Dynaread — one host, a dozen legacy sites, zero drama
Client
Dynaread (Canada)
When
Mar 2025 – present
Role
Senior DevOps Engineer, promoted to Principal DevOps Engineer
Problem
A multi-tenant host serving about a dozen client sites on legacy LAMP stacks, with part of the production estate on GCP.
What I did
Moved about 12 legacy sites from LAMP 5 to LAMP 8. Migrated the production estate from GCP to DigitalOcean. Introduced blue/green deployments. Gave each deploy user a chroot SFTP jail with bind-mounted docroots, so a user sees only their own sites. Moved sites that depend on .htaccess rewrites from Nginx to Apache. Manages Cloudflare Origin certificates by hand so certbot never overwrites them.
Result
About a dozen sites on current PHP, production off GCP, deployments without downtime.
Ubuntu
Apache
PHP
MySQL
DigitalOcean
GCP
Cloudflare
GitLab CI
SFTP chroot
JR Drilling — git push deploys into an SFTP-only host
Client
jrdrilling
Problem
A site that could only be updated over SFTP, by hand.
What I did
GitLab CI pipelines that deploy into a chroot SFTP jail, with bind mounts and a permission sync so the deploy user and the web server always agree on ownership.
Result
Deploys happen from a git push instead of a manual upload.
GitLab CI
SFTP chroot
bind mounts
Linux permissions
Encrypted, scheduled disk snapshots that actually complete
Client
Genesys Financial Intelligence (GenesysFI)
When
Sep 2025 – present
Problem
Application-consistent snapshots on GCP were failing silently under continuous disk I/O.
What I did
Found the silent failures, switched to crash-consistent snapshots encrypted with customer-managed keys (CMEK), on a schedule.
Result
Backups that run on schedule instead of failing without a trace.
GCP Compute Engine
CMEK
snapshot schedules
Cutting LLM API costs in a Claude-powered backend
Problem
A backend service built on the Claude API was spending far more on tokens than it needed.
What I did
Traced the cost to a large conversation-history window and bloated tool results, then shaped tool outputs to the fields actually used, shortened the history window and added prompt caching.
Result
Token spend brought under control without changing what the service does.
Claude API
Node.js
prompt caching
IMS Global — Microsoft 365 cutover with every email check passing
Client
IMS Global (imsglobal.io), IT managed services
Problem
Company email needed moving to Microsoft 365 without losing deliverability.
What I did
Set up Microsoft 365 Business Basic and completed the full DNS cutover — MX, SPF, DKIM and DMARC — plus mailbox warm-up guidance.
Result
MX, SPF, DKIM and DMARC all passing.
Microsoft 365
DNS
SPF
DKIM
DMARC
Earlier work
Booking platform for my own tour and hotel businesses
When
2020 – 2021
Problem
Two seasonal businesses depended on a booking platform on legacy VPS hosting and paid SaaS tools, and it had to survive peak holiday surges.
What I did
Moved it to DigitalOcean droplets and containerised the custom LAMP booking engine with Docker Compose, separating database, application and web tiers. Monitoring with sysstat and custom uptime webhook alerts.
Result
Ran in-house through peak seasons.
DigitalOcean
Docker
Docker Compose
LAMP
sysstat
Multi-tenant VPS hosting for local businesses
When
2016 – 2018
What I did
Moved clients from shared hosting to managed VPS: an Nginx caching reverse proxy in front of Apache/mod_php, clients separated by chroot jails and their own UNIX users, cron-wrapped certbot renewing SSL across dozens of virtual hosts, and automated MySQL dumps with retention.
Nginx
Apache
PHP
MySQL
Let's Encrypt
cron
chroot
Game servers for gaming communities — where it started
When
2012 – 2014
What I did
Ran bare-metal CentOS 6 servers for gaming communities that needed uptime and low latency. Bash scripts bootstrapped environments and shipped daily tarball backups to an off-site FTP server. iptables rate-limiting and connection tracking held off UDP/TCP floods, and sysctl tuning kept the network stack fast.