available for work UTC+3:30

Backend Systems. Network Architecture. Built to not break.

I'm YazdanKhodeVex. A backend developer & network architect who designs infrastructure that is reliable, observable, and secure. Golang-first, Linux-native, quietly obsessed with the systems most people never see.

PythonGolangLinuxNetworkingBack-end
01

about/me

The human behind the terminal.

Just a simple guy with an anti-social personality — who happens to love making systems work.

I architect and build the back-end plumbing that keeps products online at 3am: APIs, queues, databases, and the networks that stitch them together. I care about latency budgets, clean failure modes, and logs that actually tell you what happened.

When I'm not writing Go or wiring up a segmented network, I'm probably tuning a homelab, reading kernel changelogs, or optimizing something most people would call "already fast enough."

0+
years building backends
0+
systems & networks shipped
0%
obsession with uptime
currently
Golang services · homelab tinkering · learning one new protocol at a time
02

system/status

Live read on availability & focus.

availability
Open for freelance & contracts
operational
response time
~24h · email / DM
avg
focus
Distributed backends & network security
primary
timezone
Async-friendly · remote-first
UTC+offset
03

back-end

The services, pipes, and storage behind the screen.

API & Service Design

REST & gRPC services in Golang and Python. Idempotent endpoints, versioned contracts, sane rate limits, and auth that doesn't leak.

  • Go
  • Python
  • gRPC
  • REST

Data & Pipelines

Postgres done right, Redis for the hot path, message queues and workers that survive restarts. Migrations that don't ruin your weekend.

  • PostgreSQL
  • Redis
  • Kafka/NATS
  • SQL

Observability & Ops

Structured logs, metrics, and traces wired end-to-end. If it breaks at 3am, the dashboard tells you where before you finish your coffee.

  • Prometheus
  • Grafana
  • OTel
  • Docker
04

network/arch

Segmentation, routing, and defense at L2–L7.

Segmentation & VLANs

Trust zones, VLAN segmentation, and zero-trust assumptions. Keep the blast radius small so one compromise doesn't own the whole fleet.

  • VLAN
  • 802.1Q
  • Firewall
  • VPN

Routing & Services

Static & dynamic routing, reverse proxies, load balancing, and DNS that behaves. Traffic flows where it should and nowhere it shouldn't.

  • BGP/OSPF
  • HAProxy
  • DNS

Security & Hardening

Firewall rules, IDS/IPS, encrypted overlays, and the boring hardening checklists that actually stop incidents. Defense in depth, not in hopes.

  • iptables/nft
  • WireGuard
  • IDS/IPS
  • Hardening
05

projects/

Selected work — backends, networks, and the stuff in between.

01 backend

API Gateway Platform

A high-throughput Go gateway handling auth, routing, and rate limiting across dozens of upstream services. Sub-10ms overhead, structured tracing on every request.

GogRPCRedisOpenTelemetry
02 backend

Event Pipeline & Workers

Distributed workers consuming a message bus with exactly-once-ish semantics, dead-letter recovery, and back-pressure that protects the database instead of killing it.

PythonNATS/KafkaPostgresPrometheus
03 network

Segmented Network Fabric

A multi-VLAN, zero-trust homelab-to-edge fabric with encrypted overlays and per-zone firewalling. Traffic inspected, logged, and contained at every hop.

VLANWireGuardnftablesIDS/IPS
04 backend

Observability Stack

End-to-end metrics, logs, and traces wired into Grafana with alerting that respects on-call sanity. Built to answer "what broke, where, and why" in one glance.

PrometheusLokiGrafanaOTel
06

contact/

Got a backend that needs to scale, a network that needs hardening, or a system that keeps falling over at 3am? Let's talk.

Currently open to freelance work & contracts.