Core compute
Virtualization platforms running production services and automation workloads.
- Proxmox for VM/LXC operations
- VMware/vCenter experience and interoperability mindset
Senior IT Consultant · 20+ years
I design and operate resilient systems: virtualization and storage platforms, secure remote access, monitoring, backups, and local-first automation—validated daily in my production-grade homelab.
Design, recovery, and local-first integrations that work offline.
Intrusion + safety detection with secure remote access.
Local recording, retention, and optional offsite backup.
Who I am
Senior IT Consultant · Infrastructure, Automation & Security
I’m an IT consultant based in Reus, Spain, with 20+ years across enterprise IT: Windows and Linux administration, virtualization, storage, backups, monitoring, and automation. I’ve supported everything from datacenter operations to large-scale VMware environments and modern homelabs.
My current focus is local-first, resilient systems—especially Home Assistant, smart security for homes and RVs, and camera platforms like Shinobi. I build solutions that keep running without cloud dependencies, with clear runbooks and reliable recovery paths.
Fluent in Spanish, Catalan, and English. Comfortable leading teams, documenting processes, and shipping systems that are maintainable long after handoff.
This isn’t a toy setup: it’s an integrated environment where I validate architecture choices, hardening, backup strategies, and automation before applying the same discipline for clients.
Virtualization platforms running production services and automation workloads.
TrueNAS-backed storage exported to compute and application layers.
Proxmox Backup Server with restricted access and scheduled jobs.
Minimal exposure model: reverse proxy, VPN, log-based banning, and safe admin access.
MQTT-centric integrations, designed to survive internet outages.
Local recording first; optional offsite backup as a second layer.
What you can rely on me for, end-to-end—from design to day-2 operations.
Hands-on experience in enterprise environments, from directory services to automation and monitoring.
Real solutions built with maintainability in mind. Details are anonymized for safety.
Reverse-proxied applications with protected admin endpoints, log-based banning, and strict SSH access controls.
Proxmox Backup Server with restrictive firewall rules and scheduled backups for critical data paths.
RTSP-based camera recording to local storage, with optional rclone synchronization for offsite resilience.
Headless scripts and timers for consistent operations: upgrades, sync jobs, notifications, and service lifecycle management.
Backup server locked down with key-only access and strict firewall rules around management ports.
Edge protection using structured access logs to drive automated bans and reduce noise.
BLE data collected and published to MQTT, consumed by Home Assistant, visualized on ESP32 dashboards.
Engagements that produce measurable outcomes, clear documentation, and maintainable operations.
Home Assistant
MQTT
Espressif
Shinobi
Proxmox
TrueNAS
OpenVPN
I build Home Assistant systems around local messaging, Bluetooth, and Zigbee so everything stays local-first. The result is a resilient stack with clear automations, structured dashboards, and a runbook for recovery.
I design alarm systems that stay local and reliable. Sensors communicate over Zigbee, so the alarm works even if there is no Wi-Fi or internet. If you add a 4G router, you can enable urgent mobile push notifications (even overriding Do Not Disturb). If you do not, the alarm still runs locally with siren and on-site alerts.
Cameras record locally first, without vendor cloud dependencies. I deploy Shinobi or comparable open-source NVRs, enforce retention, and add optional offsite sync for resilience.
I deliver clean host layouts, templates, patch plans, and predictable operations so your stack scales without surprises.
Storage and backups are designed for recovery, not just for retention. I build the data paths, permissions, and backup cadence around real restore tests.
Secure access patterns with strict SSH policy, reverse proxy segmentation, and automated blocking from real access logs.
I automate repetitive work with scheduled timers and scripts, and integrate monitoring so issues are detected early.
I deploy internal services, harden access paths, and deliver documentation so the system remains maintainable long after handoff.
I build bespoke websites and storefronts you own end-to-end: custom UI, admin tools for content and products, multilingual support, and email integrations. A recent example is a paintings storefront with admin user management, bulk actions, verification tokens, email settings, and manual locales with a cookie-driven language selector.
Reliable outcomes come from repeatable process and clear operational ownership.
Design systems that keep working without external dependencies. Use cloud only as an optional layer for backups and replication.
Harden SSH and admin surfaces, apply principle of least privilege, and use log-driven controls like fail2ban and rate limiting.
Deliver runbooks, sane alerts, and automation for patching and backups—so the system remains maintainable long after handoff.
If you want to discuss a project, I’ll share the right contact channels and references on request.
Reach me here for new projects and consultations.