Training
Two paths, no tiers. Operator runs a CA; Architect designs the deployment. Each is one linear sequence — start at frame 1, stop when you know enough.
Operator
Run your own CA
Run goca yourself. The path opens with what makes this CA unusual — it runs its own PKI, ships notifications, does MFA without an identity provider, offers four-eyes approval and an audit log you can prove — then goes hands-on: stand up a local CA in fifteen minutes, issue your first certificate, and serve the console from your own hierarchy while goca renews the certificate by itself. From there it deepens at your pace: templates and access, protocols, key custody in real hardware, revocation and audit, day-two operations, and finally diagnosing your own environment. One linear path of 107 frames — start at 1, stop when you know enough.
Open OperatorArchitect Password-protected
Design the deployment
Design a goca deployment you can defend: why no externally reachable component can mint a certificate alone, what co-locating roles gives up, custody strategy per CA, the database as load-bearing state, scaling and availability, multi-region — and exactly which parts are designed but not built yet. One linear path of 80 frames; go as deep as your design needs.
Open ArchitectPassword-protected. How access is granted.