Four overlapping practices. Most engagements pull from two or three at once.
/ 01
Platform Engineering
Design and build internal platforms on Hetzner, Proxmox, OpenStack or bare-metal. Pulumi-based IaC, Cloudflare DNS, Let's Encrypt + Caddy, Ansible-driven configuration. The full IGN8 hub-and-spoke pattern, or just the pieces you need.
PulumiAnsibleHetznerCloudflareCaddyProxmox
/ 02
Ansible Automation Infrastructure as Code
Opinionated Ansible — the path is paved so teams can run their first automation on day one, not after a quarter of plumbing. Two delivery shapes from the same code: enterprise via Ansible Automation Platform (AAP), or self-hosted and containerized via Podman Quadlets. Inventory, credentials, execution environments, job templates, RBAC and rollouts — all defined as code, all reproducible.
AnsibleAAPQuadletsPodmanExecution EnvsGitOps
/ 03
Security & Vulnerability Management
NVD sync, fleet-wide vulnerability scanning (OpenVAS, OVAL, RH Insights), automated triage with GitHub Issues, secret management with HashiCorp Vault. Compliance-aware without the paperwork theatre.
VaultOpenVASOVALNVDFastAPI
/ 04
Full-Stack Product Builds
When the infrastructure needs a UI on top: Django + DRF backends, Next.js frontends, Chrome extensions for capture flows. Pragmatic shipping over framework purity.
DjangoDRFNext.jsReactPostgres