Advice shaped by running the systems.
RTFM d.o.o. is the independent practice of Matija Žeželj — an infrastructure and security engineer with more than twenty years of hands-on experience designing, scaling, and defending systems.
The work spans SecOps, Linux, cloud, CI/CD, vulnerability management, compliance, observability, and Kubernetes. Environments have ranged from homelabs to thousands of servers, hundreds of engineering repositories, large bare-metal clusters, and services handling serious traffic and data volumes. Current day-to-day work includes building security automation for a software organisation with more than 1,000 repositories.
The In a Box projects come directly out of that experience: understanding infrastructure, reducing security toil, and leaving teams with systems they can inspect and operate themselves.
Operating principles
Outcomes before components
Start with “what breaks if I change this?”, “what is being exploited?”, or “why is the service slow?” The container list comes second.
Opinionated, not opaque
Defaults should get you to a useful system quickly, but every file and trade-off stays available for inspection. A system you cannot understand is just a smaller vendor lock-in problem.
Local by default
Telemetry, asset graphs, identities, vulnerability findings, certificates, and compliance evidence stay on infrastructure you control. Cloud integrations are optional, never the price of entry.
Honest boundaries
This work reduces integration toil. It does not replace capacity planning, backups, threat modeling, incident responders, or knowing your environment. When a tool is an IDS rather than an inline IPS, the documentation says so.
Knowledge transfer is part of the deliverable
Documentation and handover are included in every engagement. A dependency on the consultant is a failure mode, not a business model.
Why “RTFM”
Because the manual is usually the thing nobody wrote. The engagements that go well are the ones that leave behind a written decision record, a runbook that matches reality, and evidence that recovery actually works — so the next person to touch the system has something to read.
If it cannot be understood when it fails at 3 AM, it is not finished.
Elsewhere
- In a Box Tools — product documentation, demos, and the project blog
- GitHub — source for the published blueprints
- LinkedIn — background and work history