Linux • open-source • networks • servers • programming and scripting

Stable IT without unnecessary expense.

Data, operations and people’s time have value. When IT stops, it is not just a technical problem - work, business and company history stop with it.

I design, deploy and manage servers, networks, private business cloud, backups, monitoring and security. Where standard tools are not enough, I add purpose-built scripts, automation and web applications.

The goal is a stable, secure and recoverable environment that does not slow operations down and makes financial sense.

IT practice since the late 1990s ISP and network background Recovery-first mindset
Abstraktní mapa IT infrastruktury
01

Systems I can build and keep under control

This is not just about installing technology. What matters is that people can work, data stays safe, outages do not last longer than necessary and operating costs make sense. The solution may include servers, networks, backups, monitoring, security, CCTV, access control and purpose-built web or intranet tools. When data, reports or operational tasks are still processed manually, suitable automation can speed up the work, reduce errors and gradually repay the development cost. The key is to understand the real operational problem first - and only then choose the technology that solves it.

Servers, virtualization and recovery

A server should not be a black box that stops the organization for days when it fails. I design environments so services can be separated, backed up, versioned and restored quickly when something goes wrong.

Technical stack: Proxmox VE, Proxmox Backup Server, snapshots, incremental backups, HA scenarios, VMs and containers.

Learn more

Central accounts, access and file services

Users should not deal with ten passwords, and administrators should not manage access separately in every place. The goal is clear management of accounts, permissions and business data.

Technical stack: Samba AD, LDAP, shared data, file recycle bins, file versions and user/group permissions.

Learn more

Private business cloud

People expect cloud convenience: web access, mobile access, file sharing and document editing. This can also be built on your own storage and connected to existing accounts, permissions and network shares.

Technical stack: Nextcloud, OnlyOffice, external Samba storage, mobile access, a web UI and integration with the existing environment.

Learn more

E-mail infrastructure

E-mail should deliver messages reliably, filter unwanted mail and avoid ending up in spam because of poor configuration. A properly built mail server requires ongoing management, checks and updates, not only a one-time installation.

Technical stack: Postfix, Dovecot, Rspamd, Sieve, DKIM, SPF, DMARC, ARC, SRS, antivirus checks and domain management.

Learn more

Networks, Wi‑Fi and connectivity

When the network misbehaves, users usually only see that “the internet” is down, the system is slow or Wi‑Fi drops out in some areas. The cause may be unsuitable cabling, weak coverage, an overloaded connection or poorly separated parts of the network.

Technical stack: MikroTik, UniFi, switches, VLANs, routing, firewalling, QoS, wireless and fibre routes.

Learn more

Monitoring, automation and early warning

A problem detected in time usually costs less than an operational outage. Monitoring helps identify full disks, unavailable services, degraded connectivity and other unusual conditions.

Technical stack: Nagios, custom plugins, logging, graphs, service maps, automated checks and scripts.

Learn more

Firewall and operational protection

Well-designed network protection is not only about blocking traffic. It should prevent unauthorized access, separate sensitive parts of the operation and protect important services without making everyday work harder for users.

Technical stack: nftables, fail2ban, MikroTik firewall, service rules, network segmentation, VPN and monitoring of suspicious traffic.

Learn more

Business data security

Sensitive data should not remain unprotected simply because someone can access a disk or obtain incorrectly configured permissions. I handle encryption, permissions, secure data storage and a sensible balance between protection and convenient work.

Technical stack: LUKS, native ZFS encryption, user/group permissions, separated storage and secure backups.

Learn more

Web applications, intranet and helper tools

Sometimes an off-the-shelf system is not enough and a small tool tailored to real operations is needed: a register, overview, form, data import, log check or service integration. I build smaller web and intranet applications and helper scripts so they solve a concrete job without unnecessary complexity.

Technical stack: PHP, HTML, JavaScript, MySQL/MariaDB, Bash and Python depending on the purpose.

Learn more
02

Pragmatic. Not ideological.

IT should serve operations, not the other way around. I use open-source where it reduces cost, improves data control and makes operational sense. If a Linux/Windows hybrid solution is the right path, I design a hybrid solution. The goal is not a fashionable label, but a working result, regular care and a system that does not collapse at the first serious incident.

less overhead

Lower operating cost

Commercial products are not automatically wrong, but many organizations pay for licences, modules or complexity they do not really need. A sensible design can reduce cost significantly.

one access

Central management

The ideal state is one account, one password and clear permissions across services. Even when perfect unification is impossible, chaos can usually be reduced.

recovery

Recoverability, not just backups

A backup has value only when it is verified that data and services can actually be restored within an acceptable time. The design must therefore cover not only storing copies, but also returning the whole operation to service.

care

Regular cooperation instead of firefighting

IT is similar to health: neglected prevention comes back expensive later. Long-term supervision, updates, restore tests and log checks cost less than emergency work when users can no longer work.

hybrid solution

Gradual transition

Sometimes a full open-source transition is possible. Sometimes the right answer is to keep part of the Windows world and build the rest more openly and efficiently.

03

Rozik Portal

More about the portal

A proprietary modular web platform for business operations, client access and standalone applications. Individual modules share users, permissions, organizations, documents, audit trails and other core services, so the same data does not need to be created and maintained separately in every application.

The goal is to make work more efficient. Users enter only the information the system genuinely cannot determine on its own. Related values are calculated or pre-filled automatically from available data, so people review and confirm them instead of repeatedly retyping the same details. Less routine work means faster processing, fewer errors and more output from the same team.

The platform can be expanded gradually around real operational needs. A new module does not become an isolated island, but can securely use data and functions from other parts of the system. This makes it possible to develop the solution over time without layering unrelated applications, duplicate records and manual data transfers.

04

Typical situations where this approach pays off

Your IT solutions cost too much

Management needs to know what is necessary, what is unnecessarily expensive and where the risks are. I map what you really use, what is critical and what can be replaced with open-source, a simpler operating model or a more sensible licence option.

Data is scattered everywhere

In daily operations this creates confusion. During a failure it can mean losing years of work and starting from zero. I design central storage, clear access permissions, change history, recovery of deleted files and secure access from office, web and mobile.

Backups exist but recovery is untested

I build a backup and recovery plan that makes sense after server failure, user error or an attack. The goal is not just to have a backup, but also to restore operations quickly.

Users need to work from anywhere

Connect from a normal computer, notebook or tablet without complicated installations. Open a web browser, sign in and work with data or a remote desktop almost as if you were sitting in the office.

The network has grown organically

The network has gradually grown around immediate needs, and it is no longer clear what is connected where, which rules are still required or where risk is accumulating. I can map it, divide it into logical parts, document it and add monitoring so future changes can be made in a controlled way.

Looking for a specialist who understands real operations

I have experience from internet service provider environments, with servers, networks, users and non-standard operational requirements. I know IT not only from theory, but also hands-on: I studied automation technology, have overlap into electrical and mechanical environments, and hold professional electrical qualification under § 7 of Czech Regulation 194/2022. I do not solve only ideal lab conditions.

05

Technical stack for people who ask specific questions

The stack can be built from proven components. The important part is that they work together, can be monitored, backed up and restored.

Virtualization and storage

Proxmox VE Proxmox Backup Server KVM/QEMU Btrfs snapshots Ceph HA designs

Identity and data

Samba AD LDAP ACL Nextcloud OnlyOffice network shares

Communication

Postfix Dovecot Rspamd Sieve Roundcube DKIM/SPF/DMARC

Networks and connectivity

MikroTik UniFi VLAN routing QoS fibre and wireless links

Network and operational security

nftables fail2ban MikroTik firewall VPN segmentation logging

Data protection and encryption

LUKS ZFS encryption encrypted backups ACL service isolation access audit

Monitoring and automation

Nagios Nagiosgraph Nagiosmap rsyslog custom plugins automation

Programming and scripting

PHP HTML/CSS JavaScript MySQL/MariaDB Bash Python
06

Interested in cooperation?

Contact me through the form. You do not need to know technology names - briefly describe the problem, current situation or your idea. I will get back to you and we will agree on a suitable next step.

Jan Rosenreiter www.rozik.net LinkedIn

Form data is used only to respond to your request. No external marketing trackers are used.