Modern operations, sized for organizations that run on volunteers and donations.
Most mission-driven teams rent their systems: donated software seats and free vendor tiers they don't own and can't leave. We help you move to infrastructure you own outright.
No invoice for nonprofits and volunteer-run orgs. Call when you need to, if you need to.
Four things we deliver into estates you own, because we practice what we publish. Every offering links to a public repo you can read today: three you can fork and run now, and the fourth is being built in the open, issues and all. Nothing here is a slide.
You'll own every piece. We'll show your people how to run it. Firing us is a runbook — a fork, not a migration off a service we run.
An anti-lock-in practice is only believable if walking away is trivial. So the boundary isn't a promise — it's the standing delivery model, true by construction.
Five systems run our own shop, and every one is free to take. Each is built so the parts specific to us swap out for yours. Where a system stands on someone else's platform, the Runs on column names it. The codenames are New England native plants.
Our AWS setup, written entirely as code: network, servers, database, web firewall, and encryption keys. Every change is proposed, reviewed, and applied automatically once it's approved, and nothing stores a long-lived password. It's what serves this site.
Turns a freshly installed Linux computer into a fully set-up work machine with one command. Running it again is always safe: it only fixes what's out of place. Five ready-made profiles cover different kinds of machines.
Shows what your systems are doing right now, on dashboards anyone can read. One small collector on each machine sends in the numbers and logs. Every dashboard is saved as code and published on approval, so nobody's hand edit gets lost or drifts. If it isn't in the repo, it doesn't exist.
Keeps a complete, searchable record of what happens on a network: every domain looked up, every connection, every encrypted session opened. Each source sends its records wherever suits it: our firewall's go to Grafana's free tier, searchable at $0 a month, and our AWS account's go to Axiom.
A small pool of AI coding assistants that work unattended on our own hardware. Drop a job in a shared folder, and a free worker picks it up, does the work on a fresh copy of the code, and proposes the change for review. It can't approve its own work; a person always decides. Today's workers run Claude Code, but any assistant could take the jobs.
Not everything is a template. Custom work — audits, migrations, incident response, hardening — sized to your constraints and delivered into your estate under the same pledge. Free for nonprofits and volunteer-run organizations; everyone else, ask. Never a subscription to something we run.
Find the NAT gateway eating the budget; the IAM role nobody owns; the bucket with forgotten logs. One-page report, no theatre.
Bare metal through cloud-native, and the platform shifts in between — moved without losing the rigor or a customer-visible outage.
Runbooks, alarms, and on-call rotations humans can live with. Service targets that reflect reality, not aspiration. Pager hygiene included.
Deploy pipelines with no stored passwords, every change reviewed before it applies, and signed builds — so a compromised pipeline can only reach what it was allowed to.
The full runbook is longer, drier, and in the repo. These are the six we'd bring into a room on day one.
The person who designs the system is the person who carries the pager for it. Otherwise the design is a suggestion, not a commitment.
Least-privilege isn't a checkbox — it's the default. If a compromised pipeline can reach production, the problem is the pipeline, not the compromise.
An incident handled by a sleepy engineer following the runbook is better than a hero who remembers. Write the doc. Update it when it lies.
You cannot operate what you cannot see. Logs, metrics, traces, and a single dashboard a human actually opens. No 'we'll add it later.'
Infrastructure changes are code review. OIDC, no long-lived credentials, signed artifacts. The pipeline is the contract.
A NAT gateway you forgot about is a security problem. A forgotten log bucket is a compliance problem. Run the audit monthly, not yearly.
I've kept production running around the clock since 1997: first in server rooms where every change had physical consequences, now in cloud systems defined entirely in code. These days I help organizations that run on donations run that same kind of reliable setup on infrastructure they own, and I do it in the open.
Moved to cloud-native work: infrastructure written as code, every change reviewed where the whole team can see it. The tools changed; the habits didn't. Rehearse the failure, write down the fix, make the next change boring. Lentago is where I practice those habits in the open, on an estate anyone can copy.
A much larger company bought us and put real money behind the platform. I ran disaster-recovery drills, cut recovery times, and made every component within reach redundant. Led the capacity buildout team, with a lot of vendor evaluation along the way. The job grew to cover internet routing, large email domains, DNS, CDNs, and cloud integrations.
Joined a small startup of fewer than 50 people in 2007 as its third infrastructure operator. Each instance of the platform was hardware we designed and racked ourselves: load balancers, storage, layers of network switching, one cabinet at first and later several. I made the buildouts repeatable and added redundancy wherever it would fit. Every hardware generation changed something, so I used configuration management and orchestration to keep those differences away from the support team.
Started as the overnight operator: data-center keys, orders to change the backup tapes, and escalations from support. I learned AIX and VMS from the career sysadmins I'd just woken for the third time that night, and never called anyone about the same thing twice. I earned the day shift by doing a full sysadmin's job on nights, trained my own replacement, and kept leading the night shift from days. By 2005 I was a principal operator who'd brought two new data centers from construction to production.
No invoice if you're a nonprofit, a volunteer-run org, or the one person keeping the lights on somewhere. If you know what you need, send the repo. If you don't, send the symptoms. Either way you'll hear back inside a day.