChat.
- Using Obsidian or Logseq for personal knowledge bases.
- Preserving web content through Hoarder/ArchiveBox.
Security and Perimeter
- Deploying pfSense or OPNsense firewalls.
- Configuring Suricata IDS/IPS with custom rulesets.
- Establishing remote access via WireGuard/OpenVPN.
- Implementing Pi-hole for DNS filtering and local resolution.
- Managing team passwords securely using Vaultwarden.
Backup, DR, and Operations
- Centralizing backups across all services with BorgBackup.
- Automating database dumps and off-site replication.
- Documenting runbooks and incident response procedures.
- Conducting capacity planning and defining scaling triggers.
- Performing quarterly sovereignty audits and dependency reviews.
Capstone Project
- Students present their fully operational sovereign stack.
- Peer review of architecture decisions and tradeoffs.
- Load testing and failure injection exercises.
- Documentation handoff and operational readiness assessment.
Requirements
- Advanced knowledge of Linux, networking, and container orchestration.
- Completion of at least two other Data Sovereignty courses or equivalent practical experience.
- Familiarity with DNS, TLS, firewall configurations, and backup concepts.
Audience
- Senior infrastructure architects responsible for designing sovereign organizations.
- CTOs and CISOs developing digital independence roadmaps.
- Government and defense digital transformation teams.
35 Hours
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer