status: Seeking IT Support & Systems Administration Roles (Dec 2026)
education: Ranken Technical College | major: Information Technology (A.T.)

Colin McGrath

Information Technology specialist focusing on enterprise systems administration, virtualization (Proxmox / VMware ESXi), and network infrastructure.

Based in the St. Louis, MO area. Hands-on experience architecting virtualized multi-site enterprise environments, deploying Active Directory domain services with Group Policy, configuring secure Linux servers (Ubuntu/Fedora/Debian), and automating infrastructure storage pipelines.

Industry Certifications:
CompTIA Security+
CompTIA A+
Microsoft AZ-900 (Expected Dec 2026)

Featured Infrastructure: Bare-Metal Proxmox Hypervisor

Production Host

// enterprise virtualization, tiered lvm storage, lxc microservices, zero-trust mesh routing & hardware passthrough

HOMELAB SPECS & ARCHITECTURE OVERVIEW
Host: Bare-Metal Proxmox VE 9.2 (Debian 13) • Eureka, MO
Hardware Specifications Physical Node
  • Processor: Intel Core i5-10400 (6C / 12T @ 2.90 GHz, up to 4.30 GHz Turbo)
  • Memory: 32 GB DDR4 RAM
  • Fast Storage: 1 TB NVMe SSD (LVM-Thin pool for sub-ms container & VM rootfs)
  • Media Pool: 3.6 TB Storage Array (2x 1.8 TB in LVM mounted at /mnt/hdd)
  • Graphics: Intel UHD 630 (QuickSync iGPU) + AMD Radeon Dedicated GPU
  • Networking: Gigabit Ethernet (vmbr0) + Intel Wi-Fi 6 AX200
Workloads & Network Design Proxmox Topology
  • Microservices: 11 isolated unprivileged LXC containers (Jellyfin, *Arr suite, Crafty, etc.)
  • Smart Home: Dedicated Home Assistant OS (HAOS) KVM virtual machine
  • Storage Links: Host-level ext4 bind mounts (mp0) with zero-copy hardlinks
  • Public Ingress: Encrypted Cloudflare Zero Trust Tunnel (colinmcgrath.dev)
  • Remote Admin: Authenticated Tailscale WireGuard Mesh overlay (192.168.1.0/24)
  • Port Forwarding: Completely disabled (0 public router ports exposed)

LXC Microservices Fabric & Atomic Storage Architecture

Homelab
LVM-Thin NVMe • 3.6TB HDD Array • Host Bind Mounts (mp0) • ext4 Hardlinks

A high-density container platform running 10+ unprivileged LXC microservices on bare-metal Proxmox VE. Ingestion and media distribution containers share host-level ext4 storage bind mounts (/mnt/hdd), enabling instantaneous zero-copy hardlinks across namespaces without duplicating multi-gigabyte files or causing unnecessary disk write wear.

Proxmox VE LXC Containers LVM-Thin Storage Host Bind Mounts (mp0) ext4 Hardlinks UID/GID Mapping

Hardware Transcoding Passthrough & Isolated VPN Kill-Switch

Security & Hardware
Intel QuickSync (/dev/dri) • WireGuard (wg0) • /dev/net/tun • cgroups v2 • Crafty

Passed host Intel GPU render nodes (/dev/dri/renderD128) directly into an unprivileged Jellyfin container via cgroups v2 device rules, enabling real-time 4K HEVC hardware transcoding. Download clients are isolated through a dedicated WireGuard tunnel with a persistent kernel kill-switch to prevent IP or DNS leaks, alongside an isolated container running Crafty Controller for game server management.

Intel QuickSync /dev/dri Passthrough WireGuard (wg0) Kernel Kill-Switch Crafty Controller

Zero-Trust Tailscale Subnet Router, KVM Home Assistant & Telemetry

Networking
Tailscale Mesh • Linux IPv4 Forwarding • KVM QEMU (HAOS) • Uptime Kuma

Configured the bare-metal Proxmox host as an encrypted edge gateway advertising the local 192.168.1.0/24 subnet across Tailscale's WireGuard mesh, granting secure remote management with zero exposed router ports. Deployed Home Assistant OS inside an isolated KVM virtual machine for IoT automation, coupled with Uptime Kuma for continuous TCP/HTTP health probing.

Tailscale Subnet Router IPv4 Forwarding KVM (HAOS) Uptime Kuma Cloudflare Tunnel Ingress

Crash-Resilient Multi-TB Storage Migration & Pool Expansion Pipeline

Automation
Python 3 • JSON State Checkpointing • Subprocess Verification • LVM Volume Expansion

Developed an automated Python migration daemon (migrate_and_expand.py) with transactional JSON state checkpointing to safely relocate multi-terabyte datasets across physical drives during a live Proxmox storage rebuild. Guaranteed zero-loss resume capability on power or system interruptions and expanded the active LVM media pool to 3.6TB (/mnt/hdd) without breaking container mount paths.

Python 3 Crash Recovery JSON Checkpointing LVM Expansion ext4 Filesystems

Ranken Technical College — Systems Labs & Implementations

Practical Implementations

// hands-on technical labs across Windows Server, cybersecurity & PKI, VMware ESXi, and Linux administration

Active Directory & Domain Architecture Enterprise Infrastructure

Forest Architecture, Cross-Forest Trusts & Read-Only Domain Controllers

Automated virtual machine deployments via WDS & PXE network boot. Installed Active Directory Forest Root, raised functional levels, established cross-forest trust relationships (`SERVER1 ↔ CORP1`), and deployed Read-Only Domain Controllers (RODCs) with password replication policies. Configured Sites & Subnets for optimized inter-site replication and enabled the Active Directory Recycle Bin for object recovery.

AD Forest Trusts RODC Deployment AD Sites & Subnets WDS / PXE Boot AD Recycle Bin
Storage Spaces & File Services Storage Networking

Distributed File System (DFS), Storage Spaces & iSCSI Target

Configured enterprise storage pools using Storage Spaces with RAID parity arrays and attached remote block storage using iSCSI Target & Initiator services. Deployed Distributed File System (DFS) Namespaces and Replication, file auditing, disk quotas, file screening rules, and managed complex NTFS vs. SMB sharing permissions.

DFS Replication Storage Spaces / RAID iSCSI Target File Screen Quotas NTFS Permissions
Identity, High Availability & Services High Availability & PKI

DHCP Failover, Domain GPOs, AD Certificate Services (PKI) & Containers

Deployed enterprise DNS zones with zone transfers and established DHCP failover for high availability. Enforced domain-wide Group Policy Objects (GPOs), provisioned internal Active Directory Certificate Services (AD CS / PKI), deployed WSUS patch updates, and hosted containerized web apps using Docker on Windows Server and Nano Server.

DHCP Failover GPO Security AD CS (PKI) WSUS Updates Windows Containers
PKI & Cryptographic Systems Security & Cryptography

Public Key Infrastructure, Certificate Signing & Attack Surface Reconnaissance

Generated Certificate Signing Requests (CSRs), inspected Root CAs and system trust stores, and tested SSL/TLS cipher suites and handshakes. Executed attack surface reconnaissance, scanned open service ports with Nmap, evaluated default credential vulnerabilities, and compared symmetric (AES) vs. asymmetric (RSA) encryption.

CSR Generation Root CA Trust Stores SSL/TLS Ciphers Port Recon (Nmap) AES / RSA Crypto
Network Attacks & Threat Analysis Threat Defense

Layer 2 Attacks, ARP Poisoning, Ransomware Telemetry & Hash Cracking

Analyzed Layer 2 attacks including ARP Poisoning and DNS Spoofing to intercept traffic in Man-in-the-Middle (MitM) scenarios. Evaluated ransomware payloads and malicious URLs using VirusTotal telemetry, tested software keylogger delivery mechanisms, performed password hash cracking, and analyzed wireless Wi-Fi reconnaissance.

ARP Poisoning / MitM DNS Spoofing Ransomware Telemetry Password Cracking Wireless Recon
vSphere ESXi Hypervisor Infrastructure Enterprise Virtualization

Bare-Metal ESXi Hosts, vCenter Server & Storage Provisioning

Configured bare-metal ESXi 7 hosts and deployed the vCenter Server Appliance. Joined ESXi hosts and vCenter to Microsoft Active Directory domain, managed SSH / TSM shell services, provisioned VMDK datastores comparing Thin vs. Thick-provisioned disks, organized VM templates, and deployed Windows 10 virtual machines with VMware Tools integration.

vCenter Server ESXi 7 Hosts AD Domain Joining VMDK Provisioning VM Templates
Server Deployment & Kernel Architecture Linux Administration

Dual-Distribution Provisioning, Live Boot & Dynamic Kernel Modules

Deployed and configured Fedora Workstation and Ubuntu Server environments. Managed Linux kernel modules using `lsmod`, `modprobe`, and persistent `/etc/modprobe.d/` configurations. Managed software packages across `apt` and `dnf`, navigated system hierarchy, and configured remote access.

Ubuntu Server Fedora Workstation Kernel Modules (modprobe) CLI Navigation Package Management
Filesystem Storage & Volume Management Filesystems & LVM

Filesystem Hierarchy, LVM Dynamic Storage & Granular POSIX ACLs

Partitioned storage devices with `fdisk` and `parted`, initialized LVM Volume Groups with dynamically expandable Logical Volumes, enforced granular permissions using POSIX ACLs (`setfacl`/`getfacl`), implemented user disk quotas, maintained filesystem integrity with `fsck`, and configured persistent `/etc/fstab` mounts.

LVM Volumes POSIX ACLs fdisk / parted vi / Regex fsck & Quotas
Shell Automation & System Administration Scripting & Admin

BASH Shell Scripting, I/O Redirection, User Lifecycles & Backups

Constructed automation BASH scripts utilizing standard I/O streams (`>`, `<`, `2>&1`) and pipelines (`|`). Administered enterprise user and group accounts with delegated `sudoers` privileges. Automated archive compression (`tar`, `gzip`, `xz`) and synchronized incremental network backups utilizing `rsync`.

BASH Scripting I/O Redirection & Pipes User/Group (sudoers) tar / gzip / xz rsync Backups
System Initialization & Process Management systemd & Init

GRUB2 Bootloader, Custom systemd Units & Process Scheduling

Configured GRUB2 bootloader parameters and systemd runlevel targets. Authored custom systemd service units, managed running processes with signals (`SIGTERM`, `SIGKILL`), adjusted CPU scheduling priorities using `nice`/`renice`, and scheduled automated background jobs with `cron` and `at`.

systemd Unit Files GRUB2 Bootloader Process Signals nice / renice Cron & at Automation
Network Routing & Interfaces Networking & Routing

Persistent Static IPs, Netplan YAML & Bottom-Up Diagnostics

Configured network interfaces and persistent static IP addressing across Fedora using NetworkManager (`nmcli`) and Ubuntu Server using Netplan YAML. Configured DNS nameservers and local `/etc/hosts` name resolution. Executed bottom-up network diagnostic procedures utilizing `ip addr`, `ip route`, `ping`, `ss`, `netstat`, and `dig`.

NetworkManager (nmcli) Netplan YAML Static Routing DNS / hosts Diagnostic Suite
Secure Remote Services & Distributed Shares Network Services

Hardened OpenSSH Key Authentication, SFTP Jails & NFS Storage

Configured OpenSSH server daemon policies with public/private key-pair authentication. Deployed restricted SFTP chroot directory jails for secure file transfers, exported multi-client Network File System (NFS) shared storage mounts, and configured Apache web service hosting.

SSH Key Auth NFS Exports SFTP Security Apache Web Server Network Services
Perimeter Hardening & Performance Profiling Security & Profiling

Host Firewalls, journalctl Log Auditing & Performance Profiling

Audited attack surfaces and open ports, configured stateful host firewall rules (UFW/iptables), aggregated and analyzed unified system logs with `journalctl` and `/var/log`, and diagnosed hardware resource bottlenecks using `top`, `vmstat`, and `iostat`.

Host Firewalls journalctl Auditing Security Hardening Performance Tuning

Technical Tooling & Competencies

// certified competencies across enterprise virtualization, networking, and systems administration

Virtualization & Cloud

  • Proxmox VE (PVE Hypervisor)
  • VMware ESXi 7 & vCenter Server
  • Microsoft Hyper-V Deployment
  • Linux Containers (LXC) & Docker
  • Microsoft Azure Cloud (AZ-900 Prep)
  • Datastores & VMDK Disk Provisioning

Enterprise Identity & Security

  • Active Directory Domain Services (AD DS)
  • Forest Trusts, Sites/Subnets & RODCs
  • Group Policy (GPO) Security Hardening
  • AD CS (Public Key Infrastructure / PKI)
  • Distributed File System (DFS) & Storage Spaces
  • ARP Poisoning, MitM & Recon Analysis

Operating Systems & Automation

  • Windows Server 2022 & Win 10/11
  • Linux (Debian, Ubuntu Server, Fedora)
  • PowerShell & CLI Administration
  • Bash Shell Scripting & Automation
  • Python 3 (File & Storage Automation)
  • Tailscale & WireGuard Mesh VPNs

// Practical Engineering Approach

Through intensive lab work at Ranken Technical College and self-hosted bare-metal infrastructure, I focus on building reliable, repeatable systems. Whether deploying multi-forest Active Directory trusts and Distributed File Systems (DFS) on Windows Server 2022, managing ESXi 7 datastores in vCenter, or isolating microservices behind WireGuard kernel VPN tunnels on Proxmox, I emphasize defense-in-depth, least-privilege RBAC access, and clear technical documentation.

College: Ranken Technical College
Certifications: CompTIA Security+, CompTIA A+
Primary Hypervisors: Proxmox VE, VMware ESXi 7, Microsoft Hyper-V