We do not name clients. We do not publish case studies with identifying details. What we can share is the architecture — anonymised descriptions of problems solved, systems built, and infrastructure delivered.
Client operated across three physical sites with independent legacy hypervisor clusters (VMware, deployed by previous provider), no cross-site failover, and aging SAN infrastructure approaching end-of-life. VMware licensing costs were escalating after the Broadcom acquisition. Public cloud was contractually prohibited by their regulatory framework.
Designed and deployed a three-site Proxmox VE cluster with Ceph (ceph.io) storage, VXLAN overlay for Layer 2 extension, and automated failover with sub-30-second recovery time. Built air-gapped by default — all nodes operate without internet access, updates flow through VPRS proxy. Cross-site connectivity via WireGuard mesh with BGP for dynamic path selection.
Zero unplanned downtime in 18 months. Storage costs reduced by 60% moving from proprietary SAN to Ceph (ceph.io) on commodity hardware. Client now operates a single logical datacenter across three physical locations.
Flat network architecture with no segmentation. VPN access granted broad network-level permissions. No identity-bound access controls. Multiple security audit failures citing lack of network segmentation and privileged access management.
Deployed Wazuh SIEM across all endpoints for threat detection and compliance monitoring. Implemented Netbird zero-trust mesh VPN with posture checking — every connection verified against OS patch level, disk encryption status, and device identity before tunnel establishment. Deployed VPMS (JumpServer) for all privileged access with session recording and Kratos one-time-password enforcement. Segmented network into 12 VLANs with inter-VLAN firewall policies managed through OPNsense.
Passed subsequent security audit with zero findings. Mean time to detect security events reduced from days to minutes. All privileged sessions now recorded and auditable.
Client needed a container orchestration platform for internal applications but could not expose any infrastructure to the public internet. Existing deployment process was manual — SSH into servers, copy binaries, configure by hand.
Deployed VKBS (Talos Linux + Cilium + containerd) as a fully air-gapped Kubernetes cluster. Container images served from VCRS (Harbor) with Antivirus API scanning at push time. OS updates delivered through VPRS proxy. DNS resolution handled by VDNS with split-horizon configuration. All cluster communication restricted to internal VXLAN — no node has a default route to any external network.
Application deployment time reduced from hours to minutes. First air-gapped Kubernetes deployment in the organisation. Platform now hosts 40+ internal services with automated CI/CD through internally-hosted GitLab runners.
Single-site deployment with no disaster recovery capability. Backup strategy was manual, untested, and stored on the same physical infrastructure as production. A cooling failure in the primary datacenter would mean total data loss.
Deployed VBKS with immutable backup chains to VNAS storage. Replication to secondary site via WireGuard tunnel with automated failover testing every 72 hours. Proxmox VE HA cluster configured with quorum across sites. Documented and tested recovery runbook — full site failover completes in under 4 minutes.
Recovery Time Objective of 5 minutes achieved and verified through automated testing. Recovery Point Objective of 15 minutes. Client survived a primary site power outage with zero data loss and 3 minutes of service interruption.
Client was dependent on Microsoft Entra ID for authentication across their entire application stack. Regulatory changes in their sector required identity data to remain within EU jurisdiction with no exposure to US-based infrastructure. Microsoft 365 and Entra ID could not meet this requirement.
Deployed VIDS (Zitadel-based identity system) as a drop-in replacement. Migrated 500+ user identities, configured OpenID Connect and SAML integration across 12 internal applications, and federated with the client's existing LDAP directory. Deployed VPWS (Vaultwarden) for company-wide password management. Ran parallel for 30 days — Entra ID and VIDS side by side — before cutting over.
Full migration completed with zero authentication downtime. All identity data now stored on EU infrastructure. Client no longer dependent on any US-based identity provider.
“This page exists because infrastructure engineering is evidence-based. We cannot name our clients. We can describe our work. If you need more detail, become a client — and you will see it firsthand.”