projects: reword index tagline; split global infra into estate + network-automation
build-and-deploy / build (push) Failing after 11m25s

- New projects tagline + open-minded lead
- Split the combined infra project: keep the estate/cloud modernisation,
  add a dedicated Network Automation at Fleet Scale case (Unimus + NetBox,
  config backup, bulk push, vaulted+rotated credentials) from the Linde role
This commit is contained in:
2026-06-29 18:32:29 +10:00
parent a685789322
commit 880b9daeac
3 changed files with 87 additions and 16 deletions
@@ -1,10 +1,10 @@
---
title: "Global Infrastructure Modernisation"
outcome: "Modernised enterprise infrastructure at scale — ~1,000 VMs, segmented networks, multi-region cloud migration."
summary: "Across global IT roles: a ~1,000-VM VMware estate, flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, firewall upgrades, and migration to Azure and Microsoft 365."
role: "Infrastructure Engineer · Virtus Health / Linde"
outcome: "Modernised a global, multi-region estate at scale — ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 — on a live 24/7 business."
summary: "Across global IT roles at Virtus Health and Linde Asia Pacific: a ~1,000-VM VMware estate managed centrally, a flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, Palo Alto / FortiGate firewall redesigns, and migration to Azure (Blob, AVS) and Microsoft 365."
role: "Infrastructure Engineer · Virtus Health & Linde Asia Pacific"
period: "2019 2025"
stack: ["VMware", "Azure", "SD-WAN", "Aruba ClearPass", "FortiGate", "Microsoft 365"]
stack: ["VMware / vSphere", "Azure (Blob, AVS)", "Microsoft 365", "SD-WAN", "Aruba ClearPass", "Palo Alto / FortiGate", "Veeam"]
featured: false
order: 40
---
@@ -12,23 +12,29 @@ order: 40
## Problem
Enterprise estates accrete. Flat networks, sprawling VM counts, aging firewalls, and
on-prem-only services become a security and operations drag. The work: modernise without
breaking a global business that runs 24/7.
on-prem-only services become a security and operations drag. The work: modernise a global,
multi-region business that runs 24/7 — without breaking it.
## Constraints
- **Keep the lights on** — change a live, multi-region estate without downtime.
- **Security and compliance** — segmentation, patching, and auditability throughout.
- **Cost-aware** — modernise to cloud where it pays, not for its own sake.
- **Cost-aware** — modernise to cloud where it pays, justified through CapEx/OpEx cases.
## Design
Across global roles I ran and improved a **~1,000-VM VMware estate** and re-segmented **flat
sites into isolated VLAN ranges**, layering in **SD-WAN** and **Aruba ClearPass** onboarding
for a tiered, authenticated network. **Palo Alto / FortiGate** firewalls were upgraded and
redesigned around the new segmentation. Workloads and identity moved to **Azure** (Blob, AVS)
and **Microsoft 365** — including an ERP hardware refresh with a new DR solution, and a
region-wide PBX-to-VoIP migration.
Across global roles I ran and improved a **~1,000-VM VMware estate**, managed centrally for
the IT team and operated across regions including the UK. I re-segmented **flat sites into
isolated VLAN ranges** with ACLs, layering in **SD-WAN** and **Aruba ClearPass** with 802.1x
onboarding for a tiered, authenticated network. **Palo Alto / FortiGate** firewalls were
upgraded and redesigned around the new segmentation — RCA, staging through FortiManager, and
a flat-to-segmented redesign.
On the platform side: workloads and identity moved to **Azure** (Blob storage, AVS — lifting
existing vSphere environments) and **Microsoft 365**, with a **hybrid AD sync** I architected
to bridge on-prem and cloud identity. The estate work also covered an **ERP hardware refresh
with a new DR / mainframe solution**, file shares to Azure Blob over Kerberos auth, **Veeam**
backups, and a region-wide **PBX-to-VoIP** migration (RingCentral).
## Security & reliability decisions
@@ -0,0 +1,64 @@
---
title: "Network Automation at Fleet Scale"
outcome: "Took a multi-region switch fleet from hand-managed to single-pane — automated config backup, bulk change in minutes, and credentials secured and rotated."
summary: "Productionised a vendor-agnostic network config-management platform (Unimus) with NetBox as the source-of-truth across an AU/NZ/PNG switch fleet: scheduled config backups, mass config push, and a centrally vaulted, rotated credential model — community tooling stood up ground-up under a corporate-supported licence."
role: "Global IT Infrastructure Engineer · Linde Asia Pacific"
period: "2019 2022"
stack: ["Unimus (NCM)", "NetBox (IPAM / SoT)", "Config backup & DR", "Bulk config push", "Credential vaulting + rotation", "Multi-vendor switching"]
featured: false
order: 45
links:
- label: "Unimus"
href: "https://unimus.net"
- label: "NetBox"
href: "https://netbox.dev"
---
## Problem
A multi-region switch fleet — Australia, New Zealand and PNG — was maintained by hand.
Configs drifted, backups were "hope someone saved the last one," bulk changes were pushed
box-by-box, and device credentials were scattered across people and scripts. For a network
that production depends on, there was no real recovery path and no audit trail.
## Constraints
- **Live production network** — change the fleet without taking sites down.
- **Mixed-vendor estate** — the tooling had to be vendor-agnostic, not tied to one OS.
- **Credentials are the crown jewels** — secured, rotated, and never sitting in a script.
- **Cost-justified** — a lean tool that earns its place through a real CapEx/OpEx case.
## Design
I productionised **Unimus** — a vendor-agnostic Network Configuration Management platform —
as the automation backbone, and stood it up **ground-up**: install, device onboarding,
backup scheduling, and change workflows. It gave the fleet three things it never had from one
place: **automated, scheduled config backups**, **change tracking with config diffs**, and
**mass / bulk config push** across many devices at once.
Paired with it, **NetBox** served as the **IPAM and source-of-truth** for the device
inventory the automation runs against — so the fleet is driven from a single, accurate model
of what exists rather than tribal knowledge. Both are lean, community-rooted tools adopted
under a **corporate-supported licence**, which made them viable inside an enterprise change
process — the open-source-into-corporate pattern, done properly.
## Security & reliability decisions
- **Centralised, vaulted credentials with rotation** — the network's secrets live in one
scoped, rotated place, never embedded in scripts or shared by hand.
- **Config backup = real network DR** — every device restorable from a known-good config.
- **Diffs + auditing** — every configuration change is visible, attributable, and reversible.
- **Source-of-truth driven** — automation acts on NetBox's model, not on guesswork.
## Outcome
The switch fleet across AU/NZ/PNG was maintained from a single pane: configs backed up
automatically, bulk changes pushed in minutes instead of days, credentials secured and
rotated, and — for the first time — a genuine recovery path for network configuration. A lean
community toolset, productionised with enterprise rigour.
## Future improvements
Drive the automation deeper from the source-of-truth — intent in NetBox, pushed to the fleet
through Unimus — and template standard site configs so a new location onboards straight from
the inventory.
+4 -3
View File
@@ -10,10 +10,11 @@ const projects = (await getCollection("projects")).sort(
---
<Layout title="Projects" path="/projects" description="Selected platform & infrastructure projects by Jonathon Wright.">
<Section id="all-projects" eyebrow="Projects" index="*" title="Everything I've built worth writing about.">
<Section id="all-projects" eyebrow="Projects" index="*" title="Some bytes I'm proud of — a starting line, not a trophy shelf.">
<p class="lead projects__intro" data-reveal>
Edge Kubernetes, GPU inference, self-hosted AI, and the automation that ties it
together — each with the problem, the design, and the outcome.
Edge Kubernetes, GPU inference, self-hosted AI, productionised network automation, and
the infrastructure rigour that ties it together — each with the problem, the design, and
the outcome. More always cooking.
</p>
<div class="grid">
{projects.map((entry) => <ProjectCard entry={entry} />)}