Get in Touch

Course Outline

Sovereign Architecture Design

  • Threat modeling: Identifying cloud dependencies and data egress points.
  • Network topology: Defining DMZ, internal zones, and management networks.
  • Hardware selection: Servers, storage, networking equipment, and UPS.
  • Disaster recovery sites and air-gap requirements.

Identity and Access Foundation

  • Deploying Authentik for SSO across all services.
  • Designing LDAP directories and group policies.
  • Implementing Step CA for service-to-service mTLS.
  • Enrolling YubiKey and hardware tokens.

Communication and Collaboration Hub

  • Utilizing Synapse/Element for chat and federation.
  • Implementing Jitsi Meet for video conferencing.
  • Deploying Roundcube/Nextcloud Mail for email services.
  • Using Nextcloud for file synchronization, calendars, and contacts.
  • Integrating OnlyOffice for document editing.

Development and Operations Platform

  • Managing source code and CI/CD with Gitea.
  • Automating builds using Woodpecker CI.
  • Handling artifact and container registries with Nexus or Harbor.
  • Monitoring security and compliance via Wazuh.
  • Tracking service health with Uptime Kuma dashboards.

AI and Knowledge Management

  • Deploying Ollama for local LLM serving.
  • Providing internal AI assistant access via LibreChat.
  • Building personal knowledge bases with Obsidian or Logseq.
  • Preserving web content using Hoarder/ArchiveBox.

Security and Perimeter

  • Deploying pfSense or OPNsense firewalls.
  • Implementing Suricata IDS/IPS with custom rules.
  • Securing remote access with WireGuard/OpenVPN.
  • Managing DNS filtering and local resolution via Pi-hole.
  • Handling team password management with Vaultwarden.

Backup, DR, and Operations

  • Establishing a BorgBackup central repository for all services.
  • Automating database dumps and off-site replication.
  • Documenting runbooks and incident response procedures.
  • Planning capacity and defining scaling triggers.
  • Conducting quarterly sovereignty audits and dependency reviews.

Capstone Project

  • Presentation of the fully operational sovereign stack by students.
  • Peer review of architectural decisions and tradeoffs.
  • Execution of load testing and failure injection scenarios.
  • Documentation handoff and operational readiness assessment.

Requirements

  • Advanced proficiency in Linux, networking, and container orchestration.
  • Successful completion of at least two other Data Sovereignty courses or equivalent professional experience.
  • Working knowledge of DNS, TLS, firewall, and backup concepts.

Target Audience

  • Senior infrastructure architects responsible for designing sovereign organizations.
  • CTOs and CISOs developing roadmaps for digital independence.
  • Digital transformation teams within government and defense sectors.
 35 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories