Free production curriculum

Learn production engineering through practical courses

Structured, hands-on courses for engineers building secure cloud-native systems, analyzing malware defensively, operating distributed platforms, centralizing authentication, and building production AI and trusted analytics.

FreeAd-freeProduction-focused98 modules

Course library

Choose the system you need to understand

Every track keeps the same shape: learn the architecture, practice the failure mode, then keep the production checklist close.

Free

devops

Mastering SPIFFE & SPIRE: Zero Trust for Cloud Native Systems

Learn modern cloud-native identity security and become the engineer who secures production Kubernetes clusters - for free.

13 modules30 labsIntermediate to Advanced
SPIFFESPIREZero TrustKubernetesmTLS
Open curriculum
Free

devops

Cloud Native Security Engineering: Securing Kubernetes, Workloads, APIs & Zero Trust Systems

From passwords and perimeter trust to workload identity, Zero Trust, runtime protection, and production cloud-native security architecture

16 modules32 labsBeginner to Advanced
Cloud Native SecurityKubernetes SecurityZero TrustWorkload IdentitySPIFFE
Open curriculum
Free

ai

Production-Grade RAG Systems Engineering

Build scalable, reliable, observable, and secure Retrieval-Augmented Generation systems - not another chatbot tutorial

16 modules31 labsBeginner to Advanced
RAGLLMVector DatabaseEmbeddingsSemantic Search
Open curriculum
Free

backend

Distributed Systems Engineering: Building Scalable, Reliable & Secure Systems

A production-grade, beginner-friendly but deeply practical course on how real distributed systems actually work - from foundations through Kubernetes, observability, Zero Trust, and real-world failure recovery.

12 modules36 labsBeginner to Advanced
Distributed SystemsCloud NativeKubernetesArchitectureScalability
Open curriculum
Free

security

Centralized Authentication and Authorization with Envoy

Build a Google-style one-login platform for Kubernetes products using plain Envoy, JWT/JWKS, external authorization, SSO, service tokens, and federated credentials.

8 modules8 exercisesBeginner to Production Grade
EnvoyAuthenticationAuthorizationSSOOIDC
Open curriculum
Free

data-engineering

Production Analytics Engineering with dbt: Metrics, Semantic Layers & Lineage

From raw tables to trusted business metrics, step by step. Beginner-friendly, interactive, and built for freshers learning production data work.

16 modules16 exercisesBeginner to Intermediate
Analytics EngineeringdbtSemantic LayerMetricFlowMetrics Layer
Open curriculum
Free

Security Engineering

Malware Analysis and Defense for Developers

Analyze evidence safely, engineer useful detections, contain incidents, and build software that is harder to compromise.

17 modules17 exercisesBeginner bridge to intermediate
Malware analysisDetection engineeringYARASigmaIncident response
Open curriculum

Browse lessons by course

Mastering SPIFFE & SPIRE: Zero Trust for Cloud Native Systems 13 lessons
  1. Understanding Zero Trust Security
  2. Cryptography and PKI Foundations
  3. SPIFFE Fundamentals
  4. SPIRE Architecture and Components
  5. Running SPIRE on Kubernetes
  6. Working with SVIDs and the Workload API
  7. Authorization and Policy Enforcement
  8. SPIRE Integrations and Service Mesh
  9. Advanced SPIRE Architectures
  10. Day Two Operations and Observability
  11. The SPIFFE/SPIRE Ecosystem
  12. Building a Complete Zero Trust Platform
  13. SPIFFE for AI Infrastructure
Cloud Native Security Engineering: Securing Kubernetes, Workloads, APIs & Zero Trust Systems 16 lessons
  1. Introduction to Cloud Native Security
  2. Kubernetes Foundations for Security
  3. Containers & Workload Security
  4. Kubernetes Authentication & Authorization
  5. Zero Trust Security Fundamentals
  6. SPIFFE & SPIRE Deep Dive
  7. Service Mesh Security
  8. Policy-as-Code Security
  9. Secrets Management & Machine Identity
  10. Runtime Security & Threat Detection
  11. Cloud Native Supply Chain Security
  12. Secure CI/CD Pipelines
  13. Observability & Security Monitoring
  14. Multi-Cluster & Multi-Cloud Security
  15. AI Infrastructure Security
  16. Production Architecture & Capstone
Production-Grade RAG Systems Engineering 16 lessons
  1. Introduction to AI & RAG Systems
  2. Foundations of Search & Retrieval
  3. Embeddings Deep Dive
  4. Vector Databases Engineering
  5. Document Processing & Chunking
  6. Building Basic RAG Systems
  7. Advanced Retrieval Engineering
  8. AI Agents & Agentic RAG
  9. Production RAG Architecture
  10. RAG Evaluation & Quality Engineering
  11. AI Observability Engineering
  12. Security for RAG Systems
  13. Deploying RAG Systems
  14. Advanced RAG Architectures
  15. AI Infrastructure & Future Systems
  16. Production Capstone Project
Distributed Systems Engineering: Building Scalable, Reliable & Secure Systems 12 lessons
  1. Foundations of Distributed Systems
  2. Networking & Distributed Communication
  3. Event-Driven & Asynchronous Systems
  4. Distributed Data Management
  5. Consensus & Coordination
  6. Scalability Engineering
  7. Reliability & Failure Engineering
  8. Distributed Security & Zero Trust
  9. Observability & Debugging
  10. Kubernetes & Cloud Native Distributed Systems
  11. Real-World Failure Scenarios
  12. Production System Design & Capstone
Centralized Authentication and Authorization with Envoy 8 lessons
  1. Google-Style Login for Many Kubernetes Products
  2. Auth Vocabulary: SSO, SAML, OIDC, JWT, JWKS, and Tokens
  3. Plain Envoy as the Central Front Door
  4. JWT and JWKS Validation at Envoy
  5. SSO with OIDC or SAML Through Envoy and External Auth
  6. Access Tokens, Service Tokens, and Federated Credentials
  7. Authorization Policy, Headers, and Product Boundaries
  8. Production Design: Security, Performance, and Scale
Production Analytics Engineering with dbt: Metrics, Semantic Layers & Lineage 16 lessons
  1. What Analytics Engineering Actually Is
  2. Tables, Grain, and Why Dashboards Lie
  3. The dbt Mental Model
  4. Staging Models
  5. Intermediate Models
  6. Marts: Facts and Dimensions
  7. Testing and Data Quality
  8. Freshness, Contracts, and Documentation
  9. Incremental Models and Backfills
  10. Metrics as Product APIs
  11. Semantic Layer Fundamentals
  12. MetricFlow and the dbt Semantic Layer
  13. Lineage with dbt Artifacts
  14. Data Incidents and Debugging
  15. CI/CD for Analytics Engineering
  16. Capstone: Build a Trusted Analytics Layer
Malware Analysis and Defense for Developers 17 lessons
  1. Authorization, Ethics, and Lab Containment
  2. Malware Concepts and Multi-Axis Taxonomy
  3. Evidence Acquisition, Provenance, and Chain of Custody
  4. Static Triage Across PE, ELF, Scripts, and Packages
  5. Assembly and Compiler Literacy
  6. Ghidra and Decompiler Workflow
  7. Managed Code, Packages, Containers, and WASM
  8. Controlled Endpoint Behavioral Analysis
  9. Offline Network Evidence
  10. Sanitized Memory and Volatile Evidence
  11. MITRE ATT&CK v19.2 and D3FEND Mapping
  12. YARA Detection as Code
  13. Sigma and Telemetry Analytics
  14. Containment, Eradication, and Recovery
  15. Reporting and Safe Intelligence Sharing
  16. Building Malware-Resistant Software
  17. Capstone: The Northstar Developer Tool Incident

Learning paths

Pick a path based on the work you own

These paths link courses with the labs, cheatsheets, and guides that make the concepts stick.

01

Cloud-native security

Start broad with Kubernetes and runtime security, then go deep on workload identity.

Open security path
02

Distributed systems

Build the operational mental model behind consensus, scaling, reliability, and Zero Trust.

Open systems path
03

Production AI infrastructure

Connect RAG architecture with retrieval quality, observability, deployment, and security.

Open AI path
04

Centralized platform auth

Design one Envoy enforcement point for SSO, JWTs, service tokens, federated credentials, and product boundaries.

Open auth path
05

Analytics engineering

Turn raw warehouse tables into tested dbt models, governed metrics, and trusted dashboards.

Open data path
06

Malware analysis and defense

Study inert evidence, build tested detections, contain incidents, and harden software delivery without using live malware.

Open malware defense path

Keep practicing

Courses are only one part of the learning loop

Use labs for decisions, cheatsheets for operations, glossary terms for vocabulary, and blog guides for deeper architecture.