Summary
Twelve years keeping Linux fleets boring: patching, hardening, monitoring and recovery for hosting and fintech companies. I automate the second time I do anything and I rehearse the restore before I trust the backup.
Skills
Systems
- Linux (RHEL, Debian)100%level 5 of 5
- Bash100%level 5 of 5
- systemd100%level 5 of 5
- KVM / libvirt80%level 4 of 5
Automation
- Ansible100%level 5 of 5
- Python80%level 4 of 5
- Terraform60%level 3 of 5
Services
- Nginx / HAProxy100%level 5 of 5
- PostgreSQL80%level 4 of 5
- Prometheus / Grafana80%level 4 of 5
Network and security
- Networking (BGP, VLAN, WireGuard)80%level 4 of 5
- Security hardening (CIS)100%level 5 of 5
Experience
- Jun 2014 – Jan 2017
Junior Systems Administrator
Kerala Netlink · Kochi
Mail, DNS, web hosting and the help desk for a regional ISP.
- Feb 2017 – Mar 2021
Linux Administrator
Paylane · Bengaluru
Ran the PCI-scoped servers of a payments company: hardening, logging, change control.
- Passed four PCI DSS audits with zero findings on the Linux estate
- Replaced hand-built servers with Kickstart + Ansible images
- Apr 2021 – Present
Senior Linux Systems Administrator
Meridian Hosting · Kochi
Fleet of 400 servers across two data centres and one cloud region; on-call lead for a team of five.
- 99.995 % availability across the fleet in 2025
- Cut the monthly patching window from 6 hours to 40 minutes with live kernel patching and Ansible
- Rebuilt backups: every restore rehearsed weekly by a bot that files a ticket when one fails
Services I run
- Nginx and HAProxy edges — 1.2 billion requests a month
- PostgreSQL 16 clusters with Patroni — 40 databases
- KVM hosts — 1,100 guests
- Prometheus, Loki and Grafana — 9 million series
- WireGuard mesh between sites
- Internal CA, Vault and step-ca
Projects
patchwatch.service - patchwatch
- Loaded:
- loaded (author; enabled)
- Active:
- active (running) since 2024 – present
- Docs:
- example.com/patchwatch
- Tags:
- Ansible, Python, open source
An Ansible-driven patching pipeline with canary hosts, automatic rollback and a Grafana board per wave. Open source, used by three other hosting teams.
restore-bot.service - restore-bot
- Loaded:
- loaded (author; enabled)
- Active:
- active (running) since 2023
- Tags:
- Python, PostgreSQL, backups
Restores a random backup every night into an isolated VM, checks it, and files a ticket when anything differs.
home-lab.service - Home lab
- Loaded:
- loaded (owner; enabled)
- Active:
- active (running) since 2019 – present
- Tags:
- Proxmox, Ceph, WireGuard
Twelve nodes, Proxmox, Ceph and a WireGuard mesh — where every change gets tried first.
Certifications
- Red Hat Certified Engineer (RHCE)May 2022 · Red Hat
- LPIC-2Sep 2018 · Linux Professional Institute
- Certified Kubernetes AdministratorMar 2024 · CNCF
Achievements
- 99.995 % fleet availability in 20252025
400 servers, two data centres, one cloud region.
- Patching window 6 h → 40 min2024
- Four PCI DSS audits, zero Linux findings2017 – 2021
About
At Meridian I own a fleet of 400 RHEL and Debian machines across two data centres and a cloud region — KVM hosts, Nginx edges, PostgreSQL clusters and the Prometheus stack that watches them all.
I write runbooks people can follow at 3 a.m., teach the juniors to read logs before they restart things, and keep a home lab that is slightly too large.
Education
B.Tech, Information Technology
Cochin University of Science and Technology
Publications
- Live kernel patching without the dramaFeb 2025 · Personal blog
- Test the restore, not the backupDec 2023 · SysAdvent
Testimonials
When Vikram says it is patched, it is patched, and the dashboard proves it.
Anita Rao — Head of Infrastructure, Meridian Hosting
Languages
- MalayalamNative
- EnglishFluent
- HindiConversational
Interests
- Retro computing
- Cycling
- Amateur radio