🐳

Infrastructure and networks

Self-hosted, private VPN networks, DevOps and monitoring

We move Notion, Zapier and Google Workspace onto the client's own servers — the company never loses access to its tools overnight, and data never leaves the perimeter. We build private VPN networks for teams and services. We set up auto-deploy, monitoring and backups — if something breaks, you find out from an alert within minutes, not from a customer complaint.

A separate line of work is censorship circumvention for business: an entry node in Russia, an exit node abroad, SNI-based routing and a custom client for Windows and Android that picks a live entry point by itself.

Problems clients bring

Typical situations and what we do about them.

The team lost access to work services

Because of regional restrictions Canva, Notion, Jira and AI tools stopped opening, and public workarounds break the security policy. We deploy a corporate gateway on the company's own servers: traffic is encrypted and access is split by role.

Websites and services share one server and get in each other's way

Editing one site can take down a neighboring service, and certificates are renewed by hand. We separate them into containers and docker networks behind a single entry nginx.

A VPN gets cut on the path between countries

A direct connection to an exit server abroad is filtered at the moment it is established. We build an entry node in Russia, a permanent tunnel between nodes and an exit node abroad, as in our own VPN service.

Who it is for

Types of clients we have already built this for.

What we build

Types of work in this area. Each links to a case where it is already done.

Corporate gateway for access to work services

The gateway runs on the company's Linux servers: Xray handles routing and encryption, nginx sits at the entrance. Access is split by employee role, and connecting takes one click. Corporate data stays inside the perimeter.

A server for several websites on Docker and nginx

A single entry nginx accepts HTTP and HTTPS and routes requests to the sites. Each site lives in its own container and its own docker network, and Let's Encrypt certificates renew themselves. The configuration is kept in a git repository.

Your own mail on your domain

A docker-mailserver container with Postfix, Dovecot, Rspamd and fail2ban receives and sends mail, and you read it in Roundcube or a mail client. We set up the DNS records: MX, SPF, DKIM, DMARC and PTR. Spam is not discarded but placed in the Junk folder.

VPN route: an entry node in Russia and an exit abroad

nginx on the entry node splits websites, the panel and the VPN by SNI on one port, and a permanent frp tunnel carries all traffic to the exit server. A separate Marzban node with VLESS Reality runs autonomously. A domain change is one command with no dropped sessions.

Voice, chat and streaming on your own server

A closed browser-based platform: SRT streaming, viewing over HLS and WebRTC, voice directly between participants (up to 10 people per channel), chats and access roles. Everything runs in Docker Compose, and a 90-day chat history sits in SQLite on your server.

VPN connection guides for staff and customers

Five static pages: Android, iPhone and iPad, Windows, macOS and Linux. They open in a Telegram Mini App from the bot, so a person with no experience doesn't have to write to support. No build step or server is needed for them.

What you get

What stays with the client after handover.

  • Infrastructure deployed in Docker: an entry nginx, containers and a separate docker network for each service
  • HTTPS certificates with automatic renewal and expiry checks
  • Nightly data backups
  • Container health checks and a Telegram message to the administrator on failure
  • Role-based access and traffic encryption
  • Step-by-step connection guides for staff, by platform
  • Configuration in a git repository; code and data stay with the client
  • A README written as a technical specification, a CHANGELOG and one month of free support after handover

How the work goes

From the first request to handover: at every step it is clear what happens next.

  1. 1

    Request and free audit

    We look at what runs now and where, which services are unavailable or get in each other's way, and which data must stay inside the perimeter. Before any estimate, you get a description of the task.

  2. 2

    Infrastructure design

    We decide which services go on which servers, how to split them into containers and networks, and who gets access with which role.

  3. 3

    Deployment in Docker

    We install the entry nginx, the service containers and HTTPS certificates with automatic renewal on the client's server or ours.

  4. 4

    Access and protection

    We set up access roles and traffic encryption, and for mail and SSH login we turn on brute-force protection (fail2ban).

  5. 5

    Backups and monitoring

    We enable nightly data snapshots, container health checks and alerts to the administrator about failures.

  6. 6

    Handover and support

    We hand over the configuration in a repository, a README written as a technical specification, a CHANGELOG and connection guides. Support is free for a month after handover.

Stack for this area

Docker Compose →
Each service and site runs in its own container and network, so one failure doesn't drag down its neighbors.
nginx →
A single entry point: it accepts HTTPS, checks access and passes the request to the right service.
certbot →
It issues free Let's Encrypt certificates and renews them by itself, with no site downtime.
Xray →
A proxy protocol core: it routes and encrypts the traffic of the corporate gateway and the VPN.
Marzban →
A panel where VPN users and subscriptions are created and traffic is tracked.
frp →
It keeps a permanent tunnel between nodes where a direct cross-border connection gets cut.

Pricing

Ballpark figures to understand the order of magnitude. Exact estimates come after the audit.

Access and mail
from $80
per setup

A corporate gateway for staff, your own mail on the domain with DKIM and SPF.

  • ✓Connection guides for staff — from $50
  • ✓VPN route with entry and exit in different countries — from $150
  • ✓Settings are documented
Voice, chat, streaming
from $650
per project

A communication server instead of Discord: voice rooms, chats, screen streaming.

  • ✓A service built for load with its own client — from $2,500
  • ✓Data does not leave for a third-party cloud
  • ✓Keeps working when public services are blocked

The audit and the proposal are free. No hourly billing: the price is fixed for the result, the exact figure comes in the proposal after the audit. Support after delivery starts at $100 a month, the first month is free. Timelines are individual and set once the specification is approved.

Cases in this area

5 projects — with the task, the solution and the numbers

In production · in-house product

Peregovorka (ToshaStream): streaming server and team voice chat

our own product in production, version 1.50.0: voice, chats and a private stream

In production · in-house product

VPN infrastructure: Russian entry node, European exit

our own product: a relay in Russia, a persistent tunnel and a node in the Netherlands

CompletedNDA

Corporate gateway on Xray and nginx for an IT team

for an IT company: work tools available again, on its own servers

In production · in-house product

A private server for several websites on Docker and nginx

our own product: site isolation, HTTPS, self-hosted mail and backups

In production · in-house product

VPN setup guides for Android, iPhone and desktop

open pages for a Telegram Mini App: five platforms, no build step, no dependencies

Frequently asked questions

How much does a server or VPN setup cost?
A corporate gateway or your own mail on the domain starts at $80, connection guides for staff at $50, a VPN route with entry and exit in different countries at $150. A server for websites on Docker and nginx with backups starts at $160, support at $100 a month. Your own voice, chat and streaming server starts at $650, a service built for load with its own client at $2,500. The exact figure comes in the proposal after a free audit; there is no hourly billing.
What is self-hosted and why does it matter?
It's a private cloud server owned only by the client: nobody can restrict access, shut down the service or peek at the data. Full control instead of someone else's “cloud” — but also full responsibility for setup and maintenance, which is usually what we do.
Do I need my own server for self-hosted solutions?
Not necessarily physical hardware — a VPS from a Russian or foreign provider works fine. We'll help you pick the right option for your budget and task, and set everything up turnkey.
How long does it take to set up a VPN network for a team?
A basic WireGuard setup for a team of up to 10 takes 1-2 days. Complex configurations (several sites, censorship circumvention, a custom client) take up to 5 business days, including instructions and team training.
Do you provide support after the project is delivered?
Yes. After handover — a month of free support. Then you can subscribe to ongoing maintenance: monitoring, updates, backups, fast response to issues.
How do I host several websites on one server so they don't interfere with each other?
One entry nginx accepts all requests, terminates TLS and routes them to the sites. Each site lives in its own container and its own docker network, so the sites cannot see each other. Databases are attached only to the internal networks of their own projects.
How do I restore a team's access to Canva, Notion, Jira and AI tools without public VPNs?
We deploy a corporate gateway on the company's servers: Xray and nginx run on Linux, traffic is encrypted and access is split by role. An employee connects in one click. Corporate data stays inside the perimeter instead of passing through public services.
Can I run mail on my own domain instead of at the host?
Yes. docker-mailserver with Postfix, Dovecot, Rspamd and fail2ban handles receiving and sending, and you read mail in Roundcube or any client. DNS records are required: MX, SPF, DKIM, DMARC and a PTR reverse record. On our own server the host blocks outgoing mail ports: receiving works, while outgoing messages wait in the queue until the route is opened.
What can be done if a VPN is blocked on the path from Russia abroad?
Measurements on 20 August 2026 showed 35–60% of TCP handshakes to our exit server were lost while ping had no loss. We replaced a connection per client with one permanent frp tunnel and split the domains into traffic, subscriptions and admin. The limit of the scheme: if all domains point to one IP address, a block by address takes them all down at once.
Can we run work calls and chats on our own server instead of a cloud messenger?
Yes. We built such a platform: three shared voice channels, calls, groups, screen sharing and chats with a 90-day history. Voice goes directly between participants and is encrypted between browsers, and the stream is delivered over SRT. It all works in the browser with no installation.
How do I avoid losing data on a server failure or being left without HTTPS?
certbot renews Let's Encrypt certificates on a timer, and a hook after renewal makes nginx reload the certificate without a restart. Nightly snapshots cover mail (kept for two weeks) and the database and files of some hosted sites. For the streaming service a separate machine pulls database snapshots and checks that they restore, and the administrator learns about a failure from a Telegram message.

Need something from “Infrastructure and networks”?

A short review is free: we'll look at the task and tell you what's worth doing and roughly for how much.