Foundation
Foundation
Everything you need before any path, starting from nothing: three Linux courses, your first programs in Python, networks, cloud, containers, delivery pipelines, observability, data and streaming, and the security habits that run through all of it. Eleven courses, no experience needed.
11 courses · 145 lessons · ~246 h of guided work
Assumes None
What you leave with
By the end you run a hardened Linux host, read a network, write and test a small program, provision a cloud account as code, run a cluster and a pipeline that deploys to it, watch it with dashboards and alerts, move data through Postgres and Kafka, and threat-model the whole thing.
Syllabus
11 courses · every lesson graded · minutes are guided work
Course 01
Linux 1: the command line to a working, secure host
Start with nothing but a login and finish able to run a Linux server on your own: install and repair packages, manage users and permissions, keep services running, read the logs when something breaks, and lock the host down.
23 lessons · 26 labs · 58 wargame levels · ~39 h· lessons 1–2 free
Tools bash, systemd, apt and dnf, vim, ssh, nftables
- 01Where Linux comes fromUnix, GNU, the kernel, and the families of distributions: Debian and its children, Red Hat and its children, Mandrake to Mageia, SUSE, and the independents. Identify three hosts by their family.60 min
- 02Meet the shellThe family tree of shells from sh to bash, zsh, dash and ash, POSIX sh, and the first commands: PATH, man, history, environment. Levels 1 to 3.100 min
- 03Files and directoriesls, cd, cp, mv, rm, find, globbing, hidden files and the FHS. Levels 4 to 8 and the FHS scavenger hunt.105 min
- 04Reading and searching textcat, less, head, tail, grep, sort, uniq, cut, tr, strings, base64, diff. Levels 9 to 12 and a web log to parse.105 min
- 05Streams, pipes and redirectionstdin, stdout, stderr, redirection, pipes, tee, xargs and exit codes. Levels 13 to 15 and a one-line report pipeline.90 min
- 06Permissions and ownershipModes as a sentence, octal, chmod, chown, umask, setuid, setgid, sticky, links. Levels 16 to 19 and a permission mess to fix.120 min
- 07Editing with viModes, motions, search and replace, undo, visual mode, .vimrc, nano as the fallback. Levels 20 to 21 and four configs edited under a grader.75 min
- 08Processes and jobsps, top, signals, kill, nice, jobs, nohup, tmux, /proc. Levels 22 to 24 and a runaway process.100 min
- 09Packages and libraries, both familiesapt, aptitude, dpkg, pinning; dnf, yum, rpm; zypper, pacman, apk; snap, flatpak, AppImage; ldd and ldconfig. Levels 25 to 27 and the same task on Debian and Rocky.120 min
- 10Boot and system architectureBIOS and UEFI, GRUB2, kernel and initramfs, dmesg, journalctl -b, systemd targets, shutdown and reboot. Levels 27 to 28 and a boot to reconfigure.90 min
- 11Services with systemdUnits, systemctl, unit files, dependencies, journalctl -u, timers, systemd-analyze. Levels 29 to 30 and a unit plus timer for a small service.110 min
- 12Disks and filesystemslsblk, fdisk, parted, mkfs, fsck, mount, fstab by UUID, df, du, swap, LVM in one page. Levels 31 to 32 and a disk to add.120 min
- 13Your shell environment.bashrc, .profile, aliases, functions, export, PS1, history control. Level 33 and a toolbelt loaded in both shell types.75 min
- 14Shell scriptingShebang, arguments, conditionals, loops, exit codes, set -euo pipefail, quoting, trap, mktemp. Levels 34 to 37 and the backup script.120 min
- 15Regular expressions, sed and awkBasic and extended regex, grep -E, sed substitutions and ranges, awk fields and sums. Levels 38 to 40 and a config rewrite plus a disk report.90 min
- 16Users, groups and sudouseradd, usermod, passwd, shadow, chage, sudo and visudo, PAM in one page, system users. Levels 41 to 42 and an onboarding and offboarding.100 min
- 17Scheduling, time and localecron, crontab, at, systemd timers, timedatectl, chrony, locale. Levels 43 to 44 and the backup scheduled both ways.80 min
- 18Loggingjournalctl filters, rsyslog, /var/log, logrotate, logger, what a login attempt leaves behind. Levels 45 to 46 and an intrusion to find in a week of logs.100 min
- 19Networking on the hostAddresses and masks, ip, ss, hosts and resolv.conf, dig, ping, traceroute, nc, curl, ports. Levels 47 to 51 and a broken network to fix.120 min
- 20SSH, keys and encryptionKey pairs, ssh-agent, ssh config, ssh-copy-id, sshd hardening, scp and rsync, GPG, checksums. Levels 52 to 55 and SSH locked down.100 min
- 21Host security basicsfind for setuid and world-writable, open ports, first nftables rules, ulimit, unattended upgrades, the morning checklist. Levels 56 to 58 and the host hardened to zero findings.110 min
- 22The practicalThe misconfigured host: twenty findings across everything in the course, three hours, graded by a re-scan.180 min
- 23The examForty questions, 70% to pass, one free retake.60 min
Course checkTo finish, you fix a misconfigured host with twenty things wrong in three hours, and a re-scan grades you; then a forty-question exam.
You leave withBy the end you can work in the shell without looking things up, install, repair and pin packages on both Debian-family and Red Hat-family systems, manage users, groups, permissions and sudo, run services with systemd, partition and mount disks, script repetitive work in bash with sed and awk, schedule it, read and rotate logs, configure the host's network and ssh, and harden a host from a checklist.
Course 02
Linux 2: the kernel, storage, networks and the services a host runs
Go from running a host to running the machines a small company depends on: the kernel, storage, networks, and the services on top of them, DNS, web, files, mail and a VPN.
18 lessons · 17 labs · 32 wargame levels · ~37 h
Tools the kernel and sysctl, systemd, LVM, LUKS, nftables, BIND, Nginx, Samba, Postfix, WireGuard
- 01The kernelVersions, /proc, /sys, sysctl; modules by reading. Lab: three persistent sysctls proven in /proc, the running kernel read from /proc and /sys.105 min
- 02Kernel configuration and dkmsKernel options, .config, olddefconfig, initramfs, dkms; building and booting by reading. Lab: read and compare real kernel configurations.105 min
- 03Boot and systemd in depthUnits, targets, dependencies, drop-ins, timers, rescue and emergency; GRUB 2 by reading. Lab: a unit and a timer; a broken fstab repaired.135 min
- 04Capacity planningvmstat, iostat, sar, load, predicting growth. Lab: three kinds of load, name each bottleneck, size the next host.110 min
- 05Filesystems in depthext4 and XFS, tuning, repair, LUKS; Btrfs and autofs by reading. Lab: grow XFS online, repair ext4, unlock LUKS from a key file.120 min
- 06udev and device namesRules, persistent names, udevadm. Lab: a rule that names a disk by its properties, proven with udevadm.105 min
- 07Storage with LVMVolumes, resizing, metadata recovery; snapshots, RAID and iSCSI by reading. Lab: a volume group on three disks, grown, a deleted volume restored from LVM's metadata archive.125 min
- 08Routing, bridges and packet filtersRoutes, bridges, namespaces, nftables, tcpdump, nmap; bonding and VLANs by reading. Lab: two networks routed, a silent drop found.150 min
- 09Source builds, backups and noticesconfigure and make into a prefix, rsync backups, restoring a file and a tree, telling users. Lab: build, back up, restore, announce.125 min
- 10DNS serversA caching resolver, an authoritative zone, DNSSEC basics. Lab: both for lab.internal, the zone signed, answered from a client.130 min
- 11Web serversApache and Nginx, TLS from your own CA, reverse and caching proxies. Lab: a TLS site, Nginx in front of an app, cache hits proven.125 min
- 12File sharing with SambaSamba shares, users and permissions; NFS by reading. Lab: a share one group writes and others read, proven from a client.115 min
- 13DHCP, PAM, LDAP and SSSDNetwork client management. Lab: a DHCP reservation, accounts in LDAP, a peer logs in over SSH through SSSD.135 min
- 14Mail serversPostfix and Dovecot, delivery rules, the queue. Lab: a mail host, mail read over IMAP, a stuck message found.150 min
- 15The router hostnftables with NAT, WireGuard, OpenVPN. Lab: route a private network with NAT, a WireGuard tunnel to a peer.110 min
- 16Securing network servicesThe SSH server, FTP, fail2ban, audits with nmap; immutable hosts by reading. Lab: harden sshd and vsftpd, a brute force blocked.125 min
- 17The Linux 2 practicalBuild the small company network on four bare hosts: DNS, web, files, mail, VPN, graded by the grader's own clients.195 min
- 18The Linux 2 examForty questions, 70% to pass.75 min
Course checkTo finish, you build the small company network from four bare hosts in one afternoon, DNS, web, files, mail and VPN all working together, graded by the grader's own clients; then a forty-question exam.
You leave withBy the end you can read and tune a running kernel, configure one for a build, write systemd units and timers, size a host from its numbers, grow, repair and encrypt filesystems, name devices with udev, run LVM, route between networks and find a dropped packet, build from source, back up and restore, and run DNS, web, Samba, DHCP, LDAP logins, mail and a VPN you set up yourself, then lock those services down.
Course 03
Programming
Your first programs, in Python, from a blank file: what a program is, how to make the computer decide, repeat and remember, how to turn a small idea into a tool you can run from the shell, and how to keep it in Git and safe from attack.
23 lessons · 23 labs · ~33 h
Tools Python 3, bash, Git, SQLite, pytest, pip and venv
- 01What a program isHow a computer runs instructions, interpreters and compilers, a short history from machine code to C to Python in 1991, why we start with Python, and your first three lines.60 min
- 02Variables and valuesNumbers, text and true or false; naming things; asking the user for input and printing an answer. Lab: a unit converter.75 min
- 03Making decisionsif, elif and else; comparing values; and, or and not. Lab: a password checker with rules.75 min
- 04Repeating thingswhile and for loops, ranges, stopping early. Lab: a guessing game that loops until you are right.90 min
- 05FunctionsSplitting a program into named pieces that take input and return output, and why it matters. Lab: the game rebuilt out of functions.90 min
- 06Lists and dictionariesOrdered collections and lookups by name; adding, removing, sorting, iterating. Lab: a grade book.105 min
- 07Strings, text and regular expressionsSlicing, searching, splitting, joining and formatting text, and regular expressions for the patterns plain methods cannot find. Lab: a word counter and a log pattern matcher.90 min
- 08Reading and writing filesOpening files safely, lines, CSV, paths. Lab: a log summariser on the logs you met in Linux 1.90 min
- 09When things go wrongReading a traceback, try and except, finding bugs with print and the debugger. Lab: the summariser refuses bad input instead of crashing.75 min
- 10Saving your work with GitWhat version control is: commits, status, the log and diff, undoing a change with restore, revert and reset, putting work aside with stash, .gitignore, tags, branches and merges. Lab: a project history you can prove, on a real lab host.90 min
- 11Working with others in GitClone, fetch, pull and push against a shared repository; resolving a merge conflict; rebase, cherry-pick, blame and bisect to find the commit that broke something; what a pull request is. Lab: a teammate's conflicting change, merged and pushed.90 min
- 12Librariesimport, the standard library (random, datetime, json), installing packages with pip in a virtual environment. Lab: a JSON report.75 min
- 13Testing your codeWhy tests exist, assert, pytest, a test that fails for the right reason. Lab: tests for the grade book.90 min
- 14Objects, brieflyClasses, attributes and methods, and when they help. Lab: an Account class.90 min
- 15Programs you run from the shellArguments, exit codes, the shebang line, chmod +x, a script in your PATH. Lab: the summariser becomes a command.75 min
- 16Bash beyond the basicsThe shells you will meet (the Bourne shell, the C shell, the Korn shell, bash and zsh) and why we teach bash; functions, arrays, reading a file line by line, options with getopts, cleanup with trap. Lab: a log check script with options and a clean exit.90 min
- 17Python as a better shell scriptWhen a bash script should become Python: running commands with subprocess, paths with pathlib, options with argparse, exit codes that mean something. Lab: the log check rebuilt in Python.90 min
- 18Talking to a web APIHTTP requests and responses, status codes, JSON, timeouts and errors, with urllib from the standard library. Lab: a client for an inventory API that runs on the lab host.90 min
- 19Code that cannot be abusedHow attackers turn input into commands: SQL injection, command injection and path traversal, and the fixes that close them for good. Lab: the grader attacks your program until it holds.90 min
- 20Configuration and secretsSettings from the environment and files, validated at start; passwords and keys never in the file, and a scan that catches one. Lab: config that validates, secrets that hide.75 min
- 21DependenciesPinning what your program needs so it runs the same everywhere; a lockfile and a check that fails when something is unpinned. Lab: a lockfile check.60 min
- 22The practical: an expense trackerFrom a spec: a command-line expense tracker with functions, files and tests, and an import that refuses bad input; the tests grade it. Then the finished work goes into Git.175 min
- 23The Programming examForty questions, 70% to pass, one free retake.60 min
Course checkTo finish, you build a command-line expense tracker from a spec, with functions, files, tests and an import that refuses bad input, and the tests grade it; you commit it to Git; then a forty-question exam.
You leave withBy the end you can read and write Python programs that take input, make decisions, loop, use functions, work with lists, dictionaries, text and files, handle errors, use libraries, come with tests, talk to web APIs and run as commands from the shell; write solid bash scripts and know when to switch to Python; keep your work in Git; and write code an attacker cannot turn against you, with secrets kept out of the file and dependencies pinned.
Course 04
Networking and protocols
Understand what really happens when a packet leaves a machine, and prove why a connection fails: Ethernet, IPv4 and IPv6, routing, TCP, DNS, HTTP, TLS including post-quantum key exchange, proxies and tunnels, read from real captures on real networks.
20 lessons · 19 labs · ~35 h
Tools ip, tcpdump, tshark, dig, curl, OpenSSL, nftables, FRR, HAProxy, WireGuard
- 01How the internet moves dataLayers and encapsulation, and the full path of one web request: name lookup, connection, encryption, request, answer. Lab: follow one request through every layer in a capture.100 min
- 02Ethernet, MAC addresses and ARPFrames, MAC learning in switches and bridges, VLANs and 802.1Q, spanning tree, ARP and the neighbour table, and how ARP spoofing works and is defended against. Lab: find the host that answers for an address it does not own.100 min
- 03IPv4 addresses and subnetsAddresses, masks and CIDR, subnets of different sizes planned by hand, private and special ranges, the IPv4 header, and DHCP as a protocol. Lab: plan the subnets of a small company and prove every host can reach what it should.105 min
- 04IPv6Addresses and prefixes, link-local and ULA, neighbour discovery, SLAAC and DHCPv6, dual stack and happy eyeballs, and why a phone on an IPv6-only network cannot reach an IPv4-only site. Lab: a dual-stack network, a rogue router advertisement, and a service reachable only over IPv4.105 min
- 05Routing: static routes, ECMP and OSPFForwarding against routing, route tables and longest-prefix match, default routes, equal-cost multipath, asymmetric paths and rp_filter, and OSPF between real routers. Lab: three routers learn each other's networks with OSPF, and a broken path is found.105 min
- 06Routing: BGP and anycastAutonomous systems, BGP sessions and route selection, prefix filters, a hijack by a more specific prefix, and anycast. Lab: a rogue network steals traffic with a more specific route, and you stop it with prefix filters.100 min
- 07NAT and stateful firewallsSource and destination NAT, connection tracking, and stateful filtering seen from the packets. Lab: find why a reply never comes back, from the conntrack table and a capture.100 min
- 08TCP: connectionsPorts and sockets, the handshake, sequence and acknowledgement numbers, the close, RST against FIN, TIME_WAIT and the MSS, with a small Python client watched on the wire. Lab: answer what happened in five TCP conversations from their captures.105 min
- 09TCP: performance and congestionWindows and window scaling, retransmission, duplicate ACKs and SACK, zero window, and congestion control from slow start to CUBIC and BBR. Lab: three slow transfers, each diagnosed from the capture alone.105 min
- 10UDP and ICMPDatagrams, how ping and traceroute really work, what unreachable means, MTU and path MTU discovery, and NTP. Lab: build your own traceroute with scapy, and find an MTU black hole.100 min
- 11Capturing and reading packetstcpdump capture filters, tshark display filters and fields, following a stream, and capturing without drowning. Lab: find the scanner and what it found in a busy capture.105 min
- 12DNS as a protocolThe resolution path, record types, TTLs and caching, dig +trace, and the DNSSEC chain of trust. Lab: three names that do not resolve, each for a different reason.105 min
- 13HTTP: 1.1, 2 and 3Requests, headers, status codes, cookies and caching, connection reuse, HTTP/2 streams and HTTP/3 over QUIC. Lab: explain a slow page and a cache that never hits, from headers and captures.100 min
- 14TLS as a protocolThe TLS 1.3 handshake, certificates and chains, SNI, ALPN, and mutual TLS. Lab: a broken certificate chain fixed and a service that demands a client certificate.110 min
- 15Post-quantum TLSHarvest now, decrypt later; ML-KEM and hybrid key exchange; checking which group a connection really used. Lab: hybrid ML-KEM turned on for a server and proven from the client and the capture.95 min
- 16Load balancers and proxiesLayer 4 against layer 7, health checks, timeouts, the PROXY protocol and X-Forwarded-For, sticky sessions. Lab: HAProxy in front of two web servers, a failing server taken out by its health check.100 min
- 17Tunnels and VPNsEncapsulation and what it costs the MTU, VXLAN, WireGuard as a protocol, IPsec by reading. Lab: two sites joined by a tunnel, and the MTU problem it brings fixed.100 min
- 18Troubleshooting methodIs it the name, the network, the transport or the application? A step by step method, baselines and counters, and packet loss reproduced on purpose. Lab: three broken services, the cause of each named and proven.100 min
- 19The Networking practicalA small company network that is broken in several places: find each fault from captures and the hosts, fix it, and prove it works. The grader tests it from its own clients.180 min
- 20The Networking examForty questions, 70% to pass, one free retake.75 min
Course checkTo finish, you repair a broken small company network from captures and the hosts, and the grader tests it from its own clients; then a forty-question exam.
You leave withBy the end you can read a packet capture and say what happened, plan IPv4 and IPv6 networks, follow a route, a NAT and a firewall, explain a TCP, DNS, HTTP or TLS failure from what is on the wire, turn on post-quantum TLS and prove it, and find the cause of a network problem with a method instead of guesses.
Course 05
Linux 3: securing Linux
Turn a working host into one that holds up: certificates and your own CA, encrypted storage, kernel and host hardening, file integrity, mandatory access control, Kerberos, firewalls and VPNs, network intrusion detection, patching, and what to do when a host is compromised.
19 lessons · 18 labs · ~33 h
Tools openssl, cryptsetup, unbound, AIDE, nftables, WireGuard and OpenVPN, Kerberos, Suricata, AppArmor and SELinux tools
- 01The threat model of a hostWho attacks a host, what they look for first, and what a hardened host denies them. Lab: an exposed host audited, every foothold listed and closed.80 min
- 02PKI and X.509Your own two-tier CA, server and client certificates, TLS, the certificate lifecycle and revocation. Lab: a two-tier CA, server and client certificates, revocation enforced.120 min
- 03Encrypted storageLUKS and dm-crypt, key slots, key files and header backups, what encryption at rest does not protect. Lab: a data volume encrypted, unlocked with a key file, its header backed up.100 min
- 04DNS securityDNSSEC in practice, DANE and TLSA records, DNS over TLS from the host. Lab: the host resolves only over TLS and a service's TLSA record matches its certificate.80 min
- 05Kernel and host hardeningsysctl baselines, boot parameters, Secure Boot and kernel lockdown, core dumps and kernel pointers. Lab: the baseline applied, each control proven by a test.100 min
- 06Host intrusion detectionFile integrity with AIDE, the audit system, log integrity. Lab: a baseline built, a changed file named from your report.100 min
- 07Isolation and resource controlResource limits, namespaces, seccomp and cgroups. Lab: a service user limited so a runaway program cannot take the host down.100 min
- 08Access control beyond modesACLs, extended attributes, file capabilities. Lab: one capability instead of setuid, a shared folder fixed with ACLs.90 min
- 09AppArmorProfiles, modes, rules from real behaviour, the tools that write them. Lab: a profile that allows exactly what a service needs, compiled and checked.100 min
- 10SELinuxContexts, types, booleans and policy modules. Lab: a policy module written from denial records, compiled, and granting nothing extra.120 min
- 11Kerberos and network authenticationTickets, the KDC, principals and keytabs, single sign-on for SSH, Kerberos for file sharing. Lab: a KDC, a Kerberos login over SSH, password logins refused.110 min
- 12Network hardeningNetwork sysctls, redirects and source routes, ARP settings, reverse path filtering, 802.1X. Lab: a host that trusts what it should not on the network, fixed.90 min
- 13Packet filtering in depthnftables, connection tracking, sets and maps, NAT, logging. Lab: a stateful ruleset for a host with three roles, every flow proven.120 min
- 14VPNsWireGuard, OpenVPN and IPsec. Lab: a site-to-site WireGuard tunnel and an OpenVPN road warrior, encryption proven with a capture.110 min
- 15Network intrusion detectionSuricata, rules, alerts and tuning. Lab: a custom rule fires on the marked traffic and stays quiet on the rest.100 min
- 16Vulnerability managementCVEs, advisories, inventories and patch management. Lab: installed packages matched to an advisory feed, patched from a local mirror, verified.100 min
- 17Incident basics on a hostContainment, evidence and first forensic steps. Lab: a host running an unknown service contained without destroying evidence; the timeline written.110 min
- 18The Linux 3 practicalBring a small company's hosts up to a security baseline in three hours; the grader proves every control with its own tests.180 min
- 19The Linux 3 examForty questions, 70% to pass, one free retake.60 min
Course checkTo finish, you bring a small company's hosts up to a security baseline in three hours, and the grader proves every control with its own tests; then a forty-question exam.
You leave withBy the end you can run a two-tier certificate authority, encrypt a data volume, harden a kernel and a host from a baseline and prove each control, detect a changed file, confine services with capabilities and ACLs, write AppArmor profiles and SELinux modules that confine a service and check them by compiling them, sign users in with Kerberos, write a stateful firewall for a host with three roles, build WireGuard and OpenVPN tunnels, write and tune intrusion detection rules, match installed packages to advisories and patch them, and contain a compromised host without destroying the evidence.
Course 06
Cloud foundations
Get an account on a real cloud provider and build the basics the right way from day one: identity, networks, storage and machines, all as code so nothing exists that is not in a file.
6 lessons · ~10 h
Tools DigitalOcean (or AWS), Pulumi, cloud CLI, object storage
- 01Accounts and identitySeparate accounts or projects, a break-glass admin, scoped API tokens, and MFA on everything that can have it.90 min
- 02Infrastructure as codeA Pulumi program that creates a VPC, a firewall and a VM; preview before apply, every time.150 min
- 03Networks in the cloudPrivate subnets, a bastion or tailnet, and firewall rules that name their purpose.90 min
- 04Storage and encryptionObject storage with encryption at rest, versioning, lifecycle rules and a signed URL that expires.90 min
- 05Compute and imagesA VM from an image you built, with cloud-init that does the least possible.90 min
- 06Cost and blast radiusBudgets, alerts, tags, and a teardown that leaves nothing behind.60 min
Course checkTo finish, you provision a described environment as code with no clicking in the console, and the grader reads the account.
You leave withBy the end you can set up least-privilege access, a private network, encrypted storage and a machine you can rebuild from an image, all from code you can run again.
Course 07
Containers and Kubernetes
Package your service as an image without a Docker daemon, run it on a Kubernetes cluster you can explain, and give it no more than it needs.
7 lessons · ~12 h
Tools Kaniko, Chainguard images, Talos or kind, kubectl, Cilium
- 01What a container isNamespaces and cgroups by hand: run a process in isolation without any container tooling.90 min
- 02Images without DockerBuild the service image with Kaniko from a Chainguard base; no daemon, no root, no shell in the result.120 min
- 03Your first clusterA Kubernetes cluster you can explain node by node; the control plane components and what each one owns.120 min
- 04WorkloadsDeployment, Service, ConfigMap and Secret for your service; rolling updates you have watched happen.120 min
- 05Ingress and DNSTraffic from the internet to the pod, with TLS, through an ingress you configured.90 min
- 06Pod securityNon-root, read-only filesystem, dropped capabilities, resource limits, and an admission check that enforces it.90 min
- 07Networking inside the clusterCilium installed; a network policy that allows exactly what the service needs and nothing else.90 min
Course checkTo finish, you containerise and deploy a given service, and the grader checks the image, the manifests and what the pod can and cannot do.
You leave withBy the end you can build an image on a minimal base, understand what a cluster does with it, deploy a workload that runs as nothing more than it needs, and debug it when it does not start.
Course 08
CI/CD and GitOps
Build a pipeline that tests, builds, signs and deploys your service from a git repository, with the runner treated as the untrusted thing it is.
7 lessons · ~11 h
Tools Forgejo, Forgejo runners, Kaniko, Argo CD, cosign
- 01Git as the source of truthA repository with branch protection, required review, and a history you can read.60 min
- 02Your first pipelineA Forgejo Actions workflow that builds and tests on every push and blocks the merge on failure.120 min
- 03Building images in CIKaniko in the pipeline with a digest-pinned base and a cache; no daemon anywhere.90 min
- 04Secrets in CIShort-lived tokens from a vault, masked outputs, and a test that proves nothing lands in the log.90 min
- 05GitOps with Argo CDA cluster that pulls its state from git; a change deployed by a merge, and a drift you detected.120 min
- 06Runner isolationEphemeral runners in their own network with no route to production; what a compromised job can and cannot reach.90 min
- 07RollbackA bad release rolled back by git revert, and the time it took, measured.60 min
Course checkTo finish, you take an empty repository to a deployed change through the pipeline you built, and the grader follows the commit.
You leave withBy the end you can set up a repository whose every push is built, tested, signed and deployed through GitOps, and explain what each step protects against.
Course 09
Observability
See what your service is doing from the outside: metrics, logs and traces you set up yourself, and one alert that fires for a real reason and reaches a human.
7 lessons · ~10 h
Tools VictoriaMetrics, Loki, Tempo, Grafana, Alloy, OpenTelemetry
- 01What to measureThe four golden signals for your service, emitted as metrics with labels you will not regret.90 min
- 02Metrics pipelineVictoriaMetrics scraping your service; a query that answers a real question; retention set on purpose.90 min
- 03Logs pipelineStructured logs shipped by Alloy into Loki; a query with the JSON parser; a rule that redacts a secret.90 min
- 04TracesOpenTelemetry in the service and the client; one request followed across both in Tempo.90 min
- 05Dashboards that get readOne Grafana dashboard with the signals in order of importance and nothing decorative.60 min
- 06Alerting to a humanAn alert rule with a threshold you justified, routed to chat, with a runbook link that resolves.90 min
- 07CorrelationFrom an alert to the logs to the trace of the failing request, in under five minutes.60 min
Course checkTo finish, you are given an unfamiliar service and a reported symptom and find the cause from its signals alone.
You leave withBy the end you can instrument a service, run the metrics, logs and traces stack, build a dashboard that answers a question, and write an alert you would want to be woken by.
Course 10
Data and streaming
Keep the data that matters safe in PostgreSQL and move events between services with Kafka, without losing or duplicating anything.
8 lessons · ~15 h
Tools PostgreSQL, CloudNativePG, Kafka, Debezium, Schema Registry
- 01Relational fundamentalsA schema for your service with constraints that make bad data impossible; migrations under version control.120 min
- 02Transactions and isolationA race condition reproduced, then fixed with the right isolation level and a test that proves it.90 min
- 03Postgres in productionCloudNativePG with replicas, object-store backups, and a restore you timed.120 min
- 04Kafka fundamentalsA three-broker cluster; topics, partitions, consumer groups; a producer and consumer you wrote.150 min
- 05Change data captureDebezium streaming Postgres changes into a topic; the outbox pattern for events you need to guarantee.120 min
- 06Schemas and evolutionA schema registry, a compatible change, an incompatible one rejected, and a consumer that keeps working.90 min
- 07Exactly-once and idempotenceIdempotent producers, transactional writes, and an idempotent consumer that survives a replay.120 min
- 08Securing the backboneTLS between brokers and clients, SASL authentication, ACLs per topic, and PII kept out of the stream.90 min
Course checkTo finish, your service that writes to Postgres and emits events must survive the grader killing things mid-flight without losing or duplicating a record.
You leave withBy the end you can run Postgres with backups you have restored, design a schema, use transactions, run a Kafka cluster with producers and consumers, and reason about ordering and duplicates.
Course 11
Security fundamentals
Look at everything you built in the courses before this one the way an attacker would, and learn the habits that keep it standing: threat modelling, cryptography in practice, identity basics.
7 lessons · ~13 h
Tools Threat modelling templates, OpenSSL, age, OWASP tooling, your own stack
- 01Threat modellingA data-flow diagram of your service and a STRIDE pass over every trust boundary, with risks ranked.120 min
- 02Cryptography you will actually useHashing, symmetric and asymmetric encryption, signatures, and the mistakes that break each; done with real keys.120 min
- 03Identity and sessionsOIDC login on your service via Zitadel; sessions, tokens, and what a stolen token can do.120 min
- 04The attacker's viewRecon and a first exploit against your own service; the fix, and a test that stops the regression.120 min
- 05Secrets and keysA vault for the service, rotation done once, and a scan for anything that escaped.90 min
- 06Least privilege everywhereEvery identity in your build, human and workload, listed with what it can do and why; trimmed.90 min
- 07Incident basicsA simulated compromise: what you look at first, what you preserve, who you tell.90 min
Course checkTo finish, you threat-model an unfamiliar system from its architecture and name the top risks and their mitigations.
You leave withBy the end you can threat-model a system from its architecture, name and rank its top risks, use cryptography without misusing it, and explain how identity and access work end to end.