HYVE UNIVERSITY · ENTERPRISE TRACK
TRAIN YOUR
ADMINISTRATORS
A structured curriculum for the people who will run HYVE Ether OS — Server Edition. Six modules take an administrator or auditor from first principles to a confident, secure, certified deployment. Every lesson maps to a section of the Enterprise Manual and to the live system.
What Server Edition is, why sovereignty matters, and how the pieces fit together.
LESSON 1
The sovereignty thesis
Fully local AI, no phone-home, air-gappable — and why that changes the threat model.
LESSON 2
The request path
Reverse proxy → identity signer → organ → RBAC gate → audit. Trace one request end to end.
LESSON 3
Services & ports
The directory, issuer, database, organs, and what is (and isn't) exposed to the network.
Stand up a box and provision the operator-chosen admin identities with no baked-in accounts.
LESSON 1
The install flow
Collecting the OS admin + root policy at install; provisioning the SSO admin on first boot.
LESSON 2
OS admin vs directory admin
Two distinct identities: sudo/SSH vs. SSO login with MFA. When to use which.
LESSON 3
Adding & rotating admins
Using the provisioning script safely, from flags, answer files, or the console.
The directory, single sign-on with enforced MFA, and per-action role-based access.
LESSON 1
Directory & federation
Users and groups in LDAP, federated into the OIDC issuer with a read-only service account.
LESSON 2
Enforcing multi-factor
How TOTP is enforced for every user, including federated directory users.
LESSON 3
Roles & the permission model
owner/admin/operator/auditor/viewer, inheritance, and why owner is local-only.
Make the box provably auditable — and know what an auditor can and cannot see.
LESSON 1
Two audit trails
The append-only access-decision log and the immutable kernel auditd — and how they complement.
LESSON 2
The Admin & Audit console
Reading the decision trail, service health, and identity — with role-based redaction.
LESSON 3
Compliance posture
Honest control mappings, the security package, and preparing for procurement review.
Run it: services, data, file shares, and backups you can actually restore.
LESSON 1
Service management
Restarting organs, the issuer, and the proxy; reading logs; the operations runbook.
LESSON 2
Data & file services
PostgreSQL, VPN-scoped SMB shares, and rootless containers.
LESSON 3
Backup & recovery
Scheduled encrypted backups, restoring the directory & databases, and superuser recovery.
The firewall, keys-only access, and the discipline that keeps you from locking yourself out.
LESSON 1
Default-deny firewall
nftables posture, what's exposed, and scoping services behind WireGuard.
LESSON 2
Access preservation
The dead-man's-switch protocol for firewall/sshd/PAM changes — never skip it.
LESSON 3
Reading a review
How the platform is adversarially reviewed, and how to act on findings honestly.
CERTIFICATION
HYVE Certified Server Administrator
Complete the six modules and a hands-on assessment — install, provision an admin, configure SSO with MFA, wire an RBAC policy, produce an audit report, and pass a firewall change under the access-preservation protocol. Certification is included with an enterprise engagement, and instructor-led cohorts are available for teams.