Services
Infrastructure as Code
NixOS Setup & Management
I specialize in NixOS because it turns your entire OS into version-controlled code. Every service, every config, every package — declared, not imperatively installed.
What I deliver:
- Complete NixOS setup for services I deploy
- Modular config system shared across all hosts
- Declarative service configurations (web servers, databases, monitoring)
- CI/CD deployment pipelines running where you want
- Atomic upgrades with instant rollback capability
You get:
- 99.98%-99.99% uptime
- Reproducible environments (dev = staging = prod)
- Full audit trail of every system change
- One config file to rule them all
Cloud Infrastructure
Explore the focused Cloud Infrastructure service page for architecture, portability, cost and recovery.
Oracle Cloud, AWS, DigitalOcean, Hetzner, etc
I’ve worked on AWS production infrastructure for over a decade, including 5 years hosting one of the world’s top 500 websites, or ranked ~130-140 in the US, with only a handful of other people.
What I deliver:
- Cloud-native architecture design
- Cost-optimized instance provisioning
- Multi-host coordination and networking
- Backup and disaster recovery strategies
You get:
- Infrastructure that scales with your budget
- No vendor lock-in (configs are portable across providers)
- Hidden costs eliminated through creative configuration
Security Engineering
Network & Endpoint Security
My entire fleet runs through a WireGuard VPN with encrypted DNS. Nothing is reachable from the internet except the one public web host, which opens only 80/443 and the TURN ports. Everything else is routed through the VPN tunnel. ISPs can’t see what sites you visit. Governments and corporations can’t easily profile your DNS queries against existing profiles of you.
What I deliver:
- Full state of the art VPN deployments
- Encrypted DNS resolvers
- Firewall configuration with minimal attack surface
- SSH hardening
- DMARC/DKIM/SPF for email domain authentication
You get:
- Zero-trust network architecture
- DNS privacy for your entire fleet
- Email that doesn’t land in spam
- A network that’s invisible until you need it
Looking to go further? Offense (recon, pentesting) or defense (monitoring, SOC) — see the Security Services page.
Want this for yourself rather than for a company? The consumer VPN service — WireGuard with a choice of DNS posture — is at VPN Service.
Monitoring & Observability
Explore the focused Monitoring & Observability service page for the complete metrics, logs, dashboards and alerting stack.
Complete Stack
From metrics to logs to alerts — I set up everything so you know what’s happening before your users do.
What I deliver:
- VictoriaMetrics — High-performance metrics storage
- VictoriaLogs — Centralized log storage and search
- Grafana — Custom dashboards for your KPIs
- Uptime Kuma — External endpoint monitoring
- Alerting — Configurable notifications via Telegram, Discord, Slack, email
You get:
- Real-time visibility into your infrastructure
- Historical data for capacity planning
- Alerts that actually matter (no alert fatigue)
DevOps & Automation
Explore the focused DevOps & Automation service page for CI/CD, containers, orchestration and health-gated delivery.
CI/CD, Containers, Orchestration
I don’t just manage servers — I automate everything.
What I deliver:
- Containerization of applications
- Kubernetes cluster setup and management
- CI/CD pipeline design
- Configuration management
- Automated backups and disaster recovery
You get:
- “It works on my machine” becomes “it works everywhere”
- Deployments you can trust
- Teams that can ship faster with less risk
Email Infrastructure
Explore the focused Email Infrastructure service page for submission, authentication, filtering and deliverability.
Self-Hosted Mail
Hosting your own email is more straightforward than most think. I’ve set up full mail servers with proper authentication, deliverability, and security.
What I deliver:
- Full mail server setup
- DKIM, SPF, DMARC configuration
- Bounce handling and list management
- Webmail setup or configuration documentation
- Spam filtering and virus scanning
You get:
- Email that respects your privacy
- No per-user licensing fees
- Full control over your mail data
Consulting & Audit
Infrastructure Audit
Not ready to commit? Start with an audit. This is a scoped, one-off review of the state of your stack: what you actually run, what is exposed, what is not enforced the way you think it is — delivered as a written report where every finding is reproducible, not a score out of ten.
What I deliver:
- An inventory of what is really running — hosts, services, ports open to the internet, DNS, mail, backups
- A security review: firewall rules, SSH access paths, TLS, authentication, secret handling
- A configuration review against your declarative source (NixOS, Ansible, Terraform) — or against the live state, if there is no source to read
- The logging posture, checked behaviourally rather than read off a config file: re-apply the setting, send a probe, then look for what was written
- Performance and cloud-spend findings, each with the number that justifies it
- Findings ranked by what to fix first, with the evidence for each attached
You get:
- A report you can hand to your own team or your board, because each finding can be re-run
- A remediation roadmap scoped to your budget rather than a wishlist
- No sales pitch: the deliverable is the document, whether or not you hire me to do the fixing
What it is not. It is not a certification audit and not an independent opinion. I am one engineer giving you an assessment of your own infrastructure; nothing in the report implies an accredited certification or a third-party attestation, and it will state which areas were checked and which were not. The vocabulary this site permits itself around certifications is set out on Standards & Claims.
The audit I run on my own fleet daily — invariant checks, an ed25519-signed report per host, published keys, monthly roll-ups that freeze once closed — is described at Infrastructure Audit. A client engagement normally stops well short of that, but it is the same method and the same standard of evidence.