STACKIT Introduction
STACKIT
No login. Sent to the Framework Core Team. The page link is included automatically.
Send your feedback via email now.
Open your email client and create a new email.
Copy the email address and paste it into the To: field:
Copy your feedback text and paste it into the email body (Ctrl+V / Cmd+V):
Last updated on
A learning path for security engineers: cloud security fundamentals, IAM, Zero Trust networking, secrets management, security operations, and secure software delivery on STACKIT.
STACKIT
An introduction to STACKIT's sovereign cloud vision, its position within the Schwarz Group, and the key customer benefits and services.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
An entry-level course that sets up everything else in STACKIT University. It explains STACKIT’s place inside the Schwarz Group and Schwarz Digits, walks through the three pillars behind the sovereign cloud promise — Scalable, Secure, Sovereign — and unpacks what each one actually guarantees in practice, from EU-only data centers to independence from foreign investors. From there it moves into the architecture itself: the IaaS and PaaS layers, how resources are managed through the Portal, API, CLI, and Terraform, and how the 6R framework (rehost, replatform, refactor, repurchase, retain, retire) maps existing workloads onto STACKIT services.
It’s built for anyone who needs a working mental model of STACKIT before going deeper — new customers, new partners, or new hires — so that later courses on the portfolio, portal, or sales don’t have to re-explain the basics. By the end, you’ll be able to place STACKIT correctly against hyperscalers and on-premise alternatives, and know which migration strategy fits a given workload.
STACKIT
A fast, video-centric tour of the STACKIT Portal: IAM and resource concepts, project setup, the cost calculator, and how to launch IaaS and PaaS services.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
A short, video-centric course that gets you comfortable in the STACKIT Portal: how projects, resources, and IAM tie together, how the interface is laid out, and how to assign users to a project. From there it moves into using the Portal day to day — reading full cost transparency into a project, choosing infrastructure services, and setting up platform services and runtimes — so you leave able to actually operate in the Portal, not just recognize it.
It’s designed as a quick second step right after the STACKIT Introduction course, before diving into the full service portfolio or a specific role path.
STACKIT
An overview of STACKIT's full service portfolio, from availability zones and IaaS/PaaS/SaaS to data, AI, security, and supporting services.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
A guided tour of STACKIT’s portfolio at a glance: what Availability Zones are and how they underpin reliability, how to tell IaaS, PaaS, and SaaS apart and pick the right one, and how cloud-native applications actually run on STACKIT’s runtime offerings. From there it covers modern data and AI services, security and compliance, and the supporting services and interfaces (Portal and APIs) that tie the whole portfolio together.
It’s the third step of the STACKIT Fundamentals path — after the Introduction and the Portal — and gives every other STACKIT University path a shared map of “what exists” before going deep on any one part of it.
STACKIT
Cloud security foundations for STACKIT: the shared responsibility model, security architecture, governance and compliance, and data sovereignty.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
The entry point into the Security Engineer path: core cloud security concepts and common cloud threats, the Shared Responsibility Model and how security duties split between STACKIT and its customers, and the key design principles behind secure cloud environments. From there it surveys STACKIT’s security services and domains, governance, risk management, and compliance frameworks such as GDPR, and closes with data sovereignty, data classification, and foundational data protection mechanisms.
STACKIT
Deepen your STACKIT IAM expertise: identity lifecycle management, authentication mechanisms, role-based access control, and least-privilege design.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
Across four modules, this course examines how identity, authentication, authorization, and access governance work together to secure STACKIT environments. You start with the foundational IAM concepts and how they map onto the platform, then move into the lifecycle of human and machine identities and the authentication mechanisms that verify them, into how access decisions get implemented through roles, permissions, and scope-based authorization, and close with a survey of real IAM attack scenarios, misconfigurations, and the best practices that prevent them.
Most cloud security incidents don’t come from someone breaking through infrastructure defenses — they come from a compromised account, an overprivileged role, or a leaked credential. That makes IAM the security control with the highest leverage in any cloud environment, and the one worth understanding deeply rather than configuring by default. This course is built for security engineers who need to reason about identity risk directly: designing least-privilege access, securing service accounts and programmatic credentials, and knowing what an insecure IAM configuration actually looks like before an attacker finds it.
STACKIT
Design Zero Trust network architectures on STACKIT: segmentation, secure service exposure, and continuous validation of workloads.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
Across four modules, this course builds secure networking foundations on STACKIT, moving from the cloud network threat landscape and defense-in-depth fundamentals through segmentation, Security Groups, and Unified Firewall controls, into secure service exposure with load balancers, TLS, Kubernetes NetworkPolicies, and service mesh technologies. It closes by bringing every building block together into a practical Zero Trust architecture applied to a hybrid STACKIT scenario.
The course is built around dismantling a dangerous but common assumption: “if it’s inside the network, it can be trusted.” Zero Trust rejects that — network location alone never grants trust, and every communication path needs an explicit, documented reason to exist. That reframing matters because it changes how you design from the start: instead of flat networks with broad access, you design for continuous verification, minimal blast radius, and explicit least-privilege connectivity between every workload.
STACKIT
Protect sensitive data on STACKIT: secrets management, encryption and key management, and Confidential Computing for data-in-use protection.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
Over four modules, this course covers the foundational practices for protecting sensitive data in the cloud: sensitive-data fundamentals and the risks of poor credential handling, secure secret storage using STACKIT Secrets Manager, encryption and key lifecycle management through the Key Management Service (KMS), and Confidential Computing for protecting data while it’s actively being processed.
Encryption at rest and in transit is standard practice, but it leaves a gap most teams don’t think about: data being processed in memory is typically plaintext, readable by anyone with sufficient host, hypervisor, or physical access — including privileged insiders and certain side-channel attacks. This course walks through all three states of data (at rest, in transit, and in use) and shows where Confidential Computing closes that last gap, alongside the everyday discipline of not leaking credentials into application code, logs, or CI/CD pipelines.
STACKIT
Secure containerized workloads on STACKIT Kubernetes Engine: cluster hardening, workload identity, network controls, and runtime operations.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
This five-module course covers the security considerations unique to containerized and Kubernetes workloads on the STACKIT Kubernetes Engine (SKE): container security fundamentals, the Kubernetes security model and what it protects, identity and access control for workloads and secrets, network security and cluster hardening, and secure day-to-day operations through audit logging and runtime monitoring.
A recurring theme runs through the course: Kubernetes access control has to be reasoned about at two distinct levels — who can create or modify cloud resources like clusters and Security Groups at the STACKIT platform level, and who can create, read, or modify Pods, Secrets, and RBAC rules inside the cluster itself. These layers are related but not identical, and conflating them is exactly where excessive-permission incidents come from. Sovereignty at the platform layer only holds if it’s matched by equally disciplined access control inside the cluster — this course builds both.
STACKIT
Cloud security operations on STACKIT: logging, monitoring, and observability for security, common indicators of compromise, and incident response.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
Maintaining a secure cloud environment requires continuous awareness of what’s happening across workloads, services, and user activity. This course introduces the principles and practices of cloud security operations on STACKIT: how security events are identified, analyzed, and addressed to keep cloud resources protected over time.
Across three modules it covers how logging and monitoring establish security visibility on STACKIT, how threat detection and alerting surface potential incidents, and the incident response lifecycle — containment, investigation, and recovery.
STACKIT
Integrate security across the software development lifecycle on STACKIT: SSDLC, application security, secure delivery, and supply chain security.
The sovereign European cloud provider behind the framework, delivering IaaS and PaaS from German and Austrian data centers with full digital independence.
Security works best when it’s built into the development lifecycle, not bolted on before deployment. This course introduces the principles, practices, and controls that help teams build, deploy, and maintain secure applications on STACKIT — from development workflow through deployment pipeline to production operations.
Across four modules it covers the Secure Software Development Lifecycle (SSDLC) and DevSecOps practices, common application security risks and how to reduce them, how security controls integrate into build and deployment pipelines, and the risks tied to third-party dependencies, container images, and build systems.
Tobias M.Tobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172
· Aug 26, 2026
Tobias M.Tobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172
· Aug 19, 2026
C.C1C.C1SCF Core · STACKITOwnerActive 5 of the last 12 weeks · 23 updatesSTACKITwww.linkedin.com/in/can-celik-645932315can.celik1@digits.schwarz
· Aug 10, 2026
C.C1C.C1SCF Core · STACKITOwnerActive 5 of the last 12 weeks · 23 updatesSTACKITwww.linkedin.com/in/can-celik-645932315can.celik1@digits.schwarz
· Aug 10, 2026
C.C1C.C1SCF Core · STACKITOwnerActive 5 of the last 12 weeks · 23 updatesSTACKITwww.linkedin.com/in/can-celik-645932315can.celik1@digits.schwarz
· Aug 4, 2026
External link
This link goes to an external site outside STACKIT. We do not vet third-party content or downloads, so follow it only if you trust the source.