projects: reword index tagline; split global infra into estate + network-automation
build-and-deploy / build (push) Failing after 11m25s
build-and-deploy / build (push) Failing after 11m25s
- New projects tagline + open-minded lead - Split the combined infra project: keep the estate/cloud modernisation, add a dedicated Network Automation at Fleet Scale case (Unimus + NetBox, config backup, bulk push, vaulted+rotated credentials) from the Linde role
This commit is contained in:
@@ -1,10 +1,10 @@
|
||||
---
|
||||
title: "Global Infrastructure Modernisation"
|
||||
outcome: "Modernised enterprise infrastructure at scale — ~1,000 VMs, segmented networks, multi-region cloud migration."
|
||||
summary: "Across global IT roles: a ~1,000-VM VMware estate, flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, firewall upgrades, and migration to Azure and Microsoft 365."
|
||||
role: "Infrastructure Engineer · Virtus Health / Linde"
|
||||
outcome: "Modernised a global, multi-region estate at scale — ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 — on a live 24/7 business."
|
||||
summary: "Across global IT roles at Virtus Health and Linde Asia Pacific: a ~1,000-VM VMware estate managed centrally, a flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, Palo Alto / FortiGate firewall redesigns, and migration to Azure (Blob, AVS) and Microsoft 365."
|
||||
role: "Infrastructure Engineer · Virtus Health & Linde Asia Pacific"
|
||||
period: "2019 – 2025"
|
||||
stack: ["VMware", "Azure", "SD-WAN", "Aruba ClearPass", "FortiGate", "Microsoft 365"]
|
||||
stack: ["VMware / vSphere", "Azure (Blob, AVS)", "Microsoft 365", "SD-WAN", "Aruba ClearPass", "Palo Alto / FortiGate", "Veeam"]
|
||||
featured: false
|
||||
order: 40
|
||||
---
|
||||
@@ -12,23 +12,29 @@ order: 40
|
||||
## Problem
|
||||
|
||||
Enterprise estates accrete. Flat networks, sprawling VM counts, aging firewalls, and
|
||||
on-prem-only services become a security and operations drag. The work: modernise without
|
||||
breaking a global business that runs 24/7.
|
||||
on-prem-only services become a security and operations drag. The work: modernise a global,
|
||||
multi-region business that runs 24/7 — without breaking it.
|
||||
|
||||
## Constraints
|
||||
|
||||
- **Keep the lights on** — change a live, multi-region estate without downtime.
|
||||
- **Security and compliance** — segmentation, patching, and auditability throughout.
|
||||
- **Cost-aware** — modernise to cloud where it pays, not for its own sake.
|
||||
- **Cost-aware** — modernise to cloud where it pays, justified through CapEx/OpEx cases.
|
||||
|
||||
## Design
|
||||
|
||||
Across global roles I ran and improved a **~1,000-VM VMware estate** and re-segmented **flat
|
||||
sites into isolated VLAN ranges**, layering in **SD-WAN** and **Aruba ClearPass** onboarding
|
||||
for a tiered, authenticated network. **Palo Alto / FortiGate** firewalls were upgraded and
|
||||
redesigned around the new segmentation. Workloads and identity moved to **Azure** (Blob, AVS)
|
||||
and **Microsoft 365** — including an ERP hardware refresh with a new DR solution, and a
|
||||
region-wide PBX-to-VoIP migration.
|
||||
Across global roles I ran and improved a **~1,000-VM VMware estate**, managed centrally for
|
||||
the IT team and operated across regions including the UK. I re-segmented **flat sites into
|
||||
isolated VLAN ranges** with ACLs, layering in **SD-WAN** and **Aruba ClearPass** with 802.1x
|
||||
onboarding for a tiered, authenticated network. **Palo Alto / FortiGate** firewalls were
|
||||
upgraded and redesigned around the new segmentation — RCA, staging through FortiManager, and
|
||||
a flat-to-segmented redesign.
|
||||
|
||||
On the platform side: workloads and identity moved to **Azure** (Blob storage, AVS — lifting
|
||||
existing vSphere environments) and **Microsoft 365**, with a **hybrid AD sync** I architected
|
||||
to bridge on-prem and cloud identity. The estate work also covered an **ERP hardware refresh
|
||||
with a new DR / mainframe solution**, file shares to Azure Blob over Kerberos auth, **Veeam**
|
||||
backups, and a region-wide **PBX-to-VoIP** migration (RingCentral).
|
||||
|
||||
## Security & reliability decisions
|
||||
|
||||
|
||||
Reference in New Issue
Block a user