Boundary 101 — Identity-Aware Access for Dynamic Infrastructure
A hands-on course on HashiCorp Boundary Community Edition. Replace standing bastions and VPNs with identity-aware, least-privilege sessions. Deploy a controller and worker, model orgs and projects, write RBAC grants, broker static and Vault-backed credentials, filter workers, and operate day-2 events and backups. Enterprise and HCP features such as credential injection, session recording, multi-hop workers, and transparent sessions are covered conceptually so you can evaluate paid editions.
Course Preview
Why This Course is Different
Get everything you need to master platform engineering and advance your career
Certificate of Completion
Earn a certificate while gaining real-world skills that go beyond traditional certification prep
Hands-on Labs
9 practical labs with real-world scenarios in pre-configured cloud environments
Expert-Led
Learn from Sam Gabrail, Former HashiCorp Sr. Solutions Engineer with 18+ years experience
Community Support
Join our community where members help each other and collaborate on learning
What You'll Master
Explain how Boundary replaces bastions and VPNs with identity-aware sessions
Navigate the domain model: scopes, auth methods, users, groups, roles, targets, workers
Authenticate with the CLI and complete a TCP session in dev mode and on a self-managed cluster
Write least-privilege grant strings and prove allow versus deny
Deploy a Community Edition controller, worker, and PostgreSQL backend from HCL
Model static host catalogs, host sets, TCP targets, and aliases
Broker static and Vault-dynamic credentials without distributing long-lived secrets
Register workers, tag them, and apply egress worker filters
Manage Boundary resources with the official Terraform provider
Operate events, health checks, and PostgreSQL backup/restore
Identify which features require HCP or Enterprise (injection, recording, multi-hop, transparent sessions)
Course Curriculum
SECTION 1 – COURSE INTRODUCTION
Course overview, the TeKanAid community, Boundary editions and licensing, and how the hands-on labs work.
- •Welcome and Course Overview
- •Community
- •Editions, Licensing, and What You Will Build
- •Environment Setup and Lab Conventions
SECTION 2 – IDENTITY-AWARE ACCESS AND WHY BOUNDARY
Bastions and VPNs versus just-in-time identity-aware proxy, what Boundary is, the core workflow, and CLI / Admin UI / Desktop clients.
- •The Bastion and VPN Problem
- •What Is an Identity-Aware Proxy
- •Boundary Core Workflow
- •Clients: CLI, Admin UI, and Desktop
- •Identity-Aware Access QuizQuiz
SECTION 3 – BOUNDARY DOMAIN MODEL
Global / org / project scopes, IAM resources, targets and catalogs, workers and sessions, and a worked org model.
- •Scopes: Global, Org, and Project
- •IAM Resources
- •Targets, Hosts, and Catalogs
- •Workers and Sessions
- •Modeling an Organization in Boundary
- •Boundary Domain Model QuizQuiz
SECTION 4 – FIRST SESSION: CLI, DEV MODE, AND CONNECT
Install the CLI, boundary dev against local Postgres, authenticate, connect to the generated TCP target, and the client cache.
- •Install the Boundary CLI
- •Boundary Dev Mode
- •Authenticate and Explore Resources
- •Connect to Your First Target
- •Client Cache and the Dev Admin Console
- •First Session QuizQuiz
- •First Session with boundary devLab
SECTION 5 – SCOPES, ROLES, AND GRANTS
Orgs and projects, users and groups, CE auth methods, roles, grant strings, and least-privilege personas.
- •Creating Orgs and Projects
- •Users, Accounts, and Groups
- •Auth Methods: Password, OIDC, and LDAP
- •Roles and Principals
- •Grant Strings and Actions
- •Least-Privilege Personas
- •Scopes, Roles, and Grants QuizQuiz
- •Scopes, Roles, and GrantsLab
SECTION 6 – ARCHITECTURE AND SELF-MANAGED DEPLOY
Control plane versus data plane, controllers, workers, PostgreSQL and KMS, HCL listeners, and the lab split versus production HA.
- •Control Plane versus Data Plane
- •Controllers and the API
- •Workers as Session Proxies
- •PostgreSQL and KMS Keys
- •HCL Configuration and Listeners
- •Recommended Architecture versus the Lab Split
- •Architecture and Self-Managed Deploy QuizQuiz
- •Self-Managed Controller and WorkerLab
SECTION 7 – HOSTS, CATALOGS, TARGETS, AND ALIASES
Static catalogs, TCP targets, global aliases, session limits, and a conceptual look at dynamic catalogs.
- •Static Host Catalogs and Host Sets
- •TCP Targets
- •Global Aliases
- •Session Limits
- •Dynamic Host Catalogs Overview
- •Hosts, Catalogs, Targets, and Aliases QuizQuiz
- •Static Hosts, TCP Targets, and Global AliasesLab
SECTION 8 – CONNECTION WORKFLOWS AND SESSIONS
Connect helpers, session lifecycle and pre-authorize, troubleshooting, and client cache plus Desktop overview.
- •Boundary Connect and Helpers
- •Session Lifecycle and Pre-Authorize
- •Troubleshooting Connections
- •Client Cache and Desktop Overview
- •Connection Workflows QuizQuiz
SECTION 9 – CREDENTIAL STORES AND BROKERING
Credential stores and types, static username/password and SSH keys, the brokering flow, and attaching brokered credentials to TCP targets.
- •Credential Stores and Types
- •Static Username/Password and SSH Keys
- •The Brokering Flow
- •Attaching Brokered Credentials to TCP Targets
- •Credential Brokering QuizQuiz
- •Broker Static Credentials on a TCP TargetLab
SECTION 10 – VAULT DYNAMIC CREDENTIALS
Why Boundary plus Vault, Vault credential stores, credential libraries, dynamic database credentials, and what this section is not.
- •Why Boundary Plus Vault
- •Vault Credential Stores
- •Credential Libraries
- •Brokering Dynamic Database Credentials
- •KV Sidebar and What This Is Not
- •Vault Dynamic Credentials QuizQuiz
- •Broker Vault Dynamic Database CredentialsLab
SECTION 11 – WORKERS, TAGS, AND FILTERS
Worker registration methods, tags, egress worker filters on CE, and worker-aware targets.
- •Worker Registration Methods
- •Worker Tags
- •Egress Worker Filters
- •Worker-Aware Targets
- •Workers, Tags, and Filters QuizQuiz
- •Worker Tags and Egress FiltersLab
SECTION 12 – TERRAFORM AS SOURCE OF TRUTH
The official provider, scopes and IAM as code, hosts/targets/credentials as code, and recovery KMS bootstrap then remove.
- •The Boundary Terraform Provider
- •Codifying Scopes and IAM
- •Codifying Hosts, Targets, and Credentials
- •Recovery KMS: Bootstrap Then Remove
- •Terraform as Source of Truth QuizQuiz
- •Codify Boundary with TerraformLab
SECTION 13 – OBSERVABILITY AND DAY-2 OPERATIONS
Events and audit logs, health endpoints, metrics and upgrades, Postgres backup and restore, and operational runbooks.
- •Events and Audit Logs
- •Health Endpoints
- •Metrics and Upgrades
- •PostgreSQL Backup and Restore
- •Operational Runbooks
- •Observability and Day-2 QuizQuiz
- •Events, Health, and Postgres BackupLab
SECTION 14 – ENTERPRISE AND HCP FEATURES
Edition matrix, credential injection and SSH/RDP target types, session recording, multi-hop and ingress filters, transparent sessions, and Boundary 1.0.
- •CE vs HCP Standard, Plus, and Enterprise
- •Credential Injection and SSH/RDP Targets
- •Session Recording and Lifecycle
- •Multi-Hop Workers and Ingress Filters
- •Transparent Sessions, Client Agent, and Project Aliases
- •Helm Charts and Boundary 1.0
- •Enterprise and HCP QuizQuiz
SECTION 15 – HARDENING, HA/DR, AND WRAP-UP
Security hardening, high availability and disaster recovery (conceptual), HashiStack adjacency, and course wrap-up.
- •Security Hardening
- •High Availability and Disaster Recovery
- •What's Next in the HashiStack
- •Course Wrap-Up
- •Hardening, HA, and Wrap-Up QuizQuiz
Course Features

Hands-on Labs
Lots of hands-on labs to learn by doing

Join our Community
Community support to ask questions and collaborate

Test Your Knowledge
Quizzes to help you grasp the material well
See what others are saying about our Courses
“I like the Crossplane 101 course a lot. I think it is one of the best online courses I have taken (and I've taken a lot in the last 2 years, transitioning into DevOps). The labs are phenomenal – every task has a long tutorial with lots of explanations, gotchas, and recaps, and you always provide the reasoning for implementing a certain solution.”
“I just completed the Crossplane 101 course! Managing infrastructure as Kubernetes resources is a total game-changer. A huge thanks to TeKanAid and Sam Gabrail for the incredible training and insights.”
“Although I've worked with Crossplane in real production environments, I always felt there were gaps in my understanding. Completing this course filled those gaps perfectly. I had to unlearn and relearn quite a few things, especially around Crossplane v2.0 concepts. Well structured and thoughtfully put together. Highly recommended for building a strong, foundational understanding of Crossplane.”
“Dear Sam, I hope this email finds you well. If you remember before the end of last year I register for one your courses Terraform 101 – Certified Terraform Associate, I must admit that I learned a lot even though I was not patient enough for all videos to be available. All in all I enjoy the way you structured the course and how you went through it. The main reason of this email, to send you my gratitude for the content you created and to let you know that I passed my exam/test last week.”

“This course was a perfect introduction to Terraform and Infrastructure as Code. Loved the gitpod, saving me a lot of time for developer environment setup. We have a project at work where we want to go from a click-ops version of server-deploy to a more automated flow using ci/cd and terraform for deploying virtual servers.”

“I want to thank you for such wonderful courses. They are more comprehensive than other courses I have taken in the past. You take the time to explain every detail of the code and what it does exactly, further enforcing your student's understanding and confidence in what they are learning. Your methods are very effective and set you apart from other instructors.”

Choose your plan
Simple, Transparent Pricing
Unlock full access to TeKanAid courses, labs, and bootcamps
Just exploring? Start free below. Want the full experience? Try Premium free for 7 days (card required, $0 today).
Pro
All courses, with lab scripts to run on your own machine
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Full access to all courses
- Lab scripts to download and run on your own machine (hosted labs not included)
- Progress tracking
- Certificate of completion
- Community access
- Self-paced bootcamps
- Premium puzzle library not included (5 free puzzles available)
- New content access
Premium
Full access, including unlimited hosted labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Everything in Pro
- Unlimited hands-on labs, fully hosted on TeKanAid Academy (nothing to set up)
- Full access to the puzzle library
- Lab AI Assistant
- Priority support
Prefer just this course?
Purchase Boundary 101 — Identity-Aware Access for Dynamic Infrastructure for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.
Buy this course for $79 →Just exploring? Start free, no account needed
Three free ways to start. All bridge into the paid Premium catalog when you're ready.
Not ready to commit? The crash course is email-only. No academy account required.
Hi there, I'm Sam
I'm a husband and father of two wonderful boys. I'm also very passionate 🔥 about all things technology. From when I was 10, I had a dream to become a computer 💻 engineer one day. Here I am today living the dream!
Thanks for visiting TeKanAid Academy. My goal is to teach you all things DevOps. Below are some of the things I've done over the years. I'm confident that I can help you achieve your dreams too.
- 18+ years of experience in various Information Technology fields from Telecommunications, Computer Networks, Digital Transformation, DevOps, Cybersecurity, and IoT
- President of TeKanAid Solutions Inc. building online content in the DevOps space
- Previous – Sr. Solutions Engineer at HashiCorp

View my Certifications

Terraform: Authorized HashiCorp Instructor
Verify my certificate
HashiCorp Authorized Instructors are experienced DevOps professionals who deliver official HashiCorp training courses in person and virtually.
Issued by HashiCorp Partner Network (HPN)

Vault: Authorized HashiCorp Instructor
Verify my certificate
HashiCorp Authorized Instructors are experienced DevOps professionals who deliver official HashiCorp training courses in person and virtually.
Issued by HashiCorp Partner Network (HPN)

HashiCorp Certified: Terraform Associate (002)
Verify my certificate
Earners of the HashiCorp Certified: Terraform Associate certification know the basic concepts, skills, and use cases associated with open source HashiCorp Terraform.
Issued by HashiCorp

HashiCorp Certified: Vault Associate (002)
Verify my certificate
Earners of the HashiCorp Certified: Vault Associate certification know the basic concepts, skills, and use cases associated with open source HashiCorp Vault.
Issued by HashiCorp
Featured Products
Week 4: AI Agents and Agentic Workflows
Part of the AI Platform Engineering Bootcamp. Week 4 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More →Week 1: AI Foundations for Infrastructure Engineers
Part of the AI Platform Engineering Bootcamp. Week 1 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More →Week 7: AI Observability and LLMOps
Part of the AI Platform Engineering Bootcamp. Week 7 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More →
30-Day Money-Back Guarantee
Try it risk-free
I'm confident you'll get everything you need from this course and be 100% satisfied. But in the unlikely event you decide it's not for you just ask for a refund any time during the first 30 days and you'll get your money back with no questions asked.