← Services


Infrastructure

Infrastructure is only as useful as its connections. A reliable hypervisor with fragmented identity, or a well-segmented network where services cannot authenticate against each other correctly, produces an environment that is hard to operate regardless of the quality of its individual components.

We work across the full stack β€” from bare-metal hypervisors and storage pools through to the identity federation, storage protocols, and API integrations that make heterogeneous systems behave as a coherent whole. On-premise and hybrid environments designed for reliability from the ground up, not patched together reactively.

Virtualisation

We run Proxmox VE as our primary hypervisor β€” a mature KVM-based platform with a clean REST API, native LXC container support, and straightforward cluster management. Virtual machines handle workloads that need full isolation or a custom kernel; LXC containers cover everything else β€” lightweight, booting in under a second, trivial to snapshot and restore.

Storage

Storage design matters more than most teams realise β€” until something fails. We use TrueNAS for shared storage, with ZFS providing end-to-end checksumming, inline compression, and snapshot-based replication. ZFS pools are configured with appropriate redundancy: RAIDZ2 for bulk storage, mirrored vdevs for latency-sensitive databases.

Networking

A flat network with a single VLAN becomes a liability as infrastructure grows. We design segmented networks from the outset β€” server VLAN, management VLAN, IoT isolation, guest networks β€” using pfSense as the perimeter firewall and routing core. Managed switches carry 802.1Q trunks; every VLAN boundary has explicit firewall rules.

Identity and Integration

Most technical debt lives at the boundaries between systems β€” the places where one application assumes something about another that is not documented, enforced, or even visible. We work at exactly these boundaries: connecting identity providers, storage protocols, and APIs so that heterogeneous environments behave as a coherent whole.

Automation

Infrastructure configured by hand drifts. We treat configuration as code: services are defined declaratively, deployments are reproducible, and every change flows through a pipeline. For homelab and small-team environments, Forgejo with a self-hosted runner delivers a complete CI/CD pipeline with no cloud dependency β€” the same pipeline that builds and deploys this site.

Who this is for

Teams running mixed environments: bare-metal servers alongside a VPS or two, with containers for modern workloads. Self-hosters who want proper SSO across their tools rather than a password manager full of individual accounts. Small businesses who want the reliability of enterprise infrastructure without the enterprise price tag.

If your current setup is a collection of servers with no documented topology, manual deployments, and no tested recovery plan β€” that is exactly the kind of situation we start from.