← Every path

H2-CDSE · Specialist path

Digital Sovereignty

H2 Certified Sovereign Infrastructure Engineer

Run a stack that answers to no one else: no foreign hyperscaler, no vendor kill-switch, no dependency you cannot rebuild. Self-hosted from the metal, data resident where the law requires, keys you alone hold, supply chain you own, and an exit from every SaaS you touch.

6 courses · 22 lessons · ~39 h of guided work

Assumes Foundation + T-Shaped core; CSDE and CSPE recommended

What you leave with

A fully self-hosted, portable stack: your own compute and network, an owned supply chain, keys under your sole control, data resident by policy, and a rehearsed exit from every external dependency.

OS
Talos
Forge
Forgejo
Registry
Owned + mirrored
Keys
OpenBao + HSM
DNS
Knot
Identity
Zitadel

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    The sovereignty threat model

    Name what you depend on and who controls it. Jurisdiction, vendor lock-in, kill-switches, and the difference between owning a system and renting one.

    4 lessons · ~7 h

    Tools Dependency mapping, jurisdiction analysis

    1. 01What sovereignty meansData, operational and technical sovereignty; the questions each answers.90 min
    2. 02Jurisdiction and lawWhose law reaches your data; the extraterritorial reach that surprises people.90 min
    3. 03The dependency mapEvery provider, what they control, and the kill-switch each one holds.120 min
    4. 04Owning versus rentingThe line between a system you run and one you are permitted to use.90 min

    Course checkProduce a dependency-and-control map of a real stack, rank the sovereignty risks, and propose the removal for the top three.

    You leave withA map of every external dependency in a stack, each with who controls it and what happens if they turn it off, and a removal plan for the worst.

  2. Course 02

    The self-hosted core

    Remove the hyperscaler. Your own compute on an immutable OS, your own network and DNS, and everything reproducible from declarative config with no managed service underneath.

    4 lessons · ~8 h

    Tools Talos, Cilium, Knot DNS, Pulumi

    1. 01Compute you controlTalos on your own or rented metal; nothing managed in the critical path.120 min
    2. 02Network and DNS you runYour own routing and authoritative DNS; no third party in the resolution path.120 min
    3. 03Reproducible from configThe whole core rebuildable from git on new hardware; a rebuild you performed.120 min
    4. 04Storage you holdData on storage you control, encrypted with keys you hold.90 min

    Course checkStand up compute, network and DNS with no managed cloud service in the critical path, reproducible from config alone.

    You leave withA self-hosted core: Talos compute, your own network and Knot DNS, all reproducible from git with no managed service beneath.

  3. Course 03

    Owning the supply chain

    Remove the vendor from your build. Chainguard and Kaniko instead of the Docker daemon, every base and dependency vendored and mirrored, your own registry, so a build works with the public internet unplugged.

    4 lessons · ~7 h

    Tools Kaniko, Chainguard, Forgejo registry, cosign

    1. 01Why not Docker HubThe registry as a foreign dependency of your build; what a rate-limit or a takedown does.90 min
    2. 02Mirroring everythingBase images and packages mirrored into your own registry with SHA256 verification.120 min
    3. 03Building air-gappedKaniko from local mirrors; a build that works with public registries firewalled off.120 min
    4. 04Verifying what you ownSignatures and attestations on your mirrored artifacts; provenance you can prove.90 min

    Course checkBuild and deploy the whole stack with public registries blocked at the firewall; nothing may reach out.

    You leave withAn owned supply chain: your own registry, every base image and dependency mirrored and verified, and a build that completes with the internet unplugged.

  4. Course 04

    Keys you alone hold

    Remove the escrow. Your own key management with an HSM, no cloud KMS holding your root, ceremonies with dual control, and post-quantum signatures under your sole authority.

    4 lessons · ~7 h

    Tools OpenBao, HSM, ML-DSA, Shamir

    1. 01No cloud KMS for the rootWhy a hyperscaler KMS undermines sovereignty; what to use instead.90 min
    2. 02HSM-backed keysA hardware root of trust; the ceremony to initialize it.120 min
    3. 03Ceremonies and quorumDual control and Shamir shares; a root-key operation that needs several people.120 min
    4. 04Sovereign signaturesPost-quantum signing under your authority; a credential no provider can revoke.90 min

    Course checkProve that no external party can decrypt your data or forge your signatures, and perform a root-key ceremony under dual control.

    You leave withKey management under your sole control: an HSM-backed root, quorum ceremonies, and post-quantum signing that no provider can touch.

  5. Course 05

    Data residency and portability

    Keep data where the law requires and prove it, and make sure you can always leave. Residency as enforced policy, and an export from everything.

    3 lessons · ~5 h

    Tools Policy engine, object storage, open formats

    1. 01Residency as policyWhere data may live, enforced in code, not promised in a contract.120 min
    2. 02Proving where data isEvidence a regulator accepts that data never left its jurisdiction.90 min
    3. 03Portability by defaultOpen formats and exports so leaving is always possible.90 min

    Course checkProve a given dataset never left its required jurisdiction, and export it into a portable, provider-neutral format.

    You leave withData residency enforced by policy with proof of where data lives, and a portable export of everything you hold.

  6. Course 06

    The exit from every dependency

    Sovereignty is proven by the exit you have rehearsed. A tested migration off every SaaS and provider you touch, and the survival drill for each one going away.

    3 lessons · ~6 h

    Tools The whole sovereign stack, migration tooling

    1. 01The exit planA tested migration off each SaaS and provider; the cost and time measured.120 min
    2. 02Survival drillsEach external provider declared hostile in turn; keep running on your replacement.120 min
    3. 03Proving independenceContinuity through every provider loss, evidenced end to end.90 min

    Course checkDeclare one external provider hostile and keep the stack running by cutting over to your owned replacement, live.

    You leave withA rehearsed exit from every external dependency, and a survival runbook for each provider you rely on going away.

Certification course

H2 Certified Sovereign Infrastructure Engineer

$799 · one price · courses + 90-day labs + exam

48-hour practical: every external provider is declared hostile in turn, the hyperscaler, the registry, the CA, the SaaS, the DNS provider. Keep running through each, proving you own the replacement. Graded on continuity and provable independence.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Create an account to enrol