Connectivity
Carrier access, fiber, xDSL, satellite and radio.
System Engineer · Infrastructure & Solution Architect
The infrastructure that keeps a business running.
Reliable, secure, operable.
I design, build and operate networks, connectivity, servers, cloud platforms, security controls and user environments as one system. The goal is practical: available services, diagnosable failures and recovery procedures that work.
More than 20 years of hands-on ICT experience. From the physical medium and carrier access to architecture, production operations and continuity of business services.
Professional profile

I am Sergio Milanese, a System Engineer and Solution Architect. I do not stop at system diagrams: I bring platforms into service, observe them, troubleshoot failures and improve their reliability and operability over time.
My background spans telecommunications, physical infrastructure, enterprise networking, Linux, virtualization, core services, cybersecurity and cloud platforms. This breadth lets me follow the real dependencies between connectivity, networks, identity, applications and workplaces instead of stopping at the boundary of one product.
Business ICT management
When a business service fails, the cause may sit anywhere along the chain. I therefore connect connectivity, networking, security, platforms, applications and workplaces in one technical view.
Carrier access, fiber, xDSL, satellite and radio.
LAN/WAN, switching, routing, Wi-Fi and VPN.
Firewalling, segmentation, access control and hardening.
Linux, virtualization, cloud, identity and core services.
Business software, databases, collaboration and integrations.
Endpoints, policies, onboarding, support and lifecycle.
The work includes technical governance, supplier coordination, inventory, patching, access management, support, root-cause analysis and change planning—not only the installation of individual products.
Core expertise
Technical depth supports better decisions: understanding dependencies, anticipating failures, protecting boundaries and making recovery genuinely executable.
Enterprise architecture, high availability, disaster recovery, segmentation and production-oriented design.
Debian, Ubuntu and CentOS environments; KVM and VMware platforms; systems integration and advanced troubleshooting.
LAN/WAN/VPN architecture, routing, switching, firewalling, micro-segmentation, secure access and network diagnostics.
Identity, productivity suites, business applications, endpoints, inventory, patching, support and supplier management.
ADSL2+, HDSL, SHDSL, VDSL, fiber, satellite, enterprise Wi-Fi, radio links and structured cabling.
Hybrid cloud, AWS, Microsoft 365, Google Workspace, DNS, mail, databases, monitoring and automation.
Connectivity expertise
Experience built through field installation, carrier circuits, enterprise networking and production operations. This helps distinguish an application issue from a physical, access or network limitation.
Provisioning, diagnostics and integration of access circuits for offices and distributed sites.
Experience with business-grade copper services and point-to-point connectivity.
Copper and fiber cabling, access and backbone links, patching, termination and fault isolation.
Enterprise Wi-Fi, radio/coaxial systems and satellite connectivity for remote or resilient access.
Problems, responsibility, outcomes
The experiences are presented in a concise and generalised form, focusing on the problems addressed, technical responsibilities and outcomes achieved. Names, organisations, infrastructure details, addressing, configurations and other confidential operational information remain excluded. These descriptions are not documentation of the original systems.
A production communications platform combining SIP, WebRTC, media relay, backend call control and multi-tenant routing.
Service continuity, codec and signaling interoperability, encrypted browser access, database resilience and low-impact troubleshooting.
Architecture, routing logic, high-availability design, observability, failure analysis and production-safe changes.
Redundant signaling and media nodes, backend pools, replicated data services and centralized traces. The result is an architecture with explicit failure domains, controlled routing and practical diagnostic paths.
Linux systems and platform services distributed across multiple functional networks and environments.
Different distributions, idempotent reruns, privileged automation, controlled remediation and monitoring independent from application databases.
Inventory model, baseline playbooks, hardened automation identities, safe conditional configuration and monitoring architecture.
Git-driven Ansible/AWX workflows combined with Zabbix and Grafana on dedicated data services, creating repeatable onboarding, consistent baselines and clearer operational visibility.
A cloud environment where direct outbound Internet access had to be reduced while Windows and Linux systems still required controlled connectivity.
Updates, package repositories, certificate automation, high availability, policy deployment, internal DNS and identity integration.
Proxy architecture, Windows/Linux policy, validation, failure testing and alignment with directory and network controls.
Redundant forward proxies, GPO/WinHTTP and APT integration, internal directory services and auditable access paths with fewer uncontrolled outbound dependencies.
Virtual workloads and application paths moving to cloud while selected dependencies remained on legacy infrastructure.
Incomplete inventories, IP continuity, L2/L3 feasibility, reverse-proxy routes, short maintenance windows and rollback requirements.
Dependency analysis, target architecture, migration boundaries, sequencing, validation criteria and rollback planning.
Segmented L3 designs, VPN and reverse-proxy service paths, redundant backends and staged cutovers that converted assumptions into explicit technical decisions and tests.
A business environment with mixed legacy and cloud services, multiple access technologies, office networks, user endpoints and external suppliers.
Operational continuity, user support, secure access, heterogeneous systems, lifecycle management and changes involving multiple providers.
Technical governance across connectivity, network security, identity, core services, management software, workplace policies, support and supplier coordination.
A joined-up operating model with clearer dependencies, repeatable onboarding and patching, documented access paths and a single technical view from carrier service to end user.
Public engineering work
The public profile brings together two historical OpenNebula integrations for ZFS and ZFS over iSCSI storage, published as technical references for the design and integration of virtualization, storage, and Linux systems.
View Sergio Milanese on GitHubInformed technology choices
Open source can provide transparency, interoperability and greater control over the evolution of infrastructure. It is not an automatic or cost-free choice: it requires design, expertise, updates, monitoring and operational accountability.
I consider open technologies when they enable systems that remain understandable, integrable and manageable over time, without mistaking the absence of a proprietary licence for the absence of cost or risk.
Understand the system, verify its components and retain technical governance.
Prefer protocols, formats and interfaces that support integration and portability.
Assess maturity, security, maintenance, available skills and project continuity.
Engineering principle
Open by design.Reliable by engineering.
Good infrastructure is not only powerful. It is understandable, observable, documented, recoverable and practical to operate.
Map technical and business dependencies before changing the architecture.
Treat degradation, failover and rollback as first-class design requirements.
Use versioned, reviewable workflows for standard configuration and validation.
A recovery procedure must be executable under pressure, not only correct on paper.
Production-first approach
Translate operational and business requirements into clear, secure and maintainable architectures, including failure modes and recovery paths.
Implement with observability, scalability, automation, documentation and operational simplicity in mind.
Troubleshoot, improve and maintain critical environments with measured, reversible and production-safe changes.
The website as an engineering project
The website at www.openmilanese.it is static, with no database, cookies, browser tracking or external dependencies. HAProxy and Apache separate transport from content; versioned assets, automated validation and backups make each release controllable and reversible.
Fewer exposed components and no public administration panel.
No cookies, browser analytics or resources loaded from third parties.
HTTPS at the frontend and explicit policies at the appropriate layer.
Version, checksums, backup, post-release tests and rollback capability.
Interactive laboratory
Infrastructure Lab turns reliability, observability, DNS, networking, deployments, capacity and diagnostics into a fictional system you can interact with. No account, cookies or transmitted results.
Contact
This profile is intended for businesses, recruiters, IT leaders and professionals interested in my experience, skills and approach to infrastructure, operational continuity and complex technical problems.
This website is intended as a professional profile and is not a catalogue or commercial offer of ICT services.