Home About Services Projects Blog Contact Hire me
Open to new opportunities

Alan Joy.

Software Engineer — Server Support

I keep production Linux infrastructure fast, hardened and online for a global managed-hosting client base. L2/L3 escalations, malware forensics and compromise recovery, InnoDB data recovery, and planned zero-downtime migrations on AWS — diagnosis through to an evidence-backed RCA.

fleet-monitor — 44 nodes
0 Years in managed hosting
L2/L3 Escalation tier
0 Largest database migrated
45–80 Peak load average resolved
Alan Joy

Alan Joy

Software Engineer — Server Support

  • Role Software Engineer
  • Employer Bobcares
  • Tier L2 / L3 escalation
  • Experience 2 years
  • Location Kochi, Kerala, India
  • Languages English, Malayalam, Hindi
About me

The engineer who gets the ticket after it's already been escalated twice.

I'm a software engineer working web hosting and server support at Bobcares in Kochi, handling the managed-hosting side of infrastructure — the place where a scanner burst without LVE caps, a disk-full event or a rogue systemd service turns into a customer outage within minutes.

Most of my day is L2 and L3 escalations across shared, VPS and dedicated Linux servers for a global client base: reproducing the fault, attributing load properly with pidstat and iostat instead of guessing, applying a fix that holds, and writing the RCA the client actually receives. The rest is planned work — malware forensics and compromise recovery, database recovery, and migrations customers shouldn't be able to feel.

I care about two things above all: not losing data, and not surprising the client. The PHP 5.6 → 8.2 migration I led ran header-based ALB routing so the new stack could be tested live before anyone was moved onto it, with a target-group rollback measured in seconds. I'm currently extending that into DevOps and cloud — AWS certifications in progress, GCP next.

RHEL / CentOS / Rocky Ubuntu / Debian cPanel / WHM Plesk DirectAdmin CloudLinux & LVE Apache / Nginx / LiteSpeed MySQL / MariaDB Exim / Postfix / Dovecot ModSecurity / CSF AWS EC2 / ALB / S3 Zabbix / Grafana
What I do

Services

Four things I do properly, rather than twenty things I do adequately.

01 —

Server Administration

Day-to-day operation of Linux fleets: provisioning, patching, tuning and keeping the lights on.

  • Provisioning & baseline config
  • Patch & kernel management
  • Apache / Nginx / PHP-FPM tuning
  • Monitoring & alert design
02 —

L2 / L3 Hosting Support

Escalated tickets that L1 can't close — root-caused, fixed, and documented so they stay closed.

  • Escalation handling & SLA response
  • cPanel / WHM & Plesk deep issues
  • Mail flow & deliverability repair
  • Written root-cause analysis
03 —

Security & Incident Response

Hardening before the incident, and calm, methodical cleanup after one.

  • CIS-aligned hardening baselines
  • Malware & rootkit remediation
  • Firewall, WAF & SSH lockdown
  • Post-incident forensics report
04 —

Migrations & Upgrades

Moving live workloads between servers, panels or providers without customer-visible downtime.

  • Server-to-server & panel migrations
  • DNS cutover & TTL planning
  • OS / PHP / MySQL version upgrades
  • Tested rollback plan, every time
Toolbox

Technical skills

What I work with day to day across a global managed-hosting estate.

Control panels

cPanel / WHM Plesk DirectAdmin CloudLinux & LVE WHMCS Softaculous

OS & web

RHEL CentOS Rocky Linux Ubuntu Debian Apache Nginx LiteSpeed PHP-FPM / CGI LAMP & LEMP tuning

Databases

MySQL MariaDB InnoDB crash recovery Corruption repair Dump / restore Slow-query tuning Index tuning Replication basics

Security

Malware forensics Webshell / backdoor removal ModSecurity (OWASP/Comodo) CSF iptables firewalld Fail2Ban Imunify / maldet / ClamAV KernelCare SSH hardening Security audits

Cloud & migration

AWS EC2 ALB S3 / EBS AWS Backup SSM Session Manager IAM DigitalOcean Cloudflare Laravel Forge GCP (learning) Cutover & rollback planning

Mail & DNS

Exim Postfix Dovecot SMTP / IMAP / POP3 SPF DKIM DMARC Spam filtering RBL delisting SSL/TLS & AutoSSL acme.sh

Monitoring & tools

Zabbix Grafana Nagios sar / pidstat / iostat top / atop journalctl Bash scripting Git & Gitolite rsync PM2 Node.js services

Applications

WordPress Joomla! PrestaShop Magento WooCommerce CS-Cart DotNetNuke

Support workflow

WHMCS Freshdesk Tawk SLA-driven ticketing RCA documentation Client reporting Shift handover logs
Selected work

Incidents & projects

Real production problems I've owned end to end, from first alert to written RCA.

Migration

PHP 5.6 → 8.2 platform migration

Led the migration of a high-traffic AWS-hosted client to Ubuntu 24.04, Apache 2.4 and MariaDB 10.11 with a ~176 GB database — header-based ALB routing so the new stack could be tested live before any user was moved, full dump/restore sync, and a Gitolite auto-deploy pipeline.

AWS ALBUbuntu 24.04MariaDBGitolite

→ Seconds-level target-group rollback path

Data recovery

WooCommerce recovery after InnoDB corruption

A disk-full event corrupted InnoDB and forced a MariaDB rebuild on a DirectAdmin server. Recovered order, tax, attribute and shipping data for multiple stores by working from pre-rebuild data-directory snapshots.

InnoDBMariaDBDirectAdminWooCommerce

→ Live commerce data recovered, not written off

Incident

Rootkit-level compromise containment

Investigated and contained active compromises involving rogue systemd services, /etc/ld.so.preload hooks, hidden payload fetchers, webshells and crypto-mining processes — forensic log analysis, cleanup and post-incident hardening on WordPress and Joomla estates.

Forensicsld.so.preloadsystemdHardening

→ Contained, cleaned and hardened against repeat

Next step

Got a server that needs looking after?

Whether it's an escalation you can't close, a migration you'd rather not do at 2am, or a fleet that's never been properly hardened — send me the details and I'll tell you honestly what I'd do.