Available for remote work

Networking & Server Hardening
for Your Business

I'm a hands-on network and infrastructure engineer. With spare capacity in my schedule, I decided to offer my well-developed skills to small and medium businesses — at fair rates, without corporate overhead.

Server Hardening

Lock down your servers against common and advanced threats.

  • SSH hardening & key-only access
  • Firewall configuration (nftables / UFW)
  • Fail2ban & intrusion prevention
  • Kernel security tuning
  • Automated security updates

Network Engineering

Design, configure, and troubleshoot networks of any scale.

  • MikroTik / RouterOS configuration
  • VLAN segmentation & routing
  • VPN setup (WireGuard / OpenVPN / SSTP)
  • Firewall rules & NAT policies
  • Network monitoring & diagnostics

Firewall & Access Control

Precise traffic control — only what's needed gets through.

  • nftables / iptables rulesets
  • Zone-based firewall design
  • Port knocking & rate limiting
  • Application-layer filtering
  • Audit & documentation

Monitoring & Observability

Full observability stack — metrics, logs, uptime, real-time dashboards.

  • Prometheus + Grafana + Grafana Alloy
  • Zabbix / Netdata real-time monitoring
  • Loki log aggregation + Promtail
  • Uptime Kuma status pages
  • cAdvisor container metrics
  • Telegram / Email / Slack alerts

Containers & Orchestration

Run workloads in containers — Docker, Podman, or Nomad orchestration.

  • Docker & Docker Compose
  • Podman rootless containers
  • HashiCorp Nomad scheduling
  • Container registry setup
  • Image security scanning

Linux Administration

Day-to-day server management and optimization.

  • Server setup & provisioning
  • Performance tuning
  • Backup & disaster recovery
  • Service management (systemd)
  • CI/CD pipeline setup

Infrastructure Automation

Repeatable, reliable deployments with modern tooling.

  • Ansible playbooks & roles
  • Bash / Python scripting
  • GitLab CI/CD pipelines
  • Nomad job specifications
  • Configuration management

Why Me?

I'm a full-time infrastructure engineer based in Ukraine. Having built solid skills managing networks, hardening servers, and automating infrastructure — I now have the bandwidth to help small and medium businesses that need professional-grade solutions without enterprise-level pricing.

Just solid engineering work, documented and delivered.

UbuntuDebianOracle Linux FreeBSDsystemdSELinuxAppArmor MikroTikCisco IOSnftablesiptables UFWfirewalldWireGuardOpenVPN IPsecHAProxyNginxTraefikCaddy PrometheusGrafanaGrafana AlloyZabbix NetdataUptime KumaLokiELK Stack mktxp DockerPodmanDocker ComposeNomad KubernetesProxmoxVMware ESXi GitLab CI/CDGitHub ActionsJenkins AnsibleTerraformChef BashPythonGoPowerShell PostgreSQLMySQL / MariaDBRedis MongoDBOracle DBSQLite AWSGoogle CloudAzureOracle Cloud DigitalOceanFail2banLet's Encrypt

Let's talk about your infrastructure

Tell me what you need — I'll give you an honest assessment and a clear quote.

Choose the channel that is most convenient for you. Messengers are checked faster; email is the fallback.

Build Your Service Package

Select the specific services you need — I'll prepare a tailored proposal.

Your Selection

Select services from the right panel to build your custom package.
0 services selected
Copy the request, then choose where to send it.

Server Hardening

SSH Hardening
Key-only auth, non-standard port, connection limits
Firewall Setup (nftables / UFW)
Inbound/outbound rules, default deny, logging
Fail2ban & Intrusion Prevention
Brute-force protection, custom jails, ban policies
Kernel Security Tuning
sysctl hardening, disable unused modules, ASLR
Automated Security Updates
Unattended upgrades, reboot policies, rollback

Network Engineering

MikroTik / RouterOS Configuration
Full router setup, firewall, queues, scripting
VLAN Segmentation & Routing
Network isolation, inter-VLAN routing, trunk ports
VPN Setup (WireGuard / OpenVPN)
Site-to-site, remote access, split tunneling
NAT & Port Forwarding
SNAT/DNAT, masquerade, hairpin NAT
Network Diagnostics & Troubleshooting
Packet capture, latency analysis, connectivity issues

Monitoring & Observability

Prometheus + Grafana Stack
Full monitoring stack deployment and configuration
Grafana Alloy (Collector)
Unified telemetry collector for metrics, logs, traces
Zabbix Monitoring
Enterprise monitoring, auto-discovery, templates
Netdata Real-time
Per-second metrics, zero-config, anomaly detection
Uptime Kuma
Status pages, HTTP/TCP/DNS monitoring, notifications
Log Aggregation (Loki + Promtail)
Centralized logs, search, retention policies
cAdvisor Container Metrics
Docker/Podman resource usage, performance data
Custom Dashboards & Alerts
Tailored metrics, thresholds, Telegram/email/Slack alerts

Containers & Orchestration

Docker / Compose Setup
Containerization, multi-service stacks, volumes
Podman Rootless Containers
Daemonless, rootless, OCI-compliant containers
HashiCorp Nomad
Workload scheduling, job specs, cluster management
Container Registry
Private registry, image management, security scanning

Automation & DevOps

Ansible Automation
Playbooks, roles, idempotent server configuration
GitLab CI/CD Pipelines
Build, test, deploy automation
Bash / Python Scripting
Custom automation scripts, cron jobs, integrations
Backup & Disaster Recovery
Automated backups, integrity checks, recovery plans