Network Automation
I automate network infrastructure using Ansible, NAPALM, and Nornir. Router, switch, and firewall configurations across multi-vendor environments with security focus.

Security-focused freelance NetDevOps Specialist. I automate networks and systems, manage Linux infrastructure, build CI/CD pipelines, and implement infrastructure as code solutions.
I automate network infrastructure using Ansible, NAPALM, and Nornir. Router, switch, and firewall configurations across multi-vendor environments with security focus.
Linux system administration and automation with security hardening. I manage servers, configure services, and automate repetitive tasks efficiently.
I build end-to-end NetDevOps pipelines with GitOps workflows for network and infrastructure changes. Automated testing, validation, and deployment.
I use Terraform, Ansible, and Pulumi for version-controlled, reproducible network and system infrastructure across any platform.
Kubernetes cluster deployment, Docker containerization, Helm charts, and service mesh implementation with security best practices.
Every solution I build prioritizes security - from network hardening and vulnerability scanning to secrets management and zero-trust architecture.
A lightweight, zero-dependency Rust Linux daemon that restricts ports 80/443 to Cloudflare IPs only via iptables. Single binary, self-installing, runs as a systemd service. Auto-refreshes Cloudflare IP ranges every 7 days at midnight with zero-gap rule swapping. Protects origin s...
Ultra-lightweight Rust daemon that monitors system load with near-zero CPU/RAM overhead and sends real-time alerts via Telegram, Discord, and Mattermost webhooks when thresholds are exceeded.
Self-hosted WireGuard VPN server with web UI. Features: client management, QR codes for mobile, real-time transfer stats, connection logging, API tokens, Tailscale routing. Single Docker container deployment.
"ipv4 reconary" is a network reconnaissance tool designed for discovering hosts, domains, and services based on IP ranges, subnets, and ASNs. It provides security professionals, pentesters, and OSINT researchers with a fast and reliable way to map network infrastructure and ident...
Real-time Certificate Transparency log monitor for tracking SSL certificate issuance. Detect phishing domains, brand impersonation, and unauthorized certificates instantly with regex filtering, DNS resolution, and webhook alerts.
Secure Git webhook handler for automated deployments. Single static binary, runs 24/7 on production. Local build modes. HMAC-SHA256 + Port filtering. Zero secrets on third-party servers. Written in Rust.