Bare-Metal Systems Engineering,
High-Availability Clusters & Fleet Automation
Rare, foundational bare-metal operations experience that precedes cloud abstractions: hand-built physical server assembly, power and network cabling, Windows Server 2008 Enterprise Failover Clustering, multi-hypervisor virtualization (VMware ESXi & Hyper-V), Active Directory forest administration for 200+ domain workstations, SharePoint intranet farms, and 150+ custom PowerShell automation scripts interfacing with low-level Win32 USB hardware drivers.
Bare-Metal HA Infrastructure & Ops
Bare-metal high-availability datacenter infrastructure powering continuous hospital server operations.
Active/passive quorum voting, SQL Server AlwaysOn availability groups, and SAN multipath failover.
6 years of 99.9% uptime, 150+ PowerShell automation runbooks, and automated disaster recovery.
Bare-Metal Infrastructure & Systems Architecture
Select any project below to inspect its architecture diagrams, clustering topology, domain configurations, and PowerShell automation engines.
Bare-Metal HA Failover Cluster & Virtualization
Hand-built physical server cluster with redundant networking, heartbeat interconnects, VMware ESXi & Microsoft Hyper-V virtualization, and MS SQL Server 2008 failover clustering on Windows Server 2008 Enterprise with RAID 10/5 sharding.
Active Directory Domain & 200+ Workstation Fleet
Complete enterprise domain governance across 200+ faculty, clinical simulation lab, and testing workstations: Group Policy Object (GPO) enforcement, automated drive mappings, SharePoint intranet farm, and enterprise print servers.
150+ PowerShell Automation & USB Driver Telemetry
Extensive PowerShell automation suite managing user provisioning, patch compliance, backup pipelines, and custom low-level Win32 USB driver communication extracting printer page counts and toner levels.
Bare-Metal High-Availability Failover Cluster (VMware • Hyper-V • MS SQL • RAID)
Physical hardware assembly, cabling, redundant heartbeat networks, hypervisor virtualization, and zero-downtime database failover on Windows Server 2008 Enterprise.
High-Availability Virtualization & Database Resiliency
Physical hardware assembly, cabling, redundant heartbeat networks, hypervisor virtualization, and zero-downtime database failover.
-
✓
Component-Level Bare-Metal Hardware Assembly: Hand-built the entire physical server infrastructure from individual silicon components: multi-socket Intel Xeon processor seating, thermal paste application, ECC registered DDR3 RAM populating across memory channels, dual redundant hot-swappable 850W power supplies (PSUs), LSI MegaRAID SAS host bus adapters with Battery-Backed Write Cache (BBWC), dual multi-port Gigabit NICs, and structured rack cabling.
-
✓
Windows Server 2008 Enterprise Failover Clustering (WSFC): Architected a 2-node active/passive failover cluster utilizing Node and Disk Majority quorum voting with dedicated witness disks. Configured sub-second heartbeat health probing across dedicated point-to-point crossover Ethernet links, guaranteeing automatic takeover without transactional loss during hardware or OS faults.
-
✓
MS SQL Server 2008 High-Availability Clustering: Deployed a clustered MS SQL Server 2008 instance bound to virtual cluster IP endpoints and shared cluster storage LUNs, serving continuous, uninterrupted database operations for college admissions scoring, faculty research grants, and departmental finance.
-
✓
Dual-Hypervisor Virtualization (VMware ESXi & Microsoft Hyper-V): Engineered and maintained side-by-side virtualization tiers hosting production guest virtual machines: VMware ESXi for high-density Linux web endpoints and Microsoft Hyper-V for Windows Server guest VMs, IIS application pools, and secondary Domain Controllers.
-
✓
Storage Fabric & RAID Sharding Architecture: Partitioned enterprise SAS disk arrays into optimized RAID tiers: RAID 10 (striped mirrors) dedicated to random write-intensive SQL transaction logs (LDF) and primary data files (MDF), RAID 5 with hot-spares for hypervisor virtual disk stores, and automated nightly snapshot rotations to dedicated backup targets.
-
✓
Isolated Heartbeat & Storage Networking: Separated network traffic using isolated physical VLANs: dedicated cluster private heartbeat interconnects, iSCSI/SAN storage multipath I/O with MPIO failover, administrative management subnets, and public-facing departmental LANs.
Cluster Quorum & Heartbeat
• Quorum Model: Node and Disk Majority
• Heartbeat Frequency: 1.2s timeout with 5 retries
• Failover Trigger: Sub-second automated VIP migration
• Shared LUNs: Cluster Shared Volumes (CSV) & Quorum Witness
RAID Storage Layout
• RAID 10: High-IOPS SQL Database & Transaction Logs
• RAID 5 + Hot Spare: Hypervisor VM Disks (VHD/VMDK)
• Controller: LSI MegaRAID SAS with BBWC Cache
• Backup: Daily Differential & Weekly Full Image Mirroring
Enterprise Active Directory Governance & 200+ Managed Workstations
Active Directory forest architecture, Group Policy Object (GPO) security enforcement, SharePoint intranet farm, and centralized administration for 200+ domain workstations.
Centralized Identity, Security Policies & Workstation Fleet
Active Directory Domain Services, automated GPO compliance, SharePoint document repositories, and multi-tier lab/testing kiosk security.
-
✓
Active Directory Domain Services (AD DS) Forest: Architected clean Organizational Unit (OU) schemas partitioned by Faculty, Administrative Staff, Nursing Students, Clinical Researchers, Simulation Laboratories, and Examination Kiosks. Implemented fine-grained password policies, Kerberos authentication, and Role-Based Access Control (RBAC).
-
✓
Group Policy Object (GPO) Hardening: Authored comprehensive GPO suites enforcing desktop security baselines, dynamic departmental network drive mapping via AD security group filtering, automated printer discovery and driver deployment, browser security zones, and silent software rollouts.
-
✓
SharePoint Intranet Farm Deployment: Deployed and maintained an on-premise Microsoft SharePoint intranet farm, configuring secure document libraries, committee workspaces, FERPA-compliant record management, and automated approval workflows integrated with Active Directory identities.
-
✓
200+ Endpoint Fleet Lifecycle Management: Administered 200+ diverse physical endpoints: faculty/staff laptops and desktops, specialized Clinical Nursing Simulation Laboratory computers running telemetry feeds for high-fidelity mannequin simulators, and locked-down student examination kiosks preventing application switching or network exfiltration.
-
✓
Enterprise Root CA & PKI Infrastructure: Architected and managed an on-premise Active Directory Certificate Services (AD CS) Public Key Infrastructure with a dedicated Root Certificate Authority (CA). Automated X.509 certificate enrollment across 200+ domain workstations, securing internal IIS and SharePoint HTTPS/TLS endpoints, mutual workstation authentication, encrypted administrative sessions, and cryptographic PowerShell code signing.
-
✓
Departmental Network Shares & Access-Based Enumeration: Configured enterprise file servers with Access-Based Enumeration (ABE), restricting folder visibility exclusively to users with explicit read permissions. Implemented Shadow Copies for Volume Snapshots (VSS) enabling instant point-in-time file recovery.
-
✓
Enterprise Print Server Infrastructure: Managed centralized Windows print servers with load balancing, automated point-and-print driver installation over Group Policy, printer queue optimization, and automated quota accounting.
OU Schema & GPO Policies
• Granular OUs: Faculty, Staff, Students, SimLabs, Kiosks
• Group Policy: Dynamic Drive Maps by Security Group
• Security Baselines: USB Storage Lockout & BitLocker
• Print Deployment: Point-and-Print via GPO Push
Root CA & Enterprise PKI
• Root CA: On-Premise Active Directory Certificate Services
• Auto-Enrollment: Automated X.509 Domain Machine & User Certs
• Transport Encryption: Internal SSL/TLS for IIS & SharePoint
• Code Signing: Cryptographic Validation for PowerShell Scripts
Simulation & Kiosk Endpoints
• Clinical Sim Labs: Mannequin telemetry data endpoints
• Exam Kiosks: Locked-down kiosk mode with no file system access
• Imaging: Automated WDS network PXE boot installation
• Patching: WSUS scheduled silent midnight updates
150+ PowerShell Automation Suite & Low-Level USB Driver Telemetry
150+ PowerShell scripts automating onboarding, patching, disaster recovery backups, and direct USB driver hardware register interrogation.
Scripted Fleet Governance & Low-Level Device Querying
150+ PowerShell scripts automating onboarding, patching, disaster recovery backups, and direct USB driver hardware register interrogation.
-
✓
Low-Level Win32 USB Driver Telemetry Extraction: Engineered custom PowerShell modules using P/Invoke to call Win32 API functions (
CreateFile,DeviceIoControl) against printer USB raw endpoints and bidirectional printer language channels (PJL / SNMP / USB-HID). Interrogated internal hardware registers directly to extract physical page counts, optical toner levels, and drum life, streaming real-time consumable telemetry into centralized MS SQL Server accounting schemas. -
✓
Automated User Lifecycle & RBAC Provisioning: Wrote automated identity pipelines parsing registrar admissions and HR employment feeds. Created Active Directory accounts, assigned security groups, initialized home directories with locked NTFS ACLs, configured Exchange mailboxes, and automatically archived/deprovisioned accounts upon departure.
-
✓
200+ Workstation Patch Compliance & Inventory Auditing: Scripted scheduled fleet auditing engines querying remote machines over WinRM/WMI. Inventoried hardware components (RAM, CPU, storage health), verified antivirus signature freshness, verified firewall state, and silently installed critical security patches.
-
✓
Automated Disaster Recovery & Database Maintenance: Automated multi-stage disaster recovery pipelines: daily MS SQL database consistency checks (
DBCC CHECKDB), index re-indexing, transactional log truncations, compressed database dumps, and offsite snapshot replication with hash verification. -
✓
Real-Time Event Log Scrapers & Incident Dispatch: Built lightweight background daemon scripts scanning Windows Event Logs across cluster nodes and Domain Controllers, immediately dispatching alerts upon detecting failover events, disk threshold warnings, or authentication anomaly bursts.
-
✓
Foundational Bare-Metal Experience Preceding Cloud Abstractions: This deep operational experience—building physical clusters, configuring kernel-level failovers, tuning RAID stripe sizes, writing low-level hardware driver integrations, and automating domain policies—provides a first-principles foundation that precedes and informs modern cloud (AWS/GCP/Azure) and Kubernetes architectures.
⚡ Low-Level USB Driver & Fleet Management Engine Example
# Win32 DeviceIoControl Low-Level Hardware Interrogation & AD Provisioning
$pInvokeSignatures = @'
[DllImport("kernel32.dll", SetLastError = true, CharSet = CharSet.Auto)]
public static extern SafeFileHandle CreateFile(
string lpFileName, uint dwDesiredAccess, uint dwShareMode,
IntPtr lpSecurityAttributes, uint dwCreationDisposition,
uint dwFlagsAndAttributes, IntPtr hTemplateFile);
[DllImport("kernel32.dll", SetLastError = true)]
public static extern bool DeviceIoControl(
SafeFileHandle hDevice, uint dwIoControlCode,
byte[] lpInBuffer, uint nInBufferSize,
byte[] lpOutBuffer, uint nOutBufferSize,
out uint lpBytesReturned, IntPtr lpOverlapped);
'@
Add-Type -MemberDefinition $pInvokeSignatures -Name "Win32RawDevice" -Namespace "HardwareOps"
# Query attached printer hardware register via raw IOCTL control code
function Get-PrinterHardwareTelemetry([string]$devicePath) {
$hDevice = [HardwareOps.Win32RawDevice]::CreateFile($devicePath, 0xC0000000, 3, [IntPtr]::Zero, 3, 0, [IntPtr]::Zero)
if (-not $hDevice.IsInvalid) {
$outBuffer = New-Object byte[] 1024
$bytesReturned = 0
# IOCTL_USB_PRINT_GET_LPT_STATUS / PJL info query
$result = [HardwareOps.Win32RawDevice]::DeviceIoControl($hDevice, 0x00220014, $null, 0, $outBuffer, 1024, [ref]$bytesReturned, [IntPtr]::Zero)
$hDevice.Close()
return (Parse-TelemetryMetrics $outBuffer $bytesReturned)
}
}