Matrix + Element: Decentralized Enterprise Chat to Replace Slack and Teams Training Course
Matrix is an open protocol for secure, decentralized, real-time communication. Organizations are increasingly adopting Matrix with the Element client as an alternative to Slack and Microsoft Teams to maintain end-to-end encryption, on-premise data residency, and federation with external trusted partners.
This instructor-led, live training (online or onsite) is aimed at intermediate DevOps and collaboration engineers who wish to use Matrix and Element to self-host a messaging platform replacing proprietary chat.
By the end of this training, participants will be able to:
- Deploy Synapse or Dendrite in Docker with PostgreSQL and Redis.
- Configure federation, bridges, and spaces for team organization.
- Enable end-to-end encryption and cross-signed device verification.
- Integrate LDAP/SSO for centralized user authentication.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Decentralized Communication Sovereignty
- Why centralized chat is a data governance risk.
- Matrix protocol overview: rooms, events, and federation.
- Synapse vs Dendrite homeserver options.
Homeserver Deployment
- Docker Compose stack with Synapse, PostgreSQL, and Element Web.
- Reverse proxy configuration with Nginx and LetsEncrypt.
- Federation configuration: .well-known delegation and port 8448.
Authentication and Identity
- Local auth, LDAP integration, and OpenID Connect.
- User registration policies and guest access control.
- SSO with Keycloak, Authentik, or Authelia.
End-to-End Encryption
- Cross-signing and device verification workflows.
- Key backup and recovery for lost devices.
- Admin implications of encrypted rooms and export rules.
Spaces, Rooms, and Bridges
- Structuring enterprise spaces for departments and projects.
- IRC, Slack, and Telegram bridges for inter-team communication.
- Threading, reactions, and bots for automation.
Security and Moderation
- Admin API for user management, room shutdown, and data deletion.
- Privacy settings: message retention, redaction, and media purging.
- Rate limiting and CAPTCHA to mitigate spam registration.
Maintenance and Scaling
- Postgres maintenance: vacuum, indexing, and long-term retention.
- Media repository sizing and S3 offloading.
- Monitoring with Prometheus and logging retention policies.
Requirements
- Intermediate Linux system administration and Docker basics.
- Understanding of federated messaging and HTTPS.
- Familiarity with web proxy configuration (Nginx/Apache).
Audience
- Enterprise IT teams replacing Slack, Teams, or Discord with sovereign messaging.
- Regulated industries: healthcare, finance, defense.
- Decentralization proponents and privacy-focused organizations.
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
Matrix + Element: Decentralized Enterprise Chat to Replace Slack and Teams Training Course - Enquiry
Related Courses
Gitea: Self-Hosted Git Forge Replacing GitHub and GitLab
14 HoursGitea is a lightweight, open-source, self-hosted Git service that offers repository management, code review, issue tracking, and CI/CD integration. It has become an increasingly popular alternative to GitHub and GitLab.com for teams seeking full control over their source code without the constraints of third-party terms of service or export restrictions.
GitLab Self-Managed: Complete DevSecOps Platform Without SaaS
21 HoursGitLab Self-Managed is the on-premises deployment of GitLab's complete DevSecOps platform, including source code management, CI/CD, container registry, security scanning, and monitoring. It is the gold standard for organizations that want the full GitLab feature set without SaaS dependency or data leaving their network.
Container Sovereignty: Kubernetes Without Cloud Dependencies
21 HoursThis instructor-led, live training in Kenya (online or onsite) is aimed at intermediate to advanced DevOps engineers and system administrators who wish to deploy and manage self-hosted Kubernetes clusters without cloud dependencies.
By the end of this training, participants will be able to: deploy production-ready Kubernetes clusters using kubeadm on bare-metal or virtual machines; configure high-availability control planes and etcd clusters; implement container networking and storage for self-managed environments; set up monitoring and observability using self-hosted solutions.
Multi-Cloud Sovereignty: Avoiding Single-Vendor Lock-in
14 HoursThis instructor-led, live training (online or onsite) targets cloud professionals who aim to design and implement multi-cloud architectures that prevent vendor lock-in and ensure data sovereignty.
By the conclusion of this training, participants will be able to identify risks related to vendor lock-in, design portable architectures, implement data sovereignty controls, and leverage cloud-agnostic tools effectively.
Open Network Operating Systems: SONiC and ONL
14 HoursThis instructor-led live training in Kenya (online or onsite) is tailored for network engineers and infrastructure professionals looking to deploy and manage open network infrastructure on white-box switches using SONiC and ONL.
By the end of this training, participants will be able to understand SONiC and ONL architecture, deploy open-source NOS on white-box hardware, configure networking features, and implement monitoring and automation.
Private Cloud Infrastructure: OpenStack for Enterprises
21 HoursThis instructor-led live training (online or onsite) is targeted at system administrators and infrastructure engineers who aim to design, deploy, and manage private OpenStack cloud infrastructure for enterprise settings.
By the conclusion of this training, participants will gain an understanding of OpenStack architecture, learn to deploy private cloud infrastructure, manage compute and storage resources, implement security via Keystone, and apply enterprise best practices.
Software-Defined Networking with Open Source Tools
35 HoursThis instructor-led, live training in Kenya (online or onsite) targets intermediate-level network engineers and infrastructure administrators who wish to implement software-defined networks using open-source tools and technologies.
By the end of this training, participants will be able to design SDN architectures, implement Open vSwitch, configure FRRouting, deploy SDN controllers, and automate network management.
Building a Self-Managed Enterprise Network with Open-Source Routers, Switching, and Wi-Fi
21 HoursThis instructor-led, live training in Kenya (online or onsite) is designed for intermediate-level network and infrastructure professionals who wish to utilise open-source routing, switching, Wi-Fi, and management tools to design, deploy, and operate a self-managed enterprise network.
By the end of this training, participants will be able to design an open-source enterprise network architecture, configure routing, switching, and wireless services, enhance security and observability, and establish an operational plan for ongoing support.
Terraform: Self-Hosted Infrastructure as Code Without Cloud Lock-in
14 HoursTerraform is an open-source infrastructure-as-code tool that empowers teams to define and provision data center infrastructure using a declarative configuration language. When paired with self-hosted backends and on-premise providers, Terraform becomes a potent instrument for sovereign infrastructure management, effectively eliminating cloud vendor lock-in.
This instructor-led, live training (available online or onsite) is designed for intermediate infrastructure engineers seeking to leverage Terraform to manage self-hosted environments, including Proxmox, VMware, libvirt, and bare-metal provisioning.
By the end of this training, participants will be able to:
- Write robust Terraform configurations for on-premise and hybrid resources.
- Securely manage state using self-hosted backends such as PostgreSQL, S3-compatible storage, and Gitea.
- Utilize provisioners and custom providers to manage the entire bare-metal lifecycle.
- Implement efficient workspaces, modular architectures, and variable hierarchies.
- Integrate Terraform into CI/CD pipelines for automated infrastructure delivery.
Format of the Course
- Interactive lectures and guided discussions.
- Extensive exercises and practical labs.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training track for this course, please contact us to arrange specific requirements.
Uptime Kuma: Self-Hosted Monitoring Replacing Datadog and Pingdom
7 HoursUptime Kuma is an easy-to-use, self-hosted monitoring tool that tracks the availability of websites, services, and infrastructure. It replaces Pingdom, Datadog Synthetics, and UptimeRobot for teams that want monitoring data under their own control. This instructor-led, live training (online or onsite) is aimed at beginner-to-intermediate SREs and DevOps engineers who wish to use Uptime Kuma to replace cloud uptime monitoring with a self-hosted, sovereign status tracking platform.
Enterprise VPN: Self-Hosted WireGuard and OpenVPN
21 HoursThis instructor-led, live training in Kenya (online or onsite) is aimed at security engineers and system administrators who wish to deploy and manage enterprise-grade self-hosted VPN solutions using WireGuard and OpenVPN.
By the end of this training, participants will be able to deploy WireGuard and OpenVPN, design scalable architectures, integrate with identity systems, and monitor/secure VPN infrastructure.
OpenVPN and WireGuard: Self-Hosted VPN Replacing ExpressVPN and NordLayer
14 HoursOpenVPN and WireGuard are the two dominant open-source VPN protocols. Running your own VPN server ensures that no third-party provider can log traffic metadata, inject advertisements, or comply with foreign data requests. This training covers both protocols for different threat models and performance requirements.
Wazuh: Open-Source Security Monitoring Replacing Splunk and Sentinel
21 HoursWazuh is an open-source security platform offering unified XDR and SIEM capabilities for threat detection, integrity monitoring, incident response, and compliance. It aggregates endpoint telemetry into a self-managed analysis engine, providing a viable alternative to Splunk Enterprise Security, Microsoft Sentinel, and other cloud-native SIEMs.
Woodpecker CI: Lightweight Self-Hosted Pipelines for Gitea and Forgejo
14 HoursWoodpecker CI is a straightforward yet robust continuous integration engine tailored specifically for self-hosted Git repositories such as Gitea and Forgejo. It offers a lean, Docker-native CI/CD solution that eliminates the complexity and licensing costs associated with enterprise-grade CI platforms.
Zero Trust Architecture with Open Source Components
35 HoursThis instructor-led, live training in Kenya (online or onsite) targets intermediate to advanced-level security professionals wishing to implement Zero Trust Architecture using open-source tools and sovereign infrastructure.
By the end of this training, participants will be able to design Zero Trust architectures, deploy identity-aware proxies, implement dynamic authentication, secure microservices with service mesh, and monitor zero trust policies.