# System Administration

> Selected Engineer ApS work demonstrating System Administration — the achievements that prove it.

- [Designed, deployed, and maintained 10 PostgreSQL and MS SQL servers on Ubuntu Linux VPS, ensuring optimal server performance and reliability.](https://engineer.company/portfolio/designed-deployed-and-maintained-10-postgresql-and-ms-13/)
- [Enhanced data security by implementing 1,000 RBAC rules for developers, application instances, PostgreSQL, MS SQL, and other Linux servers, preventing unauthorized access; documented with Ansible automation.](https://engineer.company/portfolio/enhanced-data-security-by-implementing-1-000-rbac-14/)
- [Managed 30 Ubuntu Linux VPS instances, implementing disaster recovery strategies and ensuring optimal network configurations.](https://engineer.company/portfolio/managed-30-ubuntu-linux-vps-instances-implementing-disaster-20/)
- [Prevented security breaches by leading access management initiatives, utilizing M365, 1Password, Red Hat SSO, and OKTA SSO.](https://engineer.company/portfolio/prevented-security-breaches-by-leading-access-management-initiatives-21/)
- [Managed and troubleshooted 8 WireGuard VPN and IPSEC VPN connections, ensuring secure communication across Google Cloud and Linux systems.](https://engineer.company/portfolio/managed-and-troubleshooted-8-wireguard-vpn-and-ipsec-23/)
- [Administered network infrastructure for over 1,000 servers, ensuring optimal system deployment, security, and troubleshooting.](https://engineer.company/portfolio/administered-network-infrastructure-for-over-1-000-servers-39/)
- [Established a Technical Support department, servicing over 10,000 clients with IT support and troubleshooting solutions.](https://engineer.company/portfolio/established-a-technical-support-department-servicing-over-10-40/)
- [Managed a team delivering IT support, data recovery, and hardware repair services to over 1,000 clients, ensuring high‑quality service.](https://engineer.company/portfolio/managed-a-team-delivering-it-support-data-recovery-47/)
- [Configured and deployed 1,000 Wi‑Fi routers, improving network accessibility and performance for clients.](https://engineer.company/portfolio/configured-and-deployed-1-000-wi-fi-routers-48/)
- [Managed 4,000 computer repairs, ensuring rapid and effective resolution of hardware and software issues.](https://engineer.company/portfolio/managed-4-000-computer-repairs-ensuring-rapid-and-49/)
- [Administered 100 Bare Bone servers, physical networks, and IP telephony systems, ensuring robust infrastructure for company growth.](https://engineer.company/portfolio/administered-100-bare-bone-servers-physical-networks-and-50/)
- [Administered 40 websites on Ubuntu Linux hosting servers with Apache and Nginx, ensuring high availability and performance.](https://engineer.company/portfolio/administered-40-websites-on-ubuntu-linux-hosting-servers-53/)
- [Provided round‑the‑clock 24/7 infrastructure support for an IPTV/OTT streaming platform, administering ~1,000 servers plus client‑owned systems for global customers in China, the US and Germany.](https://engineer.company/portfolio/provided-round-the-clock-24-7-infrastructure-support-82/)
- [Ensured uninterrupted delivery of IPTV streaming signals between suppliers and clients, monitoring and maintaining the streaming network and IP telephony around the clock.](https://engineer.company/portfolio/ensured-uninterrupted-delivery-of-iptv-streaming-signals-between-83/)
- [Planned and implemented new infrastructure functionality for internal and external systems, building solutions durable enough to still run years later with minimal change.](https://engineer.company/portfolio/planned-and-implemented-new-infrastructure-functionality-for-internal-85/)
- [As one of the first hires, designed and built the entire core infrastructure and supporting processes from scratch for a green‑energy SaaS startup, laying the foundation for rapid growth.](https://engineer.company/portfolio/as-one-of-the-first-hires-designed-and-86/)
- [Integrated a company‑wide password‑management system, strengthening security and streamlining access control.](https://engineer.company/portfolio/integrated-a-company-wide-password-management-system-strengthening-90/)
- [Performed data recovery across a wide range of media — SD cards, HDDs, SSDs, RAID arrays, external drives and Mac systems.](https://engineer.company/portfolio/performed-data-recovery-across-a-wide-range-of-92/)
- [Diagnosed and repaired laptop hardware — screens, hinges, keyboards, trackpads, motherboards and power — and resolved software issues across Linux, Windows and Mac.](https://engineer.company/portfolio/diagnosed-and-repaired-laptop-hardware-screens-hinges-keyboards-93/)
- [Built the operator back‑office — around 40 admin routes and 128 components covering claims, moderation, feature flags, cache and diagnostics — so the platform can be run without database access.](https://engineer.company/portfolio/built-the-operator-back-office-for-the-platform-102/)
- [Built the company's own infrastructure as 19 Ansible playbooks and 34 roles across 12,065 lines of YAML, converging a live host to a declared state with every play idempotent.](https://engineer.company/portfolio/built-the-companys-infrastructure-as-code-108/)
- [Ran the whole company on one 512 MB single‑core host — a git forge, a web server serving seven domains, Tor, two alternate‑protocol servers, backups and intrusion banning — by treating 464 MB of usable memory as the binding architectural constraint.](https://engineer.company/portfolio/ran-the-whole-company-on-one-512mb-host-109/)
- [Found and closed three SSH brute‑force protections that had never worked: a ban jail watching port 22 while the daemon listened on 1986, a rate limit shadowed by a broader rule above it, and a ban action whose binary never resolved, so no ban had ever applied.](https://engineer.company/portfolio/found-three-ssh-brute-force-protections-that-never-worked-110/)
- [Hardened SSH to 24 asserted directives with three‑stage validation — the candidate file, the assembled config, then the daemon's own read‑back — after the read‑back caught the running server silently overriding two of the twenty‑four.](https://engineer.company/portfolio/hardened-ssh-with-three-stage-validation-111/)
- [Deployed the company's own git forge on Soft Serve, private by default with no web panel and its SSH port bound to loopback behind a jump host, and made the landing page in front of it a build artefact of the main site rather than a hand‑kept copy.](https://engineer.company/portfolio/deployed-the-companys-own-git-forge-121/)

<https://engineer.company/categories/system-administration/>
