Infrastructure and security operations at scale
Ongoing infrastructure and security operations across a Czech client's on-premise server, a multi-tenant VPS running TABSAP products, and SSL and malware remediation work across roughly 77 domains.
- Client
- Mixed portfolio: Czech industrial client, TABSAP-hosted products, WordPress clients
- Sector
- Infrastructure
- Stack
- Ubuntu · Supermicro · Nginx · Cloudflare · Zabbix · OpenVPN · WordPress
- Year
- 2025
The problem
Production systems don't stay healthy on their own, and the work that keeps them that way rarely produces a single clean story — it's a running list of servers, certificates and incidents that each need to be handled correctly and then handed back to routine operation.
What I built
Across a Czech client's own Ubuntu server running on Supermicro hardware, I troubleshot OpenVPN connectivity, verified the Zabbix monitoring agent was actually reporting, disabled an unused vsftpd service that had no business being open, and installed a weekly audit cron job so drift gets caught automatically rather than at the next incident.
Separately, I run a Hostinger VPS hosting TABSAP's own products behind Nginx virtual hosts, and manage SSL certificates and Cloudflare configuration across roughly 77 domains for various clients and projects — the kind of scale where manual per-domain checks stop being viable and the tooling has to do the checking.
On the WordPress side, I remediated malware infections including the garuda-force campaign across multiple client sites, recovered a client domain that had been flagged as a deceptive site by Google Safe Browsing, fixed WooCommerce caching and SMTP delivery issues, and traced a persistent WPML bug back to its actual root cause — an orphaned admin message that was silently corrupting the multilingual sync.
Outcome
Systems stay monitored and current rather than discovered broken: certificates renew, monitoring agents report, malware gets found and removed with the infection vector closed, and root causes get fixed instead of patched around.
Why it mattered
This is the unglamorous half of the job, and it's also the part that proves the difference between building something and being the person who keeps it running. Anyone can ship a feature; fewer people will trace a WPML sync bug back to an orphaned message instead of settling for a workaround.
- Domains managed
- ~77
Have a system that needs to work in production?
Tell me what's breaking — or what you're building.