Techsage is the independent platform practice of Nariman Eghtedari — enterprise OpenShift and Ansible advisory and delivery. The decisions made in the first fortnight determine what the next five years cost.
Engagements are typically platform builds, automation programs, or the resilience work that has to be finished before a platform is allowed to carry real load.
An independent read on the design while changing it is still cheap — zone model, network topology, certificate strategy, failure domains. Delivered as a document your architecture board can act on.
Cluster architecture and build-out on bare metal, virtualised and managed cloud. Dual-NIC and egress networking, NMState policy, corporate PKI and TLS termination, on-cluster Quay, Advanced Cluster Security.
AAP 2.x across Controller, Hub, Event-Driven Ansible and PostgreSQL — then the playbooks that earn their keep: directory migrations, CVE and RHSA remediation, CIS hardening with SCAP verification.
Active-passive designs spanning separate sites, global and local load balancer failover, cross-cluster recovery, and runbooks written to be executed under pressure by someone who did not build the system.
Client names, sectors and environment specifics stay confidential — permanently, not just until a project ends. What follows is the shape of the work itself.
Multi-node OpenShift clusters designed and deployed on bare metal, on virtualised infrastructure and on managed cloud. Bonded and tagged host networking under declarative policy, controlled egress for segmented namespaces, enterprise certificate authority integration with re-encrypt routes, on-cluster image registry, and container security policy applied from day one rather than retrofitted.
Ansible Automation Platform deployed across Controller, Private Automation Hub, Event-Driven Ansible and its database tier — then the playbook libraries that justify it. Directory server major-version migrations reduced to a repeatable four-stage workflow. Vulnerability and errata remediation, benchmark hardening with scan-based verification, and authentication configuration standardised across operating system generations.
Active-passive designs spanning separate sites, global and local load balancer failover between clusters, cross-cluster application recovery, and a business-continuity cluster on managed cloud. The deliverable is not the design — it is the tested failover and a runbook written to be executed under pressure by someone who did not build the system.
Platform architecture for environments where the security zone model, not the container platform, is the binding constraint on every design decision. Certificate lifecycle, controlled egress, network separation and the documentation an accreditation process actually asks for.
Build and deployment pipelines on cloud-native and traditional CI tooling, GitOps-driven cluster configuration, and log and metric collection routed into whichever observability platform the organisation has already standardised on.
Hands-on, in production, in regulated environments.
Techsage runs a production multi-agent system of its own. It monitors infrastructure, reconciles operational records, and surfaces only the decisions that genuinely need a person — built on the same principle as a well-designed cluster: state is declared, observed and reconciled, never assumed.
Platform builds, automation programs, DR design and architecture review. Statements of work, rate cards and references on request.