Adrian P.
On-Prem Infrastructure Specialist | Linux, DevOps, Disaster Recovery
Over 20 years hands-on with GNU/Linux and 10+ years delivering remote IT solutions for international clients, I specialize in on-premise and hybrid infrastructure: bare-metal servers, advanced networking, virtualization, self-hosted services, and disaster recovery โ with data sovereignty and business continuity as first-order requirements, not afterthoughts. I work across the full stack of a physical deployment, from hardware and network topology up through the services running on it โ solving problems purely cloud-native engineers often can't, which is why clients keep me on for years, not weeks. I take on engagements of very different sizes: full builds and migrations, but also focused audits, one-off configuration work, and ongoing "call me when something breaks" support. Not sure your project fits? Ask โ I'd rather tell you honestly than take the wrong scope. AREAS OF EXPERTISE Bare-Metal Management & Virtualization Deployment, configuration, thermal optimization, and administration of high-performance physical servers. Stack: GNU/Linux (Debian, Ubuntu, Arch Linux), Proxmox VE, Unraid, VMware ESXi, QEMU/KVM. Advanced Networking & Perimeter Security Design of secure topologies, VLAN segmentation, traffic optimization, and failover/load-balancing โ including in remote or hard-to-reach environments. Stack: MikroTik (RouterOS), pfSense, OpenWRT, WireGuard, OpenVPN, Tailscale, ZeroTier. Container Orchestration & CI/CD Microservices architecture and pipeline implementation to automate the software lifecycle. Stack: Docker, Docker Compose, Portainer, Gitea Actions, Sonatype Nexus. Data Sovereignty & Enterprise Self-Hosting Private, self-hosted deployments under strict privacy requirements, with proactive monitoring. Stack: Gitea, Nextcloud, Bitwarden/Vaultwarden, Alloy, Prometheus, Loki, Grafana. Business Continuity & Disaster Recovery Automated, immutable backup architectures โ tested, not just configured. Stack: BTRFS, Restic, AWS S3, Backblaze B2. Centralized Authentication (SSO) User management, permissions, and identity integration across on-premise, hybrid, and corporate domains. Stack: OpenLDAP, Active Directory, MS Entra. Industrial & Commercial Product Engineering Linux OS integration for commercial/industrial hardware, physical/virtual test bench design for remote testing and monitoring, and Q&A validation across the product lifecycle. Stack: SaltStack, custom Linux ISO builds, VPN/PKI certificate lifecycle automation. Technical Leadership & Advisory Direct ownership of architecture and security decisions within cross-functional teams โ from strategic advisory through hands-on implementation, without dedicated management structure. Comfortable operating independently under open-ended, high-pressure mandates. KEY ACHIEVEMENT โ DISASTER RECOVERY UNDER EXTREME CONDITIONS In 2022, a data center I managed was caught inside an active conflict zone in Eastern Europe, facing imminent risk of destruction with no advance warning. I planned and remotely executed a full migration to Hetzner cloud โ while the hardware was being dismantled on-site under threat of bombardment โ improvising a temporary network topology and standing up a high-availability cluster with minimal downtime. Result: zero loss of corporate data. Once the hardware crossed international borders, I remotely coordinated its re-deployment to a new, secure data center in the European Union โ again with zero data loss. REMOTE RELIABILITY 10+ years remote-first means my home infrastructure meets the same standard I deploy for clients: high-capacity UPS backup, redundant internet connections, and monitored uptime โ so "I work remotely" doesn't mean "I might disappear mid-incident." AVAILABILITY Current availability: 20 hours/week (up to 30 during busier periods). Working window: 18:00โ10:00 CET/CEST โ overlaps comfortably with US Eastern and US Pacific business hours, plus full-day overlap with Central Europe. RATE Anchor rate: $35/hour (hourly contracts). Fixed-price available on request for scoped audits or one-off configuration work. SERVICES - Planning, deployment, and configuration of new on-premise or hybrid infrastructures. - Maintenance, scaling, and migration of existing infrastructures. - Infrastructure audits and focused troubleshooting (smaller-scope engagements welcome). - Networking & perimeter security design (VLANs, failover, VPN). - Backup architecture and disaster recovery planning/testing. - SSO / identity integration (on-prem, hybrid, cloud). - OS customization / rebranding, test bench design, and QA support for embedded/commercial hardware products. - Long-term B2B strategic consulting.