Independent infrastructure & security engineering

Systems you can actually read.

Infrastructure and security engineering for teams who would rather understand their stack than trust it. Every engagement has a decision, a deliverable, and a stopping point.

1,000+ Repositories under security automation
20+ Years operating Linux in production
11 Open-source blueprints, gaps included
Why this practice exists

Most teams do not lack tools. They lack working integration and useful context.

Asset data lives in Terraform. Runtime truth lives in metrics, logs, traces, and packets. Findings arrive from five scanners with five ideas of urgency. Identity and certificates become urgent only after they fail. RTFM closes that gap without handing you another black box.

01

Outcomes before components

Start with “what breaks if I change this?”, “what is being exploited?”, or “why is the service slow?” The container list comes second.

02

Opinionated, not opaque

Every component, config, dashboard, and trade-off stays visible. A system you cannot understand is just a smaller vendor lock-in problem.

03

You keep operating it

Documentation and knowledge transfer are part of the work, not an upsell. The goal is a team that no longer needs the engagement.

Three ways to engage

Defined work. Visible output.

011–2 weeks

Architecture & risk review

For teams deciding what to build, replace, harden, or stop pretending is temporary.

You leave with

A written decision record, architecture diagrams, a risk register, and an implementation estimate.

022–6 weeks

Hardened deployment

For teams that want a proven blueprint adapted to their real network, identity, data, and recovery requirements.

You leave with

A running, tested deployment; source-controlled configuration; evidence of recovery; and a clean handover.

03Monthly · limited slots

Ongoing operations

For small teams that own the stack but need experienced review and operational depth without hiring another full-time role.

You get

A named operator, a monthly evidence report, an ordered improvement queue, and fewer “we should probably check that” items.

Evidence, not a capabilities deck

You can read the work before you hire the engineer.

RTFM publishes In a Box — eleven published self-hosted infrastructure and security blueprints, in the open, with their tests, dashboards, configuration, and stated gaps. It is the same engineering you would be buying.

Real output from the projects — not product mockups.

If it cannot be understood when it fails at 3 AM, it is not finished.