Networks. Cloud. Possibility.

Jhonny
Jocsan
Macias
Garcia

Network & Cloud Specialist
| Infrastructure Engineer & Home-Lab Architect

I build robust digital infrastructures, from bare-metal setups to cloud services. My home lab is where curiosity becomes reliable, secure systems.

ITS Academy Angelo Rizzoli

01 / The person behind the systems

A practical mind. An
infrastructure mindset.

Learning the theory.
Building the real thing.

I’m a Network & Cloud Specialist student at ITS Academy Angelo Rizzoli, following the VET course and working toward graduation in July 2027. Enterprise-grade networking, cloud technologies, and dependable infrastructure are my focus.

I learn by designing, deploying, breaking, and improving systems. My home lab turns abstract concepts into practical experience with virtualization, access control, observability, and recovery.

Adaptable. Detail-oriented. Operations-ready.

My background in technical and administrative operations has taught me to adapt quickly and work methodically. I’m eager to bring that mindset to data center operations and infrastructure teams.

02 / Validated knowledge

A foundation built to keep growing.

Achieved

Amazon Web Services

AWS Certified Cloud Practitioner

Cloud fundamentals

Achieved

Microsoft

Microsoft Azure Fundamentals

AZ-900 · Cloud foundations

Achieved

Microsoft

Microsoft Security, Compliance, and Identity Fundamentals

SC-900 · Security foundations

Next on the roadmap

Next goal

Linux Foundation

Linux Foundation Certified System Administrator

LFCS · Linux administration

Next goal

Cisco

Cisco Certified Network Associate

CCNA · Routing & switching

03 / Built, not just studied

Small footprint. Enterprise thinking.

What started with an ISP FastGate router has evolved into a fully virtualized, enterprise-grade home lab. Workloads are deliberately distributed: heavy compute on the main host, critical network services on a dedicated node, and backups on isolated hardware.

Distributed nodes. Deliberate workloads.

01. Main Proxmox VE node

Geekom A6 Mini PC

AMD Ryzen 7 6800H · 16 GB RAM · 1 TB NVMe SSD (OS) + 1 TB external HDD

The main compute host runs all heavy virtual machines, backend containers, and the OPNsense firewall and gateway. Proxmox VE provides the foundation for a fully virtualized environment. The OS lives on the 1 TB NVMe SSD, while a 1 TB external HDD stores Immich’s photo and video library.

  • Proxmox VE
  • Heavy VMs
  • Backend containers
  • OPNsense

02. Network node 24/7

Raspberry Pi 4

2 GB RAM · 120 GB SSD

AdGuard Home provides DNS and DHCP, WireGuard secures VPN access, RustDesk handles remote support, and Prometheus scrapes the physical nodes for Grafana on AWS EC2.

  • DNS
  • VPN
  • Remote support
  • Prometheus

03. Isolated backup node

HP Notebook

4-core CPU · 8 GB RAM · 1 TB HDD · Headless

Proxmox Backup Server keeps secure, isolated incremental backups of the main Geekom node. Recovery is a separate responsibility, not an afterthought.

  • Proxmox Backup Server
  • Incremental backups

04. Development workstation

MacBook Air M3

Development + local virtualization

The MacBook Air M3 is the development workstation for the lab, supporting hands-on engineering and local virtualization alongside the dedicated infrastructure nodes.

  • Development
  • Virtualization

05. Cloud monitoring VM

AWS EC2 · Grafana

Grafana only · Private VPN connection

Grafana is the only service hosted on this cloud VM. It queries Prometheus running on the Raspberry Pi 4 at home through the private WireGuard VPN.

  • AWS cloud
  • Grafana dashboards
  • WireGuard VPN

Security isn’t a layer added later.

Perimeter security

A considered perimeter.

OPNsense

Hybrid NAT and GeoIP filtering block malicious inbound traffic from high-risk regions and define the lab’s firewall and gateway boundaries.

  • Firewall
  • Hybrid NAT
  • GeoIP filtering

Identity & access

One source of identity.

Authentik

Authentik acts as a Single Source of Truth for centralized authentication, bringing identity and access management into a coherent system.

  • Centralized authentication
  • SSoT

Reverse proxy & access control

Private by intention.

Nginx Proxy Manager + Cloudflare

SSL certificates use the custom jhonnylab.com domain managed on Cloudflare. Strict Access Lists keep critical services reachable only from the local LAN or WireGuard VPN.

  • SSL
  • Access Lists
  • LAN or VPN only

Multimedia & storage

My photos. My infrastructure.

Immich

Self-hosted photo management and synchronization, backed by a dedicated 1 TB external HDD on the main node, provide a practical workload for storage, service deployment, and maintaining control of personal media.

  • Photo management
  • Synchronization
  • Self-hosted

Governance & monitoring

Visibility before guesswork.

Prometheus at home · Grafana on AWS EC2

Prometheus runs on the Raspberry Pi 4 at home and scrapes the physical nodes. Grafana is the only service hosted on the AWS EC2 instance and queries Prometheus over the private WireGuard VPN, providing dashboards and visibility across the lab.

  • Local metrics
  • Private VPN
  • Cloud dashboards

This is an architecture showcase, not an open service directory. Critical services are intentionally restricted to the local LAN or WireGuard VPN.

04 / The next iteration

Always a work in progress. By design.

The next stage is about making the architecture more resilient, repeatable, and secure. I’m scaling the lab toward enterprise-level practices while continuing to learn from every deployment.

01 / Redundancy

Resilience by design.

Enterprise-level reliability

Scale toward enterprise-level redundancy, reduce single points of failure, and make recovery an integral part of the architecture.

Next / Reliability and continuity

02 / Automation

Repeatable, not repetitive.

Ansible

Deepen automation with Ansible, bringing greater consistency to provisioning, configuration, and the everyday management of services.

Next / Infrastructure automation

03 / Continuous improvement

Security keeps evolving.

Stronger security practices

Continuously expand security practices, refine access boundaries, and strengthen the operational habits that keep infrastructure dependable.

Next / Hardening and governance

05 / Let’s connect

Good infrastructure starts
with a conversation.

Interested in networking, cloud infrastructure, or the next challenge? I’d be glad to connect. Send a message or reach me directly.

Emailjhonny.macias@itsrizzoli.it LinkedInJhonny Jocsan Macias Garcia

Send a message

All fields are required.