Twelve years building and deploying enterprise infrastructure for classified DoD missions, from servers and networks to cloud, applications, and virtualization. I focus on understanding what the mission needs, delivering it reliably, and seeing the hard problems through.
Senior Cloud Engineer and Solutions Architect with 12 years designing, deploying, and operating secure enterprise, hybrid-cloud, and edge infrastructure for classified DoD missions. Deep across Azure, Microsoft 365, identity, VMware, Linux containers, networking, storage, and automation, and just as comfortable translating mission requirements into architectures, implementation plans, and executive briefings. Trusted by chief engineers, CIOs, and program leaders to clarify ambiguous requirements, shape technical decisions, and drive solutions from discovery through go-live.
What I bring to every engagement, across infrastructure, networking, cloud, virtualization, and the Microsoft ecosystem.
Click any role to explore it. Use ← → arrow keys to navigate.
Earlier: Computer Technician at TigerDirect (2014 to 2015) · IT Consultant at CompuPlanet (2014)
Personal testing environments I started building because of my work, sandboxes where I get hands-on with the technologies I use professionally and try things I can't touch in a live environment. These are learning labs, not production, and they don't mirror any production system.
A self-hosted AI inference lab on a bare-metal Ubuntu workstation (RTX 4090, i9, 32 GB), built from the driver up to understand the infrastructure beneath modern AI in production. Native NVIDIA driver and CUDA, GPU-accelerated Docker via the NVIDIA Container Toolkit, live DCGM telemetry, model serving through NVIDIA NIM on Triton Inference Server, and Kubernetes GPU scheduling. Turning AI-infrastructure skills from certified (NCA-AIIO) into hands-on and operational.
View on GitHub →A self-hosted Linux services lab I started because of my work, a Docker-orchestrated host running Grafana, Matrix/Element, Wiki.js, Zammad, and MobSF behind a Traefik reverse proxy with custom bots on a shared PostgreSQL backend. A personal sandbox for getting hands-on with containerized services and the full database and service lifecycle, a test environment, not production, and not a copy of one.
View on GitHub →This very site. A framework-free static portfolio engineered for armandorodriguez.cloud, with Cloudflare DNS and email routing and a deploy pipeline to Azure Static Web Apps. Hand-built UI, version-controlled on GitHub, shipping on the platform I specialize in.
View on GitHub →Claude wired into local tools and data through custom Model Context Protocol (MCP) servers, automating research, file operations, and reporting workflows. A practical exploration of applied AI and agent integration in a real toolchain.
View on GitHub →A library of PowerShell tools built on the Microsoft Graph API to automate Microsoft 365 and Intune lifecycle tasks like user provisioning, license assignment, and compliance reporting, replacing repetitive manual admin with repeatable, auditable scripts.
View on GitHub →Monitoring stack for the homelab, running on the same bare-metal RTX 4090 Ubuntu box as the AI lab. Prometheus scrapes host metrics through node-exporter, per-container metrics through cAdvisor, and live GPU telemetry through NVIDIA DCGM, all rendered in Grafana dashboards for utilization, temperature, memory, and capacity. Visibility from the node up to the GPU.
View on GitHub →Security-operations lab built on Wazuh, with agents shipping logs from Windows and Linux hosts, custom detection rules, file-integrity monitoring, and alerting dashboards to practice threat detection and incident response end to end.
View on GitHub →Home lab modeling enterprise hybrid identity: on-prem Active Directory (AD DS, DNS, GPO) synced to Entra ID via Entra Connect, with ADFS federation and conditional-access policies. Used to validate identity and authentication flows before production change.
View on GitHub →Segmented home network engineered around an OPNsense firewall, with VLAN isolation for trusted, IoT, and lab zones, a WireGuard VPN for remote access, and Suricata IDS/IPS inspecting traffic. Hands-on routing, NAT, and policy design backing the CCNA.
View on GitHub →Resilience lab built on Proxmox Backup Server and Veeam, with scheduled, deduplicated backups across VMs and containers, automated restore testing, and tiered retention. Proves recoverability with regular point-in-time restore drills.
View on GitHub →Idempotent Ansible playbooks and roles that provision, patch, and harden the homelab fleet from a single control node, version-controlled in Git, turning manual server setup into repeatable, declarative automation.
View on GitHub →Self-hosted media platform on Linux built around Jellyfin. Fronted by an Nginx Proxy Manager reverse proxy with a Cloudflare tunnel for remote access (no inbound ports opened), and the Docker socket brokered through a hardened proxy container. A hands-on exercise in container orchestration, reverse proxying, secure remote access, and service hardening.
View on GitHub →Multi-host VMware lab with ESXi hosts under vCenter running HA, DRS, and vMotion, segmented virtual networking, and shared storage. A sandbox for testing infrastructure designs, snapshots, and recovery scenarios safely before they touch production.
View on GitHub →Notes on cloud, edge AI, infrastructure, and what I'm building in the lab.
Formal grounding in network architecture, system design, and the physics behind the hardware.
Microsoft, Cisco, CompTIA, AWS, and Linux.
The stuff that keeps me balanced (and a little competitive).
Open to senior cloud, infrastructure, and solutions architect roles. Cleared and ready.