Edy ServicesCatalog Create account Sign in

Consulting

Services & consulting

Infrastructure and security engineering, offered as scoped work: zero trust architecture and cybersecurity operations, leaving VMware behind, managing Linux hosts properly, getting remote access and identity right, and automating the parts that should never be done by hand twice.

Headline offering

VMware alternative consulting

Licensing changed, and a lot of estates now need somewhere else to be. I help plan and carry out the move to a platform you can keep: KVM and libvirt, Proxmox VE, oVirt and Oracle Linux Virtualization Manager, XCP-ng, Hyper-V, or containers where a virtual machine was never the right answer. Assessment, pilot, migration and then running it — including the management tooling, backup, identity and network services that have to come with it.

The assessment is genuinely allowed to conclude that part of your estate should stay where it is. That is a result, not a failure.

KVM / libvirtProxmox VEoVirt / OLVMXCP-ngHyper-Vpodman / containers

How a migration runs

Four phases, each with its own exit. You can stop after any of them.

Phase 01

Assessment

An inventory of what you actually run — guests, storage, networking, backup, the management and automation hanging off vCenter — and an honest read on which workloads move easily, which move with effort, and which should not move at all.

Phase 02

Pilot

A small replacement platform stood up for real, with the storage and network design you would keep, and a representative workload migrated onto it. The point is to find the surprises while they are still cheap.

Phase 03

Migration

Conversion and cutover planned in waves, with rollback defined before each one: guest conversion, network and VLAN mapping, storage moves, licensing and support paths, and the runbook the operators will use on the night.

Phase 04

Operations

The part that decides whether the migration holds: backup and restore proven by restore, monitoring, patching, host management tooling, identity and certificate plumbing, and documentation your team can run without me.

Also available

Other engagements

Each of these is grounded in something that has been built and published — the links go to the source.

Zero trust architecture

Access decided by identity and posture, never by which network a packet arrived on. Per-device certificates from an internal authority with no trust-on-first-use, mutual TLS between services, an overlay (WireGuard or Headscale) as the only path between sites, and routing and firewall policy that is generated from what a node is entitled to rather than hand-kept. The estate this site runs on is built that way: nodes enrol with a one-time bundle and a pinned root, a node with no firewall policy refuses to serve, and public certificates stop at the public listener while everything behind it trusts only the internal CA.

identity-centric accessmTLS / internal PKIWireGuard / Headscalesegmentationleast privilege

Built on: cockpit-wireguard (opens in a new tab), cockpit-headscale (opens in a new tab), lin-ad-lab-with-cockpit (opens in a new tab)

Cybersecurity engineering and operations

Twenty-five years of defending Windows and Linux estates, applied to the unglamorous parts: hardening baselines and privileged-access design, secrets management that keeps keys off shared paths, replication of trust material with revocation that actually propagates, security-event capture that reaches a SOC pipeline instead of a local log, and incident-style reviews that write down what was verified, what was refused and what an attacker could still do. Assessments, remediation plans and the engineering to carry them out.

hardeningsecrets managementSOC / event pipelineincident reviewcompliance-ready evidence

Built on: cockpit-secrets (opens in a new tab), cockpit-os-tuner (opens in a new tab), linux-cockpit-remote-desktop-guac (opens in a new tab)

Active Directory, identity and PKI

Directory design and rehearsal on disposable labs: multi-controller domains, group policy, sites and services, FSMO and replication, DNS, and Kerberos-backed authentication for Linux members. Alongside it, an internal certificate authority and the issuance, renewal and trust distribution that make it usable.

Samba ADKerberosLDAPSinternal CA

Built on: lin-ad-lab-with-cockpit (opens in a new tab)

Network services: proxy, DNS, DHCP, firewall

Reverse proxying and load balancing with TLS termination, split internal and external DNS, DHCP and address management, firewall policy, and the replication that keeps a fleet of nodes agreeing with each other. This site is served through exactly that stack.

reverse proxyDNSDHCP / IPAMTLS

Security review of administrative tooling

A second pair of eyes on the consoles that hold your keys: threat model, hazard register, and an adversarial pass over the privileged surface — who the server believes you are, what a client-side check is really worth, and what remains true of an attacker on a good day. The findings are written down, including the ones left standing and why.

threat modellingred teamleast privilege

Built on: cockpit-secrets (opens in a new tab)

Getting started

Contact for a scoped engagement

Every engagement starts the same way: a conversation about what you run now, what is forcing the change, and what "done" has to look like. From that comes a written scope with phases, deliverables and an exit — before any work begins.

About

Edward Skarke

Senior infrastructure and security engineer, with twenty-five years in IT and cybersecurity. The work is Linux and Windows platform engineering: host management tooling, directory and identity services, network services and remote access, and the automation and documentation that let somebody else operate the result.

Work history lives on LinkedIn; it is deliberately not reprinted here.