---
title: "Network Security & Zero Trust"
description: "Design Zero Trust network architectures on STACKIT: segmentation, secure service exposure, and continuous validation of workloads."
scfAsset:
  managed: false
  category: "guide"
  maintainers:
    - user: "can.celik1"
  external: true
  tags: ["STACKIT University", "Learning", "Zero Trust", "Network Security", "Microsegmentation"]
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/network-security-zero-trust/"
source_file: "docs/architecture/assetcontainer/stackit/network-security-zero-trust.mdx"
---

## Course Overview

Across four modules, this course builds secure networking foundations on STACKIT, moving from the cloud network threat landscape and defense-in-depth fundamentals through segmentation, Security Groups, and Unified Firewall controls, into secure service exposure with load balancers, TLS, Kubernetes NetworkPolicies, and service mesh technologies. It closes by bringing every building block together into a practical Zero Trust architecture applied to a hybrid STACKIT scenario.

The course is built around dismantling a dangerous but common assumption: "if it's inside the network, it can be trusted." Zero Trust rejects that — network location alone never grants trust, and every communication path needs an explicit, documented reason to exist. That reframing matters because it changes how you design from the start: instead of flat networks with broad access, you design for continuous verification, minimal blast radius, and explicit least-privilege connectivity between every workload.

### What You'll Learn
- Describe the cloud network threat landscape and defense-in-depth principles
- Use STACKIT Security Group and Unified Firewall to control network access
- Apply segmentation and microsegmentation to isolate workloads and limit lateral movement
- Secure service exposure with load balancers, TLS, and Kubernetes NetworkPolicies
- Design architectures that minimize unnecessary public exposure
- Apply Zero Trust principles, including continuous verification, to STACKIT workloads

### Modules
- Network Threat Landscape & Security Fundamentals
- Network Segmentation & Access Control
- Secure Connectivity & Service Exposure
- Zero Trust Architecture in Practice

<LinkCard title="View Course on STACKIT University" href="https://university.stackit.cloud/totara/catalog/index.php" />
