DevOps & Infrastructure Engineer

I build, secure, and monitor the infrastructure that keeps systems running.

Three-plus years designing, automating, and hardening hybrid infrastructure across Azure, AWS, GCP, and on-premise environments. I focus on Infrastructure as Code, CI/CD automation, enterprise-grade observability, and security hardening.

  • Indonesia
  • Microsoft Certified: Azure Developer Associate
  • Google Cybersecurity Professional

Selected work

Infrastructure I have designed, deployed, and operate. Client identifiers are anonymized; the engineering is exactly as running in production.

High Availability

Proxmox HA + Proxmox Backup Server

Dual-node Proxmox cluster with a backup server as a VM on the second node. Snapshot backups, least-privilege tokens, tested restore, and a documented failover runbook for node-1 failure.

Write-ups

Technical incident write-ups and detection guides. Anonymized, evidence-based.

Case Study — Cryptojacking Rootkit on a Proxmox Server

How a hidden XMRig miner disguised itself as a Proxmox health service, used an LD_PRELOAD library to hide its process, files, and port, and updated itself daily to survive cleanup. Includes the forensic evidence, the rebuild, and the hardening that followed.

SIEMRootkitIncident response

Detection Signals — Userland Rootkit Mining on Hypervisors

The concrete indicators from the case above: unexpected systemd units, LD_PRELOAD outside distribution packages, processes running from improbable paths, mining-pool connections, and an immutable ld.so.preload. Each with the exact command to check it.

DetectionBlue teamHardening

DevSecOps Architecture — Separating Code Access from Production Access

A CI/CD design where contributors push code freely but cannot reach production: four automated gates on the forge they work on, a single reviewed path to the forge holding the deploy credentials, and a deploy that stays manual. Includes the token-scoping problem that took three attempts, and where this pattern stops being worth its cost.

CI/CDAccess controlDevSecOps

Technical skills

Cloud & IaC

Microsoft Azure, AWS, GCP, Terraform, Terraform Cloud, Proxmox VE, PBS

Containers & Ops

Docker, Kubernetes (KubeAdm), Dokku, Nginx, Nexus3

CI/CD & VCS

Azure DevOps, GitLab CI, Jenkins, GitHub Actions, SonarQube, Git

Monitoring & SIEM

Prometheus, Grafana, Zabbix, Loki, ELK, Alertmanager, Uptime Kuma, Wazuh SIEM

Security & IAM

Active Directory, Azure Key Vault, Private Endpoints, NSG, SSL/TLS, fail2ban, IAM

OS & Scripting

Linux (Debian, AlmaLinux, Rocky), Bash, Python, PowerShell

Certifications

  • Microsoft Certified: Azure Developer Associate — Microsoft
  • Google Cybersecurity Professional Certificate — Google
  • Sekolah DevOps Mentoring Program — Cilsy Fiolution Indonesia (2022)

Let's work together

Open to infrastructure, DevOps, and security work. The fastest way to reach me is email.