Mainframe z/OS CyberVault automation
A fully automated, NetView panel-based solution that brings up z/OS systems in an isolated CyberVault environment without human intervention.
Besides loading the system, the automation verifies key components (TSO, Db2, IMS, MQ, network) and applies the changes needed only in the CyberVault environment.
System operations can now run CyberVault loads without last-level support.
Preparation time dropped from 3 full workdays to 2 hours, including the infrastructure validation that makes the mainframe ready for application testing.
Automated product maintenance on mainframe z/OS
Fully automated verification of every IBM Z System Automation and NetView component in use.
A NetView panel application tests every component of the automation products that is in use.
After patching or migration, system operations can validate the products themselves, right after the system restart they already perform. An HTML report is sent out automatically.
Live documentation for automation
A NetView panel-based application that presents automation documentation in an interactive way.
Used by colleagues who provide on-call support for the bank's mainframe automation.
Instead of static pages, it runs display commands, shows the documentation that matches their output and suggests a fix.
The documentation logic is written in a small Markdown-like language with its own interpreter. The tool is also integrated with the maintenance automation.
Migration from CA OPS/MVS to the IBM automation stack
I migrated the automation and monitoring from CA/Broadcom OPS/MVS to IBM Z System Automation and IBM Z NetView.
The migration covered all defined subsystems, OPS/MVS rules and Rexx scripts, batch integration, monitoring software integration, alerting and monitoring.
I configured the IBM automation stack from scratch.
Self-hosted Git environment with CI and monitoring
A self-hosted Forgejo platform with CI built from my own plugins, automated security scanning and dependency updates, full monitoring and hardened edge security, running on NixOS servers provisioned with OpenTofu.
Forgejo is the heart of my self-hosted environment. It stores my personal code and packages, and everything around it is driven by Git and automated workflows.
CI runs only on Woodpecker plugins I wrote myself. It handles patching, vulnerability scanning, unit and integration tests, changelogs, releases and package uploads.
- HostingHetzner VPSs, provisioned with OpenTofu
- OS and configurationNixOS, centrally managed
- DeploymentNixOS modules and Podman Quadlets
- CI/CDWoodpecker CI with self-made plugins
- Dependency updatesRenovate
- Security scanningTrivy, with plugins for Forgejo issues and PRs
- MonitoringGrafana, Prometheus with exporters, Loki and Alloy
- Edge securityCaddy reverse proxy, CrowdSec, Fail2ban
- IdentityAuthelia
Woodpecker CI plugins I built for my own pipelines.
You can find them in my repositories ending with ".woodpecker".
Most of them run on Atis (https://code.thinkaboutit.tech/pandora/atis), a Lua runtime I made. It is statically built, so it works well on minimal images such as distroless.