Field notes on network operations.
Engineering and operations writing from the team building Centipid - monitoring at scale, MikroTik, WireGuard, DDoS defense, and the realities of running ISP infrastructure.
Latest posts
SHOWING 6 OF 24Building a self-serve customer portal in weeks
What we shipped, what we cut, and the architecture decisions that let a small team launch a production portal fast.
Automating service activation with Centipid Access
From manual provisioning to one-click activation - the workflow that removed hours of repetitive ops from every new customer.
Scaling WireGuard to 20,000+ MikroTik peers
RPS/RFS tuning, multi-queue, SNAT over MASQUERADE, and the CGNAT port-randomization fix that stopped handshake collisions cold.
Surviving L7 HTTP floods: a DDoS playbook for ISPs
Cloudflare WAF rate limits, nginx real-IP, a shared-secret API header, and Fail2Ban - the layered defense that absorbed a Slayer-L7 botnet.
MikroTik config backups that actually save you
Hourly exports, versioned diffs, and a rollback discipline that turns a 3 a.m. 'who changed this?' into a 30-second restore.
Cutting truck rolls with remote diagnostics
Every avoided site visit is fuel, labor, and hours back. The diagnostic workflow that pushed our first-call resolution past 78%.