Matt Almeida software · infrastructure · systems

Hey, I’m Matt.

I build software, run infrastructure, and care whether the whole thing actually makes sense.

SYSTEM EXHIBIT / KNG–01

FIELD STUDY / 01

The Kingdom

A production system, documented as built.

SYSTEM MAP / AS BUILT

REV 07 SCALE NTS

Cloudflare DNS

public names · DNS-01
PUBLIC HTTPS / TLS Caddy entrypoint on VM100
ONE PHYSICAL HOST

Hetzner Dedicated Host · FSN1 / Falkenstein

shared local failure domain

  • Intel Core i7-7700
  • 64 GB DDR4
  • 2 × 512 GB NVMe · mirrored ZFS/rpool
  • Intel I219-LM · 1 Gbit
PROXMOX VE
bare metal · VM100–VM103
VM100
OPNsense
Gateway · Router · Firewall · DNS
Caddy + ACME NPTv6 Tailscale subnet router

Suricata + NetFlow telemetry → VM101 Wazuh

Internal ULA · fd00:ba5e:c0de::/64 IPv6-first · private IPv4 /16 secondary
VM101
Wazuh
SIEM / XDR · security monitoring security signals
VM102
VictoriaLogs
log storage · retention · query Vector → VictoriaLogs
VM103
VictoriaMetrics + Grafana
metrics · dashboards · alerting exporters → VictoriaMetrics
HOST-LEVEL / OUTSIDE VM INVENTORY
Proxmox Backup Server
VM100–VM103 + host data · encrypted · compressed · deduplicated
encrypted off-box copy
OFF-SITE COPY

Cloudflare R2

external object storage
01

AUTHORIZED REMOTE ENDPOINT

Framework 13 Windows 11 + WSL
02 Tailscale encrypted overlay
03
VM100 subnet router to the Kingdom network
private path back in
PATH KEY routed / ingress secure management backup / retention
THE KINGDOM / FIELD SHEET KNG–01 / END OF EXHIBIT
SELECTED EVIDENCE / A

Work, methods, and tools.

SELECTED WORK

Built, shipped, and kept useful

The Hack Foundation

Software Engineering Intern ·

Implemented highly requested features for its fiscal sponsorship portal and coordinated a backend upgrade for the directory of high-school hackathons.

Different Roads to Learning

Web Development Contractor · Since

Designed, developed, deployed, and maintained a SaaS application for administering Socially Savvy, while orchestrating the surrounding infrastructure and mail pipelines.

HOW I WORK

Clear thinking compounds
  • Understand the problem before choosing the machinery.
  • Write down the reasoning.
  • Make tradeoffs explicit.
  • Own what happens after the code ships.
  • Leave things easier to understand than you found them.

TOOLS I USE

A practical working set
Build
Ruby · Rails · Postgres
Operate
Debian · Proxmox · OPNsense · Caddy
Observe
Wazuh · Vector · VictoriaLogs · VictoriaMetrics · Grafana
Work
Git · Go · Bash · SQL