Get in Touch

Course Outline

Sovereign Architecture Design

  • Threat modeling: Identifying cloud dependencies and potential data egress points.
  • Network topology: Establishing DMZs, internal zones, and management networks.
  • Hardware selection: Procuring servers, storage solutions, networking gear, and UPS systems.
  • Defining disaster recovery sites and air-gap requirements.

Identity and Access Foundation

  • Deploying Authentik to enable SSO across all services.
  • Designing LDAP directories and group policies.
  • Implementing Step CA for service-to-service mTLS.
  • Enrolling YubiKeys and hardware tokens.

Communication and Collaboration Hub

  • Utilizing Synapse/Element for chat and federation capabilities.
  • Hosting Jitsi Meet for video conferencing.
  • Setting up Roundcube/Nextcloud Mail for email services.
  • Employing Nextcloud for file synchronization, calendars, and contacts.
  • Integrating OnlyOffice for collaborative document editing.

Development and Operations Platform

  • Using Gitea for source code management and CI/CD pipelines.
  • Implementing Woodpecker CI for automated build processes.
  • Utilizing Nexus or Harbor for artifact and container registries.
  • Deploying Wazuh for security monitoring and compliance.
  • Creating service health dashboards with Uptime Kuma.

AI and Knowledge Management

  • Deploying Ollama to serve local LLMs.
  • Providing internal AI assistant access via LibreChat.
  • Managing personal knowledge bases using Obsidian or Logseq.
  • Preserving web content with Hoarder or ArchiveBox.

Security and Perimeter Defense

  • Deploying pfSense or OPNsense firewalls.
  • Configuring Suricata IDS/IPS with custom rulesets.
  • Enabling remote access via WireGuard or OpenVPN.
  • Implementing Pi-hole for DNS filtering and local resolution.
  • Managing team passwords securely using Vaultwarden.

Backup, Disaster Recovery, and Operations

  • Establishing a central repository using BorgBackup for all services.
  • Automating database dumps and configuring off-site replication.
  • Documenting runbooks and incident response procedures.
  • Conducting capacity planning and defining scaling triggers.
  • Scheduling quarterly sovereignty audits and dependency reviews.

Capstone Project

  • Students present their fully operational sovereign stacks.
  • Engaging in peer reviews of architecture decisions and tradeoffs.
  • Performing load testing and failure injection simulations.
  • Completing documentation handoff and operational readiness assessments.

Requirements

  • Advanced proficiency in Linux administration, networking concepts, and container orchestration.
  • Completion of at least two other Data Sovereignty courses or equivalent professional experience.
  • Familiarity with DNS, TLS, firewall configuration, and backup principles.

Audience

  • Senior infrastructure architects responsible for designing sovereign organizations.
  • CTOs and CISOs developing roadmaps for digital independence.
  • Government and defense teams focused on digital transformation.
 35 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories