HashiStack Bootcamp
Work through the HashiCorp stack in integration order: Terraform to provision, Packer to bake golden images, Sentinel to govern, Vault to secure, Consul to connect, Nomad to run, then Boundary for identity-aware access. This is a catalog path over existing HashiCorp courses β each course keeps its own lessons and labs. There is no extra combined HashiStack capstone. Slots are modules, not calendar weeks. The required path is six courses (~115 hours): Terraform Associate 004 on AWS, Packer 101, Sentinel 101, Vault Associate 003, Consul 101, and Nomad 101. Plan 10β14 calendar weeks at 8β12 hours per week. Optional Vault 201/202 and Boundary 101 sit on the path but are not required. Labs stay inside each course. For Vault-only depth, take the HashiCorp Vault Security Bootcamp instead.
What You'll Master
Provision infrastructure as code with Terraform Associate 004 (AWS track)
Bake golden machine images with Packer for AWS, Azure, and GCP
Write Sentinel policies that govern Terraform changes
Manage secrets, encryption, and identity with Vault Associate 003
Run Consul for service discovery, service mesh, and datacenter operations
Schedule mixed workloads with Nomad and connect it to Consul and Vault
Optionally add Vault Kubernetes injection, Vault operator topics, and Boundary identity-aware access
Who Is This Bootcamp For?
Platform and DevOps engineers who want the HashiCorp product stack in one path
SREs operating Terraform, Packer, Vault, Consul, or Nomad in production
Security engineers adding secrets and identity-aware access to infrastructure workflows
Engineers preparing for Terraform Associate 004 and Vault Associate 003 while also learning Packer, Consul, and Nomad
What You'll Build
Real portfolio artifacts you can put on your GitHub and show hiring managers.
Terraform Associate-level AWS infrastructure
Complete the hosted Terraform Associate 004 AWS course: workflow, state, modules, and HCP Terraform against real AWS labs.
Packer golden images
Bake multi-cloud golden images with Packer 101, provision with shell and Ansible, and launch a baked AMI with Terraform.
Vault Associate 003
Finish the current Vault certification course. Optionally continue into Kubernetes injection (201) and operator topics (202).
Consul and Nomad Community Edition operations
Build a Consul datacenter and mesh, then run Nomad jobs that use Consul and Vault β all inside the existing 101 courses.
Boundary identity-aware access
Optionally add just-in-time access to hosts and services, including Vault credential brokering, via Boundary 101.
Bootcamp Curriculum
Week 1: Terraform β IaC on AWS (~30 hours; plan 3 calendar weeks)
Start with Infrastructure as Code. Optional one-hour beginners course, then the current Terraform Associate 004 AWS track. Azure and GCP Associate 004 courses are the same exam on another cloud β take those from the catalog if that is your job, not as extra required modules here.
Goals:
- β’Learn Terraform workflow, state, modules, and HCP Terraform on AWS
- β’Prepare for Terraform Associate exam 004
- β’Optionally warm up with the free one-hour beginners course
Week 2: Packer 101 β Golden Images (~18 hours; plan 2 calendar weeks)
Bake golden machine images as code after you can provision with Terraform. Packer builds Ubuntu images for AWS (primary), Azure, and GCP, provisions with shell and Ansible, emits provenance, and shows how Terraform consumes the resulting AMI. HCP Packer is covered conceptually.
Goals:
- β’Write HCL2 Packer templates with required_plugins, sources, and builds
- β’Bake Docker images and Amazon EBS AMIs; adapt the same shape to Azure and GCP
- β’Consume a baked AMI from Terraform and clean up image artifacts
Week 3: Sentinel β Policy as Code (~5 hours; plan 1 calendar week)
Govern Terraform with HashiCorp Sentinel after you can write and plan infrastructure as code.
Goals:
- β’Write and test Sentinel policies
- β’Integrate policy as code with Terraform Cloud / HCP Terraform
Week 4: Vault Associate 003 (~20 hours; plan 2 calendar weeks)
Current Vault Associate certification course (exam 003). Optional Vault 201 (Kubernetes apps) and Vault 202 (operators) are depth courses, also in the Vault bootcamp. Skip them to reach Consul and Nomad sooner. Vault 201 assumes Kubernetes and Helm.
Goals:
- β’Deploy Vault and use auth methods, policies, and secrets engines
- β’Cover Vault Associate 003 objectives
- β’Optionally continue into Kubernetes injection and operator topics
Week 5: Consul 101 (~16 hours; plan 2 calendar weeks)
Service discovery, service mesh, ACLs, peering, Kubernetes, and day-2 operations on Consul Community Edition. Take this before Nomad so Connect and auto-join are not new ideas.
Goals:
- β’Bootstrap a secured Consul datacenter
- β’Use service discovery, mesh, and Consul on Kubernetes
Week 6: Nomad 101 (~26 hours; plan 3 calendar weeks)
Workload orchestration on Nomad Community Edition, including Consul and Vault integrations, federation, ACLs, and job strategies.
Goals:
- β’Cluster Nomad servers and clients
- β’Run jobs and integrate Consul service mesh and Vault secrets
Week 7: Boundary 101 β Identity-Aware Access (~20 hours; plan 2 calendar weeks)
Identity-aware access to hosts and services. Optional so you can complete the required HashiStack path without it; take it when you want just-in-time access and Vault credential brokering.
Goals:
- β’Replace standing bastions with Boundary sessions
- β’Broker credentials with Vault and declare Boundary with Terraform
Prerequisites
Linux command line familiarity
Basic networking (DNS, TCP, TLS)
Willingness to work in a terminal-heavy lab environment
No prior HashiCorp product experience required
Kubernetes is not required for the required path. Optional Vault 201 assumes pods, deployments, and Helm
Frequently Asked Questions
Why does the page say Week 1, Week 2, Week 3 if a course takes longer than a week?
This bootcamp sets unitLabel to Module, so the UI chips say Module 1, Module 2, and so on. It does not split a single course across several slots. The module title includes the course hours and a calendar estimate. The required path is about 115 hours β typically 10β14 calendar weeks at 8β12 hours per week, not seven calendar weeks.
Do I have to finish a module in one calendar week?
No. The bootcamp is self-paced. Every module is unlocked from day one. Use the hours in the module title, not the Week chip, to plan your calendar.
Is this a new set of HashiCorp courses?
No. It is a shell that sequences courses you can already take individually. Required: Terraform Associate AWS, Packer 101, Sentinel 101, Vault Associate 003, Consul 101, Nomad 101. Optional: Terraform for Beginners, Vault 201, Vault 202, and Boundary 101.
Why is Terraform 101 or Vault 101 missing?
Those are legacy Exam 002 courses. This path uses Terraform Associate 004 and Vault Associate 003.
What about Terraform Associate on Azure or GCP?
Those courses teach the same Associate 004 exam on another cloud. This bootcamp requires the AWS track so the path has one Terraform course. If you already work on Azure or GCP, take that Associate 004 course from the catalog instead of or in addition to the AWS one β it is not a second required module here.
Where does Packer fit?
Module 2, right after Terraform. Packer bakes golden images as code; Terraform can launch the AMI you produce. Packer 101 is required on this path.
Is there a Vagrant course in this bootcamp?
No. The academy does not have a Vagrant course. Waypoint is retired and is not included.
How is this different from the Vault Security Bootcamp?
The Vault bootcamp is Vault-only (including the legacy Vault 101 course). This HashiStack bootcamp is the multi-product path. Vault 201 and Vault 202 appear in both as optional depth here. Vault Associate 003 is the Vault fundamentals course here, not Vault 101.
Is Boundary required?
No. Boundary 101 is optional. You can complete the required path without it.
Will I get a combined HashiStack lab?
Not in this shell. Each course has its own labs. There is no extra capstone that runs Terraform, Packer, Vault, Consul, Nomad, and Boundary in one environment.
Do I need Kubernetes?
Not for the required path. Optional Vault 201 assumes Kubernetes and Helm. Consul 101 and Nomad 101 teach the Kubernetes pieces they need inside those courses.
Technologies Covered
Choose your plan
Simple, Transparent Pricing
Unlock full access to TeKanAid courses, labs, and bootcamps
Just exploring? Start free below. Want the full experience? Try Premium free for 7 days (card required, $0 today).
Pro
All courses, with lab scripts to run on your own machine
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Full access to all courses
- Lab scripts to download and run on your own machine (hosted labs not included)
- Progress tracking
- Certificate of completion
- Community access
- Self-paced bootcamps
- Premium puzzle library not included (5 free puzzles available)
- New content access
Premium
Full access, including unlimited hosted labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Everything in Pro
- Unlimited hands-on labs, fully hosted on TeKanAid Academy (nothing to set up)
- Full access to the puzzle library
- Lab AI Assistant
- Priority support
Prefer a single course?
Purchase individual courses for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.
Browse CoursesJust exploring? Start free, no account needed
Three free ways to start. All bridge into the paid Premium catalog when you're ready.
Not ready to commit? The crash course is email-only. No academy account required.
Ready to Transform Your Career?
Join this comprehensive bootcamp and master Platform Engineering
Get Access Now