Pravin T.
Senior DevOps and Infrastructure Engineer | AWS | Docker | Linux
23+ years in Linux/Windows administration, DevOps, and cloud infrastructure. I build, secure, and scale production systems 24/7 โ for MSP clients and direct engagements across industries. If your server is down, your deployment is failing, or you need infrastructure built right the first time โ I'm the engineer you call. โโ SERVER & SYSTEMS โโ Linux (CentOS, Debian, Ubuntu, Amazon Linux, Rocky Linux) and Windows Server (2012โ2025). Active Directory, Group Policy, Intune, hybrid identity. Nginx, Apache, Sendmail, Qmail, Postfix, Exim โ MTA setup, Dovecot, SpamAssassin, OpenDKIM, SPF/DKIM/DMARC. Veeam, Acronis, cloud-native DR. Hypervisors: KVM, VMware ESXi, Hyper-V, Proxmox VE โ HA clusters, live migration, Ceph/ZFS, Proxmox Backup Server. Redis, Varnish. QNAP NAS โ storage management, Plex Media Server deployment, VPN tunnel integration. WHM/cPanel, Plesk, Virtualmin, CloudPanel, CyberPanel. โโ CLOUD INFRASTRUCTURE โโ AWS: EC2, ECS, EKS, RDS, S3, Route 53, IAM, VPC, CloudWatch, Lambda, API Gateway, Elastic Disaster Recovery. GCP: Cloud Run, Cloud Build, Firestore, GKE, IAM, VPC, Pub/Sub, Cloud Storage, Secret Manager, Cloud Monitoring. Cloudflare (WAF, Workers, Zero Trust, CDN). DigitalOcean, Hetzner, Vultr. MinIO: S3-compatible object storage on bare metal, VMs, Kubernetes โ distributed mode, SSE-S3/KMS, lifecycle policies, drop-in S3 for backups and MLOps. Railway: Full-stack PaaS โ GitHub/Docker auto-build, managed DBs (PostgreSQL, MySQL, Redis), private networking, env variables, cron workers, auto-scaling. โโ SECRETS MANAGEMENT โโ HashiCorp Vault: Dynamic secrets for AWS IAM, databases, cloud providers โ TTL-bound credentials, auto-revoke. PKI for internal CA and on-demand TLS. Vault Secrets Operator for Kubernetes (etcd-free pod injection). Raft HA, RBAC, audit logging, Shamir unseal. Transit engine for encryption-as-a-service. CI/CD integration to eliminate hardcoded credentials. โโ DEVOPS & CI/CD โโ Docker, Kubernetes (EKS + self-managed: kubeadm, k3s, RKE2), Helm, Kamal. GitHub Actions, GitLab CI, Bitbucket Pipelines. Terraform, Ansible. ArgoCD, Flux (GitOps). Prometheus, Grafana, Datadog. Traefik: Cloud-native ingress โ auto TLS, Docker/K8s service discovery, ForwardAuth, rate limiting, canary routing. Caddy: Zero-config-TLS reverse proxy โ automatic HTTPS, on-demand certs. Preferred for self-hosted stacks. โโ NETWORKING & SECURITY โโ WireGuard, OpenVPN (MFA/ZTNA), IPSec/Libreswan, Xray/REALITY. Tailscale/Headscale โ self-hosted mesh VPN, VPS tunnel setup, ACL policies, subnet routing. MikroTik, Juniper, SonicWall, Fortinet (FortiGate, FortiManager, FortiAnalyzer). pfSense, OPNsense. BGP, OSPF. Auth0, OAuth2, OIDC, Duo Security. LDAP/RADIUS, 802.1x, NPS/AD CS/Intune. โโ DEVELOPMENT & AUTOMATION โโ Python: FastAPI, Flask, Django, RESTful APIs, OpenAI API, ETL pipelines (Airbyte), orchestration (Airflow, n8n), data processing (pandas), Retool internal tools. Clean, documented, production-ready code. โโ CONTAINERIZATION & DEPLOYMENT โโ Docker Compose, Kubernetes manifests, Helm. Portainer, Coolify, Elestio, Traefik, Caddy. MinIO (K8s Operator/Tenant). Nextcloud, n8n, self-hosted app deployment. Vercel, Railway, Netlify, Replit. โโ MSP & VOIP โโ Duo Security, SpamTitan, ScreenConnect, ESET, Acronis. M365 multi-tenant administration. Asterisk and Vicidial (AWS + on-prem) โ SIP trunks, IVR, call center setup, NetSIP integration. โโ LEGACY & EARLY CAREER โโ Foundational background in Windows desktop application development (VB, C#, Access) and web development (Core PHP, Laravel). โโ WHAT CLIENTS HIRE ME FOR โโ โบ Emergency triage: servers down, services failing, breaches in progress โบ Greenfield AWS/cloud environments built to security and compliance best practices โบ CI/CD pipelines rebuilt to work reliably โ no more failed deployments at 2am โบ Self-hosted stacks that cut cloud bills without cutting uptime โบ Kubernetes from scratch: EKS, k3s, RKE2 โ setup, Helm, GitOps, day-2 operations โบ HashiCorp Vault rollouts โ eliminate hardcoded credentials across all pipelines โบ Proxmox VE clusters: HA, live migration, Ceph storage, Proxmox Backup Server โบ Network redesigns: Zero Trust, WireGuard mesh, BGP multi-homed, FortiGate, pfSense โบ Ongoing managed infrastructure support and 24/7 incident response โบ GCP solution design & delivery โ Cloud Run, microservices, IAM, developer onboarding/offboarding โบ Infrastructure, Security & Application Audits โ server, network, database, cloud, and web stack โโ INDUSTRIES SERVED โโ SaaS ยท Fintech ยท Healthcare ยท E-commerce ยท Legal ยท Real Estate ยท Media ยท Education ยท Government ยท Telecoms ยท Startups ยท Enterprise. Single-server MVPs to multi-region, multi-account production environments. โโ COMMUNICATION & PROCESS โโ I don't disappear after the kickoff call. Clear updates at every stage, thorough documentation, and a proper handover on every engagement. Timezone-flexible. Slack, Teams, WhatsApp, Zoom, or Webex. If the work matters, it gets done right.