Get in Touch

Course Outline

Sovereign Architecture Design

  • Threat modeling: identifying cloud dependencies and data egress points.
  • Network topology: establishing DMZs, internal zones, and management networks.
  • Hardware selection: determining requirements for servers, storage, networking gear, and UPS systems.
  • Establishing disaster recovery sites and air-gap requirements.

Identity and Access Foundation

  • Deployment of Authentik for single sign-on (SSO) across all services.
  • Designing LDAP directories and group policies.
  • Utilizing Step CA for service-to-service mutual TLS (mTLS).
  • Enrolling YubiKeys and hardware tokens.

Communication and Collaboration Hub

  • Synapse/Element implementation for chat and federation capabilities.
  • Jitsi Meet setup for video conferencing.
  • Roundcube/Nextcloud Mail deployment for email services.
  • Nextcloud configuration for file synchronization, calendars, and contacts.
  • OnlyOffice integration for collaborative document editing.

Development and Operations Platform

  • Gitea deployment for source code management and CI/CD pipelines.
  • Woodpecker CI implementation for automated builds.
  • Nexus or Harbor deployment for artifact and container registries.
  • Wazuh setup for security monitoring and compliance tracking.
  • Uptime Kuma configuration for service health dashboards.

AI and Knowledge Management

  • Ollama deployment with local LLM serving capabilities.
  • LibreChat setup for internal AI assistant access.
  • Obsidian or Logseq implementation for personal knowledge bases.
  • Hoarder/ArchiveBox configuration for web content preservation.

Security and Perimeter Defense

  • pfSense or OPNsense firewall deployment.
  • Suricata IDS/IPS installation with custom rule sets.
  • WireGuard/OpenVPN configuration for secure remote access.
  • Pi-hole setup for DNS filtering and local resolution.
  • Vaultwarden deployment for team password management.

Backup, Disaster Recovery, and Operations

  • BorgBackup central repository configuration for all services.
  • Automating database dumps and off-site replication.
  • Compiling runbook documentation and incident response procedures.
  • Defining capacity planning metrics and scaling triggers.
  • Conducting quarterly sovereignty audits and dependency reviews.

Capstone Project

  • Students present their fully operational sovereign stack.
  • Peer review of architectural decisions and tradeoffs.
  • Execution of load testing and failure injection scenarios.
  • Documentation handoff and operational readiness assessment.

Requirements

  • Advanced proficiency in Linux, networking, and container orchestration.
  • Completion of at least two other Data Sovereignty courses or equivalent professional experience.
  • Familiarity with DNS, TLS, firewall configurations, and backup concepts.

Audience

  • Senior infrastructure architects designing sovereign organizational structures.
  • CTOs and CISOs planning digital independence roadmaps.
  • Government and defense digital transformation teams.
 35 Hours

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories