Andrey Penkov

DevOps Engineer

Varna, Bulgaria. Open to DevOps and SysAdmin roles.

Right now I am a NOC engineer at HPE Zerto, taking second-line incidents on enterprise disaster recovery and replication. Before that I spent two years keeping CloudSigma's public cloud running day to day.

At home I run a Proxmox server with twenty-one services on it: DNS, a mail server, private cloud storage, a proxy, monitoring and a handful of web apps, some of them for other people. Family, friends and clients use them every day, so standing still is not an option. Most of what I know about system administration and DevOps I learned there first and used at work afterwards.

  • 5 years in IT infrastructure and operations
  • 21 self-hosted services
  • 6 operating systems administered
  • 24/7 NOC rotation
Andrey Penkov

Tools

At work, daily

Production systems, under SLA.

  • Linux (Debian, Ubuntu)
  • CentOS
  • Fedora
  • NetBSD
  • Windows Server
  • TCP/IP
  • DNS
  • VPN
  • VMware
  • Zerto
  • Cloud VM, storage, networking
  • Kubernetes (k3s)
  • Loki
  • Log analysis
  • Jira
  • Confluence
  • Salesforce

Built and run myself

My own servers, at home.

  • Proxmox VE
  • Docker
  • Docker Compose
  • LXC
  • Nginx
  • Nginx Proxy Manager
  • Let's Encrypt
  • Pi-hole
  • Mailcow
  • Nextcloud
  • OpenVPN
  • Prometheus
  • Grafana
  • Alertmanager
  • PostgreSQL
  • pgbouncer
  • MariaDB
  • Redis
  • Node.js / pm2
  • Git
  • GitHub Actions
  • Bash
  • Python
  • YAML
  • PHP
  • JavaScript

Experience

Middle NOC Engineer, HPE Zerto

Apr 2025 – present

Second-line incidents on disaster recovery and replication platforms.

  • Take second-level incidents from the first report through to a fix, whether they arrive by portal, phone or email.
  • Trace root causes through system and replication logs, lining up host, storage and network events to find where a distributed setup actually failed.
  • Work out connectivity, name resolution and firewall problems inside customer networks.
  • Write up what I find. Most of my fixes end up in the internal knowledge base so the next engineer does not start from nothing.
  • Track and escalate everything through Jira, Confluence and Salesforce.

Technical Support Engineer, CloudSigma AG

Jan 2023 – Apr 2025

Daily operations of a multi-tenant public cloud.

  • Watched the platform for performance problems, outages and security events, and dealt with them before customers noticed where that was possible.
  • Ran the customer-facing side of the cloud: virtual machines, block storage, snapshots and backups, VLANs, public IPs and firewall rules.
  • Administered guest systems across Windows, Ubuntu, Debian, Fedora, CentOS and NetBSD.
  • Carried out system evaluations and quality checks, then fed the results back into how the team worked.
  • Worked with customers on capacity, migrations and configuration, explaining the infrastructure side in terms they could act on.

Technical Support Engineer, TexExperts

Mar 2022 – Sep 2022

First-line support.

  • Diagnosed and fixed hardware and software faults reported by users.
  • Learned to reproduce a problem properly before trying to fix it, which has saved me a lot of time since.

Home lab

One Proxmox node, one way in, twenty-one guests behind it. The diagram is how traffic gets from the internet to a container; the list below is what runs where.

Internet WAN / DDNS Router / firewall port forward, VLAN OpenVPN PROXMOX VE Nginx Proxy Mgr TLS, reverse proxy Pi-hole local DNS, filtering Docker Mailcow, OpenWebUI LiteLLM, Prometheus LXC / VM web apps, Postgres Nextcloud, media Storage and backups snapshots, restore tests Users family, client, public

Scroll the diagram sideways to see the whole thing.

  • Nginx Proxy Manager lxc

    Every public hostname terminates here. Reverse proxy plus automatic Let's Encrypt certificates, currently for eighteen names.

  • Pi-hole lxc

    Local DNS for the whole house and ad filtering with it. It also resolves the internal names the proxy needs.

  • OpenVPN lxc

    How I get back into the network when I am away, and how admin interfaces stay off the public internet.

  • Mailcow vm

    My own mail server, eighteen containers of it. It sends the notifications everything else generates. SPF, DKIM and DMARC are set up and passing.

  • Nextcloud lxc

    Three hundred gigabytes of file storage for the family. Apache, MariaDB and Redis installed directly rather than in Docker, with fail2ban in front, on disks I picked for reliability over speed. Open

  • Prometheus + Grafana lxc

    A node exporter on nearly every guest, plus blackbox, Proxmox and Postgres exporters. Grafana for the dashboards, Alertmanager to route anything that fires into my own mail server.

  • OpenWebUI + LiteLLM vm

    One chat front end over several model providers. LiteLLM keeps the API keys on the server so they never reach a browser. Open

  • Finance assistant lxc

    A Node app with PostgreSQL behind pgbouncer, plus a bot on its own container that only accepts traffic from the reverse proxy and nothing else.

  • ArtNails booking app lxc

    Built and hosted for a client: scheduling, portfolio and an admin area, with the database on a separate container. I wrote it and I support it. Demo

  • Sites I host for other people lxc

    Five small sites, each in its own container behind the same proxy. Some are nginx and PHP-FPM, some are Next.js or Node under pm2.

  • Media stack vm

    Plex and the automation around it. Shared storage, scheduled jobs, and the one workload that actually stresses the disks.

  • This site lxc

    Static pages and one PHP endpoint for the contact form. The source, the pipeline that deploys it and the container definition are all in the repository.

  • Landing page lxc

    Serves the main domain and points people at the right service. Open

  • BackupsSix scheduled jobs, daily and weekly, writing to two separate disks with different retention per service. I restore one now and then to check they are real.
  • PatchingOne automated window a week, after the backups finish. A health script runs thirty-six service checks before and after, so a bad update shows up as a failed check rather than a phone call.
  • MonitoringExporters on nearly every guest, dashboards I actually look at, and alerts that arrive by mail from a server I also run.
  • CertificatesLet's Encrypt, issued and renewed automatically for every hostname.
  • AccessNothing published directly. VPN for admin work, reverse proxy for the rest, and one app that will only answer the proxy.
  • CapacityI watch pool usage and I/O pressure rather than waiting for a full disk. Scheduled trims took the storage pool from 87 per cent back down to 55.

Certificates

  • Linux System Administration SoftUni, July 2024
  • Network Administration SoftUni, December 2024
  • Windows System Administration SoftUni, May 2024
  • DevOps and Cloud planned
  • Certified Kubernetes Administrator planned

See the scans

Education

  • New Bulgarian University, Sofia 2020 – 2024

    Bachelor's degree, Computer Music

  • Hristo Yasenov Secondary School, Etropole 2016 – 2020

    Secondary education