I build and run the platforms —
and ship the products on top.

I’m Adrian Jon Kriel. 28+ years building, hardening, and operating real infrastructure — Proxmox/ZFS fleets, cloud-exit, DNS/email, automation, on-prem AI — and single-handedly architecting and shipping production, multi-tenant SaaS in Go and TypeScript. AI-augmented, and disciplined about where it helps — which is how one person owns this much surface area end-to-end. And I’ve led from the front — Head of Infrastructure, CTO, and founder — owning roadmap, vendor and cost/risk decisions, and teams up to 35.

  • 28+ years in Linux & hosting
  • 1,841+ GitHub stars • 3.8M+ Docker pulls
  • 50,000+ servers built, fixed, or optimized
  • Ships full-stack SaaS solo — Go & TypeScript, AI-augmented
🛡️ NDA-friendly • Least-privilege access • Production change discipline
OPEN TOFounding · Staff/Principal · Head of Eng / CTO · Fractional · Contract WORKUK · EU · US · ZA · worldwide contract REMOTE100% · banks UK/EU/US TZGMT/UTC (now )

Products I’ve shipped — solo, end-to-end

Not just advice. I architect, build, and operate full products — original, sole-authored, production-grade. Several are private; live demos and code walkthroughs on request.

ZonePlane — DNS-as-a-Service

Multi-tenant SaaS control plane to manage DNS across providers, safely (preview/diff/approve, rollback).

  • Go (7 services) + Next.js 16 / React 19 (126 routes)
  • PostgreSQL row-level-security, Stripe billing, OIDC
  • OpenAPI + Go SDK + a Terraform provider • 746 test files
  • zoneplane.com — live

Hlumela — HR / Payroll / Compliance SaaS

Multi-tenant payroll platform with a correct, to-the-cent statutory tax engine.

  • Go + Next.js • schema-per-tenant isolation
  • Golden-tested PAYE/UIF/SDL/ETI engine; B-BBEE scorecard
  • Ed25519 JWTs, Argon2id, hash-chained audit log

Flotilla — Security-camera Operations

Operator-grade monitoring/alerting layer on top of Frigate NVR — kiosk wall, incident pipeline.

  • TypeScript monorepo, React 19, Fastify, embedded MQTT
  • Deduplicated incidents, multi-channel alerting, site maps
  • 173 test files • shipped in ~5 weeks

omniban — Universal IP-ban Manager

One CLI/TUI that detects and reconciles bans across 19 firewall/IDS/WAF backends via each tool’s native API.

  • Go 1.26 • Cobra CLI + Bubble Tea TUI
  • Owner-attribution, dedup, SSH-lockout guards
  • Released .deb/.rpm via GoReleaser CI
  • github.com/extremeshok/omniban — open source

Carrier-grade VoIP edge platform

Fleet automation for a VoIP carrier: bare-metal → clustered, multi-datacenter and on-prem.

  • Ansible + Python (PostgreSQL-driven control plane)
  • BGP/VPP/DPDK + RTPengine media plane
  • FusionIO/ZFS storage tuning (~1.3 GiB/s)

Fleet-wide cPanel mail proxy

One mail front-end for an entire hosting fleet: SMTP/IMAP/POP3 terminated centrally and routed per-domain to the correct backend mailbox server.

  • nginx mail/stream proxy + a PHP auth_http handler
  • Dynamic per-domain backend routing from a MariaDB table
  • All inbound/outbound mail + every IMAP/POP inbox via one endpoint • TLS automated

Open source — used in production worldwide

1,841★ across 54 original repos; running on real fleets and mail servers.

The point
I’m the rare engineer who can stand up the infrastructure AND ship the product on top — end-to-end and solo, AI-augmented and disciplined about where it helps. Ideal for founding-engineer, staff/principal platform, fractional-CTO, and contract work. See the code on GitHub.

More projects & open source

Beyond the flagship products — open-source tools used in production, infrastructure toolkits, and selected builds. All sole-authored.

xshok-proxmox

public · 933★ · Bash

Proxmox VE post-install optimisation & helper toolkit — one of the most-used in its niche.

clamav-unofficial-sigs

public · 549★ · Bash

ClamAV third-party signature updater running on mail servers worldwide; documented via Linux man pages.

omniban

public · Go

One CLI/TUI that reconciles IP bans across 19 firewall/IDS/WAF backends via each tool's native API.

xs.baseline

open source · Ansible

Opinionated, tested Debian/Proxmox hardening baseline: self-healing kernel-panic auto-reboot, BBR/sysctl tuning, surgical SSH allow-lists.

pve-opskit

open source · Bash

Proxmox VE/PBS operator toolkit: unattended bare-metal install, ZFS disk-replace, declarative firewall/pool reconcilers, backup verification.

zfs-fleet-toolkit

open source · Ansible

Controller-safe time-sliced ZFS scrub scheduler, RAM-aware ARC autotuner, and auto-snapshot / purge for production fleets.

domain-management

private · dnscontrol + GitHub Actions

DNS-as-Code for ~230 production domains; zero-touch GitOps deploy across Cloudflare/DO/BIND; SPF flattening, DMARC reject, CAA, DKIM.

poll-ci

private · Go

Concurrency-driven CI scheduler/runner (context lifecycle, sync.Cond) — the CI behind the Go projects.

ESP32 smart irrigation

private · ESPHome / C++

4-zone irrigation controller: calibrated soil-moisture & flow sensing, seasonal scheduling, leak detection, flood protection.

Full body of work — code, runbooks, and more — at github.com/extremeshok (1,841★ across 54 original repos).

What I do (and do well)

Technical Leadership & Decision-Making

The senior technical decision-maker — I own the call, not just the keyboard.

  • Architecture, roadmap, vendor & cost/risk decisions; build-vs-buy
  • Lead & mentor engineers; enable support/sales; hire and set standards
  • Head of Infrastructure · VP Eng · CTO · fractional — player-coach, hands-on

Proxmox + ZFS Architecture

HA design, multi-site patterns, storage tuning, performance and capacity planning.

  • Cluster health and upgrade strategy
  • ZFS layout, tuning, scrubs, replication
  • Backup/DR (PBS), recovery runbooks

Linux Performance & Reliability

Kernel, I/O, network, and application tuning with measurable outcomes.

  • Latency and throughput profiling
  • Resource isolation and guardrails
  • Root cause analysis, postmortems

Hosting Stack Modernization

Web, proxy, DB, and platform improvements that cut cost, reduce risk, and raise uptime.

  • Nginx / HAProxy / Caddy patterns
  • MySQL/MariaDB performance & HA
  • cPanel / DirectAdmin / OpenPanel operations

Database Performance (MySQL/MariaDB)

Turn “slow and fragile” into “fast and boring” with safe tuning, observability, and HA patterns.

  • Query performance, indexes, schema review
  • Replication/Galera, backups, and recovery drills
  • Operational tooling (PMM), guardrails, runbooks

Cloud Exit & SaaS Infrastructure

Move away from the cloud safely — and run a custom SaaS platform with predictable cost and performance.

  • Repatriation plans, cutovers, egress reality checks
  • Colo/on-prem designs (compute/storage/network)
  • Multi-tenant patterns, guardrails, and SRE basics

DNS & Email Systems

Authoritative + recursive DNS, fleet mail routing, deliverability, anti-spam, and continuity.

  • DNSControl, Unbound, BIND9, PowerDNS, gdnsd, dnsdist (DoH/DoT/DoQ)
  • Fleet mail proxy — per-domain SMTP/IMAP/POP3 routing; Postfix/Dovecot/Exim; Proxmox Mail Gateway + HAProxy
  • Deliverability (SPF/DKIM/DMARC), ClamAV/SpamAssassin hardening, archiving & migration

Automation (Ansible/Bash)

Build once, run forever: provisioning, hardening, lifecycle ops, runbooks.

  • Ansible roles and deployment pipelines
  • Packer + cloud-init templates
  • Docker, Coolify, Dockhand, repeatable ops

Embedded + Custom Automation

When the solution needs hardware: ESP32/Arduino projects and custom automation workflows.

  • ESP32/Arduino firmware and integrations
  • Sensors, telemetry, dashboards, alerting
  • Automation glue between hardware + infra

Incident Response & On-Call Rescue

When it’s down, I get it back up — and make sure it stays up.

  • Emergency triage and containment
  • Stability fixes and hardening
  • Monitoring + alerting improvements
Deliverables you can hold me to
  • Architecture diagrams + decisions (ADRs)
  • Action plan with risk + ROI order
  • Automation and runbooks
  • Performance baselines and KPIs
  • Hardening checklist and evidence
  • Postmortems and follow-ups

AI, agents & automations (private + production-ready)

Build AI that actually works in production: on-prem or private cloud, with guardrails, audit trails, and zero “mystery box” dependencies. Ideal for US/EU teams that care about data residency, cost, and reliability.

On-Prem / Private AI

Run modern LLM capabilities where your data lives — not the other way around.

  • Model serving (CPU/GPU), networking, and capacity planning
  • SSO/RBAC, secrets, logging, and change control
  • Cost controls, caching, observability, and latency budgets

Agents + Automations

Automation that executes, documents, and escalates — with human approval where needed.

  • n8n workflows + integrations (Slack/Jira/CRM) + voice-to-text ingestion
  • Runbook-style agents for SRE/on-call support
  • Guardrails: allowlists, approvals, and audit trails

RAG + Vector Stores

Turn internal docs into an answer engine (without leaking private data).

  • Ingestion pipelines, chunking, embeddings, permissions
  • Vector stores: pgvector, Qdrant, Weaviate (or what you already run)
  • Evaluation + drift checks so it stays correct over time
AI deliverables (no fluff)
  • Architecture + threat model
  • Proof-of-value pilot (1–2 weeks)
  • Production rollout plan + runbooks
  • Monitoring, cost model, and SLOs
  • Team training + handover
  • Data residency and compliance notes

Platforms and tooling I ship with

The production stack I actually build and run with — from the bare metal up to multi-tenant SaaS.

Languages & build

Go · TypeScript / React / Next.js · Python · PHP · Bash · Swift · gRPC/REST · OpenAPI · Stripe · Terraform provider

Platform & virtualization

Proxmox VE / PBS / PMG · ZFS · KVM / LXC · Ceph · Docker · Kubernetes · TrueNAS · cPanel/WHM · LiteSpeed

Automation & delivery

Ansible · Terraform · Packer · cloud-init · GitOps (GitHub Actions / ArgoCD) · GoReleaser · n8n

Data & messaging

PostgreSQL (RLS) · MariaDB / Galera · Redis · Memcached · NATS · RabbitMQ

Networking, DNS & mail

dnsdist (DoH/DoT/DoQ) · PowerDNS · BIND · Unbound · HAProxy · Nginx · Caddy · nftables · Postfix · Dovecot · PMG

Observability & security

Zabbix · Prometheus · Grafana · Loki · PMM · Sentry · fail2ban · CIS / auditd · ACME

eCommerce platforms (performance, uptime, and revenue protection)

I specialize in the infrastructure behind stores that must stay online: performance tuning, scaling, hardening, migrations, and “it’s broken right now” recovery.

WordPress + WooCommerce

Speed, stability, and security for WooCommerce at scale.

  • Cache strategy, PHP-FPM tuning, database performance
  • Bot/abuse mitigation, WAF patterns, mail deliverability
  • Safe plugin updates and rollback strategy

Magento (Adobe Commerce)

Production operations that keep checkout fast and predictable.

  • MySQL/MariaDB tuning, indexing, and observability
  • Queues/cron reliability, deployments, and staging discipline
  • Scale patterns, HA, backups, and recovery drills

OpenCart + Other Stacks

Pragmatic ops and performance improvements for real-world stores.

  • Hosting stack hardening (Nginx/HAProxy, TLS, headers)
  • Monitoring + alerting to catch revenue-impacting issues
  • Migrations: cloud → colo/on-prem, or broken → stable
What you get
  • Performance baseline + bottleneck map
  • Hardening checklist and rollout plan
  • DB + cache tuning with verification steps
  • Backup/restore drills and incident playbook
  • Monitoring tuned to business impact
  • Clear postmortems after incidents

Battle-tested, not theoretical

Signature outcomes

  • Head of Infrastructure (2022–2025) at a Dutch hosting provider — sole owner of a 43-node Proxmox/ZFS fleet, 261 VMs, ~20,700 accounts across 3 datacenters.
  • Built the product-defining automation: self-healing kernel-panic→Sentry telemetry, controller-safe ZFS scrub scheduling, bare-metal→cluster provisioning — ~30,000 lines / 305 production tools.
  • Built a fleet-wide mail proxy — central SMTP/IMAP/POP3 with dynamic per-domain routing to the correct cPanel mailbox server — one mail endpoint for ~20,700 accounts.
  • Built, fixed, or optimized 50,000+ servers; 50+ Proxmox clusters (PVE/PBS/PMG) deployed.
  • Remediated major failures (e.g., SAN failure) and stabilized production fast.

Open-source footprint

If you want to see how I think, the repos and runbooks are public.

Founder & operator

  • CTO of Apollo-Auto.com — designed, built, and ran the entire B2B ecommerce platform; grew to US$100M+/year.
  • Founded and ran multiple companies (EatMeat, GroWarehouse, JanHar) — managed teams up to 35 staff.
  • SVP Infrastructure (advisory) — global ZFS dRAID backup design; major-failure remediation.
  • I’ve carried the P&L, not just the pager — I think in cost, risk, and ROI.

Proxmox in production (screenshots)

Sanitized examples of Proxmox VE / Proxmox Backup Server dashboards from real deployments (50+ clusters). Click any screenshot to enlarge.

Multi-year worklog (sanitized)

This is a sanitized, multi-year timeline generated from private repositories, filtered for Proxmox, clusters, deployments, storage, databases, and related infra work.

Download JSON
Loading worklog…

Rates & engagement

Transparent ranges so we don’t waste each other’s time — final scope and a fixed quote follow a short call. Most clients start with an audit or a build sprint, then move to a retainer. Remote; US / EU / UK friendly; invoiced B2B via eXtremeSHOK or through an EOR.

Infrastructure audit & action plan

from $5,000 · fixed · 3–5 days

  • Architecture review, risk map, and “what breaks next”
  • Prioritised, ROI-ordered action plan + quick wins
  • The high-value first step — fee credits toward delivery

Build / project sprint

from $1,800 / day · ~$225/hr

  • Ship a working result — platform, automation, or SaaS feature
  • 2-week ship-it sprint from $18,000
  • Reversible, tracked changes with tests + runbooks

Fractional CTO / Advisory

from $2,000 / day · ~$250/hr

  • Technical leadership, architecture, roadmap, hiring
  • Vendor selection, build-vs-buy, cost/risk calls
  • Advisory retainer from $9,000/mo (~1 day/wk); fractional from $16,000/mo (~2 days/wk)

Managed operations / retainer

from $5,000 / mo

  • “Keep it boring” — monitoring, patching, backups/DR
  • On-call + incident response with agreed SLAs
  • Continuous hardening and monthly improvements

Emergency / incident rescue

$450 / hr · 4-hr min · 24/7

  • “It’s down right now” triage + stabilisation
  • A permanent fix and a runbook so it stays fixed
  • Faster response — and a lower rate — with a retainer

Permanent / founding roles

Let’s talk · equity-inclusive

  • Founding / Principal Platform Engineer · Staff SRE · Head of Infra/Eng · Fractional CTO
  • Selective — strong product and team fit
  • 100% remote · work-ready UK/EU/US/ZA

Rates in USD; invoiced in GBP / EUR / USD. Day rate assumes remote, ~8 hours. Packages and longer engagements are discounted.

To save us both time
  • Minimum engagement: 2 days (or $3,000)
  • Free 30-min discovery call — no open-ended “pick your brain”
  • No unpaid trials / take-homes — the portfolio & GitHub speak for themselves
  • Fixed quote available after a short scoping call
  • NDA-friendly · least-privilege access · audit trails
  • Work-ready: UK · EU · US · ZA · worldwide on contract · banks in UK/EU/US (GBP/EUR/USD)

How engagements run

1) Triage

Quick intake, define the problem, align on outcomes, and get access safely.

2) Audit

Baseline, risks, bottlenecks, and “what breaks next” — documented and prioritized.

3) Ship

Hands-on fixes, automation, hardening, and monitoring. Changes are reversible and tracked.

4) Handover

Runbooks, diagrams, and clear next steps so your team isn’t dependent on me.

5) Retainer (optional)

On-call, ongoing improvements, and “keep it boring” operations.

US & EU ready
  • Remote-first, async-friendly, documented decisions
  • NDA-friendly; least-privilege access patterns
  • GDPR-aware and privacy-minimal approach
  • Production change discipline (rollbacks, windows)
  • Time-zone overlap planning (EU/UK, US mornings)
  • Clear comms: what changed, why, and how to verify

Contact

Quick message

This form uses Web3Forms for delivery. If your environment blocks forms, email admin@extremeshok.com.

Email me

Email me and I’ll reply with available slots and next steps.

Email: admin@extremeshok.com

Send: a 2–3 sentence problem statement, your stack, urgency, and what “done” looks like.

Quick CLI
$ printf "Need help: %s\n" "your problem here" | mail admin@extremeshok.com

Questions I get a lot

Do you do short audits, or only big projects?

Both. A short audit can produce a high-ROI plan, and we can then execute the top items.

Can you work under NDA / security restrictions?

Yes. I prefer least-privilege access, audit trails, and explicit scopes. You’ll get documentation, not mystery.

Are you “cloud-only” or “on-prem only”?

Neither. I build the right mix: on-prem, colocated, cloud, hybrid — whatever makes sense for cost, latency, and risk.

Do you help with ongoing operations?

Yes. Retainers are ideal when you want stability, predictable improvements, and fast incident response.

Privacy & data handling

No trackers. No ad pixels. No “growth hacks”. If you contact me, I only use your details to reply and deliver the work.

  • Collected: name, email, company (optional), region, urgency, message
  • Purpose: respond, schedule, scope work, and provide ongoing support if requested
  • Storage: delivered via Web3Forms (form service) and received in eXtremeSHOK email
  • Retention: kept only as long as needed for the conversation and delivery; deletion on request
  • Sharing: never sold; shared only with Web3Forms for delivery
  • EU/UK: GDPR-aware handling (minimal data, least-privilege access, audit trails)

Privacy questions or deletion requests: admin@extremeshok.com.