Senior-engineer-led Proxmox practice — build · migrate · optimise · manage · South Africa & Africa first

Design, build, migrate and run virtualization, backup and mail on the full Proxmox stack — in South Africa, for Africa.

A Proxmox practice is more than a VMware exit. We design, build, migrate, optimise and run the full stack — VE, Backup Server, Mail Gateway and Datacenter Manager — for teams escaping a Broadcom renewal (increases widely reported at 800–1500%, in USD and multiplied by the rand), building greenfield, or wanting a senior hand to optimise and run an existing estate. Every engagement is led by a senior engineer in your SAST/CAT timezone, with data kept in-country under POPIA and local clients billed in ZAR.

Send your host count and renewal deadline and the senior engineer who would do the work replies directly — a clear read and scoped options in your SAST/CAT hours. No sales rep.

  • 0+ yrsLinux & infrastructure
  • SAST/CATyour timezone · data in-country
  • 0+clusters built & migrated
  • 0open-source tooling on GitHub

Owner-operated by eXtremeSHOK — Adrian Kriel; SA engagements contracted through AKMPRT (Pty) Ltd.

Products

Proxmox software logo

The full Proxmox product line — one engineer, your whole stack

Consulting, migration and support for every Proxmox product — Virtual Environment, Backup Server, Mail Gateway and Datacenter Manager — architected and run by a senior engineer in your timezone, with your data kept in-country. Screenshots below are the real software; click any to enlarge.

VE

Proxmox Virtual Environment

What it isOpen-source server virtualization platform combining KVM virtual machines and LXC containers under one web-managed control plane, with built-in HA, software-defined storage (Ceph), SDN and live migration.

What we do for youWe architect, migrate to and support VE at scale — HA clustering, Ceph/ZFS storage, SDN, and VMware-exit migration — designed around your real workloads and African power/network failure domains.

  • Virtualization
  • HA
  • Ceph
  • SDN
  • Live migration
PBS

Proxmox Backup Server

What it isOpen-source enterprise backup solution for VMs, containers and physical hosts — incremental, deduplicated and client-side encrypted, with verification jobs and remote sync for ransomware-resilient DR.

What we do for youWe design PBS with deduplicated, encrypted backups, offsite sync that tolerates intermittent links, and rehearsed restores — so recovery is something you have tested, kept in-country/on-continent.

  • Backup
  • Deduplication
  • Encryption
  • Ransomware-resilient DR
  • Offsite sync
PMG

Proxmox Mail Gateway

What it isOpen-source email security platform that sits in front of your mail server — anti-spam and anti-virus filtering for inbound and outbound mail, clusterable for high availability, with before- and after-queue filtering.

What we do for youWe deploy and tune PMG for your mail flow, clustered for HA and self-hosted under your control — backed by authorship of clamav-unofficial-sigs (549★), so the signature side is not theory.

  • Email security
  • Anti-spam
  • Anti-virus
  • HA cluster
  • Self-hosted
PDM

Proxmox Datacenter Manager

What it isCentralized overview and management across multiple Proxmox VE clusters and standalone nodes — a single cockpit with cross-cluster and cross-node live migration, central monitoring and update oversight.

What we do for youWe stand up Datacenter Manager so you run every cluster across every site from one place, with cross-cluster live migration — turning multi-site sprawl into one fleet you can actually operate day to day.

  • Multi-cluster
  • Single cockpit
  • Cross-cluster live migration
  • Central oversight
  • Multi-site

Solutions

Your problem, the Proxmox product that solves it

Each engagement starts with a blunt problem and resolves it with a specific, named Proxmox product or capability — VE, PBS, PMG, PDM, Ceph/HCI, ZFS, HA, SDN — plus the African realities of POPIA, ZAR and load-shedding, backed by a real track record and a fixed-scope assessment that confirms the numbers against your estate before you commit.

Filter:
Problem

Broadcom turned your vSphere renewal into a budget emergency — perpetual licences gone, subscription costs up sharply (widely reported at 800–1500%), priced in USD and multiplied by a weak rand, and the quote lands before you have a plan.

Proxmox VE + Proxmox Backup Server

A wave-based VMware → Proxmox VE migration that keeps production running

Is this you? You hold a Broadcom renewal quote, run vSphere with a SAN or vSAN, and need to be off VMware before the deadline. We assess, design, pilot and migrate in waves with rollback at every step, so production never skips a beat. The hard cases are named and handled up front: Windows VirtIO drivers, database consistency, large and thin-provisioned volumes, change-block-tracking limits, and network and SDN cutover. A typical move recovers the bulk of licensing spend and completes in roughly 60–120 days — both confirmed in the fixed-scope assessment against your host count, edition and support choice, modelled in ZAR for local clients, never quoted blind.

Proxmox VE OVA/OVF import — the native VMware-exit path
  • Assess → design → pilot → migrate → optimize, with a written go/no-go before any cutover
  • Rollback at every wave; a pilot validates performance and failover before the fleet moves
  • Savings modelled on your numbers in the assessment — in rand for local clients — not a stock percentage

Drawn from 50+ clusters built and migrated, including production VMware-to-Proxmox moves.

Scope your migration
Proxmox VE + PBS + PMG (data sovereignty) Sovereign, in-country infrastructure your legal team can sign off Keep workloads, backups and mail under your own jurisdiction.
Problem

POPIA and data sovereignty are non-negotiable, but you're being pushed toward foreign hyperscalers whose pricing is USD-denominated and whose datacentres sit offshore — and legal cannot sign off on where your data lives.

Proxmox VE + PBS + PMG (data sovereignty)

Sovereign, in-country infrastructure your legal team can sign off

Is this you? You must keep workloads, backups and mail under your own jurisdiction. We keep your VMs (VE), your backups (PBS) and your mail (PMG) in-country or on-continent — in your own datacenter, colo or a local provider — reducing dependence on US/EU hyperscalers. Access is least-privilege and time-boxed, a POPIA-compliant DPA is signed as standard (not GDPR retrofitted), and the same design accounts for Nigeria's NDPA, Kenya's DPA and Ghana's Data Protection Act for pan-African clients. For fintech and government, on-prem Proxmox on your own hardware is the cleanest path to SARB/Reserve Bank and sector data-localisation requirements.

Proxmox Backup Server keeps backups in-country, under your jurisdiction
  • VMs, PBS backups and PMG mail kept in-country / on-continent — no per-core USD licence leaving the continent
  • POPIA-compliant DPA as standard; least-privilege, time-boxed access; MSA / NDA / PI cover
  • Pan-African coverage (NDPA, Kenya DPA, Ghana DPA) and SARB-aligned localisation for regulated workloads

Contracting under eXtremeSHOK with full as-built/audit documentation on every engagement.

Review my data sovereignty
Proxmox VE High Availability + PBS HA and DR engineered around real grid loss, not a lab Resilience that survives stage 4–6 load-shedding and intermittent connectivity.
Problem

Half the country has load-shedding. A 'self-healing cluster' is useless if the whole site goes dark at stage 6 — and your remote support can't reach a cluster on a flaky link.

Proxmox VE High Availability + PBS

HA and DR engineered around real grid loss, not a lab

Is this you? You need resilience that survives stage 4–6 load-shedding and intermittent connectivity. We design HA quorum and watchdog fencing around your real failure domains including grid loss, advise on UPS/generator runtime, place dual-site quorum and witnesses correctly, and set up PBS offsite sync that tolerates intermittent links. Remote access and runbooks are built for low-bandwidth, high-latency conditions. Load-shedding awareness is local context a foreign hyperscaler or an overseas consultant simply does not have.

  • HA quorum, fencing and dual-site witness placement designed around grid-loss failure domains
  • UPS/generator runtime guidance and power-loss failover drills before you depend on it
  • PBS offsite sync and low-bandwidth remote access tolerant of intermittent African links

50+ clusters built with HA across hosting and enterprise workloads.

Design my resilient cluster
Hyper-converged infrastructure (Proxmox VE + Ceph) Collapse the silos onto a single hyper-converged Proxmox VE platform Retire the SAN refresh or vSAN renewal instead of re-buying the array.
Problem

Your storage and compute live in separate SAN/NAS silos — expensive arrays, a hardware refresh looming, hardware import lead times, and one more proprietary vendor to renew in USD.

Hyper-converged infrastructure (Proxmox VE + Ceph)

Collapse the silos onto a single hyper-converged Proxmox VE platform

Is this you? You face a SAN refresh or vSAN renewal and want to retire the array, not re-buy it. We consolidate compute, storage and networking onto commodity nodes as one hyper-converged appliance — no separate SAN, no per-array licence, no single point of failure. Self-healing Ceph scales out on the hardware you already buy, and the whole stack is standard open source with no vendor lock-in. Add nodes to grow; lose a node and the cluster keeps serving.

  • One platform, one control plane — compute, storage and networking on commodity nodes
  • Self-healing, scale-out Ceph with no single point of failure
  • Standard Ceph and Proxmox VE — no proprietary layer, no lock-in, no USD per-array licence

50+ Proxmox clusters designed, built and migrated, with production Ceph and ZFS operated at hosting scale.

Design my HCI cluster
Proxmox Datacenter Manager (PDM) One cockpit across every cluster — with cross-cluster live migration Run two or more clusters or sites with no central view today.
Problem

You run more than one Proxmox cluster across sites, and there is no single place to see them — every datacenter is its own island, every check is a separate login, and moving a guest between sites is a manual chore.

Proxmox Datacenter Manager (PDM)

One cockpit across every cluster — with cross-cluster live migration

Is this you? You run two or more clusters, or several sites, and have no central view. We stand up Proxmox Datacenter Manager so you manage multiple clusters and remote nodes centrally — a single overview of your whole estate, cross-cluster and cross-node live migration, central monitoring and update oversight. Multi-site sprawl becomes one fleet you can actually run day to day, which is exactly what a distributed African estate needs.

Proxmox Datacenter Manager — every cluster, one cockpit
  • Central overview and remote-node management across clusters and sites
  • Cross-cluster and cross-node live migration — move guests between sites, not just within one
  • Operational runbooks so day-2 ops scale with the fleet

Multi-cluster operations across a 50+ cluster track record.

Centralise my clusters
ZFS Storage that detects and heals its own errors Run databases or latency-sensitive workloads that cannot afford silent data loss.
Problem

Storage that silently corrupts or loses data is the nightmare under every virtualization stack — and bit-rot does not announce itself until a restore fails.

ZFS

Storage that detects and heals its own errors

Is this you? You run databases or latency-sensitive workloads and cannot afford silent data loss. We architect ZFS the way it is meant to run: end-to-end checksumming, scheduled scrubs that catch bit-rot, snapshots, and node-to-node replication. Pool layout, ARC/L2ARC and recordsize are tuned for your workload — ZFS tuning is a signature strength, refined across 50+ clusters and at hosting-scale density. Your data integrity stops being a matter of faith.

  • End-to-end checksums and scheduled scrubs catch corruption before it spreads
  • Snapshots and node-to-node replication for fast local recovery
  • Pool, ARC/L2ARC and recordsize tuning matched to your real workload

ZFS architected and tuned across 50+ Proxmox clusters and production estates at hosting-scale density.

Engineer my ZFS
Proxmox VE High Availability Multi-node HA that fails over automatically, proven before you depend on it Workloads that cannot tolerate an unplanned node outage at 3am.
Problem

When a node dies at 3am, you need the cluster to stay up on its own — not a pager you hope someone answers in another hemisphere.

Proxmox VE High Availability

Multi-node HA that fails over automatically, proven before you depend on it

Is this you? You have workloads that cannot tolerate an unplanned node outage. We build multi-node HA clusters with proper quorum, watchdog fencing and automatic failover, then validate them with real failover drills before you rely on them. Good architecture means most overnight events self-heal without a human — and any escalation lands with a named contact in your SAST/CAT timezone, not someone waking up across the world.

Proxmox VE cluster summary — quorum and node health at a glance
  • Quorum, watchdog fencing and automatic failover designed for your failure domains
  • Validated with real failover drills, not assumed from a datasheet
  • Resilience by design so most 3am events self-heal without intervention

50+ clusters built with HA across hosting and enterprise workloads.

Design my HA cluster
Proxmox VE SDN Software-defined networking and segmentation, built into the platform Need tenant isolation, micro-segmentation, or a clean SDN cutover during migration.
Problem

Your virtualization layer stops at flat networking — VLAN sprawl, manual firewall rules, and no clean way to segment tenants or workloads across the cluster.

Proxmox VE SDN

Software-defined networking and segmentation, built into the platform

Is this you? You need tenant isolation, micro-segmentation, or a clean SDN cutover during migration. We design and deploy integrated SDN — zones, VNets and VLAN/VXLAN overlays — with the built-in cluster firewall for least-privilege segmentation. Networking becomes part of the same control plane as compute and storage, planned for your tenancy and security model and carried cleanly through migration cutover.

  • SDN zones, VNets and VLAN/VXLAN overlays managed in the Proxmox control plane
  • Built-in distributed firewall for tenant and workload segmentation
  • Network cutover planned and rehearsed as part of migration, not an afterthought

SDN and firewall design across hosting-scale, multi-tenant clusters.

Plan my network
Proxmox Backup Server (PBS) Incremental, deduplicated, encrypted backups you have actually restored Your backup bill is climbing and you have never run a full restore drill.
Problem

Your backups are expensive, slow, and — worst of all — you have never actually rehearsed a restore, and you don't know if a copy survives a ransomware hit.

Proxmox Backup Server (PBS)

Incremental, deduplicated, encrypted backups you have actually restored

Is this you? Your backup bill is climbing and you have never run a full restore drill. We architect Proxmox Backup Server with incremental, deduplicated, client-side-encrypted backups, offsite sync, verification jobs and rehearsed recovery — so a restore is something you have tested, not something you hope works, and kept in-country. Legacy backup licence cost and restore risk both go away, and your team gets a DR runbook it can actually follow.

Proxmox Backup Server — snapshot-level restore points per guest
  • Incremental, deduplicated, encrypted backups with verification and offsite synchronisation
  • Rehearsed, tested restores — recovery you have proven, not assumed
  • A DR runbook your team can follow without the original consultant

PBS architecture and tested restores across the cluster track record.

Architect my backups
Proxmox Mail Gateway (PMG) A self-hosted mail gateway you control, clustered for availability Want off a per-seat mail-security SaaS or an end-of-life appliance.
Problem

Your inbound and outbound mail filtering is a tangle of legacy appliances or a per-seat SaaS bill — priced in USD — that keeps growing.

Proxmox Mail Gateway (PMG)

A self-hosted mail gateway you control, clustered for availability

Is this you? You want off a per-seat mail-security SaaS or an end-of-life appliance. We deploy and tune Proxmox Mail Gateway for inbound and outbound filtering, clustered for high availability — anti-spam and anti-virus you run, own and keep in-country, sized for your volume. Author of clamav-unofficial-sigs (549★), so the signature side is not theory.

Proxmox Mail Gateway — inbound/outbound filtering you own and run
  • Inbound and outbound filtering deployed and tuned to your mail flow
  • Clustered for high availability with no single point of failure
  • Self-hosted, owned and in-country — predictable ZAR cost, full control

Author of clamav-unofficial-sigs (549★), run by mail teams worldwide.

Deploy my mail gateway

Day 2 · operate & optimise

Once you're on Proxmox, we run it

The build is the start — these engagements keep a Proxmox estate healthy, current, secure and right-sized after go-live. The operate-and-maintain layer most resellers never offer.

Prometheus + Grafana for Proxmox VE & PBS Monitoring that warns you before your users do Nothing watching the cluster between logins, and no one paged when it matters.
Problem

The first sign of trouble is a user complaint — a full ZFS pool, a failing disk, a backup that quietly stopped verifying — because nothing was watching the cluster between logins, and no one was paged when it mattered.

Prometheus + Grafana for Proxmox VE & PBS

Monitoring that warns you before your users do

This is the telemetry-and-paging layer a central cockpit and your backups both assume but never deliver. We expose Proxmox VE metrics to Prometheus via the prometheus-pve-exporter (or push VE's built-in metric server to InfluxDB/Graphite), build the Grafana boards, then add Alertmanager routing tuned for load-shedding and intermittent links — so an alert during grid loss reaches a named contact in your SAST/CAT window, not a dashboard no one is looking at.

Proxmox VE node metrics — the source we export into Prometheus and Grafana
  • Node, VM, cluster, HA, ZFS/SMART and Ceph health on Grafana boards, with real metric history and thresholds
  • PBS verify and garbage-collection job status monitored — so a silently failing backup raises an alert, not a surprise
  • Alertmanager routing to email, Slack or SMS, tuned for load-shedding and flaky links, escalating to a named contact

Real monitoring stood up across 50+ Proxmox clusters, built on the standardised-node discipline behind xshok-proxmox (933★).

Set up my monitoring
Ansible + Terraform/OpenTofu for Proxmox VE Repeatable, version-controlled Proxmox builds — codified, not clicked Every node is hand-built in the web UI, so no two are alike and hardening drifts.
Problem

Every node is hand-built in the web UI, so no two are quite alike, hardening drifts, and rebuilding a cluster after a failure or adding a site means days of click-by-click work nobody has written down.

Ansible + Terraform/OpenTofu for Proxmox VE

Repeatable, version-controlled Proxmox builds — codified, not clicked

Build automation is the discipline beneath every other engagement, and it is the one we literally wrote the tooling for. We codify node post-install, users and ACLs, storage, firewall and SDN with Ansible (community.general / proxmoxer), provision VMs and LXC through Terraform/OpenTofu on the bpg/proxmox provider, and template guests with cloud-init — all Git-tracked, peer-reviewable and re-runnable. The honest caveat: IaC is an investment that pays back across rebuilds and new sites, so a small two-node shop may not need the full pipeline.

  • Ansible roles for post-install, hardening, users/ACLs, storage, firewall and SDN — the xshok-proxmox flow codified into a pipeline
  • Terraform/OpenTofu (bpg/proxmox) plus cloud-init templates for repeatable VM/LXC provisioning
  • Your whole estate version-controlled in Git — reviewable changes, rollback, and a documented rebuild path

Author of xshok-proxmox (933★) — the secure, repeatable PVE post-install and hardening toolkit itself.

Codify my Proxmox builds
Proxmox VE templates · cloud-init · image pipelines Golden VM templates and cloud-init — every machine built the same, in minutes VMs hand-built from an ISO are slow, inconsistent and drift from your baseline.
Problem

Every new VM is hand-built from an ISO — slow, inconsistent, and drifting from your security baseline. Standing up a fleet, a dev/test estate or a fresh site means days of repetitive clicking nobody has written down.

Proxmox VE templates · cloud-init · image pipelines

Golden VM templates and cloud-init — every machine built the same, in minutes

We build hardened, ready-to-clone Proxmox VE templates — Debian, Ubuntu, Rocky/Alma and Windows — with cloud-init wired in, so a new VM comes up fully configured (hostname, users, SSH keys, packages, network and your security baseline) in minutes, not hours. Golden images are version-controlled and rebuilt on a schedule so they never go stale, and the same cloud-init snippets feed your Terraform/Ansible provisioning — one image library serving dev, test and production identically.

  • Hardened golden templates per OS (Debian, Ubuntu, Rocky/Alma, Windows), cloud-init enabled, rebuilt on a cadence so they never drift
  • cloud-init / Proxmox snippets for hostname, users, SSH keys, packages, network and your baseline — clone to a running VM in minutes
  • A version-controlled image library that feeds Terraform/Ansible, so dev, test and production build from one source

Built on the same secure, repeatable-build discipline as xshok-proxmox (933★).

Build my image pipeline
Proxmox VE clustering · PDM cross-cluster migration · ZFS / Ceph / PBS Reshape your Proxmox estate without a maintenance-window outage Clusters to merge or split, ageing hardware, or guests moving between datacenters.
Problem

Your Proxmox estate has outgrown its original shape — clusters that should be merged, one that should be split, ageing hardware due for refresh, or guests that need to move between datacenters — and every option you can see involves a maintenance window and crossed fingers.

Proxmox VE clustering · PDM cross-cluster migration · ZFS / Ceph / PBS

Reshape your Proxmox estate without a maintenance-window outage

Your infrastructure is already Proxmox — this is estate surgery, not a platform exit. We consolidate or split clusters, convert standalone nodes into a quorate cluster (pvecm), and move running guests between sites with PDM cross-cluster and cross-node live migration. Storage moves come with it — ZFS send/recv, Ceph, PBS datastore relocation and live storage migration — and corosync/quorum is re-architected so the new topology stays safe. Cutover is staged and reversible; the few changes that genuinely need a window are named up front, not discovered mid-move.

Proxmox VE bulk actions — moving guests across the estate during a cluster reshape
  • Cluster consolidation, splitting and standalone-to-clustered conversion (pvecm), with corosync/quorum re-architected for the new topology
  • Cross-datacenter guest moves via PDM cross-cluster/cross-node live migration, plus ZFS send/recv, Ceph and PBS datastore relocation
  • Hardware-refresh and topology-change rebuilds run in reversible waves, with a written go/no-go and as-built docs at handover

From 50+ Proxmox clusters designed, built and migrated — cluster lifecycle work across hosting and enterprise estates, not only VMware exits.

Plan my cluster move
Proxmox VE, PBS, PMG & Ceph release upgrades Stay current across Proxmox major releases without a forklift rebuild Stuck on an ageing Proxmox or Debian release nobody wants to risk upgrading.
Problem

You're stuck on an ageing Proxmox or Debian release because nobody wants to risk the upgrade — the EOL clock is ticking, security patches have dried up, and a botched in-place upgrade across a live cluster is the kind of outage that makes the news.

Proxmox VE, PBS, PMG & Ceph release upgrades

Stay current across Proxmox major releases without a forklift rebuild

Crossing a major-release boundary in place — pinning the repos, ordering corosync, Ceph, kernel and Debian-base steps, and keeping HA quorum up the whole way — is a different discipline from building a cluster, and it's where we live. We run the readiness checks (pve8to9 / pve7to8 style), upgrade node-by-node so guests keep running, and prove a rollback path before touching production. Scope and sequencing are confirmed against your actual versions in the assessment first.

  • Readiness audit and a written, sequenced upgrade runbook — VE, PBS, PMG, Ceph and the Debian base, in the right order
  • Rolling node-by-node upgrades that preserve HA quorum, plus repo hygiene (no-subscription vs enterprise) sorted out
  • A tested rollback path and a go/no-go gate before any production node is touched

25+ years in production Linux across 50+ Proxmox clusters — many Debian, Proxmox and Ceph upgrade cycles survived live; xshok-proxmox (933★) encodes the repo and post-install hygiene clean upgrades depend on.

Plan my upgrade
Proxmox VE & PMG hardening (host, API, identity) An auditable Proxmox hardening baseline your auditors can actually read Hosts went in fast at defaults, and now an auditor wants a baseline you lack.
Problem

Your Proxmox hosts went in fast and stayed at defaults — shared root logins, a flat API, no enforced 2FA, no audit trail — and now a POPIA assessor, a bank's vendor questionnaire or a cyber-insurer wants to see a documented security baseline you simply don't have.

Proxmox VE & PMG hardening (host, API, identity)

An auditable Proxmox hardening baseline your auditors can actually read

This is the host, API and identity layer — not where data lives or how the network is segmented. We harden the PVE host and API, enforce role-based ACLs and least-privilege, mandatory two-factor auth, TLS/certificate management, kernel and network hardening, SSH lockdown, fail2ban and audit logging, then tighten PMG's mail-security posture. The xshok-proxmox flow is applied and documented as a repeatable, CIS-style baseline. It is a defensible starting point aligned to recognised controls, not a certified compliance stamp.

  • Hardened PVE host & API: least-privilege ACLs, enforced 2FA, TLS/cert management, kernel/network hardening, SSH lockdown, fail2ban
  • Audit logging and a written, versioned baseline document — the evidence questionnaires and assessors ask for
  • The xshok-proxmox hardening flow applied repeatably across the estate, plus PMG mail-security posture review

Built on xshok-proxmox (933★), a secure, repeatable PVE post-install and hardening toolkit, and clamav-unofficial-sigs (549★) on the mail side — owned security tooling, not slideware.

Harden my Proxmox estate
Managed Proxmox operations (VE · PBS · Ceph/ZFS) A Proxmox operations retainer that keeps the cluster healthy after go-live The cluster is built, but now it has to be run — patches drift, alerts fire at 2am.
Problem

The cluster is built and the migration is done — but now it has to be run. Patches drift, alerts fire at 2am, backups need verifying, and the engineer who knows your estate is across an ocean and a timezone.

Managed Proxmox operations (VE · PBS · Ceph/ZFS)

A Proxmox operations retainer that keeps the cluster healthy after go-live

This is the operate-and-maintain wrapper that follows the build — not another project. Building on the monitoring and config-management foundations we put in, we run day-2: patch and upgrade planning, alert response, PBS restore rehearsals and verify-job oversight, Ceph and ZFS health, and capacity reviews before you run out of room. SLA tiers and change windows are set in SAST/CAT hours, with a named senior engineer on the other end.

  • Managed patching and version upgrades on a planned, tested cadence — with change control, never a surprise reboot
  • Alert-response SLA tiers in SAST/CAT working hours; PBS restore rehearsals and verify-job oversight on schedule
  • Ongoing Ceph/ZFS health management and quarterly capacity reviews so growth is planned, not firefought

Day-2 operations is the day job: production Proxmox estates run continuously at hosting scale, across a 50+ cluster track record — by the same senior engineer who holds your retainer.

Set up my operations retainer
Proxmox VE capacity & performance engineering Know exactly what your Proxmox estate can carry — and tune it before it bites Over-buying nodes to feel safe, or finding out you are short when IO stalls.
Problem

You are guessing at headroom — over-buying nodes to feel safe, or finding out you are short only when IO stalls and tenants complain. With kit imported at the rand exchange rate, both the waste and the firefight are expensive.

Proxmox VE capacity & performance engineering

Know exactly what your Proxmox estate can carry — and tune it before it bites

You're scaling on a hunch instead of evidence. This is whole-estate sizing and cross-stack diagnosis — compute, storage and network together — not a single-layer build. We profile your real workloads, benchmark storage with fio, tune Ceph and ZFS, apply NUMA and CPU pinning where it pays, and model growth so node-adds are planned, not panicked. An advisory engagement; findings and the tuning plan are confirmed against your measured numbers.

  • Workload profiling and right-sizing with fio IO benchmarks and network throughput planning
  • Ceph and ZFS tuning — recordsize, ARC/L2ARC, OSD/PG layout — plus NUMA and CPU pinning
  • Growth model and node-add roadmap so you scale on evidence, not a hunch

Direct evidence: 50+ Proxmox clusters sized and tuned across production and hosting-scale estates — real capacity work, not a spreadsheet.

Right-size my estate

The 2026 migration wave

VMware → Proxmox migration, run from your timezone

Broadcom's licensing changes pushed many vSphere renewals up sharply — increases widely reported at 800–1500%, USD-denominated and magnified by the rand. Moving the right workloads to Proxmox VE typically recovers the bulk of licensing spend — confirmed in a fixed-scope assessment against your host count, edition and support choice — while keeping HA, live migration, shared storage and tested backups. The move is planned and run end to end in your SAST/CAT business hours so production never skips a beat, with rollback at every wave and your data kept in-country throughout.

01

Assess

Inventory vSphere, map dependencies, size the target cluster, and model savings and risk on your numbers — in ZAR for local clients. This is the fixed-price VMware-Exit Assessment (from R24,500), credited in full against the migration: you get a written go/no-go and a my-numbers savings model before any commitment, never a quote in the blind.

02

Design

HA cluster topology, Ceph or ZFS storage, SDN and firewall, backup and DR with Proxmox Backup Server, and a cutover runbook that names the hard cases — Windows VirtIO, DB consistency, large and thin-provisioned volumes, CBT limits. Power and grid-loss failure domains are designed in, not assumed.

03

Pilot

Stand up the target, migrate a representative slice including a Windows guest and a database, and validate performance and failover — including a power-loss drill — before committing the fleet.

04

Migrate

Wave-based VM migration with rollback at every step and tested restores along the way. Most engagements complete in roughly 60–120 days, confirmed in the assessment, with data kept in-country/on-continent throughout.

05

Optimize

Tune ZFS and Ceph, harden, automate the post-build, set up Datacenter Manager for multi-site oversight, hand over runbooks and as-built docs — and train your team to run it themselves.

Scope your migration Try the indicative estimator ↓ Fixed-scope assessment available — know the cost and savings before you commit.

Estimator

Indicative engagement estimator — a starting band, not a quote

Drag the slider and pick a delivery model to see an indicative day-rate / retainer band for the scale you are running. This is a self-qualification tool only: it uses the same transparent bands published under Pricing below, makes no savings or payback promises, and every figure is confirmed in the fixed-scope assessment against your real estate before any commitment. Local clients are modelled in ZAR; international/remote in USD/EUR/GBP at engagement.

Indicative band

≈ ZAR 24k–36k / day

Senior architecture, design and hands-on build across VE, PBS, PMG and PDM.

Indicative · confirmed in the fixed-scope assessment. Not a quote, not a savings or payback promise; final pricing depends on scope, scale, SLA, currency and location.

Get an exact, scoped quote

Training

Workshops & courses — across the whole Proxmox stack

Practical, production-grade Proxmox training across VE, PBS, PMG and PDM — live virtual by default, or a private cohort for your team in your timezone (on-site by arrangement, travel-costed). Delivered by an engineer who runs these systems daily, not a slide-reader. Custom workshops are available now; the official curriculum is partner-track, becoming available once Authorized Training Partner status is granted.

Custom workshops Available now

  • Proxmox VE in production — deploy & manage
  • HA clustering & Ceph deep-dive
  • ZFS for Proxmox — design & tuning
  • Hyper-converged infrastructure & multi-cluster management with PDM (incl. cross-cluster live migration)
  • PBS backup & disaster-recovery, including restore drills
  • PMG mail security — anti-spam/anti-virus, clustering & tuning
  • Resilient HA for load-shedding — quorum, fencing & witness placement
  • VMware-migration bootcamp — including Windows, GPU & DB workloads
  • Hardening & automation with xshok-proxmox

1–4 day intensives · certificate of attendance · live virtual or private cohort in your SAST/CAT timezone (on-site by arrangement, travel-costed).

Official curriculum Partner-track

I'm pursuing Authorized Proxmox Training Partner status to deliver the official instructor-led courses and certificates:

  • Proxmox VE Deployment & Management (14h) — partner-track
  • Proxmox VE Clustering & Shared Storage / Ceph (14h) — partner-track
  • The combined official bundle — partner-track, available once authorization is granted

Official courses and certificates become available once partner authorization is granted; custom workshops cover the same ground today across every product.

Why me

Proof, not promises

Most Proxmox consulting is a reseller bolt-on. This is a senior infrastructure engineer who has personally built and run the full stack at production scale for clients — including a 43-node ZFS Proxmox VE fleet (261 VMs, ~20,700 hosting accounts) delivered for a European hosting provider — and open-sourced the tooling thousands of others now use. Every number below is verifiable and attributable. International client work stays confidential — under NDA or client confidentiality, engagement depending; named South African references are provided on request as the local pipeline builds, and no client logo is claimed that does not exist.

0+

Proxmox clusters designed, built, migrated and run — across hosting and enterprise workloads, including production VMware-to-Proxmox exits.

0+ yrs

senior production Linux, virtualization, storage and networking — delivered in your SAST/CAT hours, in-country under POPIA, ZAR-billed and load-shedding-aware.

0

on my own open-source infrastructure tooling — led by xshok-proxmox (933★) and clamav-unofficial-sigs (549★), used by operators worldwide.

0 products

the full Proxmox stack — Virtual Environment, Backup Server, Mail Gateway and Datacenter Manager — engineered end to end: build · migrate · optimise · manage.

0-node fleet

a production ZFS Proxmox VE platform — 261 VMs and roughly 20,700 hosting accounts — designed, built and run single-handed as lead engineer for a European hosting provider. Client-delivery scale, not a slide.

Put this track record on your migration

Pricing

Transparent pricing — bands, not a phone call

Most rivals hide their rates behind a call. Here are indicative bands so you can self-qualify; exact quotes are tailored to scope once you send your requirements. South African and African clients are billed and invoiced locally in ZAR (local VAT where applicable); international and remote clients in USD/EUR/GBP. Anchor the value in rand: a typical 10-host vSphere renewal now runs roughly R800k–R1.6m+/yr (≈ USD 45k–90k+) — recovering the bulk of that pays for the work several times over, and removes the USD-times-rand multiplier from every future renewal.

Project & advisory

from R24,000 / day · ≈ USD 1,400 · indicative

  • Architecture, design & reviews across VE, PBS, PMG and PDM
  • Hands-on build & cluster bring-up
  • Billed per day or as a fixed-scope package
  • Fixed-scope migration priced from your assessment — no quote in the blind
Request a quote

Support retainer

Flat monthly tiers · from R12,000/mo · indicative

  • Starter — single cluster, business-hours SLA · from R12,000/mo
  • Growth — 4–10 nodes, faster SLA, pooled hours · R24,000–38,000/mo
  • Fleet — 10+ nodes, priority SLA & named after-hours · from R48,000/mo
  • A flat fee sized to your estate — not per server; annual prepay discount
Discuss a retainer

Training

from R12,000 / seat · private from R26,000/day · indicative

  • Public / small cohort — from R12,000 per seat·day (min 4 seats)
  • Private whole-class — from R26,000/day, any product (on-site travel-costed)
  • 4-day intensive ≈ R44,000/seat
  • Custom workshops now; official courses once partner-authorized
Book training

Senior-specialist rates: on par on scope with the EU Proxmox specialists, typically 15–30% below them, and a clear step above local generalist day-rates. Indicative bands, not a fixed quote; ZAR figures use an indicative ZAR/USD rate and are confirmed at engagement. Final pricing depends on scope, scale, SLA, currency and location. Production Proxmox enterprise subscriptions are procured direct from Proxmox or an authorized reseller; what this practice bills is senior architecture, migration execution and an independent support retainer on top.

About

An owner-operated practice — run by the engineer you would actually hire

I am Adrian Kriel (eXtremeSHOK), a senior infrastructure and platform engineer with more than 25 years building and running Linux at scale, based in South Africa and working in your SAST/CAT business hours. As an independent contractor I have worked for companies across Europe and beyond — hosting providers and enterprises alike — designing, building and migrating 50+ Proxmox clusters, including production VMware-to-Proxmox exits — and I run the full lifecycle: build, migrate, optimise and manage. For one European hosting provider I was engaged as Head of Infrastructure (on contract) to design, build and run its production estate single-handed — a 43-node ZFS Proxmox VE fleet, 261 VMs and roughly 20,700 hosting accounts, architected, deployed and operated by me. That is client delivery at hosting density, not a slide.

I am also the author of widely-used open-source infrastructure tooling. xshok-proxmox (933★) ships secure, repeatable Proxmox VE post-install builds to operators worldwide, and clamav-unofficial-sigs (549★) is run by mail teams everywhere — part of 1,841★ across all my open-source projects. When you engage this practice you get that depth directly: the principal engineer does the architecture, the build and the handover. No account managers, no junior hand-offs, no reseller reading a datasheet.

I understand the African operating reality, not a copy-pasted European offering: POPIA and pan-African data-protection obligations, ZAR billing and forex exposure, load-shedding and grid resilience, bandwidth costs and hardware import lead times. Delivery is remote-first in your SAST/CAT business hours — the same timezone, real-time overlap for scoping, cutover and day-2. On-site visits are available across South Africa and the rest of Africa by arrangement (travel-costed) when a project genuinely needs hands at the rack.

How we contract: South African engagements are contracted and invoiced through AKMPRT (Pty) Ltd — the registered South African company behind this eXtremeSHOK practice (reg 2019/206169/07, VAT 4490293869, established 2019) — billed in ZAR with local VAT; international engagements contract under eXtremeSHOK (Adrian Jon Kriel). Either way I sign an MSA, NDA and a POPIA-compliant DPA, carry professional indemnity cover (certificate on request), and work to least-privilege, time-boxed access into your estate. Every engagement ends with you owning the as-built docs, runbooks and automation — so your team, or any competent engineer, can run it without me. You move off one proprietary vendor without becoming locked into one consultant.

Roadmap to Authorized Partner. This practice is pursuing official Proxmox Reseller and Training Partner authorization. Until that is granted, engagements are delivered as an owner-operated consultancy, production subscriptions are procured direct from Proxmox or an authorized reseller, and official courses and certificates are clearly marked partner-track.

This is an owner-operated, senior-engineer-led practice — independent of, and not affiliated with, Proxmox Server Solutions GmbH.

Scope your Proxmox project

FAQ

Straight answers to the hard questions

The questions a CIO, a procurement lead and a security team actually ask — answered up front, so you can hand this page to your stakeholders without a call.

Are you based in South Africa, and how do you deliver — remote or on-site?

The practice is based in South Africa and works in your SAST/CAT business hours, so scoping, cutover and day-2 support happen in real-time overlap — not from another hemisphere. Delivery is remote-first: most architecture, migration and support work is done remotely, which keeps it fast and cost-effective. On-site visits — anywhere in South Africa or the rest of Africa — are available by arrangement and travel-costed for the moments a project genuinely needs hands at the rack. Evidence is in the work: 50+ Proxmox clusters designed, built and migrated for clients (including production VMware exits), a 43-node ZFS Proxmox VE fleet built and run for a European hosting provider, and 25+ years running Linux infrastructure. International client engagements stay confidential — under NDA or client confidentiality, engagement depending; named South African references are provided on request as the local pipeline builds. No African client logos are claimed that do not exist.

Where will my data and my backups physically live — and are you POPIA-literate, not just GDPR?

Your VMs, your PBS backups and your PMG mail stay in-country or on-continent — in your own datacenter, your colo, or a local provider — so you reduce dependence on US/EU hyperscalers and keep data under your jurisdiction. A POPIA-compliant DPA is signed as standard (not GDPR retrofitted), with least-privilege, time-boxed access. For pan-African clients the same design accounts for Nigeria's NDPA, Kenya's DPA and Ghana's Data Protection Act. Proxmox on your own hardware is itself the sovereignty play: no per-core USD licence leaves the continent.

Can I be billed in ZAR with a local invoice, instead of taking on more forex exposure?

Yes. South African and African clients are billed and invoiced locally in ZAR (with local VAT where applicable) for predictable budgeting and no surprise FX exposure; international and remote clients are billed in USD/EUR/GBP. The savings case is made in rand too: Broadcom's increase is USD-denominated and multiplied by a weak ZAR, so moving to Proxmox — which carries no per-core USD licence — removes that currency-risk multiplier. The exact rand saving is confirmed in the fixed-scope assessment against your estate.

Half the country has load-shedding. How does your HA story or your remote support survive stage 4–6 outages and flaky links?

Resilience is designed around real African failure domains, including grid loss — not assumed. That means HA quorum and watchdog fencing planned around your actual power and network topology, UPS/generator runtime guidance, dual-site quorum with correct witness placement, PBS offsite sync that tolerates intermittent links, and remote access plus runbooks built for low-bandwidth, high-latency conditions. Load-shedding awareness is local context a foreign hyperscaler or an overseas consultant simply does not carry.

If I'm African-based but not in South Africa — Kenya, Nigeria, Ghana — does any of this apply? And are you dropping international clients?

It applies. The geography is layered: South Africa first; African-based companies across the continent second (shared timezone band, on-continent data-residency options, remote-first with on-site by arrangement); and international/remote worldwide retained as a clear secondary offering. Existing and overseas clients are not dropped — remote delivery into EU, UK and US continues exactly as before.

For fintech or government, can you meet our regulator's data-localisation and sovereignty requirements on Proxmox?

Regulated workloads are addressed directly: in-country processing and backup, auditable least-privilege access, MSA/NDA/POPIA-DPA, professional indemnity cover, and full as-built/audit documentation. On-prem or sovereign-cloud Proxmox on your own hardware keeps data under your institution's own control and jurisdiction — the cleanest path to SARB/Reserve Bank guidance and sector data-residency obligations, versus a foreign hyperscaler whose pricing and processing sit offshore.

Do you deliver the whole Proxmox stack — VE, Backup Server, Mail Gateway and Datacenter Manager — or are you really just a VMware-migration shop?

The full product line, as equal peers. Virtual Environment for virtualization, HA, Ceph and SDN; Backup Server for deduplicated, encrypted, ransomware-resilient backup and DR; Mail Gateway for anti-spam/anti-virus email security; and Datacenter Manager to run every cluster across every site — including cross-cluster live migration — from one cockpit. Backed by real full-stack deployments (VE, PBS, PMG in production) and authorship of clamav-unofficial-sigs (549★), so the mail-security side is not theory.

It is one person. For a 60–120 day migration or a 3am P1 in my timezone, isn't that an unacceptable single point of failure?

Continuity is engineered in. Every engagement ships full as-built docs, runbooks and open-source automation (xshok-proxmox, 933★) so your team or any competent engineer can operate the result, and the architecture itself — HA, watchdog fencing, tested PBS restores — is built so most overnight events self-heal. For larger projects a named backup and escalation arrangement is available. The SLA is honest and tiered in SAST/CAT — business-hours response by default with priced after-hours cover — rather than a 24/7 promise a solo practice cannot truly staff.

You are not yet an Authorized Proxmox Partner — who provides my production subscriptions and vendor support?

Cleanly separated and stated up front: production Proxmox enterprise subscriptions and the vendor support SLA come direct from Proxmox or an authorized reseller, and this practice helps you procure them. What this practice bills is senior architecture, migration execution and an independent support retainer with its own SLA on top. Reseller and Training Partner authorization is actively being pursued; when it lands, subscriptions can be supplied directly and official courses move from partner-track to available.

There are already named SA Proxmox players — why you over an actual authorized partner like Rackzar or Summit?

Differentiation is senior engineering depth, not reseller status: 25+ years in production Linux, 50+ Proxmox clusters designed, built and migrated across the full lifecycle, and globally-used open-source tooling (1,841★, led by xshok-proxmox at 933★) — versus a box-shifter reading a datasheet. Production subscriptions and vendor SLA still come direct from Proxmox or an authorized reseller, and partner authorization is in progress. Where the contest is architecture, migration execution and a deep support retainer, the operator who has run this at scale beats the reseller.

If I leave VMware, do I just become locked into you instead?

No — independence from the consultant is an explicit deliverable. You receive open-source tooling, full automation, as-built docs, runbooks and team training across whichever products you run (VE, PBS, PMG, PDM). Everything is standard Proxmox, Ceph and ZFS with no proprietary layer, so you can take over day-2 operations or hire anyone else at any time.

Why does a firm use the domain proxmox.co.za, and does that expose me to risk?

The contracting entity and every deliverable are under a properly registered firm — AKMPRT (Pty) Ltd (reg 2019/206169/07) for South African engagements, and eXtremeSHOK / Adrian Kriel internationally — never a company called Proxmox. The domain is a descriptive landing page. The official Proxmox logo and the product screenshots shown here are used only under the Proxmox media-kit guidelines to identify the Proxmox software, remain the property of Proxmox Server Solutions GmbH, and never replace this site's own eXtremeSHOK / proxmox.co.za branding; the footer carries a full trademark, attribution and independence disclaimer. Your contract and continuity are with eXtremeSHOK and are unaffected by the domain. Authorized Partner status is being pursued as the long-term resolution.

Got the answers you needed? Scope your Proxmox project

Contact

Tell us what you need

Tell me what you are running and where you want to get to — server count, sites, the renewal clock, where your data must legally live. Send it through and I reply directly with a clear, honest read on whether a Proxmox move fits and scoped options you can take to procurement, security and legal — no open-ended sales call required. South African and African enquiries answered in your SAST/CAT business hours; remote/international clients welcome too.

  • A clear, honest read on whether a Proxmox move fits your estate — no hard sell
  • The hard cases named up front (Windows VirtIO, DB consistency, CBT limits, SDN cutover)
  • Indicative ZAR/USD bands and a path to a fixed-scope assessment that confirms the numbers
  • Enough detail to take to procurement, security and legal

Prefer email? hello@proxmox.co.za

Scope your Proxmox project