I am a technically focused individual with experience in infrastructure engineering, software development, and privacy‑first systems design. My work blends automation, documentation, and architectural clarity across hardware and software layers.
- Infrastructure resilience using Proxmox, LXC, Docker, Podman (Quadlets), and LXD
- Redundant access pipelines built on pfSense, WireGuard, and segmented subnet routing
- Documentation frameworks inspired by S1000D for modular and traceable system design
- Custom control interfaces in React and Go for orchestration and observability
- Monitoring, fallback logic, and automated recovery strategies for distributed and edge environments
- Self‑hosting, private‑by‑design services, and secure remote access models
- Proxmox VE with a mix of LXC, Docker, and VM workloads
- pfSense/OpeN*Sense as a virtualized gateway for network segmentation and traffic inspection
- Matrix server (Synapse)
- Documentation workflows using Docmost
- Secure access with WireGuard, Pangolin, Cloudflare Zero Trust, and WAF
- DNS strictly via TLS 1.2+
- Always‑on VPN with killswitch and failover
- Grafana dashboards for telemetry and analytics
- Home Assistant OS (VM)
- Automated backups via cron‑driven Bash scripts
- Suricata for active threat detection and alerting
- Leak detection including DNS and WebRTC pathways
- DNS auditing and strict avoidance of Google or other spyware‑oriented resolvers
- DNS using Unbound + Pi‑hole on
lowith metrics exported to Grafana - Secure reverse proxy via Caddy combined with CrowdSec + Firewall‑Bouncer, with metrics exported to Grafana
Infrastructure should be understandable, maintainable, and private by default. I build systems designed to withstand failure gracefully, document themselves intelligently, and operate securely outside of corporate constraints.
Privacy and clarity aren’t optional — they are architectural pillars.
I avoid hosting code on platforms operated by non‑trustworthy third‑party providers with unclear data usage, analysis, and LLM training practices.
All critical development therefore lives on my own self‑hosted infrastructure. I may upload some general ideas in the future, depending on how GitHub and its ownership evolve in 2026 and beyond.
All work is exploratory, built with an emphasis on resilience and modular structure.