Infrastructure I have designed, deployed, and operate. Client identifiers are
anonymized; the engineering is exactly as running in production.
Observability & Security
Open source
Observability & Security Stack
A self-hosted monitoring and SIEM platform for a small fleet of production
servers. Prometheus, Grafana, Loki, and Alertmanager for metrics and logs;
Wazuh for intrusion detection and log correlation. Twenty alert rules split
by scope, fail2ban and nginx rate limiting, all deployed from code.
- 20 alert rules
- 2 sites monitored
- 100% infrastructure as code
Incident Response
Case study
Cryptojacking Rootkit — Detection & Rebuild
A Proxmox host mined Monero behind a userland rootkit disguised as a system
service. I traced the evidence, mapped the hiding techniques, and led the
rebuild and hardening. The write-up covers the detection path and the
indicators that catch this class of attack early.
- LD_PRELOAD rootkit
- 5 hiding techniques
- Full rebuild + runbook
DevSecOps
Open source
DevSecOps Pipeline Patterns
A CI/CD architecture for teams where not everyone who writes code should be
able to reach production. Four automated quality gates on the forge where
contributors work, a single reviewed path to the forge holding the deploy
credentials, and a manual deploy as the last gate. Built with GitHub Actions,
GitLab CI/CD, Docker, Ruff, ESLint, pytest, Trivy, Bandit, and SonarQube.
- 4 quality gates
- 8 scanner & test tools
- 0 secrets in the repo
High Availability
Proxmox HA + Proxmox Backup Server
Dual-node Proxmox cluster with a backup server as a VM on the second node.
Snapshot backups, least-privilege tokens, tested restore, and a documented
failover runbook for node-1 failure.
Included in the stack repository
Infrastructure as Code
Open source
Terraform IaC Patterns
Five reusable Terraform modules across Azure, AWS, and GCP — VNet and
subnets with service delegation, Linux VMs with managed disks, App Service
with VNet integration and deny-by-default restrictions, a two-tier AWS VPC,
and a private GCP instance. Secure defaults, explicit egress, and the
reasoning documented alongside the code.
- 5 modules
- 3 cloud providers
- 8 configs validated