Systems management

We build and run infrastructure — from first server to hand-off, or for the long haul.

What we do

Ansible-based deployments across bare metal, VMs, and containers. Our playbooks handle everything from base system setup to network configuration, storage, and CI/CD plumbing.

Whether you need a standalone system bootstrapped from scratch (DNS, storage, networking, and all), an isolated lab environment, or a drop-in appliance added to existing infrastructure, we can deploy it, document it, and either keep it running or train your team to take over.

Deployment styles

Style Typical use case
Greenfield / standalone New project or startup. We build the complete stack — from OS installation and DNS to backups and monitoring.
Isolated environment Internal labs, CI farms, security zones. Separate networking, strict firewall boundaries, reproducible from scratch. Example: a multi-generation CI lab managing bare-metal build farms for embedded and cross-platform builds.
Appliance / add-on Drop a managed service into your existing datacenter or cloud tenant. Minimal coupling, clear interfaces.

Platform coverage and specializations

Our automation handles Linux (Debian, Red Hat, SUSE families), macOS, and Windows — including less common needs like WSL distributions, cross-compilation farms, and embedded toolchains under Wine.

Beyond standard server setup, we have deep experience with:

Storage clusters — We run Ceph in production for safe data storage and training.

Container orchestration — We deploy and manage k3s clusters for lightweight Kubernetes workloads, including persistent volume management, ingress configuration, and namespace isolation.

Build systems and embedded CI — We maintain OBS (Open Build Service) backends and workers for complete distribution builds, and we built Schedy, a firmware flashing and hardware test automation platform that has run over 46 million test runs across shared device labs since 2016. More on our test automation page.

Monitoring and observability — Our deployments include Zabbix for traditional infrastructure monitoring, and Prometheus/Grafana/Loki stacks for metrics, dashboards, and log aggregation.

LLM and AI infrastructure — We deploy local model hosting stacks (OpenWebUI, LiteLLM) for teams that need private AI tooling without sending data to third-party APIs.

Infrastructure visibility

We don't just manage systems — we make them understandable.

Our inventory system generates self-contained, interactive HTML visualizations directly from the same source of truth that drives deployments. No separate documentation to maintain, no diagrams that go stale.

These pages include:

  • Overview dashboards with live stats, sortable and filterable host tables
  • Rack views showing physical layout at a glance
  • Network topology diagrams as interactive force-directed graphs
  • Switch port mappings and workload relationship views
  • Click-through host detail panels with interfaces, guests, and dependencies

Because the visualization is generated from the actual inventory data, it is always current with the deployed state.

Three main ways to work with us

Fully managed We stay on as your infrastructure team. You get uptime, backups, patching, and a documented, version-controlled setup. You don't need to hire a full-time infrastructure engineers until you're ready.

Bootstrap & handover We design and build the initial system, then transition it to your team. Documentation, runbooks, and knowledge transfer are included as deliverables — not afterthoughts.

Consulting alongside your team We embed as advisors and implementors next to your existing staff. We bring the automation patterns, inventory tooling, and deployment expertise; your team retains ownership and grows their skills. Ideal when you have people on board but need temporary depth in areas like bare-metal provisioning, network automation, or CI pipeline design.

For startups and small teams

You don't need a full-time ops hire to get production-grade infrastructure.

Our tooling and processes happen to be a good fit for small deployments at early-stage companies — rented servers, owned hardware, or a mix. For us, it is part-time work. For you, it is full coverage: monitoring, patching, backups, and incident response. You only pay for the time you actually need, which tends to come in well below the cost of a fixed hire until you are big enough to keep someone busy full-time. When that day comes, the handover path is built in.

Our approach grew out of running a multi-generation CI lab for a medical-device team — bare metal, containerized services, cross-platform builds, and strict reproducibility requirements. We apply the same discipline to smaller deployments.

Deliverables you can keep

  • Version-controlled Ansible playbooks and inventory definitions
  • Infrastructure documentation that lives in the same repo as the code
  • Self-updating HTML visualizations generated from live inventory data
  • Disaster recovery procedures tested against the actual environment
  • Dependency graphs covering power domains, network topology, and service relationships

No lock-in

Most of the roles that power your deployment are our own work — we built them, we maintain them, and we publish them openly. That means if you later take over management yourself, you still get the improvements and fixes we ship.

For the few roles that remain closed, you keep the version deployed at handover and can continue using it indefinitely. If you want ongoing updates for those, we can arrange a licensing agreement that suits you.