TPTito Pinardo Gutiérrez
Español

Hi, I'm

Tito Pinardo Gutiérrez

Systems Administration · Infrastructure as Code · DevOps

ASIR + DAW graduate. I run real infrastructure with Terraform and Ansible, deploy with Kubernetes and GitOps, and I care about understanding why something fails before fixing it.

Looking for my first role as a junior systems administrator, DevOps or SRE engineer.

Quick view

The essentials for a first screening, in one minute.

Higher Vocational Qualification in ASIR + DAW (2026), focused on Linux systems, networking and DevOps. Internship experience building internal software at a university centre and as an IT technician in Malta, working entirely in English. I run a production homelab managed as code with Terraform, Ansible and Proxmox.

Looking for
Junior systems administrator, DevOps or SRE role
Location
Alcalá de Henares, Madrid, Spain
Education
ASIR + DAW (2023–2026) · Microcomputer Systems & Networks (2021–2023)
Languages
Spanish native · English C1 listening/reading, B2 speaking/writing
Strongest in
Linux, Terraform, Ansible, Proxmox, Docker, Kubernetes, networking

Download CV Get in touch

Or explore the map: each zone unlocks a part of my work.

01

Base

Who I am

I've just completed a combined Higher Vocational Qualification in Systems Administration (ASIR) and Web Application Development (DAW), so I have both halves: I can run systems and networks, and I can write the tools that automate them.

Outside class I run a homelab that is not a toy: it serves my household every day and is defined entirely as code. If a server disappears, Terraform recreates it and Ansible configures it exactly as it was.

How I work: measure before changing, one change at a time, verify it in production and document it, including what didn't work. I'd rather turn a manual fix into maintainable automation than do it twice.

I've worked in English with clients and a technical team during an international internship in Malta.

  • Cause, not symptom

    I look for why something fails before touching it. My postmortems explain the root cause and how to detect it next time.

  • Everything as code

    Versioned infrastructure, encrypted secrets, and changes reviewed with plan/diff before they're applied.

  • Measure, don't guess

    One measurement is not a result. I compare against a baseline, repeat, and keep measured and estimated apart.

Before and after

Drag to compare setting up a service by hand with how I do it now.

✗ By hand

$ ssh root@servidor
# apt install ... (¿qué más hacía falta?)
# nano /etc/app/config.yml
# systemctl restart app   # ¿funcionará?
  • SSH in and install packages as I remember them.
  • Edit configs directly on the server.
  • What did I change last month? Nobody knows.
  • If the container breaks: an afternoon of trial and error.
  • Passwords in plain text files.

✓ As code

resource "proxmox_virtual_environment_container" "landing" {
  vm_id        = 125
  unprivileged = true
}
$ terraform plan   →  1 to add, 0 to change, 0 to destroy
$ ansible-playbook playbooks/landing.yml   →  failed=0
  • Terraform creates the container and Ansible configures it.
  • Every change is a commit reviewed with plan or --diff.
  • Git history says what changed, when and why.
  • If it breaks: one command and it's back exactly as it was.
  • Secrets encrypted with Ansible Vault.
02

Skill tree

What I can do

Pick a skill to see where I've used it.

Infrastructure as code

Provisioning and configuration with no manual steps.

Containers & delivery

Packaging, deploying and running applications.

Linux & networking

The foundation everything else runs on.

Observability & security

Knowing what's happening and shrinking the attack surface.

Development & data

Writing the tools that automate the rest.

Use it daily in production · Deployed and maintained it · Used in a project

03

Quests

Real projects

  1. Ongoing

    Security & monitoring

    Knowing what happens on every machine and closing what shouldn't be open.

    • Wazuh
    • Zabbix
    • Linux / SSH hardening
    • MikroTik
    • VLANs
    • WireGuard
    • Ansible
    Ongoing personal project within the homelab.

    With more than twenty containers and VMs, checking each one's security and health by hand doesn't scale.

    • Automated Zabbix and Wazuh agent rollout with Ansible, with email and chat alerts tested end to end.
    • Vulnerability review with Wazuh: fixed all 430 entries that had a published fix and documented the remaining ones and their limits.
    • Reusable Linux and SSH hardening applied as an Ansible role, and a network audit with fixes on the router and firewall.
    • Took every dashboard that didn't need to be public off the internet: only the essentials stay exposed.

    A smaller exposed surface, and alerts that arrive on their own instead of manual reviews.

    I document what an audit doesn't prove as carefully as what it does: 'no findings' is not 'no vulnerabilities'.

    Private code (happy to walk through it in an interview)

  2. Completed

    OpenShift cluster (OKD)

    A three-node cluster on Proxmox to practise OpenShift administration.

    • OpenShift (OKD)
    • Kubernetes / K3s
    • Terraform
    • Ansible
    • Proxmox VE
    • Technitium DNS
    Personal lab, installation completed and verified.

    I wanted to practise OpenShift for real, with real installation problems, not a guided tutorial.

    • Three nodes defined in Terraform, DNS prepared and installed with the Agent-Based Installer.
    • Solved the real problems along the way: an ISO with a boot bug, insufficient RAM, boot order after install and etcd latency on spinning disks.
    • Verified result: 3/3 nodes Ready and 33/33 healthy operators, with a test application deployed through Ansible.

    A working OpenShift cluster and an installation log with every failure and its fix.

    etcd doesn't forgive slow disks: storage latency shows up in the control plane long before it shows in the apps.

    Private code (happy to walk through it in an interview)

  3. Completed

    Automatic document classification

    Python scripts that classify and assign student documents on their own.

    • Python
    • Docker
    Internship at Centro Universitario Cardenal Cisneros.

    Student documents were classified and assigned by hand.

    • Python scripts on the Paperless-ngx API that classify and assign documents automatically.
    • Researched AI and handwriting recognition to support automated replies to student enquiries.

    Less repetitive manual work for the centre's staff.

    Private code (happy to walk through it in an interview)

  4. In production

    This website

    Rust, PostgreSQL and my own homelab, no templates or site builders.

    • Rust
    • PostgreSQL
    • Traefik
    • Terraform
    • Ansible
    • Git
    Personal project, in production.

    I wanted a way to show my work that is, in itself, an example of how I work.

    • Rust server with Axum and compiled templates; PostgreSQL with compile-time checked queries.
    • Pre-rendered pages behind Cloudflare: almost no visit ever reaches the server.
    • Deployed with Terraform and Ansible on my homelab, behind Traefik and monitored.
    • Works without JavaScript; the map, terminal and achievements are an enhancement on top.

    What you're looking at.

    The fast part of a website isn't the server's language, it's not having to call the server.

    View code ↗

04

Journey

Experience and education

  1. Sep 2025 – Jun 2026

    Software Development Technician · Internship

    Centro Universitario Cardenal Cisneros · Alcalá de Henares, Spain

    • Developed and maintained internal software and utilities for university staff.
    • Redesigned relational databases to improve organisation, data access and automated workflows.
    • Migrated the centre's website and application ecosystem to a newer version.
    • Built Python scripts to classify and assign student documents through Paperless-ngx.
  2. Sep 2023 – Jun 2026

    Higher Vocational Qualifications · ASIR + DAW

    GSD International School Buitrago · Madrid, Spain

    • Network Systems Administration and Web Application Development, as a combined programme.
    • Final project: XPIFY, graded 10/10.
  3. Apr – Jun 2023

    IT Technician · International internship

    Micro Technology Consultancy Ltd · Ħaż-Żebbuġ, Malta

    • Worked entirely in English, coordinating the local technical team on client projects.
    • Led the rollout of dual-tablet charging splitters and client software for a fleet of 250 taxis.
    • Helped deploy 700 IP phones for a hotel, including PBX configuration.
  4. Sep 2021 – Jun 2023

    Vocational Qualification · Microcomputer Systems & Networks

    GSD International School Buitrago · Madrid, Spain

05

The lab

Inside my homelab

This is my server from the inside. Pick a journey and watch the real path things take, or tap any piece to see what it does.

The interactive server map and its animated journeys are in the full view.

Hermes

Tap a piece of the server or pick a journey.

    • Outside
    • Network
    • Compute & media
    • Control
    • Observability
    • AI
    • Application
    Your visit to this site
    1. Internet — You type titopinardogutierrez.com into your browser.
    2. Cloudflare — Cloudflare gets the request, checks it isn't an attack and forwards it to my home.
    3. MikroTik router — The MikroTik router only lets web traffic through to Traefik.
    4. Traefik — Traefik terminates TLS and knows from the domain that it's for this site.
    5. This website — The Rust binary already has the page rendered in memory: it answers in microseconds.
    6. Cloudflare — The response goes back through Cloudflare, which keeps a copy of whatever can be cached.
    7. Internet — And you're looking at it. The whole trip, in milliseconds.
    When you write to me
    1. Internet — You fill in the contact form and hit send.
    2. Cloudflare — Cloudflare filters automated traffic.
    3. MikroTik router — The router lets it through to Traefik.
    4. Traefik — Traefik hands it to the website.
    5. This website — The site validates the fields, checks the honeypot and the per-IP sending limit.
    6. PostgreSQL — It's stored in PostgreSQL first: if anything fails later, the message isn't lost.
    7. This website — A background worker picks up messages waiting to be announced.
    8. Matrix (Synapse + Element) — It posts it to my Matrix room and doesn't count it as delivered until it gets an event id back.
    9. My phone (Element) — It reaches my phone. I'll reply myself, in person.
    I deploy a service
    1. Git repository — It all starts with a commit: the new service is described as code.
    2. IaC control node — On the control node, Terraform works out the plan: what gets created, what changes and what's left alone.
    3. Proxmox VE — Proxmox creates the container exactly as the code says.
    4. This website — The service starts in its new container.
    5. IaC control node — Ansible configures it: hardening, firewall, the app itself and a check that it answers.
    6. Zabbix — The Zabbix agent starts sending metrics.
    7. Wazuh — Wazuh starts watching its security.
    8. Repository backup — And the change is saved in the backup repository too.
    Updating containers
    1. Hermes (AI assistant) — Hermes notices there are new images for several Docker containers.
    2. Matrix (Synapse + Element) — It tells me on Matrix: which ones and since when.
    3. My phone (Element) — I read it on my phone and decide when to update.
    4. IaC control node — I run the update playbook from the control node.
    5. n8n — Each container is updated and Ansible waits for its healthcheck to go green before moving on.
    6. Zabbix — Zabbix confirms everything is healthy again.
    Renewing certificates
    1. Traefik — A TLS certificate is about to expire: Traefik notices on its own.
    2. Cloudflare — It asks Let's Encrypt for a new one, proving the domain is mine with a DNS record in Cloudflare (DNS-01).
    3. Traefik — Traefik gets the new certificate and uses it without restarting anything.
    4. Hermes (AI assistant) — Hermes checks certificate and domain expiry every day.
    5. Matrix (Synapse + Element) — Only if something goes wrong does it post to Matrix.
    6. My phone (Element) — If an alert comes in, I see it on my phone. Usually I don't even notice.
    My IP changes
    1. MikroTik router — The ISP changes my public IP without warning.
    2. IP sync — Within 5 minutes the sync job spots the new IP.
    3. Cloudflare — It updates each domain's record in Cloudflare through its API.
    4. Internet — Visitors keep arriving as if nothing happened.
    Hermes learns by itself
    1. IaC control node — After every change I write a note: what happened, how it was measured and what didn't work.
    2. Obsidian — The note goes into Obsidian, the homelab's documentation.
    3. Qdrant — Every 15 minutes it's chunked and indexed into Qdrant as vectors.
    4. Hermes (AI assistant) — From then on Hermes can cite it in its answers.
    Deploying on OpenShift
    1. Git repository — The application and its deployment are described as code.
    2. IaC control node — Ansible applies the manifests to the cluster.
    3. OpenShift cluster (OKD) — OpenShift spreads the pods across its three nodes and exposes a route.
    4. Technitium DNS — The internal DNS resolves the cluster's application domain.
    5. Home devices — And the app opens from any device at home.
    An intrusion attempt
    1. Internet — A bot crawls the internet looking for misconfigured servers.
    2. Cloudflare — Cloudflare stops much of the automated traffic.
    3. MikroTik router — The router firewall drops anything that isn't the website; SSH isn't even visible from outside.
    4. Wazuh — Wazuh agents record any failed login inside the containers.
    5. Hermes (AI assistant) — Hermes reviews failed logins and sums them up.
    6. Matrix (Synapse + Element) — If something looks off, it posts it to its Matrix room.
    7. My phone (Element) — And it reaches my phone.
    Something breaks
    1. Plex — A service starts failing: say, Plex runs out of temporary space.
    2. Zabbix — Zabbix catches it with its checks.
    3. Hermes (AI assistant) — Hermes receives the problem and explains it in plain words, with context from the docs.
    4. Matrix (Synapse + Element) — It posts it to the Matrix alerts room.
    5. My phone (Element) — I know before anyone in the house notices.
    Getting in from outside
    1. My phone (Element) — I'm away from home and need a document.
    2. MikroTik router — I connect to the router's WireGuard VPN: the dashboards aren't on the internet.
    3. Technitium DNS — The internal DNS resolves the service's name.
    4. Caddy + Authelia — Authelia asks for my username and second factor.
    5. Paperless-ngx — And I'm in Paperless as if I were at home.
    I ask Hermes
    1. My phone (Element) — I message Hermes from my phone: "how are the disks?".
    2. Cloudflare — The message comes in through Cloudflare.
    3. Matrix (Synapse + Element) — It reaches my Matrix server.
    4. Hermes (AI assistant) — Hermes decides which tools it needs to answer.
    5. Qdrant — It searches Qdrant for the relevant Obsidian documentation.
    6. Zabbix — It asks Zabbix for the real state of the disks and ZFS.
    7. GPU PC (Ollama) — The local model, on the GPU PC, drafts the answer. Nothing leaves home.
    8. Hermes (AI assistant) — Hermes checks the answer: whatever can be computed is done by code, not the model.
    9. Matrix (Synapse + Element) — The answer goes back through Matrix.
    10. My phone (Element) — And I read it on my phone.
    The morning digest
    1. Hermes (AI assistant) — At 7:00 Hermes prepares the daily digest.
    2. Zabbix — It asks Zabbix about open problems and resources.
    3. Wazuh — It asks Wazuh about security: agents and failed logins.
    4. Repository backup — It checks the backup repository has been updated.
    5. Matrix (Synapse + Element) — It puts it all into a single Matrix message.
    6. My phone (Element) — And I read it over coffee.
    Movie night
    1. Automated library (*arr) — The library organises itself: names, metadata and subtitles.
    2. ZFS storage — Everything is stored on the ZFS pools, with redundancy.
    3. Plex — Plex presents it with artwork and synopses.
    4. GPU passthrough — If the device can't play the format, the GPU converts it in hardware.
    5. Plex — Plex streams the adapted video.
    6. MikroTik router — Out through the router.
    7. My phone (Element) — And it plays on any screen, at home or away.
    Game night
    1. My phone (Element) — From my phone I open the game server panel.
    2. Cloudflare — It comes in through Cloudflare, like the other sites.
    3. Traefik — Traefik takes it to the panel.
    4. Game servers (AMP) — I start tonight's game server.
    5. MikroTik router — The router firewall opens its port automatically, only while it's running.
    6. Internet — My friends connect from their homes.
    7. Zabbix — Zabbix watches CPU and memory while we play.
    Browsing without ads
    1. Home devices — The TV at home tries to load an ad.
    2. Technitium DNS — It asks the home DNS, which has that domain on a blocklist.
    3. Home devices — No answer: the ad never loads. Not on the TV, not on any device.
    4. Technitium DNS — A normal website does resolve, and gets cached for next time.
    5. Internet — The page loads faster and without trackers.
    A new piece of paper
    1. Home devices — I scan a document at home.
    2. Caddy + Authelia — Authelia checks it's me, with a second factor.
    3. Paperless-ngx — Paperless runs OCR, classifies it and tags it.
    4. ZFS storage — The original and its text are stored on ZFS, with redundancy.
    1. Internet

      Any visitor, anywhere in the world.

    2. Cloudflare

      First stop for all outside traffic: hides my home IP, filters attacks and caches copies close to the visitor.

    3. My phone (Element)

      From Element I talk to Hermes and get alerts and messages, wherever I am.

    4. MikroTik router

      Connected straight to the fibre. Network split into VLANs, audited firewall and a WireGuard VPN to get in from outside.

      • MikroTik
      • VLANs
      • WireGuard
    5. Home devices

      Laptops, the TV, phones: everything on the home network, split into VLANs.

    6. GPU PC (Ollama)

      Hermes's language model runs here, locally: nothing leaves my network. If the PC is off, questions wait in a queue.

      • LLM locales (Ollama, Qdrant, RAG)
    7. Git repository

      All the infrastructure lives as versioned code. Every change starts here.

      • Git
    8. Traefik

      The server's only public door: automatic TLS certificates and one route per published service. Internal dashboards never go through it.

      • Traefik
    9. Caddy + Authelia

      The way into internal dashboards, only from home or the VPN, with single sign-on and two-factor auth.

      • Linux / SSH hardening
    10. Technitium DNS

      Resolves internal names and blocks ads and trackers for the whole house. Migrated from Pi-hole without losing a single query.

      • Technitium DNS
    11. IP sync

      My connection has no fixed IP: every 5 minutes it checks the public IP and, if it changed, updates Cloudflare so the domains keep pointing home.

      • Technitium DNS
    12. This website

      An 11 MB Rust binary using about 12 MB of RAM, in its own unprivileged container with the strictest firewall on the server.

      • Rust
      • PostgreSQL
    13. PostgreSQL

      Stores contact form messages. No network at all: it's only reachable through the local socket.

      • PostgreSQL
    14. Matrix (Synapse + Element)

      My own messaging server. Hermes, server alerts and this site's messages all live here.

    15. Paperless-ngx

      Scans and classifies documents with OCR. Deliberately isolated: it holds personal paperwork.

      • Python
      • Docker
    16. Obsidian

      The homelab's documentation: procedures, incidents and postmortems. Hermes reads it to answer.

      • Docker
    17. n8n

      Automations between services: scheduled jobs and notifications.

      • Docker
    18. Homepage

      The landing dashboard for every service, generated by Ansible from the same list Traefik uses.

      • Ansible
    19. Game servers (AMP)

      Game servers for friends, with the firewall opened automatically only while they're running.

    20. Plex

      The household media server, with hardware transcoding.

      • Proxmox VE
    21. Automated library (*arr)

      A set of services that keeps the library tidy on its own: names, metadata, subtitles and the quality I choose.

      • Docker
    22. Live TV

      Free-to-air public channels with their programme guide, served to Plex as if it were a TV tuner.

      • Docker
    23. GPU passthrough

      An NVIDIA GPU assigned to the Plex container to convert video in hardware without loading the CPU.

      • Proxmox VE
    24. Hermes (AI assistant)

      The bot that answers questions about the server's health in natural language. The one on this page is its no-AI version.

      • Python
      • LLM locales (Ollama, Qdrant, RAG)
    25. Qdrant

      Vector database: stores the documentation and conversations so Hermes finds what's relevant (RAG).

      • LLM locales (Ollama, Qdrant, RAG)
    26. Zabbix

      Metrics and alerts for every machine: CPU, disks, RAID, ZFS, Docker containers.

      • Zabbix
    27. Wazuh

      Security: vulnerabilities, suspicious logins and CIS checks on every container.

      • Wazuh
    28. IaC control node

      From here Terraform creates the machines and Ansible configures them. The AI agents I work with run here too.

      • Terraform
      • Ansible
    29. ZFS storage

      ZFS pools and software RAID for the systems and the library, watched by Zabbix.

      • ZFS
    30. Proxmox VE

      The hypervisor: about twenty LXC containers and the lab's virtual machines.

      • Proxmox VE
      • LXC
    31. OpenShift cluster (OKD)

      Three nodes to practise OpenShift: 3/3 Ready and 33/33 healthy operators.

      • OpenShift (OKD)
      • Kubernetes / K3s
    32. Repository backup

      A second repository that updates itself on every infrastructure commit.

      • Git

    Simplified view: no addresses, ports or internal names.

    06

    Right now

    What I'm working on

    What I'm up to these days, with live data.

    • Looking for my first role in systems administration or DevOps.
    • Improving Hermes, my local AI assistant, with measured evaluations.
    • Growing the homelab as code: watched container updates and monitoring.
    • Learning Rust by building this website.

    Homelab status

    Live data isn't available right now.

    Recent GitHub activity

    1. Live data isn't available right now.
    07

    Contact

    Let's talk

    Have an opening, a question, or want to talk infrastructure? Drop me a message and I'll get back to you as soon as I can.

    I only use your details to reply to you. I don't share them or use them for anything else.

    Terminal