Online professional certificate
Professional Certificate in Cloud Engineering
Build the skills to scope cloud services, prepare reviewable infrastructure changes, verify deployments, read service signals and hand off decisions with evidence.
- Format
- Online, self-paced
- Study time
- Up to 1 month
- Curriculum
- 20 applied lessons
- Language
- English
Practical capability
Build cloud services that can be changed and operated with evidence.
Practise six connected capabilities: service scope, controlled infrastructure, deployment verification, reliable signals, platform trade-offs and a useful handoff.
Define the service, the engineer’s remit, decision rights and the evidence needed for a safe first action.
Review a versioned change, inspect the plan and check network and identity effects before approval.
Trace checks, artifacts and approvals through a release; verify a staged rollout and record a stop or rollback decision.
Choose service signals, triage incidents, build an evidence timeline and test recovery against user outcomes.
Compare container state, capacity and cost options, and test a workload migration mapping.
Write guides and first-shift records that let the next owner understand the result, open risk and next decision.
Who this course is for
A practical route into cloud platform work.
For beginning and transitioning practitioners who want to turn a service need into a controlled change, verified result and clear operating record.
The operating cycle
Move from service request to decision-ready handoff.
Follow one connected platform-team case as you define the service, prepare a reviewable change, check its effect, respond to service signals and pass the open decision to its owner.
Curriculum
Four modules. Twenty applied lessons.
Scope and Define Cloud Infrastructure
Start with a bounded service remit, clear owners and trustworthy current state. Build a reviewable infrastructure definition and check network and identity effects before a change.
01Establish the Service and Your Role Boundary
Define the bounded cloud-engineer remit for one request.
Five practical steps
- Preserve the request and identify the requester
- Name the service and environment
- Separate user outcome from platform observation
- Mark the engineer's owned layer and other owners
- Record the open question and hand the first safe action to its owner
Primary deliverable: Service remit record.
02Map Decision Rights Before a Cloud Change
Map the decision owner before a production action.
Five practical steps
- Write the action in one verb and one environment
- Check the local role source
- Name technical reviewers and affected owners
- Separate the safe engineer step from the held decision
- Route the triggered decision and record the owner’s answer
Primary deliverable: Decision-rights routing map.
03Trace the Service's Cloud Dependencies
Construct a source-linked service dependency map.
Five practical steps
- State the user action and expected result
- List only components supported by a source
- Turn connections into verbs
- Compare the intended path with read-only state
- Document the unresolved dependency check and ask its owner
Primary deliverable: Service dependency map.
04Prepare a Reviewable Infrastructure-as-Code Change
Produce a versioned IaC change packet.
Five practical steps
- Confirm the requested resource and target
- Check the baseline
- Make the narrow source edit
- Read the diff as a reviewer would
- Package the plan limits for the named decision owner
Primary deliverable: Versioned IaC change packet.
05Check Network and Identity Change Impact
Complete a bounded access-and-connectivity impact review.
Five practical steps
- Restate the requested connection
- Record the current path and its source
- Compare proposed network reachability
- Compare identity and data permission
- Record the access impact and route the change decision
Primary deliverable: Access-and-network impact sheet.
Control and Verify Deployment Changes
Follow the path from source and checks through deployment approval. Verify a bounded rollout with platform and user-facing signals, then record a pause or rollback decision.
06Locate Guardrails in the Change Path
Trace one change through the configured control path.
Five practical steps
- Anchor the change to one service and environment
- Trace the source and trigger
- Place each check where it really runs
- Follow the decision and apply route
- Summarize the route gap and propose the next safe check
Primary deliverable: Change-path control map.
07Validate an IaC Plan with CLI and Script Evidence
Verify an IaC plan against read-only Linux/CLI and scripted test evidence.
Five practical steps
- Identify the exact source and target
- Read the proposed actions before their totals
- Choose one behavior to test
- Inspect the supplied CLI or service evidence
- Record the test evidence and its decision boundary
Primary deliverable: Infrastructure validation record.
08Map the Source-to-Deployment Pipeline
Specify a source-to-deployment workflow with evidence gates.
Five practical steps
- Choose one release candidate and its source
- Follow the build trigger
- Connect tests and checks to that build
- Establish artifact identity
- Document deployed service evidence and the rollback route
Primary deliverable: Pipeline evidence map.
09Observe a Bounded Deployment to Full Service Health
Run a staged deployment observation plan.
Five practical steps
- Confirm the approved release and strategy
- Write down the platform completion rule
- Capture a baseline and the application check
- Observe the staged change as the authorized operator runs it
- Document the user-facing result for the rollout owner
Primary deliverable: Deployment observation sheet.
10Decide When to Pause or Roll Back
Record a defensible release decision and rollback route.
Five practical steps
- Anchor the decision to the approved release
- Read platform and application signals on one timeline
- Apply the local stop rule exactly
- Lay out the bounded options
- Recommend a bounded stop or rollback action for owner approval
Primary deliverable: Release decision and rollback record.
Observe, Respond, and Recover Services
Choose service signals, set actionable measures, triage incidents and build a reliable timeline. Rehearse recovery and confirm the result with the owners who decide next steps.
11Choose Signals That Reflect Service Health
Specify one signal for a defined service question.
Five practical steps
- Phrase the service question
- Draw only the path needed for that question
- Compare candidate evidence
- State the measurement boundary
- Record blind spots and review the signal with its owner
Primary deliverable: Service signal specification.
12Set Actionable Service Measures and Alerts
Write a bounded SLI/SLO and alert rule record.
Five practical steps
- State the service action and owner
- Define the SLI population
- Choose a measurement window and draft objective
- Propose an alert condition
- Route the alert draft for approval and future review
Primary deliverable: SLI-SLO alert rule record.
13Triage an Incident Within Your Role
Open a scoped incident intake and ownership record.
Five practical steps
- Acknowledge and preserve the first signal
- Check for a confirmed user effect
- Bound the affected service and recent change
- Identify command and decision routes
- Send a scheduled evidence update to incident command
Primary deliverable: Incident intake and ownership log.
14Build an Evidence-Based Incident Timeline
Build an incident evidence timeline.
Five practical steps
- Define the window and service boundary
- Collect source-specific observations
- Order without inventing precision
- Separate fact from interpretation
- Propose a discriminating test and brief the commander
Primary deliverable: Incident evidence timeline.
15Verify a Recovery Rehearsal
Document one recovery test and its open gaps.
Five practical steps
- Confirm purpose, scope and acceptance
- Verify the candidate and baseline
- Execute the authorized restore and record platform milestones
- Test the application path and data state
- Document recovery gaps and request the retest decision
Primary deliverable: Recovery test worksheet.
Operate Platforms and Hand Off Work
Operate shared platforms after launch: compare container state, weigh capacity and cost, review migration mappings and write an operating guide for a first-shift handoff.
16Check Desired and Observed Container Workload State
Compare desired and observed container workload state and choose a safe operating action.
Five practical steps
- Name the workload and the expected service action
- Capture desired state from an approved source
- Capture observed state and calculate the difference
- Read the health and progression evidence
- Recommend hold, continue or escalation against the local gate
Primary deliverable: Container workload operating check.
17Explain a Capacity and Cost Trade-Off
Compare one capacity/cost option to user-facing performance evidence.
Five practical steps
- Frame the service question and cost boundary
- Collect a comparable baseline
- Model a small set of options
- Test service effect and failure modes
- Route a cost-capacity recommendation for stakeholder review
Primary deliverable: Capacity-cost decision note.
18Review a Workload Migration Mapping
Produce a bounded migration mapping review.
Five practical steps
- State the source outcome and target boundary
- Inventory critical source dependencies
- Read the proposed target mapping as claims
- Choose tests that could disprove a weak mapping
- Prepare a staged cutover and fallback recommendation for approval
Primary deliverable: Migration mapping review.
19Write an Operating Guide Others Can Use
Write a bounded operational handoff guide.
Five practical steps
- Name the reader, service and use condition
- Gather the local prerequisites
- Write ordered checks before actions
- Place decision points and stop rules where they occur
- Test the guide with a receiving engineer and revise gaps
Primary deliverable: Operating handoff guide.
20Complete a First-Shift Handoff
Complete a source-checked first-shift handoff for a bounded cloud work event.
Five practical steps
- Name the service and competing work
- Take a safe first check and route active concern
- Check the change boundary
- Verify the user-facing question with the right owner
- Write the first-shift record and confirm the receiving owner
Primary deliverable: First-shift operation record.
Applied capstone
Make a cloud rollout decision with evidence.
Read a supplied change record, compare platform observations with customer behavior and use the relevant course methods to prepare one clear recommendation.
The situation
A queue-worker rollout reports healthy platform tasks while customer confirmations remain slow. The release record shows desired capacity, a staged change, initial service signals and an application-owner concern. The next production action needs an evidence-based decision.
Your task
Prepare a production change decision brief for the release owner. Compare observed state and service result, recommend a bounded next action, name the check that could change your view and hand open risk to the person authorized to decide.
The people behind MTF
Meet MTF faculty and the learner community.
Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.
Enrollment
Enroll in Professional Certificate in Cloud Engineering
One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.
You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.
Questions and details
Frequently asked questions
Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.
Who is this cloud engineering course for?
The course is designed for aspiring cloud engineers, junior platform engineers, infrastructure automation practitioners and cloud operations specialists who want a practical route from service scope to controlled change and operating handoff.
How does the course work?
Study online at your pace over up to one month. Four modules contain 20 applied lessons, each with a work product, worked example and AI practice. A separate capstone asks for one production change decision brief based on a supplied service case.
How is AI used in the practical work?
Each lesson offers a drafting prompt and a separate critic prompt. Use fictional or authorized inputs, check the answer against source evidence and complete the same exercise without AI when needed. You retain responsibility for the final record and its decision route.
What evidence supports the curriculum?
MTF Institute reviewed 100 current U.S.-eligible cloud and platform engineering postings and separately analysed current provider and standards changes. The research report, trend article and archived record at https://doi.org/10.5281/zenodo.23224432 document the evidence and methods.
What practical work will I complete?
You will make 20 distinct workplace artifacts, including a service remit, decision-rights map, versioned infrastructure change packet, deployment verification record, incident timeline, recovery check and first-shift operation record. The capstone uses the relevant methods in one decision brief.
How does cloud engineering connect to cloud security operations?
Cloud engineering focuses on service infrastructure, controlled deployment, observability and operation. The related Cloud Security Operations program develops a deeper security focus on posture, identity, detection and control evidence.
What certificate and access will I receive?
After enrollment you receive access to the MTF learning platform. The closing section provides the MTF Institute course-completion certificate for Professional Certificate in Cloud Engineering and a separate Student ID activity.