PATRIK
ZIMA
Designing resilient enterprise infrastructure — from multi-site routing fabrics and DR architectures to secure edge platforms, automation pipelines and hardened Linux environments.
About me
I specialize in enterprise infrastructure — designing systems that don't fail when it matters. From multi-site DR topologies and routing fabrics to hardened edge platforms and full automation pipelines.
Currently operating as sole IT at CODYA, a Czech investment firm, where I own infrastructure architecture, networking, security operations, automation, monitoring and internal tooling.
I build to last, automate everything repeatable, and treat documentation as infrastructure.
Expertise
Networking & Routing
Security & Edge
Automation & Linux
Network architecture
I design and operate multi-site routed fabrics for enterprise environments. My current focus is a dual-datacenter PROD/DR topology built on a MikroTik IPIP/IPsec underlay with a Cisco GRE/OSPF overlay — a clean separation that keeps the tunnel transport independent from the routing domain.
The architecture replaces a legacy stretched L2 EoIP topology and delivers deterministic failover, per-prefix visibility in OSPF, and a foundation for future BGP peering without readdressing the core.
I also manage VLAN segmentation, ACL policy, firewalld zone design and VPN gateway configuration across both sites.
Projects
Dual-DC Routing Fabric
Migration from a flat stretched L2 topology to a MikroTik IPIP/IPsec underlay + Cisco GRE/OSPF overlay. Deterministic failover, per-prefix routing visibility, zero readdress.
Enterprise DR Architecture
Full disaster recovery design covering replication strategy, failover procedures, RTO/RPO targets and operational validation. Backup Platform backup integration.
Edge Platform · pzforge.cz
Hardened Nginx reverse proxy with ModSecurity/OWASP CRS WAF, Fail2Ban, Let's Encrypt TLS, rate limiting and per-subdomain vhost routing on Rocky Linux.
Security monitoring Integration
Custom decoders, rules and alerting for internal application access logs. GeoIP enrichment pipeline, brute-force detection rules and dashboard tuning.
Automated Update Pipeline
Ansible/AWX playbook for fleet-wide security patching of RHEL-family VMs. Aggregated multi-host digest reporting, failure handling and AWX job scheduling.
Internal Apps
Secure internal applications and operational tools designed for real business workflows, centralized access and reliable day-to-day use.
Certifications & stack
Certifications
MTCNA
CCNA