Module 12 of 12 · 210 min

Self-Hosted Model Operations Capstone

Deploy and defend a portable self-hosted model service whose identity, security, evaluation, capacity, telemetry, lifecycle, recovery, and approvals are proven by reviewable evidence.

Core concept

By the end

You will be able to

  • Assemble a portable model-service package that separates provider-neutral contracts from environment-specific adapters.
  • Prove artifact identity, legal and provenance review, endpoint security, representative evaluation, load capacity, and privacy-conscious telemetry.
  • Execute a controlled update, forced rollback, and incident recovery exercise with explicit human approval boundaries.
  • Map every mastery judgment to immutable evidence and produce an operator-ready handoff with residual risks.
01

Choose a bounded deployment mission

Choose one portable lab shape: workstation, container on premises, edge, or cloud-managed compute. Define the learner, intended workload, prohibited data, expected request contract, non-goals, service objectives, cost boundary, and stop conditions. Homestead Foundry may be used as an optional reference adapter, but the evidence contract must remain independently deployable.

Create one release identity spanning the model artifact, runtime, endpoint, security policy, infrastructure configuration, evaluation set, load profile, telemetry, and lifecycle plan. State which steps are portable and isolate environment-specific commands so another implementation can satisfy the same contract.

02

Build from verified artifacts and explicit authority

Select an immutable model revision, record publisher and source, review license and intended use, capture provenance and digest, inventory dependencies, and quarantine any failed verification. Document hardware assumptions and prove the runtime can reconstruct the selected build.

Expose the minimum endpoint contract with health, readiness, and model-identity evidence. Define caller and operator principals, authorization, network boundary, secret source, limits, audit events, revocation, and recovery. Never place credentials in the package, prompts, screenshots, transcripts, or repository.

03

Evaluate quality, safety, compatibility, and capacity

Build representative routine, boundary, adversarial, and failure cases for the intended workload. Use deterministic checks where possible, calibrated human review for judgment, and independently configured model-assisted review only where documented. Record exact candidate identity and slice results.

Run a bounded load profile through the actual gateway and endpoint. Measure latency distributions, queue time, throughput, error and rejection rates, resource saturation, cost assumptions, warm-up, and failure behavior. Issue a capacity decision with safe limits and stop conditions.

04

Observe, update, roll back, and recover

Correlate secret-safe logs, metrics, and traces across request, gateway, serving build, infrastructure, evaluation, and outcome. Prove alert behavior and telemetry-loss detection while documenting redaction, retention, access, and deletion.

Qualify a candidate change, obtain required human approvals, release it with bounded exposure, inject a failed gate, and roll back the complete known-good serving unit. Then run an incident scenario through detection, containment, diagnosis, recovery-objective validation, communication, closure, and prevention work.

05

Submit mastery evidence, not a demo claim

Submit the portable lab package and evidence digests for artifact, license and provenance, endpoint and security, evaluation, load and capacity, telemetry and cost, update and rollback, incident recovery, and approvals. Every rubric score must cite submitted evidence or a recorded assessment.

The handoff names versions, operating owner, reviewer roles, service and cost limits, alerts, runbook, rollback trigger, recovery objectives, residual risks, and next review date. A passing demonstration without reproducible artifacts, failed-path evidence, and human review does not establish mastery.

Practice activity

Build and defend a portable self-hosted model service

  1. Complete the portable self-hosted model lab package for one deployment shape and keep adapter-specific commands outside the portable evidence contract.
  2. Deploy the exact verified build and capture artifact, license, provenance, endpoint, identity, access, and infrastructure evidence.
  3. Run representative evaluation and bounded load suites, produce capacity and cost decisions, and verify privacy-conscious telemetry and alerts.
  4. Qualify a candidate update, obtain human approval, force a release gate failure, and prove complete rollback to the known-good build.
  5. Run an incident exercise through recovery and closure, map rubric criteria to immutable evidence, and submit the operator handoff and residual-risk statement.

What to produce

  • A schema-valid portable lab package with immutable evidence digests and no secrets.
  • Evaluation, load, capacity, telemetry, cost, update, rollback, and incident-recovery results tied to exact identities.
  • Criterion-level evidence, human approvals, revision history, and an operator-ready handoff.

Reflect before continuing

Which mastery claim in your package would be hardest for an independent operator to reproduce, and what evidence would remove that ambiguity?

Applied capstone

Portable Self-Hosted Model Operator Evidence

Pass at 80%

A criterion-level review of a secure, evaluated, observable, reversible, and recoverable model-service package.

Required artifacts

Provide a path, URL, or short stable reference for every artifact.

Evidence rubric

Award whole points from 0 to the criterion maximum. The total is checked against the published rubric.

Artifact, license, and provenance

The exact model and dependency build is authorized, integrity-checked, reproducible, and traceable to primary evidence.

Evidence required
  • Artifact identity and digest
  • License and intended-use review
  • Provenance and dependency evidence
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Endpoint and security

The serving contract, principals, authorization, network, secrets, limits, audit, revocation, and recovery boundaries are explicit and tested.

Evidence required
  • Endpoint compatibility contract
  • Identity and authorization tests
  • Network, secret, audit, and revocation evidence
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Evaluation and safety

Representative, boundary, adversarial, and failure cases produce slice-level quality and safety evidence for the exact serving build.

Evidence required
  • Versioned evaluation cases and configuration
  • Deterministic and calibrated review results
  • Gate disposition and residual risks
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Load, capacity, and performance

Measured latency, queueing, throughput, saturation, rejection, failure, and cost evidence supports bounded operating limits.

Evidence required
  • Representative load profile
  • Distribution and saturation results
  • Capacity, admission, and cost decision
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Telemetry and operations

Correlated logs, metrics, traces, alerts, and data-handling controls explain service behavior without unnecessary sensitive data.

Evidence required
  • Correlated telemetry evidence
  • Alert and telemetry-loss test
  • Redaction, retention, access, and deletion plan
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Update and rollback

A human-approved candidate change is qualified, bounded, stopped on a failed gate, and completely reversed to a verified known-good state.

Evidence required
  • Compatibility and release manifest
  • Approval and bounded rollout evidence
  • Rollback and restored-postcondition proof
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Incident and recovery

A realistic incident is detected, contained, diagnosed, recovered, communicated, closed, and converted into owned prevention work.

Evidence required
  • Incident timeline and evidence ledger
  • Runbook and recovery-objective validation
  • Communication, closure, and improvement records
Map this score to evidence

Choose one or more submitted artifacts or a recorded knowledge check.

Evidence

Sources and verification

Knowledge check

Make it stick.

Pass at 80%

Choose the strongest answer for each question. Your attempts become part of your device-local transcript.

01What makes the capstone portable?
02Which submission proves artifact mastery?
03Why are representative slices required?
04What proves rollback mastery?
05Who can approve consequential release and recovery decisions?
06When is mastery established?