01 Infrastructure & Systems

Arqonara Infrastructure & Fleet Operations

Designing, provisioning, and operating a multi-node Linux and Proxmox virtualization fleet for game and application hosting with automated provisioning and strict firewall isolation.

Role
Lead Infrastructure Engineer & Founder
Technologies
Linux (Debian/Ubuntu) · Proxmox VE · KVM · Docker · Bash · UFW Firewall · Cockpit
Key Result
7,800+ Discord Community Ecosystem · Multi-Node Hypervisor Cluster · Zero Unscheduled Outages on Core Nodes
Arqonara Infrastructure & Fleet Operations preview
Infrastructure & Systems Lead Infrastructure Engineer & Founder

Context & Overview

Arqonara Hosting runs VPS instances and game server nodes on hardware we own. What started as a single box at QuenssHost did not hold up: one kernel shared between customers meant one noisy neighbour could drag everyone down. Rebuilding on Proxmox VE gave each guest its own KVM slice with pinned CPU and fixed memory, and moved management ports off the public interface.

My Role & Responsibilities

As founder and principal infrastructure operator, I am responsible for:

  • Sourcing bare-metal dedicated servers and provisioning custom Linux base images.
  • Designing and configuring hypervisor topology using Proxmox VE and KVM.
  • Securing host access, configuring basic firewall rules (UFW), and isolating service ports.
  • Implementing scripted server provisioning to reduce deployment time from hours to under five minutes.
  • Overseeing day-to-day capacity planning, kernel tuning, and disk I/O scheduling.

The Problem & Operational Challenges

Managing gaming workloads presents unique operational constraints:

  • Bursty CPU & Memory Pressure: Game runtime processes frequently spike CPU cores and consume volatile heap memory, causing starvation for neighboring containers if not bounded strictly.
  • DDoS Exposure & Host Security: Public gaming endpoints are constant targets for volumetric floods and port scans.
  • Manual Overhead: Manual configuration of virtual machines, port forwards, and access permissions led to operational fatigue and delayed client deliveries.

Architectural Approach & Engineering Decisions

  1. Bare-Metal Virtualization with KVM & Proxmox VE: Migrated from unconstrained shared containers to hardware-isolated KVM slices for compute-heavy clients, ensuring strict CPU pinning and guaranteed memory ballooning controls.
  2. Access Control & Port Isolation: Applied standard firewall policies with UFW and isolated management ports (SSH, Proxmox web interface) from public gaming ports.
  3. Automated Shell Provisioning: Authored modular Bash routines for automated OS installation, baseline hardening (fail2ban, SSH key-only auth, sysctl TCP buffer optimization), and template deployment.

The Machines

Arqonara runs on dedicated bare-metal servers we own and operate ourselves — not rented panels or resold capacity. Game hosting and VPS hosting share the same physical fleet.

NodeRoleCPUMemoryStorage
Node 01Game hosting + VPSNVMe
Node 02Game hosting + VPSNVMe

Each machine runs Debian with Proxmox VE on top, so every guest gets its own KVM slice instead of sharing one kernel with strangers.

Measurable Outcomes & Limitations

  • Scalability: Fleet comfortably powers infrastructure for an active community of over 7,800 Discord members.
  • Zero Loss Operations: Eliminated catastrophic cross-tenant memory leakage through strict cgroup and hypervisor quotas.
  • Deployment Velocity: Automated orchestration reduced routine node provisioning time from 45 minutes to under 5 minutes.
  • Honest Limitations: DDoS defense remains bounded by upstream data center transit capacity; Layer 7 application mitigation requires ongoing heuristic adjustments for novel traffic patterns.

Technologies Used

  • Operating Systems: Debian 12 (Bookworm), Ubuntu Server LTS
  • Hypervisor: Proxmox Virtual Environment, QEMU/KVM
  • Isolation: Docker Engine, Linux Namespaces, Cgroups v2
  • Networking: iptables, UFW, Bridge Interfaces, VLANs
  • Tooling: Bash Shell, Systemd, Cockpit Console