Users and branches
Offices, remote teams and secure VPN access
IPsec VPN · Tailscale
Warsaw, Poland · since 2012
I build and run server environments that do not fall over at the first traffic peak: private cloud, configuration automation, and security treated as a layer rather than an add-on.
B2B engagements, under contract, with an agreed response time.
Scope of operations
An example scope for a single production environment. This is not live monitoring data.
What it runs on
Services
From designing the infrastructure, through securing it, to running it day to day with an agreed response time.
Architecture
A layered model connects networking, compute, data and cloud, while automation and observability span the entire environment.
Offices, remote teams and secure VPN access
IPsec VPN · Tailscale
Firewall, VPN, WAF and traffic balancing
Fortigate · WAF · HAProxy
Controlled traffic between zones and services
BGP · NetBox · Cisco
Highly available virtual machines, containers and apps
Proxmox VE · Docker
Distributed storage, backups and restore testing
Ceph · PBS · MinIO
Public and on-premise resources connected by design
Azure · AWS · Google Cloud
Repeatable configuration, infrastructure as code and deployment pipelines.
Metrics, alerts and central logging across every layer.
Technology
Tools chosen for a specific problem. Nothing here is used because it happens to be fashionable.
High-availability Proxmox clusters, distributed storage and containers. Your own cloud instead of someone else’s invoice.
How I work
No audit means no design, no design means no rollout. This order saves money by the third step.
Step 01
Audit and analysis
An inventory of what is actually running and a risk list ordered by business impact. Without this step everything that follows is guesswork.
Step 02
Architecture design
The target shape of the environment, with cost, schedule and a rollback plan. Decisions are made before the rollout, not during it.
Step 03
Implementation
Staged delivery, with configuration described in Ansible and Terraform. Every step is repeatable and reversible.
Step 04
Operations and monitoring
Monitoring with thresholds tuned to real traffic, updates, restore testing and a report on the state of the environment.
Certifications
Hands-on exams and training that genuinely changed how I design environments.
Linux Foundation
A hands-on Linux system administration exam. Tasks are performed live on a running system, with no multiple-choice questions.
Read the postNiebezpiecznik
Training in penetration testing and network attack techniques. The attacker’s perspective is the basis for sane defence.
Read the postCisco
Network design and operations: routing, switching, VLANs and troubleshooting. The foundation for working with BGP and multi-site networks.
Read the postReferences
References from the space, emerging technologies, insurance and insurtech sectors.
Space industry
Emerging technologies
Insurance and insurtech
Blog
Technical notes from practice: configurations, lessons from rollouts and certifications.

4 min read
Deploying GlusterFS behind a 40 TB+ redundant storage cluster on four nodes: volume types, trade-offs, and how it compares to Ceph and BeeGFS.

1 min read
A custom panel for managing cloud servers: automated instance provisioning, online payments, invoicing, 2FA and provider API integration.

1 min read
What the LFCS certification is, how its hands-on exam works, and the full scope of material covered by the LFS201 course.
Contact
The fastest way to get to the point is to outline your current environment and what needs to change in your first message.