# Portfolio

> Browse the full portfolio of Engineer ApS engineering achievements, each with a detailed review.

- [Developed and launched the company's first observability dashboard, providing real‑time system performance insights and data visualization on the large office TV.](https://platform.engineer.company/portfolio/developed-and-launched-the-company-s-first-observability-9/)
- [Designed, deployed, and maintained 10 PostgreSQL and MS SQL servers on Ubuntu Linux VPS, ensuring optimal server performance and reliability.](https://platform.engineer.company/portfolio/designed-deployed-and-maintained-10-postgresql-and-ms-13/)
- [Enhanced data security by implementing 1,000 RBAC rules for developers, application instances, PostgreSQL, MS SQL, and other Linux servers, preventing unauthorized access; documented with Ansible automation.](https://platform.engineer.company/portfolio/enhanced-data-security-by-implementing-1-000-rbac-14/)
- [Automated GIS SaaS application deployment, data processing, and reporting system using GitHub Actions CI/CD, Python, Bash, and SQL.](https://platform.engineer.company/portfolio/automated-gis-saas-application-deployment-data-processing-and-16/)
- [Automated delivery of 20 GIS data pipelines and app data ETL processes, streamlining infrastructure automation and reporting.](https://platform.engineer.company/portfolio/automated-delivery-of-20-gis-data-pipelines-and-17/)
- [Automated 100 critical data backups using Barman, Google Cloud, Bash, and Python, ensuring data integrity across databases.](https://platform.engineer.company/portfolio/automated-100-critical-data-backups-using-barman-google-18/)
- [Deployed and maintained 20 Docker containerized applications, troubleshooting with Podman and Kubernetes, and managing R‑based apps on Google Cloud and AWS.](https://platform.engineer.company/portfolio/deployed-and-maintained-20-docker-containerized-applications-troubleshooting-19/)
- [Managed 30 Ubuntu Linux VPS instances, implementing disaster recovery strategies and ensuring optimal network configurations.](https://platform.engineer.company/portfolio/managed-30-ubuntu-linux-vps-instances-implementing-disaster-20/)
- [Prevented security breaches by leading access management initiatives, utilizing M365, 1Password, Red Hat SSO, and OKTA SSO.](https://platform.engineer.company/portfolio/prevented-security-breaches-by-leading-access-management-initiatives-21/)
- [Mitigated operational risks by implementing a monitoring dashboard using Grafana and Prometheus, improving system reliability.](https://platform.engineer.company/portfolio/mitigated-operational-risks-by-implementing-a-monitoring-dashboard-22/)
- [Managed and troubleshooted 8 WireGuard VPN and IPSEC VPN connections, ensuring secure communication across Google Cloud and Linux systems.](https://platform.engineer.company/portfolio/managed-and-troubleshooted-8-wireguard-vpn-and-ipsec-23/)
- [Improved team communication and collaboration by implementing Slack, Mattermost, 1Password, and Jira, saving 8,000 hours of labor.](https://platform.engineer.company/portfolio/improved-team-communication-and-collaboration-by-implementing-slack-34/)
- [Overhauled internal processes, saving 8,000 hours by improving software architecture, systems, and scheduling efficiency.](https://platform.engineer.company/portfolio/overhauled-internal-processes-saving-8-000-hours-by-38/)
- [Administered network infrastructure for over 1,000 servers, ensuring optimal system deployment, security, and troubleshooting.](https://platform.engineer.company/portfolio/administered-network-infrastructure-for-over-1-000-servers-39/)
- [Automated SSL/TLS certificate creation for 100 Docker applications, ensuring secure connections across Ubuntu Linux hosts.](https://platform.engineer.company/portfolio/automated-ssl-tls-certificate-creation-for-100-docker-41/)
- [Streamlined CI/CD processes, saving 4,000 hours by introducing automation in software development pipelines.](https://platform.engineer.company/portfolio/streamlined-ci-cd-processes-saving-4-000-hours-42/)
- [Streamlined data analysis and software development processes, saving 4,000 hours by introducing GitHub, GitLab, Bash, and Python CI/CD practices.](https://platform.engineer.company/portfolio/streamlined-data-analysis-and-software-development-processes-saving-43/)
- [Automated data processing tasks using Shell scripting, PL/pgSQL, Python, and Transact‑SQL, increasing productivity and efficiency.](https://platform.engineer.company/portfolio/automated-data-processing-tasks-using-shell-scripting-pl-45/)
- [Configured and deployed 1,000 Wi‑Fi routers, improving network accessibility and performance for clients.](https://platform.engineer.company/portfolio/configured-and-deployed-1-000-wi-fi-routers-48/)
- [Administered 100 Bare Bone servers, physical networks, and IP telephony systems, ensuring robust infrastructure for company growth.](https://platform.engineer.company/portfolio/administered-100-bare-bone-servers-physical-networks-and-50/)
- [Administered 40 websites on Ubuntu Linux hosting servers with Apache and Nginx, ensuring high availability and performance.](https://platform.engineer.company/portfolio/administered-40-websites-on-ubuntu-linux-hosting-servers-53/)
- [Architected, developed, implemented, supported infrastructure, data processing, and the map application for 2 years non‑stop without any weekends, holidays, or vacations, 10–14 hours a day.](https://platform.engineer.company/portfolio/architected-developed-implemented-supported-infrastructure-data-processing-and-55/)
- [Optimized budget costs 10 times with zero loss in productivity for the Saudi Arabia company by reimagining the overall infrastructure, eliminating unnecessary services, and relocating from the AWS cloud.](https://platform.engineer.company/portfolio/optimized-budget-costs-10-times-with-zero-loss-56/)
- [Designed an organization context‑switching system with client localStorage and server‑side cookie mirroring, letting users act as managed organizations while enforcing least‑privilege authorization.](https://platform.engineer.company/portfolio/designed-an-organization-context-switching-system-with-client-59/)
- [Generated the API contract outward from the database — OpenAPI, a 44,076‑line typed TypeScript client, 61 mock handlers and the limits the UI enforces — with a guard at every hop that fails on drift.](https://platform.engineer.company/portfolio/built-a-request-schema-validation-contract-with-automated-61/)
- [Built email as a platform capability — three providers with failover, delivery webhooks, send and delivery logging, templating and campaigns — behind a startup check that will not boot without one.](https://platform.engineer.company/portfolio/built-email-as-a-platform-capability-with-failover-62/)
- [Provisioned Azure infrastructure as code with Bicep — Container Apps, PostgreSQL Flexible Server, Front Door/WAF and networking — across the development, staging and production environments.](https://platform.engineer.company/portfolio/provisioned-azure-infrastructure-as-code-with-bicep-container-68/)
- [Built GitHub Actions CI/CD pipelines with a distroless production frontend image and multi‑environment promotion.](https://platform.engineer.company/portfolio/built-github-actions-ci-cd-pipelines-with-a-69/)
- [Authored 578 go‑task automation targets spanning native, Docker and HTTPS dev modes, linting, testing, database and deployment.](https://platform.engineer.company/portfolio/authored-578-go-task-automation-targets-70/)
- [Owned end‑to‑end deployments of the platform to Azure, managing releases across development, staging and production environments.](https://platform.engineer.company/portfolio/owned-end-to-end-deployments-of-the-platform-71/)
- [Configured database backup retention as infrastructure‑as‑code, then audited the recovery position and documented the restore procedure — naming the remaining gaps rather than leaving them to be found during an incident.](https://platform.engineer.company/portfolio/configured-database-backup-retention-as-infrastructure-as-code-72/)
- [Hardened the application with nonce‑based CSP, HSTS, SameSite cookies, least‑privilege database roles and server‑side entitlement re‑checks.](https://platform.engineer.company/portfolio/hardened-the-application-with-nonce-based-csp-hsts-77/)
- [Set a zero‑warnings quality bar across six languages — Go, TypeScript, SQL, Python, Shell and Markdown — enforced by pre‑commit hooks.](https://platform.engineer.company/portfolio/set-a-zero-warnings-quality-bar-across-six-79/)
- [Provided round‑the‑clock 24/7 infrastructure support for an IPTV/OTT streaming platform, administering ~1,000 servers plus client‑owned systems for global customers in China, the US and Germany.](https://platform.engineer.company/portfolio/provided-round-the-clock-24-7-infrastructure-support-82/)
- [Ensured uninterrupted delivery of IPTV streaming signals between suppliers and clients, monitoring and maintaining the streaming network and IP telephony around the clock.](https://platform.engineer.company/portfolio/ensured-uninterrupted-delivery-of-iptv-streaming-signals-between-83/)
- [Planned and implemented new infrastructure functionality for internal and external systems, building solutions durable enough to still run years later with minimal change.](https://platform.engineer.company/portfolio/planned-and-implemented-new-infrastructure-functionality-for-internal-85/)
- [As one of the first hires, designed and built the entire core infrastructure and supporting processes from scratch for a green‑energy SaaS startup, laying the foundation for rapid growth.](https://platform.engineer.company/portfolio/as-one-of-the-first-hires-designed-and-86/)
- [Automated team collaboration, password management, task and time management, and built a semi‑automatic project‑showcase system, raising team productivity.](https://platform.engineer.company/portfolio/automated-team-collaboration-password-management-task-and-time-89/)
- [Integrated a company‑wide password‑management system, strengthening security and streamlining access control.](https://platform.engineer.company/portfolio/integrated-a-company-wide-password-management-system-strengthening-90/)
- [Built a layered automated test suite — 981 Go tests, 543 frontend and browser specs, 494 SQL behavioural tests — with mutation testing, property‑based tests and an accessibility gate.](https://platform.engineer.company/portfolio/built-a-layered-automated-test-suite-across-four-layers-94/)
- [Built the repository's guard engine — 268 registered commit checks, 277 lint rules and 15 custom ESLint rules — plus 146 tests of the guards themselves, so the build holds the standard, not review.](https://platform.engineer.company/portfolio/built-the-repository-s-guard-engine-of-268-checks-95/)
- [Built the payments and entitlements layer — Stripe alongside Apple and Google in‑app purchase — gating the directory, search and export through an 11‑table access model checked on the server.](https://platform.engineer.company/portfolio/built-the-payments-and-entitlements-layer-96/)
- [Moved slow work off the request path onto a River job queue — 15 worker modules, 8 scheduled tasks and 20 pg_cron jobs — so a request returns while the work behind it carries on.](https://platform.engineer.company/portfolio/moved-slow-work-onto-a-river-job-queue-97/)
- [Built first‑party error monitoring and OpenTelemetry tracing rather than buying them — payload sanitising, spike and regression detection, symbolication and a synthetic heartbeat — behind 11 operator views.](https://platform.engineer.company/portfolio/built-first-party-error-monitoring-and-tracing-98/)
- [Kept the schema honest across 1,022 migrations with a CI gate that builds the database both ways — a fresh install, and an install plus every migration — and fails when the two disagree.](https://platform.engineer.company/portfolio/kept-the-schema-honest-across-1022-migrations-99/)
- [Built fail‑closed abuse controls — 22 Redis‑backed rate limiters, Cloudflare Turnstile, request idempotency and an origin lock — so the platform sheds bots and floods instead of trusting its callers.](https://platform.engineer.company/portfolio/built-fail-closed-abuse-controls-and-rate-limiting-100/)
- [Built company ownership claims end to end — a user claims a company, an administrator adjudicates, and an approval rewrites the authorization graph that decides who is allowed to edit what.](https://platform.engineer.company/portfolio/built-company-ownership-claims-end-to-end-103/)
- [Established a continuous security programme — code scanning, DAST, dependency and vulnerability checks, SBOM generation, secret scanning and SHA‑pinned actions — alongside 21 written security audits.](https://platform.engineer.company/portfolio/established-a-continuous-security-programme-104/)
- [Built the company's own infrastructure as 19 Ansible playbooks and 34 roles across 12,065 lines of YAML, converging a live host to a declared state with every play idempotent.](https://platform.engineer.company/portfolio/built-the-companys-infrastructure-as-code-108/)
- [Ran the whole company on one 512 MB single‑core host — a git forge, a web server serving seven domains, Tor, two alternate‑protocol servers, backups and intrusion banning — by treating 464 MB of usable memory as the binding architectural constraint.](https://platform.engineer.company/portfolio/ran-the-whole-company-on-one-512mb-host-109/)
- [Found and closed three SSH brute‑force protections that had never worked: a ban jail watching port 22 while the daemon listened on 1986, a rate limit shadowed by a broader rule above it, and a ban action whose binary never resolved, so no ban had ever applied.](https://platform.engineer.company/portfolio/found-three-ssh-brute-force-protections-that-never-worked-110/)
- [Hardened SSH to 24 asserted directives with three‑stage validation — the candidate file, the assembled config, then the daemon's own read‑back — after the read‑back caught the running server silently overriding two of the twenty‑four.](https://platform.engineer.company/portfolio/hardened-ssh-with-three-stage-validation-111/)
- [Proved the intrusion‑banning path end to end on every hardening run by banning a reserved test address, reading the resulting kernel rule and unbanning in a guaranteed cleanup block, so a jail that stops working fails a run instead of reporting healthy.](https://platform.engineer.company/portfolio/proved-the-intrusion-banning-path-on-every-converge-112/)
- [Verified firewall rules by position rather than presence, reading the numbered rule list and the live packet‑filter chain, because a rule that exists is not a rule any packet reaches.](https://platform.engineer.company/portfolio/verified-firewall-rules-by-position-113/)
- [Built encrypted off‑host backups on restic with retention pruning, an integrity check and a monthly automated restore drill, then audited the recovery position and wrote down the gaps rather than leaving them to be found during an incident.](https://platform.engineer.company/portfolio/built-encrypted-backups-with-a-monthly-restore-drill-114/)
- [Built dead‑man's‑switch monitoring that pings only while memory and disk are healthy, so a degraded host raises an alert by going silent — and caught six variable names saying "free" where the check correctly measured "available", an order of magnitude apart on a 464 MB box.](https://platform.engineer.company/portfolio/built-dead-mans-switch-monitoring-115/)
- [Made check mode tell the truth across the whole platform after finding six probes deciding on a value the host never gave, because Ansible's command module reports success under --check while skipping the command entirely.](https://platform.engineer.company/portfolio/made-ansible-check-mode-tell-the-truth-116/)
- [Added a preflight play that runs the same code as the converge against operator‑local secrets in about a second, after a half‑applied production run died on its ninth task with the swap settings already written to the live host.](https://platform.engineer.company/portfolio/added-a-preflight-play-for-secrets-117/)
- [Reconciled a 20‑record DNS zone declaratively against the Cloudflare API with separate audit and BIND‑export entry points, and turned the CDN proxy back off on privacy grounds after building it.](https://platform.engineer.company/portfolio/reconciled-a-dns-zone-declaratively-118/)
- [Cut systemd sandbox exposure across every unit this platform installs — a dead‑man's‑switch service from 9.6 UNSAFE to 1.5, an internet‑facing git forge from 8.3 EXPOSED to 1.5 — and added a converge‑time parser check after finding a misspelled directive silently ignored in three unit templates.](https://platform.engineer.company/portfolio/cut-systemd-sandbox-exposure-across-every-unit-119/)
- [Built seven read‑only reporting roles that render a live host to Markdown — facts, access, git, metrics, traffic, security and provider inventory — under a rule that no number is printed the run did not measure.](https://platform.engineer.company/portfolio/built-seven-read-only-host-reporting-roles-120/)
- [Deployed the company's own git forge on Soft Serve, private by default with no web panel and its SSH port bound to loopback behind a jump host, and made the landing page in front of it a build artefact of the main site rather than a hand‑kept copy.](https://platform.engineer.company/portfolio/deployed-the-companys-own-git-forge-121/)
- [Deployed a container plane on Podman and Quadlet under systemd rather than Docker, because Docker publishes container ports above the host firewall's own rules — and gave deploys an unprivileged user with one fixed command instead of root.](https://platform.engineer.company/portfolio/deployed-a-container-plane-on-podman-and-quadlet-122/)
- [Automated the provisioning of a second server on a second cloud provider, creating the firewall before the machine so it is born behind one, with both providers' firewalls written directly against their REST APIs to avoid a third‑party collection.](https://platform.engineer.company/portfolio/provisioned-a-second-server-from-code-123/)
- [Wrote a scope rule into the repository after a restructure carried another company's inventory, firewall allowances and prose into it — and kept the quarantined residue under the secret scanner rather than excluding it.](https://platform.engineer.company/portfolio/wrote-a-scope-rule-after-a-credential-leak-124/)
- [Split the four per‑host operational secrets after establishing that two hosts sharing one dead‑man's switch alert less than two switches, not more, and that a shared backup passphrase makes two hosts one repository.](https://platform.engineer.company/portfolio/split-every-operational-secret-per-host-125/)
- [Built a commit gate of 22 one‑line linters plus five that earn a paragraph, with no warning tier and no inline suppressions permitted, covering HTML, CSS, JavaScript, Python, YAML, Markdown, shell, links, spelling, secrets and typography.](https://platform.engineer.company/portfolio/built-a-22-linter-commit-gate-127/)
- [Cut the site's browser‑driven quality gate from 1,636 seconds to 615 by scheduling its checks longest‑first through a worker pool bounded to four lanes, after measuring that alphabetical order cost 320 seconds against 224.](https://platform.engineer.company/portfolio/cut-the-visual-quality-gate-to-ten-minutes-128/)
- [Mirrored the entire site as 777 Gemini documents and 777 Gopher documents off the same deployed tree, at zero bytes of change to the HTML.](https://platform.engineer.company/portfolio/mirrored-the-site-to-gemini-and-gopher-137/)
- [Fixed a sitemap where 172 of 176 URLs shared one modification timestamp, by taking the date from git history after establishing that the export rewrites every file on every run.](https://platform.engineer.company/portfolio/fixed-a-sitemap-with-one-shared-timestamp-140/)
- [Brought 10,242 lines of quality‑gate JavaScript under a formatter and a linter after establishing it was the largest body of code in the repository and the only one nothing read, fixing 13 findings and suppressing none.](https://platform.engineer.company/portfolio/brought-the-quality-gate-code-under-a-linter-143/)
- [Held the generator to 981 test cases at a 92% branch‑coverage floor with warnings treated as failures, and asserted idempotence by running the whole build pipeline twice from an empty file and requiring the second pass to change nothing.](https://platform.engineer.company/portfolio/held-the-generator-to-964-tests-and-a-coverage-floor-145/)
- [Selected every rule the Python linter has as an error, working through 1,815 findings to reach zero, with each of the few exemptions carrying a written reason and two of them backed by a checker instead of a comment.](https://platform.engineer.company/portfolio/enabled-every-python-linter-rule-as-an-error-147/)
- [Wrote tests for the checkers themselves after establishing that a checker fed only clean input will one day report clean because it read nothing — planting a misspelling to confirm the spell‑check finds it, and taking an id range from the database rather than from a number in the test.](https://platform.engineer.company/portfolio/wrote-tests-for-the-checkers-themselves-149/)
- [Found the commit hooks and the quality gate running different checks while a document promised they were the same, by comparing the two lists in a test — the five that only ever ran by hand were the ones reading the CV prose.](https://platform.engineer.company/portfolio/found-the-commit-hooks-and-the-gate-disagreeing-150/)
- [Rehearsed the forge‑side CI hook and found two defects unreachable by reading the file: a fallback that put an unresolvable argument on the hook's input, and git's own environment variable following the gate into the checkout and turning 19 tests red.](https://platform.engineer.company/portfolio/rehearsed-the-forge-side-ci-hook-151/)
- [Stopped an application filling memory at 41 MB a second — a recorded 111 GB of compressed pages on a 36 GB machine — by bounding every event stream, subscribing by event type and putting a rate budget on logging, taking 610,996 log lines down to 1,411.](https://platform.engineer.company/portfolio/stopped-an-application-filling-memory-at-41mb-a-second-155/)
- [Wrote a parser that reads the real 7,308‑line C header and verifies every call site, every enum constant and that every pointer‑owning class is final, after a hand‑written placeholder header let calls to three removed functions compile, link and crash.](https://platform.engineer.company/portfolio/wrote-a-parser-that-verifies-every-ffi-call-site-157/)
- [Took the test suite from six tests over a sixty‑second limit to 135 passing in 8.9 seconds by profiling the main thread and removing the two calls it sat inside for 3,989 samples out of 4,017.](https://platform.engineer.company/portfolio/took-the-test-suite-under-nine-seconds-158/)
- [Reached the half of the messaging core the application had never used — backup transfer, disappearing messages, message editing and resending, verified invitations, proxies and encryption policy — driving every test against the real library with no mocks.](https://platform.engineer.company/portfolio/reached-the-unused-half-of-the-messaging-core-161/)
- [Audited 644 Rust crates for licence compatibility on every build, and proved the check fires by rewriting one crate's licence and by moving the pinned core revision without regenerating.](https://platform.engineer.company/portfolio/audited-644-rust-crates-for-licence-compatibility-163/)
- [Held four repositories to one history standard — conventional, emoji‑free, no attribution trailers, enforced by a commit‑message hook — alongside 46 instruction documents that govern how the work is done.](https://platform.engineer.company/portfolio/held-five-repositories-to-one-history-standard-165/)

<https://platform.engineer.company/portfolio/>
