PROJECTS / ENGINEERING STORIES
Projects, told through the problems behind them.
A closer look at production work I’ve handled — the problem, the approach, and the result.
2026 · PUPUK KALTIM
Nextcloud multi-server production upgrade
Problem
The upgrade touched the full production stack, not just Nextcloud: 2 Web APP servers, 3 database cluster nodes, 2 ProxySQL servers, 1 OnlyOffice server, and 1 S3 storage server. The main challenge was moving Nextcloud 25 → 28 and PXC 8.0 → 8.4 safely while keeping the service available. During cut-over, ProxySQL also marked the new database backends SHUNNED even though the PXC cluster itself was healthy.
Approach
I upgraded Nextcloud incrementally 25 → 26 → 27 → 28, built and synchronized the new 3-node PXC 8.4 cluster, and upgraded the ProxySQL layer from 2.x → 3.x without service downtime. During cut-over, I rolled back when the new backends became SHUNNED, traced the issue to mysql_native_password, moved the database authentication to caching_sha2_password, and brought the new backends ONLINE.
Result
The migration was completed in 1 month, roughly 67% shorter than the original 3-month timeline, with <10 minutes of downtime. Nextcloud reached version 28, the three-node PXC 8.4 cluster reached Primary / Synced state, and the new database backends were ONLINE through ProxySQL. Data integrity was fully preserved: 100% of ~1 TB of data remained intact in MinIO object storage, with 100% metadata consistency in Percona XtraDB Cluster and no data loss.
1 month delivery · ~67% shorter than 3-month timeline
2 Nextcloud Web APP servers
3 PXC 8.4 database nodes
2 ProxySQL servers
1 OnlyOffice server
1 MinIO S3 storage server
<10 minutes of downtime
~1 TB data preserved · 100% data & metadata consistency
2025 · KEJAKSAAN AGUNG
Zimbra email security hardening
Problem
The production email environment required stronger protection against phishing, account compromise, and SMTP abuse. Security controls at both the user authentication and mail transport layers needed to be strengthened without disrupting normal email services.
Approach
I implemented 2FA for stronger account protection and hardened the Zimbra MTA and SASL authentication policies with stricter sender, recipient, HELO, and domain validation. I also tuned Amavis anti-spam rules and applied a targeted CVE-2025-68645 mitigation at the Zimbra proxy layer, validating that malicious requests were blocked while normal webmail and mail flow remained operational.
Result
The combined hardening significantly improved the email security posture and reduced phishing incidents by approximately 30%. Authentication and SMTP controls became more restrictive against unauthorized activity, while normal email delivery and webmail access remained operational after implementation.
~30% reduction in phishing incidents
2FA implementation
MTA + SASL security hardening
Amavis anti-spam tuning
CVE-2025-68645 mitigation and validation
2024 · BARESKRIM POLRI
Zimbra 8 to 10 migration
Problem
The existing Zimbra 8 environment was split across two separate nodes, with production roles spread across 1 LDAP VM, 2 Mailbox VMs, and 1 MTA VM. Around 5 TB of mail data had to be moved to Zimbra 10, while several MySQL errors appeared during the migration.
Approach
I handled the end-to-end implementation and migration, resolved the MySQL issues, and kept the production cut-over tightly controlled. The new Zimbra 10 environment was simplified to 1 LDAP VM, 1 Mailbox VM, and 1 MTA VM, reducing the production footprint from 4 VMs → 3 VMs.
Result
The full implementation and migration was completed in 7 days, around 77% shorter than the original 1-month timeline. All ~5 TB of mail data was migrated successfully with 100% data migration, while the final production cut-over resulted in <5 minutes of downtime during office hours. The new environment runs on 3 VMs instead of 4 and has been more stable in day-to-day operation.
~5 TB migrated · 100% data migrated
7-day delivery · ~77% shorter than the original 1-month timeline
<5 minutes of downtime
4 VMs → 3 VMs
2024 · MIDDLE EAST CLIENT
Web Hosting Migration & Infrastructure Modernization
Problem
The client was running more than 40 websites on shared hosting, which limited infrastructure control, scalability, and operational reliability. The environment needed to be migrated to dedicated infrastructure while keeping all production websites available throughout the transition.
Approach
I migrated the environment from shared hosting to bare metal infrastructure and managed the hosting layer using DirectAdmin. For database high availability, I built a 5-VM MySQL Galera cluster with multi-master replication, fronted by 2 ProxySQL VMs for database traffic distribution. I also strengthened server security with ClamAV and implemented real-time File Integrity Monitoring (FIM) using inotify to detect file changes immediately.
Result
The new architecture supported 40+ production websites with zero downtime and provided a more resilient database layer through Galera and ProxySQL. The centralized infrastructure improved operational efficiency by approximately 40%. Real-time file monitoring also reduced human-error-related incidents by approximately 50% and made troubleshooting around 40% faster by providing immediate visibility into filesystem changes.
40+ production websites
5 MySQL Galera nodes · multi-master replication
2 ProxySQL nodes
Zero downtime
~40% improvement in operational efficiency
~50% reduction in human-error-related incidents
~40% faster troubleshooting
ClamAV + inotify FIM for security monitoring
CLIENT REVIEW · ★★★★★ 5.0
“I had an exceptional experience working with this freelancer. His skills are truly amazing, and the quality of work exceeded my expectations. Communication was smooth throughout the project, making the entire process seamless and stress-free.”
“He finished the job on time and was very cautious and careful with my data, even taking the extra step to back it up. I highly recommend this freelancer to anyone looking for great results and a reliable partner for their projects.”
2023 · KEJAKSAAN AGUNG
Backup & recovery implementation
Problem
The 6-VM Zimbra production environment was running on Sangfor HCI, which Veeam did not natively support at the time. Backups also relied heavily on rsync, leaving more room for manual error and making recovery less predictable.
Approach
I implemented Veeam Backup & Replication across the Zimbra environment, using a kernel-module workaround so the Veeam agent could operate on the Sangfor-hosted VMs. I validated full and incremental backups, tested VM recovery, configured scheduling and retention, and added backup copy and offsite replication. Monthly Zimbra exports using zmmailbox are also stored on separate offsite storage as an additional recovery layer.
Result
The environment moved from a largely manual backup process to a structured 3-2-1-0 backup strategy with separate backup copies and offsite protection. This reduced backup-related human-error risk and improved recovery readiness across the 6 Zimbra VMs. Based on operational recovery expectations, the new workflow can reduce recovery time by approximately 20–30% during an incident, with multiple recovery paths available instead of relying on a single backup method.
6 Zimbra production VMs protected
3-2-1-0 backup strategy
Full + incremental backups · backup copy · offsite replication
~20–30% faster recovery during incidents
Monthly Zimbra exports stored on separate offsite storage
The tools are easier to understand after the work.
If you want the broader view of the platforms and technologies I work with, I keep that separately from the project stories.