anton@infra:~$
STATUS: available for infrastructure work

anton@infra:~$ whoami

ANTON BABASKIN

>

I keep the systems a business runs on online, secure and fast. 15+ years of real production infrastructure — servers, email, networks, backups, deployment pipelines. I take environments that are fragile, undocumented or on fire and turn them into something boring, monitored and safe to touch.

  • 0years in production
  • 0open-source tools
  • 24/7incident response
  • UAremote · worldwide
anton@infra — bash — 96×28 --:--:--
click to run →

this terminal is real — type help for the short list, or commands for all ~40, jokes included.

[01]

In plain words

No jargon in this section — this is what the job actually is, why companies pay for it, and what you get.

What I actually do

Every company runs on computers it does not see: web servers, databases, email, VPNs, backups. I design, build and look after that layer. When it breaks, I fix it. Before it breaks, I find the weak points and remove them.

Who I work with

Businesses that depend on their own infrastructure — hosting and SaaS companies, e-commerce, agencies, and teams that inherited servers nobody understands anymore. Usually I am the person brought in when it has to be right.

What you get

A written report your team can act on and your management can read. Systems that stop waking people up at night. Documentation, so the knowledge is not locked inside one person's head — including mine.

Why it matters

Downtime, lost email and lost data cost money and customer trust. Most of it is preventable, and usually cheaply — if somebody competent looks at the system before the incident rather than after it.

At a glance

Experience
15+ years, Linux & infrastructure
Seniority
Senior / Lead engineer & consultant
Main areas
DevOps · Infrastructure · Networks · Mail · Security
Also strong in
Monitoring, backups & disaster recovery, AI automation
Location
Ukraine — remote, worldwide (UTC+3)
Languages
Ukrainian · Russian · English
Open to
Full-time · Contract · One-off audits
Response time
Usually within 24 hours
[02]

$ ls -la /srv/services

What you can hire me for. Each one has a fixed scope and a written deliverable — every card starts with a plain-language summary, then the technical detail underneath.

01flagship

Infrastructure Audit

In plain words: a full health check of your servers. I look at everything, break nothing, and hand you a ranked list of what to fix first.

Read-only, non-destructive assessment of servers, network, mail, security posture, backups and monitoring. Findings are ranked critical → high → hygiene, with concrete commands and a remediation roadmap.

  • Host inventory, services, resource and capacity review
  • Security posture: SSH, firewall, users, sudo, CVEs, exposure
  • Backup reality check — does the restore actually work?
  • Single points of failure, bus factor, missing documentation

Deliverable: PDF/Markdown report + remediation plan + walkthrough call

02devops

DevOps, CI/CD & Automation

In plain words: your developers stop deploying by hand at midnight. Code goes to production automatically, repeatably, and can be rolled back in seconds.

Pipelines, infrastructure as code and release process. Everything a machine can do twice, a machine should do — with the whole environment described in a Git repository instead of someone's memory.

  • GitHub Actions / GitLab CI pipelines with real tests and gates
  • Ansible & Terraform — servers described as code, not clicked
  • Blue/green and rolling deploys, automated rollback
  • Dev / staging / production parity and secrets handling

Deliverable: working pipelines + IaC repo + release runbook

03security

Hardening & Compliance Baseline

In plain words: making your servers a hard target. Cheap to do now, very expensive to skip.

Turning a default install into something that survives the internet. A CIS-style baseline applied carefully, documented and reversible — nothing lands in production without a rollback path.

  • SSH keys-only, jump hosts, least-privilege sudo
  • nftables/iptables, Fail2Ban, brute-force containment
  • TLS everywhere, certificate automation and expiry alerts
  • auditd, log retention, centralized logging

Deliverable: hardened baseline + Ansible role + before/after evidence

04mailops

Mail Infrastructure & Deliverability

In plain words: your email reaches the inbox instead of the spam folder — and you stop losing customers you never knew you missed.

My deepest specialism: Postfix, Dovecot, rspamd, Mail-in-a-Box. From "our mail lands in spam" to a clean, authenticated, monitored mail platform — including blacklist recovery and queue forensics.

  • SPF / DKIM / DMARC / PTR / MTA-STS done properly
  • Deliverability rescue, RBL delisting, reputation repair
  • Queue, bounce and relay analytics from raw logs
  • Anti-spam tuning without losing legitimate mail

Deliverable: working mail platform + monitoring + runbook

05sre

Monitoring & Alerting

In plain words: you find out something is wrong before your customers do — and the alert tells the on-call engineer what to actually do.

Dashboards nobody looks at are decoration. I build alerting that fires only when something is genuinely wrong, routes to where you actually read it, and comes with a next step attached.

  • Prometheus, Grafana, Loki, Alertmanager, Zabbix
  • Symptom-based alerts, noise reduction, escalation paths
  • Telegram / Slack notification pipelines with context
  • Synthetic checks for mail, DNS, TLS, VPN and web

Deliverable: dashboards, alert rules, on-call runbook

06resilience

Backup & Disaster Recovery

In plain words: if the worst happens, you are back online in hours — with a restore that has been tested, not assumed.

A backup you have never restored is a rumour. 3-2-1 strategy, offsite copies, encryption, and — the part everyone skips — scheduled restore drills with measured recovery time.

  • ZFS snapshots, restic/borg, Proxmox Backup Server
  • Immutable / offsite copies, retention policy
  • Documented, timed restore procedure
  • Backup failure alerting — silence is not success

Deliverable: DR plan + verified restore + automated alerts

07platform

Migration & Platform Build

In plain words: moving your systems to better or cheaper infrastructure — planned and rehearsed, so customers never notice it happened.

Lift an entire environment without downtime drama: bare metal ↔ cloud, hypervisor consolidation, containerization. Rehearsed cutover, rollback ready, DNS TTLs planned days in advance.

  • Proxmox VE on Hetzner/OVH, ZFS RAID, IPMI-less installs
  • Docker / Compose / Kubernetes workload migration
  • Cost review — right-sizing instead of paying for idle capacity
  • Cutover plan, rehearsal and rollback procedure

Deliverable: migrated platform + IaC repo + cutover report

08network

Networking, VPN & Secure Access

In plain words: your team and your offices connect to internal systems privately and reliably — and you are told when a tunnel dies.

Private, dependable connectivity between people, offices and machines — with health monitoring, so a dead tunnel does not stay dead silently.

  • WireGuard, site-to-site and road-warrior topologies
  • Xray / VLESS + REALITY for censored networks
  • Routing, VLANs, split DNS, NAT and firewall design
  • Nginx / HAProxy edge, TLS termination, rate limiting

Deliverable: documented topology + configs + tunnel monitoring

09emergency

Firefighting & Root Cause

In plain words: something is down right now, and you need someone who has seen it before. Stabilise first, explain second, prevent third.

Production is down, the disk is full, mail is blacklisted, the previous admin is gone and nobody has the password. I have been there many times.

  • Rapid triage and stabilization
  • Log-driven root cause analysis — no guessing
  • Recovery of inherited / undocumented systems
  • Written post-mortem and prevention plan

Deliverable: stable system + post-mortem + prevention backlog

[03]

$ cat /etc/audit/workflow

How an engagement actually runs. Predictable, read-only first, and nothing is changed on your systems without your approval.

  1. 01

    Recon day 0–1

    Scoping call, read-only access, inventory collection. I map what exists before forming any opinion — hosts, services, data flows, dependencies, who owns what.

  2. 02

    Analysis day 1–4

    Automated diagnostics plus manual review: logs, configs, security posture, backups, monitoring gaps, capacity. Findings are ranked by real business risk, not by scanner severity.

  3. 03

    Report day 5

    A document your engineers can execute and your management can read: critical issues, quick wins, structural debt, effort estimates and exact commands.

  4. 04

    Remediation optional

    I implement the fixes myself, or coach your team through them. Every change is announced, backed up, reversible and verified afterwards.

[04]

$ systemctl status ai-ops.service

Where AI genuinely helps operations — and, more importantly, where it must be kept on a leash.

ai-ops.service — AI-assisted operations layer

Loaded: loaded (/etc/systemd/system/ai-ops.service; enabled)

Active: active (running) — human-in-the-loop

Guardrails: read-only default · command allowlist · full audit log

In plain words: I use AI models as a fast, tireless assistant — reading thousands of log lines, explaining failures, drafting procedures — while keeping every decision that changes a live system in human hands.

I build AI into operations the way I build everything else: the model gets context, not root access. Agents collect and explain; humans approve anything that mutates state. Every action is logged, attributable and reversible. That is the only way an LLM belongs anywhere near production.

This is not theory — miab-sentry is a working Telegram agent that manages mail servers over SSH with key-based auth, an SQLite audit trail and optional Claude / OpenAI / OpenRouter reasoning on top.

LLM log triage

Feed noisy Postfix, systemd and kernel logs to a model that clusters them, names the failure and drafts the fix — you review the diff, not 40k lines.

ChatOps agents

Telegram / Slack control surfaces over SSH: status, queues, restarts, updates — with allowlisted commands and per-action audit logging.

Runbook generation

Turn tribal knowledge and shell history into versioned runbooks and Ansible roles that a new hire can execute at 3 a.m.

Self-diagnosing fleets

Agentless collectors sweep the fleet on a schedule; anomalies get an explanation attached before a human ever opens the ticket.

Config & IaC review

AI-assisted review of Nginx, Postfix, firewall and Terraform changes for footguns — as a second pair of eyes, never as the approver.

Guardrails by design

Read-only by default, no secrets in prompts, deterministic scripts for anything destructive, and a kill switch a tired human can find.

[05]

Technology stack

Grouped by area, starting with DevOps. Each group opens with a one-sentence explanation of what it is for — so the list means something whether or not you write code.

[06]

$ cat ~/.engineering_rules

Five lines that have saved more production systems than any dashboard.

  • [01]Logs before assumptions.

    The system already told you what happened. Read it before theorizing.

  • [02]Backups before changes.

    A snapshot costs seconds. Explaining data loss costs a career.

  • [03]Architecture before hype.

    Kubernetes will not fix a design problem. It will scale it.

  • [04]Security is not optional.

    It is not a phase after launch. It is part of the install.

  • [05]Stability over beautiful theory.

    Boring infrastructure that never pages anyone is the highest form of elegance.

[07]

$ ./connect.sh

Tell me what is broken, what you are building, or what you are not sure about. Short reply, no sales funnel.

anton@infra:~$ cat contact.json

{
  "name":     "Anton Babaskin",
  "role":     "DevOps / Linux Infrastructure Engineer",
  "location": "Ukraine — remote, worldwide",
  "timezone": "Europe/Kyiv (UTC+3)",
  "status":   "open to audits, consulting & long-term work",
  "response": "usually within 24h"
}

Need a second opinion on your infrastructure before it becomes an incident?

./request-audit --priority=high
[08]

$ git log --oneline --author=anton

Tools I wrote for problems I hit on real systems, published as open source. A few highlights — the full catalogue lives on its own page.