Case studies
Projects explained through the problem solved.
Personal infrastructure and field experience: every project covers context, method, outcome and demonstrated skills. Technologies remain secondary.
Evidence → method → outcome
Seven representative achievements
Published figures come from retained checks; sensitive operational information is intentionally excluded.
Infrastructure
Home Lab platform consolidation
2026A single-node Proxmox platform operated over time with 10 VMs and rationalized specialized roles.
- Problem
- Make the actual running infrastructure match configurations that are understandable, reconstructible and controllable.
- Method
- Inventory dependencies and runtime state
- Compare each service with its Compose definition
- Pin images and validate without a global recreate
- Retain evidence, rollback and residual debt
- Outcome
- 44 running services across 24 canonical Compose projects, with 42 registry images and two explicit local builds.
- Demonstrated skills
- Audit • Linux • Virtualization • Containers • Change management
Proxmox VEDebianDocker ComposeGit
Monitoring
Diagnostic-focused observability
2026The platform needed to correlate availability, system state, public exposure, logs and backups.
- Problem
- Reduce noise, remove obsolete signals and prevent a misplaced probe from producing a falsely reassuring status.
- Method
- Map targets and signal ownership
- Remove duplicates and rules without a source
- Test Error, NoData and recovery states
- Measure availability, latency and capacity over 30 days
- Outcome
- 66/66 targets and 27/27 probes available, instrumented local proxy health and no active alert at the final check.
- Demonstrated skills
- Troubleshooting • Metrics • Alerting • Log analysis • SLO
PrometheusGrafanaLokiBlackboxntfy
Continuity
Backups and recovery planning
2026VM backups existed, but their presence alone did not demonstrate controlled recovery.
- Problem
- Prove coverage and verification, define dependencies, then clearly distinguish backup, recovery and high availability.
- Method
- Check tasks, retention and verification
- Classify services by criticality
- Produce an offline USB copy with a manifest
- Validate restoration inside an isolated scope
- Outcome
- PBS coverage confirmed, offline copy controlled, restore validator protected against collisions and DR documented without claiming unavailable high availability.
- Demonstrated skills
- Backup • Disaster recovery • Risk analysis • Documentation • Integrity checks
Proxmox Backup ServerUSB offsiteSHA-256Runbooks
Resilience
UPS monitoring and orchestration
2026The UPS is attached to the Synology NAS, which exposes its telemetry to monitoring over SNMP.
- Problem
- An actual outage had remained silent and PVE orchestration had performed no reliable action.
- Method
- Keep the UPS-to-NAS-to-SNMP chain
- Validate Prometheus, Grafana and ntfy independently
- Constrain SSH and sudo to a dedicated helper
- Simulate battery and mains recovery without shutdown
- Outcome
- Consistent telemetry, received critical/resolved notifications, periodic PVE preflight and enabled orchestration with persistent state.
- Demonstrated skills
- SNMP • Alerting • Scripting • Least privilege • Resilience testing
SynologyPrometheusGrafanantfyPython
Networking & security
Publishing and attack-surface reduction
2026Selected internal services need remote access without directly exposing their hosts.
- Problem
- Centralize publishing, retain consistent TLS termination and make public-path state measurable.
- Method
- Separate functional zones
- Publish through a central control point
- Add filtering, headers and detection
- Validate locally and externally
- Outcome
- Exposure limited to the reverse proxy, monitored path health and retained rollback procedures.
- Demonstrated skills
- Segmentation • Reverse proxy • TLS • Hardening • End-to-end validation
NPMplusCrowdSecDNSTLSVLAN
Field experience
Professional progression toward cybersecurity
2025 — presentAt STT INFOPRO / IP INFOPRO in Le Muy, I am continuing my work-study path from a professional degree into CNAM's Cybersecurity Master's programme.
- Problem
- Resolve incidents and requests while preserving permissions, policies, connectivity and service continuity.
- Method
- Qualify the request and impact
- Diagnose from endpoint to service
- Apply the smallest necessary change
- Verify the outcome and record the intervention
- Outcome
- After a year focused on L1/L2 support, deployment and on-site work, my responsibilities are progressing toward infrastructure security, operations and more advanced systems and networking projects.
- Demonstrated skills
- L1/L2 support • Windows administration • Networking • Communication • Operations
Windows ServerActive DirectoryGPOVLANVPN
Engineering practice
Documentation and repeatable controls
2026Decisions and operations needed to remain understandable after each change window.
- Problem
- Prevent validation, commands and rollback paths from depending on operator memory.
- Method
- Write prerequisites and success criteria
- Automate non-destructive controls
- Generate dated, hashed evidence
- Version declarative material without secrets
- Outcome
- A locally validated repository, integrity manifest, change log and runbooks connected to technical evidence.
- Demonstrated skills
- Documentation • Scripting • Git • Quality control • Traceability
BashPythonGitMarkdownSHA-256