Infrastructure Engineer

PATRIK
ZIMA

Edge Networking Automation Linux Routing DR

Designing resilient enterprise infrastructure — from multi-site routing fabrics and DR architectures to secure edge platforms, automation pipelines and hardened Linux environments.

// 01

About me

I specialize in enterprise infrastructure — designing systems that don't fail when it matters. From multi-site DR topologies and routing fabrics to hardened edge platforms and full automation pipelines.

Currently operating as sole IT at CODYA, a Czech investment firm, where I own infrastructure architecture, networking, security operations, automation, monitoring and internal tooling.

I build to last, automate everything repeatable, and treat documentation as infrastructure.

5+
Years in IT
2DC
PROD / DR fabric
IaC
Ansible · AWX
HA
Availability mindset
// 02

Expertise

Infrastructure

Servers · Virtualization · Storage
VMware vSphereProxmoxWindows ServerHyper-VRocky / AlmaLinuxShared StorageBackup & Recovery

Networking & Routing

MikroTik · Cisco · Dynamic routing
MikroTik RouterOSCisco IOSOSPFGRE / IPIP tunnelsIPsecVLANBGP conceptsL2/L3 design

Security & Edge

Hardening · WAF · Security
Nginx reverse proxyModSecurity / OWASP CRSFail2Banfirewalld / iptablesSecurity monitoringTLS hardening

Automation & Linux

IaC · Pipelines · Scripting
Ansible / AWXDockerPowerShellBashAPI IntegrationInternal AppsTelemetry / Monitoring
// 03

Network architecture

I design and operate multi-site routed fabrics for enterprise environments. My current focus is a dual-datacenter PROD/DR topology built on a MikroTik IPIP/IPsec underlay with a Cisco GRE/OSPF overlay — a clean separation that keeps the tunnel transport independent from the routing domain.

The architecture replaces a legacy stretched L2 EoIP topology and delivers deterministic failover, per-prefix visibility in OSPF, and a foundation for future BGP peering without readdressing the core.

I also manage VLAN segmentation, ACL policy, firewalld zone design and VPN gateway configuration across both sites.

// DUAL DATACENTER FABRIC · SIMPLIFIED
PROD SITE
MIKROTIK
IPIPIPSECunderlay transport
CISCO
GREOSPFoverlay routing
↕ encrypted tunnel · failover aware
DR SITE
MIKROTIK
IPIPIPSECunderlay transport
CISCO
GREOSPFoverlay routing
Resilience: Backup & Recovery Visibility: Telemetry Operations: Automation
// 04

Projects

P.01

Dual-DC Routing Fabric

Migration from a flat stretched L2 topology to a MikroTik IPIP/IPsec underlay + Cisco GRE/OSPF overlay. Deterministic failover, per-prefix routing visibility, zero readdress.

MikroTikCiscoOSPFIPsec
P.02

Enterprise DR Architecture

Full disaster recovery design covering replication strategy, failover procedures, RTO/RPO targets and operational validation. Backup Platform backup integration.

Backup & RecoveryVirtualizationDR runbook
P.03

Edge Platform · pzforge.cz

Hardened Nginx reverse proxy with ModSecurity/OWASP CRS WAF, Fail2Ban, Let's Encrypt TLS, rate limiting and per-subdomain vhost routing on Rocky Linux.

NginxModSecurityWAFFail2Ban
P.04

Security monitoring Integration

Custom decoders, rules and alerting for internal application access logs. GeoIP enrichment pipeline, brute-force detection rules and dashboard tuning.

SecuritySecurityDetection rules
P.05

Automated Update Pipeline

Ansible/AWX playbook for fleet-wide security patching of RHEL-family VMs. Aggregated multi-host digest reporting, failure handling and AWX job scheduling.

AnsibleAWXRHEL fleet
P.06

Internal Apps

Secure internal applications and operational tools designed for real business workflows, centralized access and reliable day-to-day use.

Internal ToolsAutomationOperations
// 05

Certifications & stack

Certifications

MikroTik
MTCNA
Cisco
CCNA

Tools & technologies

VMwareProxmoxWindows ServerRocky LinuxCiscoMikroTikDockerAnsibleAWXNginxPowerShellTelemetry / MonitoringSecurityBackup & RecoveryOSPFIPsec