- Home
- Case studies
Case studies
A selection of projects from recent years. Without client names for confidentiality reasons, but with task, approach and result.
I sign non-disclosure agreements and keep them. That is why no clients are named here, not even on request. Reference calls can be arranged after consultation with the respective client.
Hosting providerDDoS mitigationGREKeepalivednftables
DDoS protection with highly available scrubbing connectivity
- Task
- Publicly reachable servers were regularly hit by volumetric attacks. Protection had to work without moving customer servers and without a single point of failure.
- Approach
- Connection to a scrubbing centre via GRE tunnels, two gateway systems with Keepalived and a virtual IP, traffic monitoring with nftables, VictoriaMetrics and Grafana, flow analysis with sFlow and ClickHouse, MSS clamping and per-IP limits.
- Result
- Terabit-class attacks are filtered before they reach the network. The failure of one gateway remains invisible to customers, incidents are traceable with dashboards.
Hosting providerBGPAutonomous systemIPv4/IPv6RPKI
Own autonomous system with own IP space
- Task
- Independence from providers and the ability to move own addresses between locations.
- Approach
- Application for and setup of an autonomous system, BGP connectivity in the data centre, RPKI signing, routing policies and monitoring of announcements.
- Result
- Own addresses are portable, DDoS protection and location changes can be implemented without renumbering.
Enterprise environmentAnsibleAWXKeepalivedHAProxyCheckmk
Highly available load balancing across four stages, fully automated
- Task
- Multi-stage load balancer environments (development, test, acceptance, production) had to be operated reproducibly, audit-proof and without manual intervention.
- Approach
- Ansible roles for Keepalived in LVS-DR mode and HAProxy, rollout via AWX with separated credentials, automatic monitoring integration, documentation in the repository.
- Result
- New environments are created in minutes instead of days, every configuration is traceable in the repository, audits are answered with playbooks.
Enterprise environmentOpenShiftKubernetesAnsibleArgoCD
OpenShift patch days and lifecycle operations
- Task
- Several OpenShift clusters had to be updated regularly and traceably, including storage operator and GPU nodes.
- Approach
- Monthly patch days with Ansible and ArgoCD, runbooks for special cases such as storage drivers on tainted nodes, health gates before every step.
- Result
- Updates run predictably in the maintenance window, special cases are documented and repeatable.
Data centre networkAristaMLAGFault analysisPacket analysis
Sporadic packet loss traced back to an MLAG problem
- Task
- Individual servers lost connections irregularly without logs or monitoring providing any hint.
- Approach
- Systematic measurement with packet captures on both sides, ARP analysis, reproducing the fault in the maintenance window, adjustment of the MLAG and ARP configuration.
- Result
- Cause clearly identified and fixed, permanent monitoring established.
Hosting providerProxmox VEKVMVirtualizorStorage
Virtualisation platform with several hundred VMs
- Task
- Operating and expanding a platform for hundreds of customer VMs with high demands on stability and performance.
- Approach
- Standardised host systems, NVMe storage with RAID, automatic provisioning, traffic and resource monitoring, migrations between providers without customer interruption.
- Result
- Stable operation under heavy load, predictable costs and fast provisioning of new systems.
Hosting providerPHP 8WHMCSWebAuthnSecurity review
Custom WHMCS modules and passwordless passkey login
- Task
- Provisioning, billing and security of a customer portal had to be implemented without marketplace modules and with a high security level.
- Approach
- Development of custom modules for server provisioning, registrar integration and payments, passkey login based on FIDO2 with origin checks, rate limiting and replay protection, regular security reviews of the entire code.
- Result
- Thousands of transactions run automatically every day, customers and administrators log in without a password, platform updates are survived without manual work.
HealthcareMedical practiceBackupAutomationOn site
IT operations and billing automation for a medical practice in Vienna
- Task
- Reliable IT operations of a practice with sensitive data and recurring billing processes that caused a lot of manual work.
- Approach
- Network and workstations looked after on site, backup concept with offsite copy, automated invoicing via the client portal.
- Result
- Less manual work, verified backups and a fixed contact person for problems.