Infrastructure as Code
NixOS Setup & Management
I specialize in NixOS because it turns your entire OS into version-controlled code. Every service, every config, every package — declared, not imperatively installed.
What I deliver:
- Complete NixOS flake setup for your infrastructure
- Modular config system shared across all hosts
- Declarative service configurations (web servers, databases, monitoring)
- CI/CD deployment pipelines for your OS
- Atomic upgrades with instant rollback capability
You get:
- Zero-downtime deployments
- Reproducible environments (dev = staging = prod)
- Full audit trail of every system change
- One config file to rule them all
Cloud Infrastructure
Oracle Cloud, AWS, DigitalOcean
I’ve built production infrastructure on Oracle’s free tier (4 vCPU, 24GB RAM, 200GB storage) and know how to squeeze maximum value from minimal budgets.
What I deliver:
- Cloud-native architecture design
- Cost-optimized instance provisioning
- Multi-host coordination and networking
- Backup and disaster recovery strategies
You get:
- Infrastructure that scales with your budget
- No vendor lock-in (configs are portable across providers)
- Hidden costs eliminated through creative configuration
Security Engineering
Network & Endpoint Security
My entire fleet runs through a WireGuard VPN with encrypted DNS. No port is open unless explicitly routed through the VPN tunnel. ISPs can’t see what sites you visit. Governments can’t easily profile your DNS queries.
What I deliver:
- WireGuard/AmneziaWG VPN deployment
- Encrypted DNS resolvers (Unbound, DNS over TLS)
- Firewall configuration with minimal attack surface
- SSH hardening (key-only auth, fail2ban, custom ports)
- DMARC/DKIM/SPF for email authentication
You get:
- Zero-trust network architecture
- DNS privacy for your entire fleet
- Email that doesn’t land in spam
- A network that’s invisible until you need it
Monitoring & Observability
Complete Stack
From metrics to logs to alerts — I set up everything so you know what’s happening before your users do.
What I deliver:
- VictoriaMetrics — High-performance metrics storage
- Grafana — Custom dashboards for your KPIs
- OpenObserve — Centralized log management
- Uptime Kuma — External endpoint monitoring
- Alerting — Configurable notifications via Telegram, Discord, email
You get:
- Real-time visibility into your infrastructure
- Historical data for capacity planning
- Alerts that actually matter (no alert fatigue)
DevOps & Automation
CI/CD, Containers, Orchestration
I don’t just manage servers — I automate everything.
What I deliver:
- Docker containerization of applications
- Kubernetes cluster setup and management
- CI/CD pipeline design (GitHub Actions, GitLab CI)
- Configuration management (NixOS modules, Ansible)
- Automated backups and disaster recovery
You get:
- “It works on my machine” becomes “it works everywhere”
- Deployments you can trust
- Teams that can ship faster with less risk
Email Infrastructure
Self-Hosted Mail
Hosting your own email is more straightforward than most think. I’ve set up full mail servers with proper authentication, deliverability, and security.
What I deliver:
- Full mail server (Postfix + Dovecot) via NixOS
- DKIM, SPF, DMARC configuration
- Bounce handling and list management
- Webmail setup (Rainloop, Roundcube)
- Spam filtering and virus scanning
You get:
- Email that respects your privacy
- No per-user licensing fees
- Full control over your mail data
Consulting & Audit
Infrastructure Review
Not ready to commit? Start with an audit.
What I deliver:
- Comprehensive infrastructure assessment
- Security review and vulnerability analysis
- Performance optimization recommendations
- Cost optimization for cloud spend
- Technical documentation of your current setup
You get:
- A roadmap tailored to your specific situation
- No sales pitch, just honest technical assessment
- Clear prioritization of what to fix first