Training

Two paths, no tiers. Operator runs a CA; Architect designs the deployment. Each is one linear sequence — start at frame 1, stop when you know enough.

Operator

Run your own CA

~4½ h · 107 frames

Run goca yourself. The path opens with what makes this CA unusual — it runs its own PKI, ships notifications, does MFA without an identity provider, offers four-eyes approval and an audit log you can prove — then goes hands-on: stand up a local CA in fifteen minutes, issue your first certificate, and serve the console from your own hierarchy while goca renews the certificate by itself. From there it deepens at your pace: templates and access, protocols, key custody in real hardware, revocation and audit, day-two operations, and finally diagnosing your own environment. One linear path of 107 frames — start at 1, stop when you know enough.

Open Operator

Architect Password-protected

Design the deployment

~3½–4 h · 80 frames

Design a goca deployment you can defend: why no externally reachable component can mint a certificate alone, what co-locating roles gives up, custody strategy per CA, the database as load-bearing state, scaling and availability, multi-region — and exactly which parts are designed but not built yet. One linear path of 80 frames; go as deep as your design needs.

Open Architect

Password-protected. How access is granted.