Infrastructure · Intermediate

Cloud and Platform Engineering Foundations

Run a small internal platform with OpenTofu: declare infrastructure as code, gate every change through Git, keep secrets out of state, and operate what you built - without a public-cloud account.

About this course

Cloud engineering is not a console. It is a way of working: you describe the state you want in code, you review the change before it happens, you keep the description and the reality in step, and you run the result for other people. This course teaches that way of working on a machine you can see all of, with no vendor subscription anywhere. Your lab machine **plat01** is your platform. Its own Docker engine is the cloud you provision: OpenTofu creates the networks, volumes and containers, and you can `docker inspect` every resource you declared. Over ten lessons you build one repository for a synthetic internal team - Team Kestrel at Fennimore Diagnostics - and it grows the way a real platform repository grows: - the vocabulary of cloud computing in vendor-neutral terms, mapped to primitives you measure on your own machine, and what a platform team actually provides; - OpenTofu from zero: HCL, providers, `init`, `plan`, `apply`, state, the lock file, `destroy`; - modules, input validation, `moved`, drift you cause on purpose and then detect and reconcile, and adopting a resource somebody made by hand with `import`; - a two-colour web service with a reverse proxy on a user-defined network, with your OpenTofu outputs feeding an Ansible inventory, continuing the work you did in ULC-106; - machine images, cloud-init user data you validate and build into a NoCloud seed, and a Proxmox VE virtual machine written and validated - never applied, because this lab has no hypervisor and the course says so; - a Git pipeline whose `pre-receive` gate really refuses a badly formatted, invalid or secret-carrying push; - secrets with age and sops, OpenTofu state encryption, and a secret scanner that finds a real leak; - health checks, a probe timer writing to journald, a backup you restore into a new container and verify, and a zero-downtime image replacement measured with a request loop. Two lessons start from a deliberately seeded fault - a credential a colleague pasted into a variables file, and a service somebody "fixed" by hand on a Friday - and you work them the way an operations team does: observe, form one hypothesis, test one thing, fix, verify, record. The final project is a second environment for the same team, delivered with a change record, a runbook, a restore drill and an architecture note. This is a learning pathway toward platform engineer and cloud administrator roles. It awards an Ultiblob Certificate of Completion; it is not a vendor certification and makes no promise about employment.

Content time
22 h
Lessons
10
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Infrastructure — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 22 h
  1. Lesson 1: Cloud without a vendorFree preview

    The vocabulary of cloud computing, mapped to resources you can measure on your own machine.

    1 h 30 min
  2. Lesson 2: What a platform team provides

    Golden paths, paved roads, cattle and pets — and the contract that makes a platform a product rather than a favour.

    1 h 40 min
  3. Lesson 3: Infrastructure as code with OpenTofu

    HCL, providers, init, plan, apply, state and destroy — against a provider mirror on a machine with no internet.

    2 h 10 min
  4. Lesson 4: Modules, variables and drift

    Refactor without destroying, validate inputs, cause drift on purpose and find it, and adopt a resource somebody made by hand.

    2 h 20 min
  5. Lesson 5: A local cloud on Docker

    Networks, volumes and containers from HCL, images pinned by digest, and an Ansible inventory generated from state.

    2 h 30 min
  6. Lesson 6: Images, cloud-init and a hypervisor target

    How an instance gets its first configuration, and what the same workflow looks like aimed at Proxmox VE — written and validated, never applied.

    2 h 10 min
  7. Lesson 7: A GitOps change flow

    Git as the source of truth, with a pre-receive gate that really refuses a change — and the reason it cannot be a post-receive hook.

    2 h
  8. Lesson 8: Secrets and state protection

    age keys, sops-encrypted files, OpenTofu state encryption, and a scanner that catches a real credential before it is committed.

    2 h 30 min
  9. Lesson 9: Operating the platform

    Health checks the engine can see, a probe that writes to journald, a backup you restore and verify, and an incident worked end to end.

    2 h 50 min
  10. Lesson 10: Change, resilience and portability

    Replace a running version with no failed requests, through a change record — and sketch the same model somewhere else, honestly.

    2 h 20 min

Where it leads

Part of these career paths