Infrastructure · Intermediate
Cloud and Platform Engineering Foundations
Run a small internal platform with OpenTofu: declare infrastructure as code, gate every change through Git, keep secrets out of state, and operate what you built - without a public-cloud account.
About this course
Cloud engineering is not a console. It is a way of working: you describe the state you want in code, you review the change before it happens, you keep the description and the reality in step, and you run the result for other people. This course teaches that way of working on a machine you can see all of, with no vendor subscription anywhere. Your lab machine **plat01** is your platform. Its own Docker engine is the cloud you provision: OpenTofu creates the networks, volumes and containers, and you can `docker inspect` every resource you declared. Over ten lessons you build one repository for a synthetic internal team - Team Kestrel at Fennimore Diagnostics - and it grows the way a real platform repository grows: - the vocabulary of cloud computing in vendor-neutral terms, mapped to primitives you measure on your own machine, and what a platform team actually provides; - OpenTofu from zero: HCL, providers, `init`, `plan`, `apply`, state, the lock file, `destroy`; - modules, input validation, `moved`, drift you cause on purpose and then detect and reconcile, and adopting a resource somebody made by hand with `import`; - a two-colour web service with a reverse proxy on a user-defined network, with your OpenTofu outputs feeding an Ansible inventory, continuing the work you did in ULC-106; - machine images, cloud-init user data you validate and build into a NoCloud seed, and a Proxmox VE virtual machine written and validated - never applied, because this lab has no hypervisor and the course says so; - a Git pipeline whose `pre-receive` gate really refuses a badly formatted, invalid or secret-carrying push; - secrets with age and sops, OpenTofu state encryption, and a secret scanner that finds a real leak; - health checks, a probe timer writing to journald, a backup you restore into a new container and verify, and a zero-downtime image replacement measured with a request loop. Two lessons start from a deliberately seeded fault - a credential a colleague pasted into a variables file, and a service somebody "fixed" by hand on a Friday - and you work them the way an operations team does: observe, form one hypothesis, test one thing, fix, verify, record. The final project is a second environment for the same team, delivered with a change record, a runbook, a restore drill and an architecture note. This is a learning pathway toward platform engineer and cloud administrator roles. It awards an Ultiblob Certificate of Completion; it is not a vendor certification and makes no promise about employment.
- Content time
- 22 h
- Lessons
- 10
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: Cloud without a vendorFree preview
The vocabulary of cloud computing, mapped to resources you can measure on your own machine.
1 h 30 minLesson 2: What a platform team provides
Golden paths, paved roads, cattle and pets — and the contract that makes a platform a product rather than a favour.
1 h 40 minLesson 3: Infrastructure as code with OpenTofu
HCL, providers, init, plan, apply, state and destroy — against a provider mirror on a machine with no internet.
2 h 10 minLesson 4: Modules, variables and drift
Refactor without destroying, validate inputs, cause drift on purpose and find it, and adopt a resource somebody made by hand.
2 h 20 minLesson 5: A local cloud on Docker
Networks, volumes and containers from HCL, images pinned by digest, and an Ansible inventory generated from state.
2 h 30 minLesson 6: Images, cloud-init and a hypervisor target
How an instance gets its first configuration, and what the same workflow looks like aimed at Proxmox VE — written and validated, never applied.
2 h 10 minLesson 7: A GitOps change flow
Git as the source of truth, with a pre-receive gate that really refuses a change — and the reason it cannot be a post-receive hook.
2 hLesson 8: Secrets and state protection
age keys, sops-encrypted files, OpenTofu state encryption, and a scanner that catches a real credential before it is committed.
2 h 30 minLesson 9: Operating the platform
Health checks the engine can see, a probe that writes to journald, a backup you restore and verify, and an incident worked end to end.
2 h 50 minLesson 10: Change, resilience and portability
Replace a running version with no failed requests, through a change record — and sketch the same model somewhere else, honestly.
2 h 20 min
Where it leads