Linux · Server Management · AWS

Freelance Linux server administration — hardened, patched, monitored.

Reliable Linux administration on AWS and beyond: CIS hardening, patching, monitoring, backups and DR, web servers, and automation — with security baked in. 16+ years, CISA + AWS Solutions Architect Professional. Available for projects or 24/7 retainers.

Book a free 30-min callEmail me

What you get

Hardening & security

  • CIS Benchmark hardening for Ubuntu / Amazon Linux / RHEL
  • SSH lockdown, fail2ban, least-privilege sudo, auditd
  • Patch management and vulnerability remediation

Reliability & ops

  • Monitoring (Prometheus/CloudWatch), alerting, log aggregation
  • Automated backups + tested restores, DR planning
  • Nginx / Apache tuning, TLS, reverse proxies, load balancing

Automation

  • Bash / Ansible / Python for repeatable ops and evidence
  • Config management and drift control
  • Cron / systemd services, log rotation, health checks

Migration & support

  • Server migrations (colo to AWS, OS upgrades) with minimal downtime
  • Performance troubleshooting and capacity planning
  • Project or ongoing 24/7 managed support

Proof

150+servers migrated colo→AWS with <4h downtime
16+years administering Linux & Windows
24/7managed support available
LinuxUbuntuAmazon LinuxRHELCIS hardeningAnsibleBashNginxsystemdCloudWatch

What actually goes wrong on Linux servers

After sixteen years, the incidents repeat. Almost none of them are exotic, and almost all of them are cheaper to prevent than to fix at 3am.

What I findWhy it happensFix
Unpatched kernel and packagesNo patch window anyone ownsScheduled patching with a documented rollback
SSH open to the worldConvenience during setup, never revisitedBastion or SSM, key-only, fail2ban
Disk full at 2amLog rotation never configuredlogrotate plus a disk alert that fires at 75 percent
Backups that have never been restoredBackups are monitored, restores are notScheduled restore tests with recorded results
Config drift across “identical” serversManual fixes applied to one boxAnsible, and config as code
Root used for everythingIt was faster on day oneLeast-privilege sudo with auditd

A monitored backup is not a tested backup. That distinction has saved more of my clients than any other single practice.

How an engagement runs

Assess. Inventory what is actually running, not what the documentation claims. This step routinely finds servers nobody could name an owner for.

Harden. CIS baseline applied in a reviewable, reversible way — SSH lockdown, least-privilege sudo, auditd, patch management. Scan output before and after, so the improvement is measurable rather than asserted.

Automate. Whatever was done by hand becomes Ansible or scripted, so the tenth server matches the first and drift stops accumulating.

Observe. Monitoring, alerting and log aggregation that page a human for things that matter and stay silent otherwise. Alert fatigue is a reliability problem, not a tuning preference.

Hand over. Runbooks, tested restores and documentation your team can actually operate. If an engagement leaves you dependent on me, I have done it wrong.

Hardening is also audit evidence

CIS hardening, patch compliance and audit logging are not only security controls; they are the artefacts an ISO 27001 or SOC 2 auditor asks for directly. Doing them properly once produces the evidence as a by-product, instead of reconstructing it under deadline. If compliance is on your roadmap, see ISO 27001 consulting and how to pass SOC 2 Type 2.

Related services: AWS DevOps consulting · secure cloud landing zone · AWS cost optimisation.

FAQ

Do you offer ongoing server management?

Yes. Monthly retainers cover patching, monitoring, backup verification and incident response, and I also take one-off projects such as a hardening pass or a migration. Most clients start with a project and move to a retainer once they see what the estate actually needs.

Which distributions do you support?

Ubuntu, Amazon Linux, RHEL and CentOS derivatives, and Debian, all hardened against CIS Benchmarks. If you are running something older that is out of vendor support, I will say so plainly and price the upgrade rather than pretend it can be secured in place.

Can you migrate our servers to AWS?

Yes. I have migrated over 150 servers from colocation to AWS with under four hours of total downtime, including database replication and cutover. The work that makes that possible happens before the cutover: inventory, dependency mapping and a rehearsed rollback.

Is security included?

Always. CIS hardening, SSH lockdown, patch management and audit logging are part of every engagement rather than an upsell. If a server is worth administering it is worth hardening, and separating the two is how estates drift.

What happens if a server goes down at 3am?

On a 24/7 retainer, alerting reaches me and I respond. On a project engagement, I make sure your team has runbooks, working alerts and tested restores so the on-call person is not improvising. Either way the goal is fewer incidents, not faster heroics.

Do you work with Windows servers too?

Yes, though Linux is where I spend most of my time. I have administered mixed estates for sixteen years, and in practice most environments are mixed. I will not pretend a Windows-heavy estate is a Linux problem.

How do you prove the servers are actually hardened?

With evidence rather than assertions. CIS benchmark scan output before and after, patch compliance reporting, audit log samples, and restore tests with timestamps. This is the same evidence an ISO 27001 or SOC 2 auditor will ask for, which is why I produce it as a matter of course.

Keep your servers fast, patched and quiet.

Free 30-minute call — tell me your stack and pain points.

Book a callAll AWS DevOps services →