~ lucabolanz.de

Luca Bolanz

IT Administrator · IT Specialist for System Integration

Luca Bolanz profile picture

$ whoami

I build, run, secure and document IT infrastructure. My focus is on Linux, virtualization, networking and automation.

$ ls ~/homelab

proxmox/ opnsense/ docker/ ansible/ terraform/

// about

I work as an IT administrator in the banking sector. There I am mainly responsible for VMware and the server infrastructure and look after the Sophos firewalls, and now and then pfSense. On top of that come backups with Veeam and security monitoring with Wazuh. Availability, security and clean documentation are part of my daily work. I got to know Linux during my apprenticeship as an IT specialist for system integration, including a project with Red Hat Enterprise Linux. At home I run a homelab with Proxmox, OPNsense and Docker. Right now I am going deeper into automation with Ansible and Terraform and learning Kubernetes.

// experience

  1. since 06/2025

    IT Administrator

    Bank

    • Administering the VMware environment and the Windows Server infrastructure
    • Looking after the Sophos firewalls and their rule sets, occasionally pfSense too
    • Security monitoring with Wazuh XDR/SIEM and looking into suspicious events
    • Assessing vulnerabilities and fixing them with patches or config changes
    • Helping roll out network access control
    • Backup and restore with Veeam
    • First and second level support through the ticket system
    • Documenting changes and working with external service providers
  2. 09/2022 to 06/2025

    Apprenticeship as IT Specialist for System Integration

    Data center

    • Looking after Linux and Windows systems in a large virtualized data center
    • Working on networking and virtualization, installing hardware and software
    • Proof of concept with Red Hat Enterprise Linux including service and network setup, tuned VMware resources and benchmarks of several AI models
    • Tickets in Jira and documentation in Confluence

// quick facts

VirtualizationVMware, Proxmox VE
Server OSWindows Server, RHEL, Ubuntu, Rocky
DesktopLinux (Fedora, Arch)
FirewallSophos, OPNsense
SecurityWazuh XDR/SIEM
BackupVeeam Backup & Replication
AutomationAnsible, Terraform, cloud-init
LanguagesGerman, English (B2), French (A1)

// skill clusters

professional apprenticeship & projects homelab & learning

Virtualization & Servers

  • VMware (professional)
  • Windows Server (professional)
  • Red Hat Enterprise Linux (apprenticeship & projects)
  • Proxmox VE (homelab & learning)
  • Ubuntu Server (homelab & learning)
  • Rocky Linux (homelab & learning)

Networking & Firewalls

  • Cisco Meraki (professional)
  • Sophos Firewall (professional)
  • pfSense (professional)
  • Firewall rule sets (professional)
  • Network Access Control (professional)
  • TCP/IP, VLANs & routing (professional)
  • OPNsense (homelab & learning)

Security & Monitoring

  • Wazuh XDR/SIEM (professional)
  • Security event analysis (professional)
  • Vulnerability management (professional)
  • Patch management (professional)
  • System hardening (homelab & learning)
  • WAF fundamentals (homelab & learning)

Backup & IT Operations

  • Veeam Backup & Replication (professional)
  • L1/L2 support (professional)
  • Ticketing systems (professional)
  • Technical documentation (professional)
  • Jira & Confluence (apprenticeship & projects)

Containers & Automation

  • Ansible (homelab & learning)
  • Terraform (basics) (homelab & learning)
  • cloud-init (homelab & learning)
  • Docker & Portainer (homelab & learning)
  • Nginx Proxy Manager & TLS (homelab & learning)
  • Kubernetes / K3s (in progress) (homelab & learning)

Development & Cloud

  • Python (apprenticeship & projects)
  • Bash (basics) (homelab & learning)
  • Git (homelab & learning)
  • AWS (lab) (homelab & learning)

// training

Cisco Networking Academy · Skills for All

Badges on Credly
  • Networking Basics
  • Network Addressing and Basic Troubleshooting
  • Networking Devices and Initial Configuration
  • Network Defense
  • Endpoint Security
  • Cyber Threat Management

// homelab

Home network on OPNsense with separate VLANs for clients, servers, management, guests, OT and VPNrunning
DNS and DHCP via dnsmasq, integrated UniFi access pointsrunning
Proxmox VE with a VLAN-aware bridge, VMs provisioned via Terraform (least-privilege API token) and cloud-initrunning
Idempotent Ansible baseline for new hosts, run through Semaphore UIrunning
Container services with Docker behind Nginx Proxy Manager with TLSrunning
Change documentation with backup, rollback and evidence for every changerunning
VPS operations with public DNS and HTTPSrunning
Step-by-step onboarding of hosts into Ansible, fact collection from servers and network gearbuilding
Monitoring lab with Checkmk, Prometheus and Grafana plus Wazuh with CIS checksbuilding
Backup/restore testing with Proxmox Backup Server and Resticbuilding
Kubernetes with K3s, isolated Windows AD lab, NetBoxbuilding
Self-built skill-tree dashboard (React/Node, encrypted at rest)building

// blog

On my blog I write about my homelab, Linux and things I measured myself.

// get in touch