Manuel Powers

Systems Administrator Infrastructure Security Automation

I design, secure, and automate the infrastructure a business runs on.

About

Manuel Powers

I run end-to-end infrastructure for a multi-building manufacturing organization: servers, identity, networking, endpoints, security, and the internal applications that sit on top.

I came into IT through cybersecurity, so security is a design input for me, not a cleanup task. When something breaks, I chase the root cause instead of the symptom, then automate the fix so it stays fixed.

The goal behind all of it: turn reactive IT into documented, proactive operations.

Terminal

Prefer a shell? Type help, or pick a command below. Everything it prints is also on this page.

This terminal needs JavaScript. Everything it can tell you is on this page.

Featured work

Four projects, each written up as problem, approach, stack, and outcome.

  • 01 / platform

    Self-hosted Kubernetes platform

    A highly available k3s platform for internal applications, with load-balanced ingress, TLS, and push-to-deploy CI/CD.

    • k3s
    • Nginx
    • keepalived
    • Traefik
    • GitHub Actions
    • GHCR
  • 02 / application

    Real-time production floor dashboard

    Live production reporting on digital signage, replacing Excel reports that were maintained by hand.

    • FastAPI
    • PostgreSQL
    • Docker Compose
    • k3s
  • 03 / identity

    Certificate-based enterprise Wi-Fi

    Wireless access tied to managed devices through an internal PKI, RADIUS, and Group Policy. No shared password.

    • AD CS
    • NPS / RADIUS
    • Group Policy
    • 802.1X
    • WPA2/WPA3-Enterprise
  • 04 / operations

    Company-wide RMM rollout

    Pitched to ownership, deployed across the organization, then extended with EDR integration, IT ticketing, and automated server patching.

    • RMM
    • Active Directory
    • Group Policy
    • EDR API
    • PowerShell

Tools and experiments

Small open-source utilities. Source is on GitHub.

  • qps7

    A port scanner that checks a host for a given set of ports and reports which ones are open.

    Python

  • xbreaker

    Decrypts a hex-encoded string with XOR, using a key supplied as a passphrase.

    Python

  • ascii-art

    Turns images into ASCII art, using PIL and NumPy for the image processing and character mapping.

    Python

All repositories on GitHub

Tech stack

The tools behind the work above, grouped by domain.

Windows Infrastructure

  • Windows Server
  • Active Directory
  • Group Policy
  • DNS
  • DHCP
  • AD CS / PKI
  • NPS / RADIUS

Virtualization and Backup

  • Hyper-V
  • Veeam
  • Dell PowerEdge

Cloud

  • Microsoft 365
  • Exchange Online
  • Entra ID
  • SharePoint
  • Teams
  • Power Automate
  • Power BI

Security

  • CrowdStrike Falcon
  • Proofpoint
  • SPF / DKIM / DMARC
  • 802.1X
  • Phishing simulation
  • Incident response

Networking

  • UniFi
  • VLAN segmentation
  • Routing
  • Firewall rules

Linux and DevOps

  • Ubuntu Server
  • Kubernetes (k3s)
  • Docker
  • Traefik
  • Nginx
  • keepalived
  • GitHub Actions
  • Git

Scripting and Data

  • PowerShell
  • Python
  • Bash
  • SQL / T-SQL
  • SQL Server
  • PostgreSQL

Industrial / OT

  • Ignition SCADA
  • Allen-Bradley PLCs
  • MQTT

Certifications

  • CompTIA Security+
  • CompTIA Network+
  • CompTIA A+
  • CompTIA Secure Infrastructure Specialist (CSIS)
  • CompTIA IT Operations Specialist (CIOS)

How this site works

Hand-written HTML and CSS, plus a few kilobytes of vanilla JavaScript for the terminal. No framework, no build step, no cookies, no trackers.

GitHub Pages serves it straight from the main branch, and the custom domain resolves through Cloudflare DNS. A strict Content Security Policy means the only files a browser will load are this site's own.

Every push and pull request runs CI: the W3C Nu validator checks the HTML and lychee checks the links, internal and external. CI checks the site. It never deploys it.

Read the source on GitHub

On every push

  1. git pushany branch or PR
  2. GitHub Actionsread-only token
  3. W3C NuHTML validation
  4. lycheelink check

Serving

  1. mainbranch, repo root
  2. GitHub Pagesstatic hosting
  3. Cloudflare DNScustom domain
  4. BrowserHTTPS

Contact

Reach me by email, or find me on GitHub and LinkedIn.

email
manuel@powers-technology.systems
github
github.com/a-ghost-named-x
linkedin
linkedin.com/in/manuelp-itconsulting