rokky.online

Infrastructure engineering

Infrastructure that stays predictable.

Linux, MikroTik, VPN, Docker, Nginx, monitoring, backups. Clean changes, clear rollback paths, and documentation that actually helps at 3 a.m.

Linux MikroTik VPN Docker Nginx Monitoring

What “good” looks like

Not flashy. Not fragile. The kind of infrastructure that behaves the same on Tuesday afternoon and during an incident.

Server racks in a datacenter

Services

Practical help across the stack — from routing and access to deployments and visibility. Minimal drama, maximum clarity.

Abstract infrastructure stack panels and routes

Linux server administration

Hardening, upgrades, incidents, performance, baseline standards that don’t rot.

MikroTik routing & switching

Routing, VLANs, firewall, QoS, and safe remote management without lockouts.

VPN & secure remote access

WireGuard/IPsec, access policies, onboarding, and audit-friendly setup.

Security hardening

Least privilege, safe exposure, logging, and “no surprises” access control.

Docker & containers

Compose deployments, health checks, image hygiene, and rollbacks you can trust.

Nginx / reverse proxy

HTTPS, routing, sane headers, timeouts, and configs you can read later.

Monitoring & alerting

Signals over noise. Alerts that wake you up only when they should.

Backups & recovery

Automated backups, retention, restore drills, and a clear “restore story”.

Approach

Less folklore, more repeatability. The goal is infrastructure you can reason about.

Automation

Repeatable steps. Minimal drift. Changes you can reproduce, not “recreate”.

Documentation

Runbooks, diagrams, and “how to revert” — not just “how it works on my laptop”.

Reliability

Safer rollouts, rollback paths, and redundancy where it pays for itself.

Transparency

Clear scope, clear trade-offs, and status updates that don’t waste your time.

Security-first

Access control, logging, least privilege, and conservative defaults.

Work examples

A few common storylines. The details always depend on constraints and risk appetite.

Abstract delivery timeline with cards and flow

VPN rollout for distributed team

  • Problem: fragmented access and ad-hoc tunnels
  • Action: WireGuard design + access policy + onboarding that doesn’t require heroics
  • Result: predictable access, easier audits, fewer “it worked yesterday” surprises

MikroTik firewall cleanup

  • Problem: rules grown over time, unclear intent
  • Action: normalize rules, address lists, safe remote admin, a rollback window
  • Result: simpler change management and fewer “don’t touch it” zones

Containerized app behind Nginx

  • Problem: unstable deployments, manual steps
  • Action: Docker Compose + Nginx reverse proxy + health checks + sensible timeouts
  • Result: repeatable deploys, clean rollback path, and fewer midnight pages

Network basics, done right

The boring layer matters: cabling, VLAN intent, routing boundaries, and access control.

RJ45 Ethernet connector close-up

Contact

Send a short description. I’ll reply with next steps and a clear plan.

Opens your email client and sends to ikyper@gmail.com.