orloff.me

I run infrastructure. All of it.

From the application on the user's screen down to the switch port. Virtualisation, Windows and Active Directory, Linux, storage and the networks underneath all of it, and for the last few years as much AI as I can sensibly put to work. 26 years in IT. Registered in Georgia. I work remotely.

Stylised portrait of Andrei Orlov, half human and half machine

The whole column, one engineer

Where a fault can live
How the work is usually divided
Here
The application on a user's screen
The operating system under it
The hypervisor under that
The overlay network
The switch port
Applications Operating systems Virtualisation Storage Networks
One engineer,
the whole column

A fault does not respect these boundaries, and one that crosses two of them belongs to nobody. It gets handed between specialists, each of whom can demonstrate that it is not theirs, and a week goes by while the environment stays broken.

I hold the column end to end. One person to call, one person who can follow the symptom down to whichever layer it actually lives in, and nobody to hand it to.

What I do

01 / Retainer

Ongoing operation

A monthly agreement covering the day-to-day life of your infrastructure: virtualisation on VMware, Proxmox or Hyper-V, Windows and Active Directory, Linux, storage and data centre networks, capacity planning, incident handling, and the documentation that keeps all of it reproducible. Billed by the hour against a monthly report.

02 / Entry

Fixed-scope work

A defined piece of work with a start, an end and a price agreed before it begins. A migration, a platform build, a capacity sizing, taking stock of an environment nobody has documented in years. If it is infrastructure, it is most likely something I have already done once. Useful when you want to see how I work before committing to anything longer.

03 / Automation

IaC, tooling and AI

Terraform modules and GitLab CI/CD pipelines for the infrastructure itself rather than for application delivery: provisioning, configuration and change, driven from code. Plus the small internal tools that take routine work off a team: automated verification, certificate and account monitoring, inventory, resource-reuse analytics. Increasingly with AI doing the first pass, always under review.

Full description of services and rates

Where this comes from

It started at the bottom of the column, writing the software that drove banks of dial-up modems and the distributed database that replicated over them, then client networks, PBXs and Perl. Then a decade of Windows and Linux environments: Active Directory and Exchange migrations, Linux gateways, a fault-tolerant data centre serving the regional sites of an industrial group. Then public cloud, where I built a platform from nothing, put DDoS protection in place and wrote the upstream traffic analysis. Since 2020 the work has been network virtualisation with a DevOps toolchain, infrastructure as code, sizing and capacity planning, and support to the operations team on the cases that will not yield to a run-book.

2000In IT since
24Regional sites run as one environment at the largest scale so far
20+Vendor certifications: VMware, AWS, Zscaler, Zerto, Arbor, ITIL

Full background and certifications

How an engagement works

  1. You write. A few sentences on what you run and what is going wrong are enough to start.

  2. We scope it. Usually a short call, then a written scope: what is covered, what is not, and what it costs. An NDA first if you would rather talk specifics, as most clients do.

  3. We start small. A fixed-scope piece of work first, so both sides can see how this goes.

  4. It becomes ongoing, or it does not. If the fit is there, the work moves to a monthly agreement. If not, the fixed piece is finished and delivered, and that is a fine outcome.

Ongoing work starts at USD 70 per hour, invoiced monthly against a report of hours actually worked. Fixed-scope projects start at USD 90 per hour, or a total quoted up front; the difference covers the estimating risk, which on a fixed price is mine alone. No retainers billed for time not spent, no minimum commitment beyond the current month. If you would rather work to a ceiling, we agree a monthly budget in hours up front and I estimate each larger piece against it before starting, so the month does not overrun without you hearing about it first.

Working together

Before we discuss anything specific about your systems, we sign a non-disclosure agreement. What I see inside your infrastructure stays there, and no client is named or identified on this site or anywhere else without their written consent.

I keep the client list short on purpose. In infrastructure, knowing one environment properly is worth more than holding a dozen at arm's length, and a short list is what lets me give each client real time every week rather than a place in a queue.

I am taking on new work at the moment. If your infrastructure needs someone who will still be there in two years, that is the kind of arrangement I am looking for too.

Write to me