Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
CentOS Stream Architecture and Release Philosophy
- Evaluating the CentOS Stream rolling-release methodology in contrast to traditional point release distributions.
- Analyzing the upstream development relationship between CentOS Stream and Red Hat Enterprise Linux.
- Adhering to naming conventions, managing stream repositories, and implementing content versioning strategies.
- Selecting and transitioning between multiple streams to ensure application compatibility for government systems.
Installation and Automated Deployment
- Conducting interactive Anaconda graphical and text-based installer procedures.
- Utilizing Kickstart files to facilitate fully automated, unattended installations.
- Implementing PXE network boot and TFTP-based network-install workflows.
- Deploying containerized environments and utilizing cloud-init for cloud-based provisioning for government infrastructure.
- Establishing partitioning strategies and selecting filesystems, including defaults such as Btrfs and XFS.
Package Management and Module Streams
- Executing advanced DNF operations, managing transactions, and resolving dependencies.
- Leveraging module streams to support flexible software versions and language runtimes.
- Configuring repositories, verifying GPG signatures, and establishing custom repository structures.
- Monitoring content views and errata to manage enterprise updates effectively for government compliance.
System Service Management with systemd
- Interpreting systemd targets, units, and dependency graphs.
- Creating, enabling, and troubleshooting custom service units.
- Managing journal logging, implementing log rotation, and maintaining persistent log storage.
- Controlling resources through systemd slices and resource manager policies.
- Configuring Kdump for crash dump analysis and handling kernel panics.
Modern Network Configuration
- Mastering network configuration essentials via the NetworkManager CLI and CUI.
- Configuring interface bonding, bridges, VLANs, and teaming for robust connectivity.
- Implementing firewalld rich rules, zones, services, and port forwarding for secure access control.
- Managing IPv6 routing, firewall rules, and DNS resolution via systemd-resolved.
- Utilizing network debugging tools and packet capture techniques for operational transparency.
Container and Pod Infrastructure
- Distinguishing between Podman and Docker architectures, focusing on daemonless container workflows for government security.
- Creating container images with Buildah without requiring a Dockerfile or daemon.
- Deploying rootless containers and configuring user namespace mappings.
- Utilizing Red Hat Universal Base Images and Alpine-based lightweight containers.
- Managing storage drivers, volume mounts, and inter-container network communication.
- Monitoring container lifecycles and performing operational checks with skopeo and crun.
Security Hardening
- Configuring SELinux in enforcing mode, managing policies, and troubleshooting audit logs.
- Designing hardened firewalld zones and composing precise access rules for government networks.
- Harden SSH configurations, implement key-based authentication, and establish bastion host protocols.
- Enforcing password policies, configuring PAM modules, and managing privilege escalation via sudo.
- Establishing FIPS 140-2/140-3 compliance configurations and conducting validation for federal standards.
- Applying kernel live patches and executing CVE remediation workflows.
Storage and Filesystem Management
- Utilizing LVM2 logical volume management to support dynamic capacity planning.
- Managing Btrfs snapshots, subvolumes, and auto-decompression features.
- Configuring NFS and Samba services for secure file sharing.
- Implementing Multipath I/O to ensure SAN storage redundancy and failover capabilities.
- Encrypting disks with LUKS and automating unlock procedures via initramfs.
System Monitoring and Kernel Management
- Monitoring system performance using sar, top, and perf profiling tools.
- Diagnosing issues with strace, ltrace, and GDB for detailed service analysis.
- Managing kernel updates, configuring bootloaders, and customizing GRUB2 settings.
- Managing system state and performing crash analysis for operational continuity.
Automation and Infrastructure as Code
- Designing Ansible inventories for efficient CentOS Stream host management across government environments.
- Automating patching processes and detecting compliance drift through established workflows.
- Deploying Infrastructure as Code modules to manage configuration at scale.
- Executing provisioning playbooks and orchestrating deployment strategies for standardized operations.
Requirements
- Demonstrated proficiency in Linux system administration and command-line operations
- Understanding of core networking principles and TCP/IP architecture
- Practical experience utilizing Linux package and system service management tools
Audience
- System administrators responsible for enterprise Linux infrastructure oversight
- DevOps engineers designing cloud-native deployment environments for government applications
- Technical staff transitioning from legacy Linux distributions to modern standards
21 Hours