bRRAIn Certified Installation Specialist
Take a signed bRRAIn engagement to a running, verified, recoverable instance and a clean handoff.
- Level
- Practitioner
- Learning time
- 19 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- Rebuilt around the real deployment path: the install.brrain.io installer on Linux amd64, the brrain CLI and hosted pods. The v1 container, cluster and infrastructure-as-code material described products that do not exist and has been removed.
- Hosting is taught as the four options customers actually buy (Hosted Standard, Co-located, Data-Resident, Sovereign On-Prem), with the Residency Language Prohibition.
- Architecture uses the published eight zones, Z1 Vault to Z8 Code Sandbox.
- Identity is OIDC single sign-on with Okta, Entra ID and Google, group-to-role mapping, Login with bRRAIn, Google and GitHub sign-in and personal access tokens.
- New lessons on the Handler and LLM Registry, Operator ENV encryption, MCP client setup, brrain dr snapshots and restores, and explicit upgrades with automatic rollback on hosted pods.
- Cross-organization session readiness is taught as a method built on per-project permissions, recorded dual approvals, the audit log and revocation.
- Every lab and the capstone is now an AI role-play with a customer IT lead, administrator or security reviewer, scored against a published rubric.
What you will be able to do.
- You will be able to run a pre-install readiness review and recommend a hosting option from the customer's legal constraints and operational capacity.
- You will be able to prepare and harden a Linux amd64 host and install bRRAIn with the install.brrain.io installer, securing recovery phrase custody.
- You will be able to put TLS in front of the brain, verify the installation, and operate hosted pods without losing clients or data.
- You will be able to configure the Handler as the default model, govern commercial model opt-ins, encrypt Operator ENV credentials and connect MCP clients.
- You will be able to federate identity over OIDC, map groups to roles safely, and prove per-project permissions and cross-organization readiness.
- You will be able to set up monitoring, audit evidence, encrypted snapshots and restores, and measure RPO and RTO in a drill.
- You will be able to upgrade and roll back deliberately with brrain upgrade, validate the installation end to end, and hand it off with a runbook.
Who it's for
- DevOps, platform and infrastructure engineers
- Linux system administrators and SREs taking on AI platforms
- Partner-firm deployment and cloud practice leads
- Customer IT leads who will own a Sovereign On-Prem installation
Not covered here
- Sales motion, plan selection and hosting quotes (see Sales Specialist)
- Business onboarding, adoption and ingestion planning (see Implementation Specialist)
- The customer's long-term permission design and audit review (see Access Controller and Security Controller)
- Ongoing operations governance and scheduled maintenance (see Operations Controller and Maintenance Specialist)
- SDK and application integration (see SDK Developer)
8 modules, 67 lessons.
About 19 hours of learning. Open a module to see every lesson.
-
Deployment Planning and Readiness
What an Installation Specialist delivers, the eight zones from an installer's seat, the four hosting options, and the pre-install readiness review.
- Pretest: deployment planning and readiness
- The Installation Specialist's job and the eight-zone architecture
- Hosting options: Hosted Standard, Co-located, Data-Resident, Sovereign On-Prem
- The pre-install readiness review
- Worked example: a readiness review with a customer IT lead
- Scenario: map three customer profiles to a hosting option
- Lab 1: Run a readiness review with a customer IT lead
- Retrieval: Module 1
-
Host Preparation and Hardening
For customer-run hosts: choosing and sizing the server, firewall baseline, SSH and fail2ban, OS patching without surprise upgrades, admin accounts and secret custody, and the post-hardening audit.
- Pretest: host preparation and hardening
- Choosing and sizing the host
- Firewall baseline with UFW: ingress and egress
- SSH hardening and fail2ban
- OS patching without surprise upgrades
- Admin accounts, sudo and file custody on the host
- Worked example: the post-hardening audit
- Lab 2: Defend your hardening plan to a security reviewer
- Retrieval: Module 2
-
Install and First Boot
What the install.brrain.io installer does, vault initialization and recovery phrase custody, TLS and installation verification, hosted pod lifecycle, first-boot health checks, and recovering from a failed install.
- Pretest: install and first boot
- Anatomy of the installer
- Worked example: first boot, vault initialization and the recovery phrase
- TLS in front of the brain, and verifying the installation with bRRAIn
- Hosted pods: provisioning, lifecycle and the brain URL
- Worked example: first-boot health checks and smoke tests
- Recovering from a failed install
- Lab 3: Talk a customer's Linux admin through an on-prem install
- Retrieval: Module 3
-
Models, Credentials, Clients and Vault Structure
The Handler as default and LLM Registry opt-ins, Operator ENV and its encryption key, connecting and verifying MCP clients, and the first projects in the vault.
- Pretest: models, credentials, clients and vault structure
- The Handler and the LLM Registry
- Operator ENV: third-party credentials and the key that protects them
- Worked example: connecting MCP clients
- First projects and vault structure
- Lab 4: Configure models, credentials and clients with a customer's operations manager
- Retrieval: Module 4
-
Identity, Access and Security
OIDC single sign-on and group-to-role mapping, debugging sign-in, roles and custom roles, per-project permissions, tokens and MFA, encryption and key custody, TLS, and readiness for governed cross-organization sessions.
- Pretest: identity, access and security
- OIDC single sign-on with Okta, Entra ID and Google
- Worked example: debugging SSO sign-in and role mapping
- Initial roles, custom roles, per-project permissions, tokens and MFA
- Encryption at rest and key custody
- TLS in transit: configuration, testing and renewal
- Scenario: readiness for a governed cross-organization session
- Lab 5: Design and debug SSO role mapping with a customer's identity administrator
- Retrieval: Module 5
-
Health, Monitoring and Audit
The brain's health and telemetry surfaces, routing logs, events and audit evidence to customer systems, designing an alert baseline, and demonstrating the audit trail.
- Pretest: health, monitoring and audit
- Health and telemetry surfaces
- Getting logs, events and audit evidence to the customer's systems
- Designing the alerting baseline
- Worked example: verifying the audit trail
- Lab 6: Agree monitoring and audit evidence with a customer's security operations lead
- Retrieval: Module 6
-
Backup and Disaster Recovery
What to back up and how often, encrypted snapshots with brrain dr, restores and portable exports, validating a restore, measuring RPO and RTO, and writing the DR runbook.
- Pretest: backup and disaster recovery
- What to back up, and how often
- Worked example: taking encrypted snapshots with brrain dr
- Worked example: restoring a vault
- Validating a restore
- Measuring RPO and RTO
- Writing the DR runbook
- Lab 7: Run a DR drill debrief with a customer's operations manager
- Retrieval: Module 7
-
Upgrade, Validation and Handoff
Explicit upgrades with brrain upgrade, rollback paths including automatic rollback on hosted pods, the end-to-end validation suite, common post-install issues, the operations runbook, the handoff call, and the capstone.
- Pretest: upgrade, validation and handoff
- The upgrade path: brrain upgrade
- Rollback paths and when to recreate
- Worked example: the post-install validation suite
- Common post-install issues: symptoms, diagnosis, fix
- The operations runbook
- Scenario: the handoff call
- Retrieval: Module 8
- Capstone: deliver a Sovereign On-Prem installation from readiness to handoff
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Deployment Planning and Readiness
AI role-play: readiness review with a customer's Head of IT
-
Lab 2 · Host Preparation and Hardening
AI role-play: defending a host hardening plan to a customer security engineer
-
Lab 3 · Install and First Boot
AI role-play: guiding a customer's Linux administrator through install, an unexpected problem and verification
-
Lab 4 · Models, Credentials, Clients and Vault Structure
AI role-play: configuring models, Operator ENV and clients with a customer's operations manager
-
Lab 5 · Identity, Access and Security
AI role-play: designing and debugging Entra ID role mapping with a customer's identity administrator
-
Lab 6 · Health, Monitoring and Audit
AI role-play: agreeing monitoring, alerting and audit evidence with a customer's security operations lead
-
Lab 7 · Backup and Disaster Recovery
AI role-play: DR drill debrief with a customer's operations manager
-
Lab 8 · Upgrade, Validation and Handoff
Capstone AI role-play: a Sovereign On-Prem engagement from readiness to handoff with a customer's Head of Infrastructure
Deliver a Sovereign On-Prem installation from readiness to handoff
AI role-play scored against the published rubric
Pass mark: 72%
Scored on
- Readiness and hosting decision15%
- Install and first boot20%
- Identity and access15%
- Platform configuration15%
- Monitoring, audit and recovery20%
- Validation, runbook and handoff15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: At 3 years, by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bRRAIn Certified Installation Specialist
Take a signed bRRAIn engagement to a running, verified, recoverable instance and a clean handoff.