󰠮 cat /etc/services — what I offer
󰣨 cat /etc/services
80/tcp # HTTP — 󰏗 Web Infrastructure
443/tcp # HTTPS — 󰀦 SSL/TLS & Security
22/tcp # SSH — 󰣈 Remote Systems Management
465/tcp # SMTP — 󰢮 Email Infrastructure
53/tcp # DNS — 󰌬 DNS & Network Security
41020/udp # WG — 󱂵 VPN & Encrypted Networks

Infrastructure as Code

NixOS Setup & Management

I specialize in NixOS because it turns your entire OS into version-controlled code. Every service, every config, every package — declared, not imperatively installed.

What I deliver:

You get:

Cloud Infrastructure

Explore the focused Cloud Infrastructure service page for architecture, portability, cost and recovery.

Oracle Cloud, AWS, DigitalOcean, Hetzner, etc

I’ve worked on AWS production infrastructure for over a decade, including 5 years hosting one of the world’s top 500 websites, or ranked ~130-140 in the US, with only a handful of other people.

What I deliver:

You get:

Security Engineering

Network & Endpoint Security

My entire fleet runs through a WireGuard VPN with encrypted DNS. Nothing is reachable from the internet except the one public web host, which opens only 80/443 and the TURN ports. Everything else is routed through the VPN tunnel. ISPs can’t see what sites you visit. Governments and corporations can’t easily profile your DNS queries against existing profiles of you.

What I deliver:

You get:

Looking to go further? Offense (recon, pentesting) or defense (monitoring, SOC) — see the Security Services page.

Want this for yourself rather than for a company? The consumer VPN service — WireGuard with a choice of DNS posture — is at VPN Service.

Monitoring & Observability

Explore the focused Monitoring & Observability service page for the complete metrics, logs, dashboards and alerting stack.

Complete Stack

From metrics to logs to alerts — I set up everything so you know what’s happening before your users do.

What I deliver:

You get:

DevOps & Automation

Explore the focused DevOps & Automation service page for CI/CD, containers, orchestration and health-gated delivery.

CI/CD, Containers, Orchestration

I don’t just manage servers — I automate everything.

What I deliver:

You get:

Email Infrastructure

Explore the focused Email Infrastructure service page for submission, authentication, filtering and deliverability.

Self-Hosted Mail

Hosting your own email is more straightforward than most think. I’ve set up full mail servers with proper authentication, deliverability, and security.

What I deliver:

You get:

Consulting & Audit

Infrastructure Audit

Not ready to commit? Start with an audit. This is a scoped, one-off review of the state of your stack: what you actually run, what is exposed, what is not enforced the way you think it is — delivered as a written report where every finding is reproducible, not a score out of ten.

What I deliver:

You get:

What it is not. It is not a certification audit and not an independent opinion. I am one engineer giving you an assessment of your own infrastructure; nothing in the report implies an accredited certification or a third-party attestation, and it will state which areas were checked and which were not. The vocabulary this site permits itself around certifications is set out on Standards & Claims.

The audit I run on my own fleet daily — invariant checks, an ed25519-signed report per host, published keys, monthly roll-ups that freeze once closed — is described at Infrastructure Audit. A client engagement normally stops well short of that, but it is the same method and the same standard of evidence.

󰣻 NixOS Expertise
󰣖 Linux All Distros
󰋖 Cloud Multi-Provider
󰀦 Security Zero-Trust
󰔟 Not sure what you need? Let's figure it out together.
Send me a message describing your infrastructure or your pain points. I'll respond with a technical assessment and a proposed approach — no fluff, no buzzword bingo.
[ SEND REQUEST ]
󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8