*Projects
Systems I've built and run.
Edge Kubernetes, GPU inference, self-hosted AI, productionised network automation, and the infrastructure rigour that ties it together - each with the problem, the design, and the outcome.
Single-Touch Edge AI Platform
Outcome Turned a high-level edge-AI design into a single-touch deployment running on Kubernetes at the store edge.
- Kubernetes
- Edge
- NVIDIA GPU
- CD pipelines
- Helm
- Python
Self-Hosted AI & Homelab Platform
Outcome A homelab - GitOps from bare metal to local AI, and the platform that serves this very site.
- Talos
- OpenShift
- Argo CD
- Proxmox
- Local LLM
- Cloudflare Tunnel
IaC Fleet Automation
Outcome Stood up identical edge sites from code - every store comes up the same way, every time.
- Ansible
- AWX
- GitOps
- ACR / NVCR
- Image pre-pull
- Secrets mgmt
The Exploded Cluster
Outcome A scroll-driven teaching site that takes container platforms apart one machine at a time.
- Dependency-free static build
- GSAP ScrollTrigger
- Strict CSP
- Cloudflare Tunnel
- Argo CD
- zot mirror
The Mirror: A Pull-Through Registry
Outcome Ended anonymous registry rate-limits across a six-node fleet, then published the failure modes the deployment revealed - including the one that contradicted my own first write-up.
- zot v2.1.17
- Talos Linux
- containerd
- OCI distribution
- Argo CD
- External Secrets
GPU-as-Code on the Edge
Outcome Brought GPUs online as code - passthrough, init-gated at startup, and reproducible across the fleet.
- GPU passthrough
- ESXi
- DCGM Exporter
- Prometheus
- Bash
- Watchdogs
Global Infrastructure Modernisation
Outcome Modernised a global, multi-region estate at scale - ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 - on a live 24/7 business.
- VMware / vSphere
- Azure (Blob, AVS)
- Microsoft 365
- SD-WAN
- Aruba ClearPass
- Palo Alto / FortiGate
- Veeam
Network Automation at Fleet Scale
Outcome Took a multi-region switch fleet from hand-managed to single-pane - automated config backup, bulk change in minutes, and credentials secured and rotated.
- Unimus (NCM)
- Config backup + restore
- Config diffs
- Bulk config push
- Credential vaulting + rotation
- Multi-vendor switching

