Techsage Inc.
Waterloo
Ontario

Judgement, before engineering.

Techsage is the independent platform practice of Nariman Eghtedari — enterprise OpenShift and Ansible advisory and delivery. The decisions made in the first fortnight determine what the next five years cost.

Enterprise engagements since2015
Platforms delivered onBare metal · ROSA · ARO
Directory migrations automatedv10 → v12
Disaster recoveryDesigned & tested
Practice

Four things, done to production standard.

Engagements are typically platform builds, automation programs, or the resilience work that has to be finished before a platform is allowed to carry real load.

Advisory

Architecture review, before commitment

An independent read on the design while changing it is still cheap — zone model, network topology, certificate strategy, failure domains. Delivered as a document your architecture board can act on.

Platform engineering

OpenShift, from bare metal upward

Cluster architecture and build-out on bare metal, virtualised and managed cloud. Dual-NIC and egress networking, NMState policy, corporate PKI and TLS termination, on-cluster Quay, Advanced Cluster Security.

Automation

Ansible Automation Platform, idempotent by default

AAP 2.x across Controller, Hub, Event-Driven Ansible and PostgreSQL — then the playbooks that earn their keep: directory migrations, CVE and RHSA remediation, CIS hardening with SCAP verification.

Resilience

Disaster recovery you have actually tested

Active-passive designs spanning separate sites, global and local load balancer failover, cross-cluster recovery, and runbooks written to be executed under pressure by someone who did not build the system.

What gets
delivered

The work, described by what it is.

Client names, sectors and environment specifics stay confidential — permanently, not just until a project ends. What follows is the shape of the work itself.

Deliverable

Platform build-out

Multi-node OpenShift clusters designed and deployed on bare metal, on virtualised infrastructure and on managed cloud. Bonded and tagged host networking under declarative policy, controlled egress for segmented namespaces, enterprise certificate authority integration with re-encrypt routes, on-cluster image registry, and container security policy applied from day one rather than retrofitted.

  • OpenShift
  • Bare metal
  • ROSA / ARO
  • NMState
  • EgressIP
  • Quay
  • ACS
Deliverable

Automation programs

Ansible Automation Platform deployed across Controller, Private Automation Hub, Event-Driven Ansible and its database tier — then the playbook libraries that justify it. Directory server major-version migrations reduced to a repeatable four-stage workflow. Vulnerability and errata remediation, benchmark hardening with scan-based verification, and authentication configuration standardised across operating system generations.

  • AAP 2.x
  • Event-Driven Ansible
  • Directory migration
  • CVE / errata
  • CIS & SCAP
  • RHEL 7/8/9
Deliverable

Resilience and recovery

Active-passive designs spanning separate sites, global and local load balancer failover between clusters, cross-cluster application recovery, and a business-continuity cluster on managed cloud. The deliverable is not the design — it is the tested failover and a runbook written to be executed under pressure by someone who did not build the system.

  • Multi-site HA/DR
  • Global load balancing
  • Cross-cluster recovery
  • Tested runbooks
Deliverable

Secure and segmented environments

Platform architecture for environments where the security zone model, not the container platform, is the binding constraint on every design decision. Certificate lifecycle, controlled egress, network separation and the documentation an accreditation process actually asks for.

  • Zone architecture
  • Classified workloads
  • PKI lifecycle
  • Controlled egress
Deliverable

Pipelines and observability

Build and deployment pipelines on cloud-native and traditional CI tooling, GitOps-driven cluster configuration, and log and metric collection routed into whichever observability platform the organisation has already standardised on.

  • Tekton
  • Jenkins
  • Argo CD
  • Log forwarding
  • APM integration
Capability
index

What Techsage works in.

Hands-on, in production, in regulated environments.

Container platform
OpenShift Container Platform · ROSA · Azure Red Hat OpenShift · OpenShift Virtualization
Operating system
RHEL 7 / 8 / 9 · lifecycle · CIS hardening · SCAP scanning
Automation
Ansible Automation Platform 2.x · Controller · Private Automation Hub · Event-Driven Ansible
CI/CD and GitOps
Tekton Pipelines · Jenkins · Argo CD · Quay registry
Networking
NMState / NNCP · EgressIP · dual-NIC topologies · F5 GTM and LTM · corporate PKI
Security
Advanced Cluster Security · CVE and RHSA remediation · Protected B / C zone design
Directory and identity
Red Hat Directory Server 10 / 11 / 12 · LDAP multi-suffix replication
Observability
Dynatrace · Splunk · Loki · Fluent Bit · cluster logging
Languages
Ansible · Python · Bash · PowerShell
AI
operations

The same discipline, applied to autonomous systems.

Techsage runs a production multi-agent system of its own. It monitors infrastructure, reconciles operational records, and surfaces only the decisions that genuinely need a person — built on the same principle as a well-designed cluster: state is declared, observed and reconciled, never assumed.

01extractorsPull raw facts from source systems. No interpretation, no inference.
02event storeAppend-only record, so any conclusion traces back to its evidence.
03correlatorsJoin events deterministically — matching is code, not a language model.
04derived stateCurrent truth, recomputed from ground truth rather than edited in place.
05narratorsThe only layer that uses a model, and only to explain state a human must act on.
Contact

Arrange an introduction.

Platform builds, automation programs, DR design and architecture review. Statements of work, rate cards and references on request.

Techsage Inc. Incorporated in Ontario, Canada Waterloo, Ontario