Home About Services Projects Blog Contact Hire me
Services

What I do

Four areas I work in day to day, each with a defined scope and a clear deliverable — so you know what you're getting and how you'll know it worked.

Service 01 —

Linux Server Administration

Ongoing operation of your Linux servers so you don't need an in-house sysadmin. Provisioning, patching, tuning, monitoring and the boring maintenance that prevents interesting outages.

  • Server provisioning and baseline configuration
  • OS, kernel and package patch management
  • Apache / Nginx / LiteSpeed and PHP-FPM tuning
  • MySQL / MariaDB configuration and query triage
  • Monitoring setup with alerts that mean something
  • Backup jobs plus scheduled restore verification

Deliverable → documented, monitored, patched servers

Service 02 —

L2 / L3 Managed Hosting Support

Escalation cover for hosting providers and agencies. The tickets your L1 team can't close — root-caused properly, fixed once, and written up so the knowledge stays with your team.

  • Escalated ticket handling within your SLA
  • cPanel / WHM, Plesk and DirectAdmin deep issues
  • Mail flow, queue and deliverability problems
  • DNS, SSL and propagation troubleshooting
  • Performance investigations on loaded servers
  • Runbooks and RCAs your L1 team can reuse

Deliverable → closed tickets + written root cause

Service 03 —

Security Hardening & Incident Response

Two halves of the same job. Before: bring servers up to a defensible baseline. After: contain, clean and document a compromise without destroying the evidence or the customer's data.

  • Security audit against a CIS-aligned baseline
  • SSH, firewall and service exposure lockdown
  • WAF (ModSecurity) rules and tuning
  • Malware, backdoor and rootkit remediation
  • Compromise scoping and containment
  • Post-incident report with prevention steps

Deliverable → hardening report + remediation log

Service 04 —

Server Migrations & Upgrades

Moving live workloads between servers, control panels, data centres or providers — planned so that the customer's only evidence it happened is the email you sent them afterwards.

  • Pre-migration audit and compatibility check
  • Server-to-server and panel-to-panel transfers
  • Staged DNS cutover with TTL management
  • Final delta sync to catch last-minute changes
  • OS, PHP and MySQL major-version upgrades
  • Written rollback plan agreed before we start

Deliverable → migrated workload + rollback plan

Process

How an engagement runs

The same five steps whether it's a single server or a fleet.

Step 01

Discovery

I look at what you actually have — inventory, versions, access paths, monitoring, backups — before proposing anything. Surprises found now are cheap.

Step 02

Plan & sign-off

A written plan: what changes, in what order, in which window, what the risks are, and exactly how we roll back. Nothing starts until you've agreed to it.

Step 03

Safety net

Verified backups and snapshots before a single destructive command runs. I test that the restore works — a backup nobody has restored is a rumour.

Step 04

Execute

The work itself, in the agreed window, with progress visible to you as it happens. If something goes sideways, you hear it from me first, not from a customer.

Step 05

Verify & hand over

Post-change checks against a written test list, then documentation: what changed, why, and what to watch. You keep the knowledge, not just the result.

Always

Aftercare

A defined window after any major change where I'm available if something surfaces. Migrations and hardening changes have a tail — I stay for it.

Working together

Ways I can help

I'm employed full time and open to roles; for contract or project work, tell me the problem and I'll say honestly what I can commit to.

Project-based

A defined piece of work with a start and an end — a migration, a hardening pass, a version upgrade, a post-incident cleanup.

  • Fixed scope, agreed deliverable
  • Written plan before execution
  • Handover documentation included

Ongoing role

Full-time or long-term: day-to-day administration and escalation cover as part of your team, not billed by the ticket.

  • Escalation cover as part of the rota
  • Proactive patching & monitoring
  • Runbooks and RCAs your team keeps

Incident support

Something is down, compromised, or badly broken. Rapid triage, containment first, root cause afterwards — the work I do most.

  • Triage from first alert
  • Containment before cleanup
  • Full incident report afterwards
Questions

Before you ask

Do you work with an existing team?

Always — my current work is alongside an L1 team rather than replacing one. I'm the escalation point and the person who writes down what happened.

Can you work in our maintenance windows?

Yes. Migrations and risky changes almost always happen out of hours — shift work and handover logs are already part of my routine.

How do you handle access and credentials?

Named accounts with the minimum privilege the task needs, key-based SSH, and revocation at the end of the engagement. I don't want your root password in a chat window any more than you do.

What if the migration goes wrong?

That's what the rollback plan is for. It's written and agreed before the window opens, and the old server stays intact and reachable until you confirm you're happy.

Do you provide documentation?

Always. Every engagement ends with a written record of what changed and why. If I disappeared tomorrow, your team should still be able to run what I built.

Which panels and distros do you support?

Primarily RHEL-family (Rocky, Alma, CentOS) and Debian-family (Ubuntu, Debian), with cPanel/WHM, Plesk and DirectAdmin. Plain unmanaged boxes are fine too.

Get started

Tell me what's broken — or what you'd rather not break

Describe the problem in as much or as little detail as you like. I'll come back with how I'd approach it, roughly how long it takes, and where the risks are.