Skills
What I can actually do, and how far
28 technologies across six areas. Every one carries a tier, because "familiar with" and "responsible for in production" are not the same claim and should not look the same on a page.
Proficiency is marked honestly.
- Production used in a live environment I am responsible for 11 entries
- Working knowledge hands-on but not yet production-critical 11 entries
- Learning project built in a self-directed lab or personal project 6 entries
Skills matrix
Cloud & Containers
Where the next step is. Built in self-directed labs, on real cloud bills.
- Learning project
AWS EC2
- Learning project
Kubernetes (k3s)
single-node and multi-node
- Working knowledge
Docker, Docker Compose
- Learning project
Microsoft Azure
AZ-104 in progress
- Working knowledge
Tailscale
WireGuard-based mesh
- Working knowledge
Cloudflare
DNS, proxy, TLS modes
Windows Infrastructure
The day job. A live domain of roughly 120 users depends on this working.
- Production
Windows Server, Active Directory, Group Policy
- Production
DNS, DHCP
- Production
WSUS
SSL, port 8531
- Production
ManageEngine ServiceDesk Plus
incl. NTLM SSO
- Working knowledge
1C administration
Networking & Security
Routing, tunnels, and finding out what is actually reachable from where.
- Production
MikroTik / RouterOS
routing, NAT, firewall, VPN, dual-WAN
- Production
Kerio Control / Kerio Connect
- Production
IPsec site-to-site tunneling and diagnostics
- Working knowledge
VLAN segmentation
- Working knowledge
Authorized internal security auditing
recon, service enumeration, reporting
- Learning project
Suricata IDS/IPS
- Working knowledge
HikVision video infrastructure
Automation & Scripting
Doing a thing once by hand, then never again.
- Production
PowerShell
fleet automation, monitoring, GPO, AD
- Working knowledge
Python
LDAP tooling, BLE clients, automation, multi-agent orchestration
- Working knowledge
Bash
- Learning project
GitLab CI/CD
- Learning project
Ansible
Virtualization & Backup
A production ESXi cluster, and the backups that make it survivable.
- Production
VMware ESXi under vCenter / vSphere
cluster
- Production
Veeam Backup & Replication
- Working knowledge
iSCSI / LUN storage
Monitoring
Knowing something broke before a user has to tell you.
- Production
Custom PowerShell monitoring with alerting
- Working knowledge
Grafana / Prometheus
installed and configured from scratch for server monitoring
No skills in that tier.
The lab work is where the cloud tier gets earned
The Learning project entries above are not aspirational — each one is something I built and broke. The k3s cluster write-up has the failures in it.