sysops@karem-node01:~# boot

[OK] Initializing Core Stack...

Systems Operational • Available for Roles & Freelance
šŸ“ UTC+1 • SalĆ©, Morocco

SysOps Engineer

OUSSAMA

KAREM

Linux Specialist IaC & Automation Virtualization Specialist
sysops@karem-node01:~

Type 'help' to see available commands or click quick actions below.

sysops@karem:~$

/ Core_Philosophy

Passionate SysOps Engineer specialized in the Linux ecosystem. I build infrastructure that scales with ease and runs without friction.

I leverage Ansible and Terraform to treat infrastructure as code—ensuring perfect server configurations, automated package management, and reproducible environments across Proxmox and Docker.

"While I am an expert in Bash and Python for custom logic, my heart is in total Automation. I use IaC to make complex systems predictable and life fundamentally much more easier for everyone."

/ Certifications

RHCSA

Red Hat Certified

NSE

Fortinet Certified

Scrum SFC

SCRUMstudy Certified

EF

EF SET

English B2 Upper Intermediate

/ Technical_Arsenal

IaC & Automation

Terraform (Provisioning), Ansible (Server Config & Security Hardening), Portainer Stack Automation & Zero-Touch DR.

Advanced Scripting

Expert-level Bash & Python scripts with embedded Mattermost webhook alerts for automated workflows and instant error visibility.

Observability & Alerting

Mattermost Webhooks Integration, Zabbix, Nagios Core, Prometheus, Grafana Dashboards, ELK Stack (Log Management).

OS & Self-Hosted VCS

RHEL, CentOS, Debian, Ubuntu, Windows Server AD, Self-Hosted Forgejo Git & GitHub.

Networking

Cisco IOS, MikroTik RouterOS, OPNSense Firewall, TCP/IP, VLAN Segmentation, VPN (WireGuard/OpenVPN).

Cyber Security

Fortinet NSE standards, OPNSense Protection, SSH Hardening, SSL/TLS Lifecycle, Cloudflare WAF.

/ Featured_Projects

Ansible Fleet Security

Automating the deployment of critical security patches and OS hardening policies across mixed RHEL and Debian environments using idempotent playbooks.

AnsibleSecurityRHEL

Cloudflare IaC Security

Managing global edge security using Terraform to automate Cloudflare WAF rules, DNS zones, and Zero Trust access policies with version-controlled safety.

TerraformCloudflareIaC

OPNSense Virtual Security

Deploying and orchestrating OPNSense firewalls within Proxmox clusters to secure internal VM traffic and automate site-to-site VPN tunnels.

OPNSenseProxmoxFirewall

Portainer & Forgejo Automated DR

Zero-touch backup, stack management, and disaster recovery scripts for Portainer version-controlled via self-hosted Forgejo Git, with embedded Mattermost notification webhooks in every script for real-time observability.

PortainerForgejoMattermostDR

Learning New Tech

"Currently exploring Kubernetes orchestration, Advanced CI/CD patterns, and Go-based system tools. Always evolving."

/ Hosting_Infrastructure_&_Pipeline

Production Architecture • Edge Hosting

Portfolio Hosting Stack

Automated with modern GitOps workflows, tested inside Docker containers, protected at the edge by Cloudflare, and backed by extensive experience in Self-Hosting, Disaster Recovery, and Automated Observability.

Self-Hosting & DR Automation

Orchestrating Proxmox/oVirt clusters, Portainer stacks, self-hosted Forgejo Git, zero-touch disaster recovery scripts, and embedded Mattermost webhook notifications.

/ Automated_CI-CD_Deployment_Flow

01. Version Control

GitHub & Forgejo

GitOps source code & self-hosted VCS backup

02. Automation

GitHub Actions

Automated linting, Astro build & test verification

03. Containerization

Docker Container

Portainer managed multi-stage Nginx build

04. Edge Hosting

Cloudflare Pages

Global Edge CDN, TLS 1.3 & WAF Protection

Disaster RecoveryForgejo Git Backups
ObservabilityMattermost Alerts
Edge SecurityCloudflare WAF
Infrastructure SLA99.99% Availability

/ Freelance_&_Consulting_Services

Solutions I Deliver

Open for Contract & Freelance Projects
Freelance Ready

Self-Hosted Infra & Virtualization

Setting up high-availability Proxmox/oVirt clusters, Docker stacks, and Portainer management for zero-friction self-hosting.

Production-Grade Guarantee
Freelance Ready

CI/CD & GitOps Pipeline Setup

Building automated GitHub Actions / Forgejo CI/CD workflows, automated build testing, and multi-environment container deployments.

Production-Grade Guarantee
Freelance Ready

Linux OS & Fleet Hardening

Auditing RHEL/Debian environments, deploying idempotent Ansible security playbooks, SSH hardening, and SSL/TLS lifecycle configuration.

Production-Grade Guarantee
Freelance Ready

Disaster Recovery & Observability

Designing automated backup/restore routines with self-hosted Git and embedding Mattermost webhook alerts for instant anomaly visibility.

Production-Grade Guarantee

Scale with confidence.

Explore my full professional experience and code contributions.