The strongest engineering work rarely belongs to one product. These sanitised cases show how I approach identity, infrastructure, application delivery and operational ownership when they meet.
01 / DataBalk
Cloud Service Engineer
Cloud engineering with guardrails.
Selected patterns from Microsoft cloud operations, identity, application integrations and deployment design. Customer names, tenant details and live topology are intentionally omitted.
01
Azure governance · PowerShell · ARM · Microsoft Graph
Cloud inventory without a secret-value path
Designed bounded, multi-tenant inventory tooling for Key Vault metadata, access models, role assignments and scan coverage. Strict host allowlists, request budgets and an explicit metadata-only boundary kept the tool useful without creating another route to sensitive values.
Coverage is evidence too: an inaccessible subscription remains visibly incomplete instead of being reported as an empty result.
02
Microsoft Entra · PIM · Least privilege
Privileged access with an operator still in control
Built a guarded role-activation helper around exact tenant matching, bounded duration, justification, interactive confirmation, WhatIf support and authoritative readback.
Administrative convenience should reduce repetition, not remove the moment where an operator understands and approves elevated access.
03
Entra applications · Service principals · Consent
Identity configuration as comparable evidence
Created deterministic exports of application registrations, enterprise applications, permissions and consent to support cross-environment investigation and alignment while deliberately removing credentials and public-key material.
Configuration comparisons become dependable when collection is exact, repeatable and separate from secret material.
04
Business Central · Azure DevOps · Preflight design
Find the deployment boundary before changing it
Mapped the boundary across vaults, access, diagnostics, pipelines and service connections with a read-only preflight before a broader deployment-identity change was considered.
The preflight contained no mutation path. When the surrounding architecture did not support a safe assumption, the migration direction stayed parked.
05
OIDC federation · Azure RBAC · Cloudflare One
Secretless delivery and simpler network paths
Worked on workload-identity federation for deployment and on routed Cloudflare connectivity for managed desktops—favouring short-lived identity and direct supported paths over stored secrets, proxy layers or guessed topology.
A simpler architecture is valuable only when its identity, network and verification boundaries are explicit.
02 / Visnovo
DevOps Engineer
Build it, operate it, prove the result.
Development and customer delivery sit alongside responsibility for hosting, mail and infrastructure. I continue to work with Visnovo following its takeover of Obsite, alongside a small amount of independent freelance work. The examples below stay at architecture level to protect operational detail.
01
Python · DNSSEC · DANE/TLSA · Cloudflare · Plesk
Certificate state reconciled across systems
Engineered an active reconciliation platform that compares mail-service certificate state with DNS and provider state, then applies bounded additive changes through separate privilege layers.
Rollover is additive first. Manually owned records are never silently claimed, ambiguous DNSSEC state fails closed and cleanup waits through two TTL windows.
02
Linux · systemd · Plesk · Roundcube
Managed hosting that repairs drift safely
Combined customer-facing hosting customisation with operational guards that snapshot, hash, repair through supported tooling and verify convergence when generated configuration drifts.
Branding remains decorative and inherits vendor-managed assets; it does not modify authentication or create a fragile fork of the upstream interface.
03
Registrar · DNS · Mail · Hosting · Account ownership
Service handover as a systems problem
Separated domain registration, DNS, web hosting, mail, DNSSEC/DANE and account access into explicit handover tracks with allowed, denied and incomplete acceptance states.
A nameserver change is not a complete handover—and becomes dangerous when security records and non-DNS services are treated as incidental.
03 / Obsite
Founder · 2019–2024
Technical ownership became business ownership.
Obsite was where infrastructure, web delivery and direct client accountability became one role. Visnovo later took over the agency; the work continued through Visnovo while a small independent freelance practice remained alongside it.
01
Founded and operated a technical digital agency from 2019 to 2024 before its takeover by Visnovo.
02
Owned Linux and Proxmox infrastructure alongside customer web and email hosting.
03
Combined development, optimisation and SEO with direct client advice and partner delivery.
04
Continued working with Visnovo after the takeover while retaining a small independent freelance practice.