Get in Touch

Course Outline

Architecture Design for Sovereign Governance

  • Threat modeling: Mapping cloud dependencies and identifying data egress pathways.
  • Network topology configuration: Defining DMZ, internal zones, and management networks.
  • Hardware procurement: Selecting servers, storage, networking equipment, and uninterruptible power supplies.
  • Establishing disaster recovery sites and implementing air-gap requirements.

Identity and Access Control Framework

  • Implementing Authentik for Single Sign-On (SSO) across all operational services.
  • Designing LDAP directories and group policies.
  • Deploying Step CA for secure service-to-service mutual TLS.
  • Enrolling YubiKeys and hardware security tokens.

Communication and Collaboration Infrastructure

  • Using Synapse/Element for secure chat and federation.
  • Deploying Jitsi Meet for video conferencing capabilities.
  • Configuring Roundcube/Nextcloud Mail for email services.
  • Utilizing Nextcloud for file synchronization, calendars, and contact management.
  • Integrating OnlyOffice for collaborative document editing.

Development and Operations Environment

  • Leveraging Gitea for source code management and CI/CD pipelines.
  • Implementing Woodpecker CI for automated build processes.
  • Using Nexus or Harbor for artifact and container registry management.
  • Deploying Wazuh for security monitoring and regulatory compliance.
  • Utilizing Uptime Kuma for service health dashboards.

Artificial Intelligence and Knowledge Management

  • Deploying Ollama with local Large Language Model (LLM) serving.
  • Providing internal AI assistant access via LibreChat.
  • Establishing personal knowledge bases using Obsidian or Logseq.
  • Preserving web content using Hoarder/ArchiveBox.

Security and Perimeter Defense

  • Deploying pfSense or OPNsense firewall solutions.
  • Configuring Suricata IDS/IPS with custom security rules.
  • Implementing WireGuard/OpenVPN for secure remote access.
  • Managing DNS filtering and local resolution via Pi-hole.
  • Utilizing Vaultwarden for team password management.

Backup, Disaster Recovery, and Operations

  • Maintaining a central BorgBackup repository for all services.
  • Automating database dumps and off-site replication.
  • Documenting operational runbooks and incident response procedures.
  • Executing capacity planning and defining scaling triggers.
  • Conducting quarterly sovereignty audits and dependency reviews.

Capstone Project

  • Participants demonstrate their fully operational sovereign stack.
  • Peer review of architectural decisions and strategic tradeoffs.
  • Performance load testing and failure injection simulations.
  • Documentation handoff and operational readiness assessment.

Requirements

  • Advanced proficiency in Linux, networking, and container orchestration.
  • Completion of at least two other Data Sovereignty courses or equivalent experience.
  • Familiarity with DNS, TLS, firewall, and backup concepts.

Audience

  • Senior infrastructure architects designing sovereign organizations.
  • CTOs and CISOs planning digital independence roadmaps.
  • Government and defense digital transformation teams.
 35 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories