// Selected work
Things I've built
Infrastructure that runs in production, not a sandbox. Each project is built, operated, and documented to the same standard I'd hold at work.
Active
securebytes.net
Personal engineering platform built with Astro and deployed globally through Cloudflare Pages - enterprise-grade security, zero infrastructure, $0/month.
SecureBytes Platform
Self-managed Proxmox cluster running production-style network and security infrastructure. Wildcard TLS, public status page, and selective Cloudflare Tunnel exposure.
Network Design Lab
Multi-vendor lab on Cisco Modeling Labs and EVE-NG. Routing, switching, wireless, security, SD-WAN, identity, and observability platforms for design validation, failure testing, and certification work.
Tailscale Zero-Trust Access
Identity-based remote access to private infrastructure over a WireGuard overlay. No open inbound ports, deny-by-default ACLs as policy-as-code, pfSense as subnet router. The internal network is never directly reachable from the internet.
Splunk
Dedicated Splunk Enterprise VM on the cluster. Live firewall, UniFi, guest syslog, IDS, and CloudTrail. Internal SIEM, not a search bar on a shared guest.
SecureBytes NOC Stack
Internal observability stack for the platform: Grafana dashboards over Prometheus with Node Exporter on every Proxmox node, LXC, and VM. Sixty-second scrape interval, push notifications via ntfy.
BGP Mesh with Private ASNs
Full eBGP triangle across a two-node Proxmox cluster and pfSense edge firewall using FRRouting. Private ASNs, redundant path learning, zero static routes. The same routing protocol that runs the internet, running in a home lab.
In progress
Completed
AWS Private Cloud Lab
Production-style AWS stack with zero public EC2 exposure. Application traffic through an ALB; instance management via SSM Session Manager and VPC endpoints. no SSH, bastion, or NAT gateway.
Netgate DNS Cutover Toolkit
A safety-gated toolkit on the pfSense REST API that caught a real outage before it could write anything, traced it to a Tailscale routing trap, fixed a bug in its own API client, then ran the actual DHCP cutover live.
Cisco FTD + FMC Enterprise Security Lab
Multi-site Firepower lab in Cisco Modeling Labs. Two FTD firewalls managed by a central FMC. access control policy, IPS, URL filtering, NAT, and full event analysis.
Akwaaba Solutions Environment
Enterprise network simulation in Cisco Modeling Labs. Three-zone topology with BGP peering, ASA perimeter security, NAT, and segmented DMZ servers.